A strategy analysis method, device, equipment and readable storage medium
By performing asset fingerprint analysis and firewall policy similarity calculation on IPv4 and IPv6 address sets, the problem of inconsistent protection policies during the IPv4 and IPv6 transition period was solved, reducing the risk of security attacks and improving the security of protection devices.
Patent Information
- Application Number
- CN202110778964.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-07-09
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2041-07-09
AI Technical Summary
During the transition from IPv4 to IPv6, the dual-stack protection strategies of firewalls and gateways suffer from inconsistencies and gaps, leading to increased security risks.
By obtaining sets of IPv4 and IPv6 addresses, asset fingerprint information analysis is performed to form IP address pairs. The similarity of firewall protection policies is then calculated, and policies are adjusted based on the similarity to ensure policy consistency.
It reduces the risk of security attacks on firewalls and gateways during the transition from IPv4 to IPv6 dual-stack, and improves the effectiveness of security protection by identifying and adjusting inconsistent or missing protection policies.
Smart Images

Figure CN115603931B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, and in particular to a policy analysis method and device, equipment and a readable storage medium. BACKGROUND
[0002] An IP address is an important basic resource for communication network construction. The IPv6 (Internet Protocol Version 6) protocol is a next-generation IP protocol used to replace the IPv4 (Internet Protocol Version 4) protocol. The IPv6 can effectively solve the problem of insufficient IPv4 addresses by extending the address length to 128 bits.
[0003] In the popularization process of the IPv6, most of the schemes are gradually transitioned from the IPv4 to the IPv6. The specific schemes include a dual stack, a tunnel, a translation and the like. Among them, the proportion of the dual stack scheme of the IPv4 and the IPv6 is relatively large, which brings the security risk of the corresponding transition mechanism, that is, there is a security risk of the dual stack configuration during the transition period of the implementation of the IPv4 and the IPv6.
[0004] Specifically, the network deployed with the dual stack during the transition period simultaneously runs two logical channels of the IPv4 and the IPv6, which increases the exposure surface of the device and the system. Accordingly, the device and the system need to be configured with the dual stack protection policy. In addition, it also means that the protection device such as the firewall and the security gateway needs to be configured with the dual stack policy, thereby increasing the complexity of the policy management and increasing the opportunity of the penetration of the security protection.
[0005] The dual stack protection policy of the IPv4 and the IPv6 has the following two problems in the dual stack protection policy of the protection device such as the firewall and the gateway: first, the inconsistency of the protection policy; and second, the lack or the leakage of the protection policy. Therefore, further other security problems are caused, for example, an attacker launches an attack to break into an enterprise intranet or an operator network.
[0006] Therefore, the dual stack protection policy of the protection device such as the firewall and the gateway needs a corresponding analysis and early warning mechanism to facilitate the timely discovery of the problems of the dual stack protection policy of the IPv4 and the IPv6, and further to better improve and reinforce the security protection policy to reduce the risk of the security attack. SUMMARY
[0007] The embodiments of the present application provide a policy analysis method, device, equipment and readable storage medium to reduce the risk of the security attack.
[0008] In a first aspect, the embodiments of the present application provide a policy analysis method, comprising:
[0009] obtain an IPv4 address set and an IPv6 address set respectively;
[0010] perform asset fingerprint information analysis on the IPv4 address set and the IPv6 address set to obtain a to-be-processed IP address set; wherein the to-be-processed IP address set includes at least one IP address pair, the IP address pair includes an IPv4 address and an IPv6 address, and asset fingerprint information corresponding to the IPv4 address in each IP address pair is completely identical or partially identical to asset fingerprint information corresponding to the IPv6 address;
[0011] for any first IP address pair in the IP address pair, obtain a first firewall protection policy corresponding to a first IPv4 address in the first IP address pair and a second firewall protection policy corresponding to a first IPv6 address in the first IP address pair;
[0012] determine the similarity between the first firewall protection policy and the second firewall protection policy;
[0013] obtain an adjustment policy based on the similarity.
[0014] wherein the asset fingerprint information analysis on the IPv4 address set and the IPv6 address set to obtain the to-be-processed IP address set comprises:
[0015] obtain a first multi-tuple of each IPv4 address in the IPv4 address set and a second multi-tuple of each IPv6 address in the IPv6 address set respectively;
[0016] for any target IPv4 address, when all or part of the elements of the first multi-tuple of the target IPv4 address are identical to all or part of the elements of the second multi-tuple of a target IPv6 address, form an IP address pair using the target IPv4 address and the target IPv6 address;
[0017] form the to-be-processed IP address set using the obtained multiple IP address pairs;
[0018] wherein the multi-tuple includes OS (Operating System) information, port number, port information, service information, service version information, and host name information.
[0019] wherein the firewall protection policy includes the following information: source IP address, source port number, destination IP address, destination port number, and action information.
[0020] the determination of the similarity between the first firewall protection policy and the second firewall protection policy comprises:
[0021] respectively, to obtain a plurality of text similarities;
[0022] an average of the obtained plurality of text similarities is calculated, and the average is taken as the similarity between the first firewall protection policy and the second firewall protection policy.
[0023] The firewall protection policy includes the following information: source IP address, source port number, destination IP address, destination port number, and action information.
[0024] The determination of the similarity between the first firewall protection policy and the second firewall protection policy includes:
[0025] A first policy graph is formed according to the first firewall protection policy.
[0026] A second policy graph is formed according to the second firewall protection policy.
[0027] The similarity between the first policy graph and the second policy graph is taken as the similarity between the first firewall protection policy and the second firewall protection policy.
[0028] The policy graph is formed in the following manner:
[0029] The source IP address and the destination IP address in the firewall protection policy are respectively taken as different points.
[0030] The source port number in the firewall protection policy is taken as the vertex of a first angle, and the destination port number in the firewall protection policy is taken as the vertex of a second angle, wherein different port numbers correspond to different angles.
[0031] The action information in the firewall protection policy is taken as the vertex of a third angle.
[0032] The policy graph is formed using the points, the first angle, the second angle, and the third angle.
[0033] When the first firewall protection policy and the second firewall protection policy are one, the adjustment policy is obtained based on the similarity, which includes:
[0034] When the similarity is greater than or equal to a similarity threshold, it is determined that the first firewall protection policy and the second firewall protection policy are consistent, and no policy adjustment is needed.
[0035] When the similarity is less than the similarity threshold, it is determined that the first firewall protection policy and the second firewall protection policy are inconsistent, and the first firewall protection policy and the second firewall protection policy are adjusted to be consistent.
[0036] When the first firewall protection policy is multiple or the second firewall protection policy is multiple, the determining of the similarity between the first firewall protection policy and the second firewall protection policy comprises:
[0037] For any first firewall protection policy in the multiple first firewall protection policies, the similarity between the first firewall protection policy and each second firewall protection policy is determined, and multiple similarities are obtained.
[0038] The obtaining of the adjustment policy based on the similarity comprises:
[0039] When the multiple similarities are all greater than or equal to the similarity threshold, it is determined that the first firewall protection policy and the second firewall protection policy are consistent, and no policy adjustment is needed.
[0040] When one or more of the multiple similarities is less than the similarity threshold, it is determined that the first firewall protection policy and the second firewall protection policy are inconsistent, and the first firewall protection policy and the second firewall protection policy are adjusted to be consistent.
[0041] In a second aspect, the embodiments of the present application further provide a policy analysis device, comprising:
[0042] A first obtaining module is configured to obtain an IPv4 address set and an IPv6 address set respectively.
[0043] A second obtaining module is configured to perform asset fingerprint information analysis on the IPv4 address set and the IPv6 address set to obtain a to-be-processed IP address set, wherein the to-be-processed IP address set comprises at least one IP address pair, the IP address pair comprises an IPv4 address and an IPv6 address, and asset fingerprint information corresponding to the IPv4 address in each IP address pair is completely identical or partially identical to asset fingerprint information corresponding to the IPv6 address.
[0044] A third obtaining module is configured to, for any first IP address pair in the IP address pair, obtain a first firewall protection policy corresponding to a first IPv4 address in the first IP address pair and a second firewall protection policy corresponding to a first IPv6 address in the first IP address pair.
[0045] A first determining module is configured to determine a similarity between the first firewall protection policy and the second firewall protection policy.
[0046] The fourth obtaining module is configured to obtain an adjustment strategy based on the similarity.
[0047] The second obtaining module includes:
[0048] The first obtaining sub-module is configured to obtain a first multi-tuple of each IPv4 address in the IPv4 address set and a second multi-tuple of each IPv6 address in the IPv6 address set respectively.
[0049] The second obtaining sub-module is configured to, for any target IPv4 address, form an IP address pair by using the target IPv4 address and a target IPv6 address when all or part of elements of the first multi-tuple of the target IPv4 address are the same as all or part of elements of the second multi-tuple of the target IPv6 address.
[0050] The third obtaining sub-module is configured to form the to-be-processed IP address set by using the obtained plurality of IP address pairs.
[0051] The multi-tuple includes operating system (OS) information, a port number, port information, service information, service version information, and host name information.
[0052] The firewall protection strategy includes the following information: a source IP address, a source port number, a destination IP address, a destination port number, and action information.
[0053] The first determining module includes:
[0054] The first calculating sub-module is configured to calculate a text similarity between each element in the first firewall strategy and a corresponding element in the second firewall strategy respectively to obtain a plurality of text similarities.
[0055] The first determining sub-module is configured to determine a similarity between the first firewall protection strategy and the second firewall protection strategy according to the plurality of text similarities.
[0056] The first firewall protection strategy includes the following information: a source IP address, a source port number, a destination IP address, a destination port number, and action information.
[0057] The first determining module includes:
[0058] The first obtaining sub-module is configured to form a first strategy graph according to the first firewall protection strategy.
[0059] The second obtaining sub-module is configured to form a second strategy graph according to the second firewall protection strategy.
[0060] The first determining sub-module is configured to determine the similarity between the first firewall protection policy and the second firewall protection policy as the similarity between the first policy graph and the second policy graph.
[0061] The policy graph is formed in the following manner:
[0062] The source IP address and the destination IP address in the firewall protection policy are taken as different points.
[0063] The source port number in the firewall protection policy is taken as the vertex of a first angle, and the destination port number in the firewall protection policy is taken as the vertex of a second angle, wherein different port numbers correspond to different angles.
[0064] The action information in the firewall protection policy is taken as the vertex of a third angle.
[0065] The policy graph is formed by using the points, the first angle, the second angle and the third angle.
[0066] The fourth obtaining module comprises:
[0067] The first obtaining sub-module is configured to, when the first firewall protection policy and the second firewall protection policy are one, if the similarity is greater than or equal to a similarity threshold, determine that the first firewall protection policy and the second firewall protection policy are consistent, and no policy adjustment is needed.
[0068] The second obtaining sub-module is configured to, when the similarity is less than the similarity threshold, determine that the first firewall protection policy and the second firewall protection policy are inconsistent, and adjust the first firewall protection policy and the second firewall protection policy to be consistent.
[0069] The first determining module is configured to, when the first firewall protection policy is multiple or the second firewall protection policy is multiple, for any first firewall protection policy in the multiple first firewall protection policies, determine the similarity between the first firewall protection policy and each second firewall protection policy, and obtain multiple similarities.
[0070] The fourth obtaining module comprises:
[0071] The third obtaining sub-module is configured to, when the first firewall protection policy is multiple or the second firewall protection policy is multiple, if the multiple similarities are all greater than or equal to a similarity threshold, determine that the first firewall protection policy and the second firewall protection policy are consistent, and no policy adjustment is needed.
[0072] The fourth obtaining sub-module is configured to determine that the first firewall protection policy and the second firewall protection policy are inconsistent and adjust the first firewall protection policy and the second firewall protection policy to be consistent when one or more of the plurality of similarities is less than the similarity threshold.
[0073] In a third aspect, the embodiments of the present application further provide a policy analysis device, comprising a processor and a transceiver.
[0074] The processor is configured to:
[0075] Obtain an IPv4 address set and an IPv6 address set respectively;
[0076] Perform asset fingerprint information analysis on the IPv4 address set and the IPv6 address set to obtain a to-be-processed IP address set; wherein the to-be-processed IP address set comprises at least one IP address pair, the IP address pair comprises an IPv4 address and an IPv6 address, and asset fingerprint information corresponding to the IPv4 address in each IP address pair is completely identical or partially identical to asset fingerprint information corresponding to the IPv6 address;
[0077] For any first IP address pair in the IP address pair, obtain a first firewall protection policy corresponding to a first IPv4 address in the first IP address pair and a second firewall protection policy corresponding to a first IPv6 address in the first IP address pair;
[0078] Determine a similarity between the first firewall protection policy and the second firewall protection policy;
[0079] Obtain an adjustment policy based on the similarity.
[0080] The processor is configured to:
[0081] Obtain a first multi-tuple of each IPv4 address in the IPv4 address set and a second multi-tuple of each IPv6 address in the IPv6 address set respectively;
[0082] For any target IPv4 address, when all or part of elements of the first multi-tuple of the target IPv4 address are identical to all or part of elements of the second multi-tuple of a target IPv6 address, form an IP address pair by using the target IPv4 address and the target IPv6 address;
[0083] Form the to-be-processed IP address set by using the obtained plurality of IP address pairs;
[0084] The multi-tuple comprises operating system (OS) information, a port number, port information, service information, service version information, and host name information.
[0085] The firewall protection policy includes the following information: source IP address, source port number, destination IP address, destination port number, and action information; and the processor is configured to:
[0086] Calculate the text similarity between each element in the first firewall policy and the corresponding element in the second firewall policy, respectively, to obtain a plurality of text similarities;
[0087] According to the plurality of text similarities, determine the similarity between the first firewall protection policy and the second firewall protection policy.
[0088] The firewall protection policy includes the following information: source IP address, source port number, destination IP address, destination port number, and action information; and the processor is configured to:
[0089] Form a first policy graph according to the first firewall protection policy;
[0090] Form a second policy graph according to the second firewall protection policy;
[0091] Take the similarity between the first policy graph and the second policy graph as the similarity between the first firewall protection policy and the second firewall protection policy.
[0092] The processor is configured to form a policy graph in the following manner:
[0093] Take the source IP address and the destination IP address in the firewall protection policy as different points, respectively;
[0094] Take the source port number in the firewall protection policy as the vertex of a first angle, and take the destination port number in the firewall protection policy as the vertex of a second angle, wherein different port numbers correspond to different angles;
[0095] Take the action information in the firewall protection policy as the vertex of a third angle;
[0096] Form a policy graph using the points, the first angle, the second angle, and the third angle.
[0097] The processor is configured to:
[0098] When the first firewall protection policy and the second firewall protection policy are one, if the similarity is greater than or equal to a similarity threshold, it is determined that the first firewall protection policy and the second firewall protection policy are consistent, and no policy adjustment is needed;
[0099] determining that the first firewall protection policy and the second firewall protection policy are inconsistent when the similarity is less than the similarity threshold, and adjusting the first firewall protection policy and the second firewall protection policy to be consistent.
[0100] The processor is configured to: when the first firewall protection policy is multiple or the second firewall protection policy is multiple,
[0101] For any first firewall protection policy in the multiple first firewall protection policies, determine the similarity between the first firewall protection policy and each second firewall protection policy, to obtain multiple similarities.
[0102] When the first firewall protection policy is multiple or the second firewall protection policy is multiple, if the multiple similarities are all greater than or equal to a similarity threshold, it is determined that the first firewall protection policy and the second firewall protection policy are consistent, and no policy adjustment is needed.
[0103] When one or more of the multiple similarities is less than the similarity threshold, it is determined that the first firewall protection policy and the second firewall protection policy are inconsistent, and the first firewall protection policy and the second firewall protection policy are adjusted to be consistent.
[0104] In a fourth aspect, an embodiment of the present application further provides a communication device, comprising a memory, a processor, and a program stored in the memory and executable on the processor, and the processor implements the steps in the policy analysis method as described above when executing the program.
[0105] In a fifth aspect, an embodiment of the present application further provides a readable storage medium, the readable storage medium stores a program, and the program is executable on a processor to implement the steps in the policy analysis method as described above.
[0106] In the embodiment of the present application, the obtained IPv4 address set and IPv6 address set are analyzed for asset fingerprint information, and a to-be-processed IP address set is obtained. The similarity between the firewall protection policies corresponding to the IPv4 address and the IPv6 address of the IP address pair of the obtained to-be-processed IP address set is calculated, so that the adjustment policy can be determined according to the similarity. Therefore, by using the scheme of the embodiment of the present application, the dual-stack protection policy of the firewall, gateway, and other protection devices can be analyzed, and the missing or inconsistent problems in the policy can be found, thereby reducing the risk of security attacks. BRIEF DESCRIPTION OF DRAWINGS
[0107] Figure 1 is one of the flowcharts of the policy analysis method provided by the embodiment of the present application;
[0108] Figure 2is a schematic diagram of a policy analysis system provided by an embodiment of the present application;
[0109] Figure 3(a) is a flowchart of a policy analysis method provided by an embodiment of the present application;
[0110] Figure 3(b) is a flowchart of a policy analysis method provided by an embodiment of the present application;
[0111] Figure 4 is a structural diagram of a policy analysis device provided by an embodiment of the present application;
[0112] Figure 5 is a structural diagram of a policy analysis device provided by an embodiment of the present application;
[0113] Figure 6 is a structural diagram of a policy analysis device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0114] In the embodiments of the present application, the term "and / or" describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can represent the following three cases: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after it.
[0115] In the embodiments of the present application, the term "a plurality of" means two or more, and other quantifiers are similar.
[0116] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of the present application.
[0117] Referring to Figure 1 , Figure 1 is a flowchart of a policy analysis method provided by an embodiment of the present application, as shown in Figure 1 , comprising the following steps:
[0118] Step 101, respectively acquiring an IPv4 address set and an IPv6 address set.
[0119] The IPv4 address set and the IPv6 address set can be an IPv4 address segment and an IPv6 address segment respectively, and can include one or more IPv4 addresses and IPv6 addresses respectively. In actual application, the IPv4 address set and the IPv6 address set can be directly acquired according to the address segment of an institution or administrative region, or the address segment of a park.
[0120] Step 102, performing asset fingerprint information analysis on the IPv4 address set and the IPv6 address set to obtain a to-be-processed IP address set.
[0121] The to-be-processed IP address set includes at least one IP address pair, and the IP address pair includes an IPv4 address and an IPv6 address. The asset fingerprint information corresponding to the IPv4 address in each IP address pair is completely identical or partially identical to the asset fingerprint information corresponding to the IPv6 address.
[0122] The asset fingerprint information can be obtained in the form of nmap, get, telnet, etc. The extracted asset fingerprint information includes but is not limited to OS (Operating System) information, a port number, port information, service information, service version information, and hostname information, and is recorded as a multi-tuple, for example, [OS|port number|port|service name|service version|hostname].
[0123] Specifically, in this step, a first multi-tuple of each IPv4 address in the IPv4 address set and a second multi-tuple of each IPv6 address in the IPv6 address set are obtained. For any target IPv4 address, when all or part of the elements of the first multi-tuple of the target IPv4 address are identical to all or part of the elements of the second multi-tuple of a target IPv6 address, an IP address pair is formed by using the target IPv4 address and the target IPv6 address. Then, the to-be-processed IP address set can be formed by using the obtained IP address pairs. The target IPv4 address can be any IPv4 address, and the target IPv6 address can also be any IPv6 address.
[0124] Each multi-tuple includes OS information, a port number, port information, service information, service version information, and hostname information.
[0125] Here, completely identical means that all elements in the multi-tuple are identical; partially identical means that part of the elements in the multi-tuple are identical. When comparing, a text comparison method can be used, or a character comparison method or other comparison methods can be used. For example, if the elements in the multi-tuple of an IPv4 address and the multi-tuple of an IPv6 address are all identical, the asset fingerprint information is considered to be completely identical; if the OS information in the multi-tuple of an IPv4 address and the multi-tuple of an IPv6 address is identical, the asset fingerprint information is considered to be partially identical.
[0126] Step 103, for any first IP address pair in the IP address pairs, obtaining a first firewall protection policy corresponding to a first IPv4 address in the first IP address pair and a second firewall protection policy corresponding to a first IPv6 address in the first IP address pair.
[0127] For the first IPv4 address, all corresponding firewall protection policies in the firewall are extracted as the first firewall protection policy; for the first IPv6 address, all corresponding firewall protection policies in the firewall are extracted as the second firewall protection policy. Here, the obtained first firewall protection policy can be one or more, and the second firewall protection policy can also be one or more.
[0128] Specifically, the obtained firewall protection policy can be recorded in the form as follows, including but not limited to policy quintuple [srcIP, srcPort, dstIP, dstPort, Action], the elements in the policy quintuple respectively represent source IP address, source port number, destination IP address, destination port number and action information.
[0129] Step 104, determining the similarity between the first firewall protection policy and the second firewall protection policy.
[0130] In this step, text similarity calculation method or graph-based similarity calculation method can be used to calculate the similarity.
[0131] Specifically, when the text similarity calculation method is used, the text similarity between each element in the first firewall policy and the corresponding element in the second firewall policy can be calculated respectively to obtain a plurality of text similarities, and then the similarity between the first firewall protection policy and the second firewall protection policy is determined according to the plurality of text similarities.
[0132] Wherein, each firewall protection policy can include the following information: source IP address, source port number, destination IP address, destination port number and action information.
[0133] The "corresponding element" can be understood as follows: the corresponding element of the source IP address of the first firewall protection policy is the source IP address of the second firewall protection policy; the corresponding element of the source port number of the first firewall protection policy is the source port number of the second firewall protection policy; the corresponding element of the destination IP address of the first firewall protection policy is the destination IP address of the second firewall protection policy; the corresponding element of the destination port number of the first firewall protection policy is the destination port number of the second firewall protection policy; and the action information of the destination port number of the first firewall protection policy is the destination action information of the second firewall protection policy.
[0134] In the calculation of the similarity between the first firewall protection policy and the second firewall protection policy according to multiple text similarities, the average of the multiple text similarities can be taken as the similarity between the first firewall protection policy and the second firewall protection policy, or each text similarity can be multiplied by a corresponding weight value, and then the multiple products obtained are added to obtain the similarity between the first firewall protection policy and the second firewall protection policy. Of course, other ways can also be used to determine the similarity between the first firewall protection policy and the second firewall protection policy, which is not limited in the embodiments of the present application.
[0135] Taking the [srcIP, srcPort, dstIP, dstPort, Action] policy quintuple as an example, each element in the quintuple is taken as a text in the calculation of the text similarity, and then the corresponding elements are compared to calculate the text similarity of the firewall protection policies corresponding to the IPv4 and IPv6 pairs.
[0136] In the embodiments of the present application, the similarity between the first firewall protection policy and the second firewall protection policy can also be determined based on the similarity of the graph.
[0137] Specifically, taking the [srcIP, srcPort, dstIP, dstPort, Action] policy quintuple as an example, the obtained firewall protection policy is converted into a graph form according to the following rules:
[0138] The source IP address and the destination IP address in the firewall protection policy are taken as different points, that is, the source IP address and the destination IP address correspond to different points.
[0139] The source port number in the firewall protection policy is taken as the vertex of the first angle, and the destination port number in the firewall protection policy is taken as the vertex of the second angle, wherein different port numbers correspond to different angles; the corresponding relationship between the port number and the angle can be set as needed.
[0140] The action information in the firewall protection policy is taken as the vertex of a third angle. The action information can include approval and rejection, etc. Different action information can correspond to different angles, and the correspondence between them can be set as needed.
[0141] The point, the first angle, the second angle and the third angle are used to form a policy graph. For example, the point, the vertex of the first angle, the vertex of the second angle and the vertex of the third angle can be connected in turn to form a graph.
[0142] Then, according to the above rules, in this step, a first policy graph can be formed according to the first firewall protection policy and a second policy graph can be formed according to the second firewall protection policy. Then, the similarity between the first policy graph and the second policy graph is taken as the similarity between the first firewall protection policy and the second firewall protection policy. When calculating the similarity between the two policy graphs, the similarity can be determined according to the radian, direction of the arc formed by each line in the graph, and the size of each angle in the graph. For example, the average of the similarity of the lines in the graph and the similarity between the angles can be taken as the similarity between the two measurement graphs.
[0143] In actual application, there can be multiple first firewall protection policies and multiple second firewall protection policies. Then, for each first firewall policy, the similarity with each second firewall policy can be calculated according to the above method.
[0144] Step 105, obtaining an adjustment policy based on the similarity.
[0145] When the first firewall protection policy and the second firewall protection policy are one, if the similarity is greater than or equal to a similarity threshold, it is determined that the first firewall protection policy and the second firewall protection policy are consistent, and no policy adjustment is needed; when the similarity is less than the similarity threshold, it is determined that the first firewall protection policy and the second firewall protection policy are inconsistent, and the first firewall protection policy and the second firewall protection policy are adjusted to be consistent. The adjustment policy can be a policy that adjusts the first firewall protection policy and the second firewall protection policy to be consistent. For example, the first firewall protection policy or the second firewall protection policy can be used as the firewall protection policy corresponding to the first IPv4 address and the first IPv6 address, or other consistent firewall protection policies can be determined for the first IPv4 address and the first IPv6 address.
[0146] The similarity threshold can be set as needed, for example, it can be set to 100%, 99%, 95%, etc.
[0147] As mentioned earlier, in practical applications, there may be multiple first firewall protection policies or multiple second firewall protection policies. Therefore, for each first firewall policy, the similarity between it and each second firewall policy can be calculated using the method described above.
[0148] Therefore, the similarity between each first firewall policy and each second firewall policy can be calculated using the above method, thus obtaining multiple similarity scores. In step 105, only when multiple similarity scores are greater than or equal to the similarity threshold is it determined that the firewall protection policies corresponding to the first IPv4 address and the first IPv6 address are consistent, and no policy adjustment is required; otherwise, when one or more of the multiple similarity scores are less than the similarity threshold, it is determined that the firewall protection policies corresponding to the first IPv4 address and the first IPv6 address are inconsistent, and the first firewall protection policy and the second firewall protection policy are adjusted to be consistent.
[0149] In this embodiment, asset fingerprint information analysis is performed on the obtained IPv4 address set and IPv6 address set to obtain a set of IP addresses to be processed. The similarity between the firewall protection policies corresponding to the IPv4 and IPv6 addresses of the obtained IP address pairs in the set of IP addresses to be processed is calculated, thereby determining the adjustment policy based on the similarity. Therefore, using the solution of this embodiment, the dual-stack protection policies of firewalls, gateways, and other protection devices can be analyzed, thereby discovering missing or inconsistent issues in the policies and reducing the risk of security attacks.
[0150] like Figure 2 The diagram shown is a schematic of a policy analysis system according to an embodiment of this application. The system includes: a terminal node 201 with both IPv6 and IPv4 addresses, a router 202, and a firewall component 203. The terminal node component with both IPv6 and IPv4 addresses can be various networked devices such as laptops, desktops, IoT devices, and industrial internet devices. It implements IPv6 through a dual-stack approach, possessing both IPv4 and IPv6 addresses. The router component consists of various routers in the network's routing path. There can be one or multiple routers. The router ensures network reachability for the terminal devices. The firewall component is a network security protection device. It implements various security protections for the network, promptly detects and handles potential security risks and data transmission problems during network operation, including isolation and protection measures. It can also record and detect various operations within the network security framework to ensure the security of network operation.
[0151] Referring to Figure 3(a), which is a flowchart of the strategy analysis method provided in the embodiment of this application, as shown in Figure 3(a), the method includes the following steps:
[0152] Step 301, obtaining an IPv4 address set and an IPv6 address set.
[0153] In actual application, the IPv4 address set and the IPv6 address set can be directly obtained according to the address segment of an organization or an administrative region, or the address segment of a park.
[0154] Step 302, performing asset fingerprint information on the IPv4 address set and the IPv6 address set.
[0155] Specifically, the asset fingerprint information of the IPv4 address set and the IPv6 address set can be obtained by nmap, get, telnet and the like.
[0156] Step 303, comparing the asset fingerprint information to obtain a set of IP addresses to be processed.
[0157] The asset fingerprint information in step 302 includes but is not limited to OS information, banner information, hostname information and the like, and is recorded as a multi-tuple such as [OS|banner|hostname].
[0158] Suppose the obtained asset fingerprint information includes OS information, port number, port information, service information, service version information and hostname information, and is recorded as a multi-tuple of [OS|port number|port|service name|service version|hostname].
[0159] When comparing the asset fingerprint information, the comparison is actually a comparison of the above multi-tuple. The comparison method here can be a text comparison method, a character comparison method or other comparison methods. Through the comparison of the asset fingerprint information, one or more IP address pairs can be determined, each IP address pair including an IPv4 address and an IPv6 address. The asset fingerprint information corresponding to the IPv4 address in each IP address pair is completely identical or partially identical to the asset fingerprint information corresponding to the IPv6 address.
[0160] Here, the asset fingerprint information is completely identical, which means that the asset fingerprint information of the IPv4 address and the IPv6 address is identical only when the information in the multi-tuple of [OS|port number|port|service name|service version|hostname] of the IPv4 address and the IPv6 address is completely identical. The OS information in the multi-tuple of the IPv4 address and the multi-tuple of the IPv6 address is identical, which means that the asset fingerprint information is partially identical.
[0161] Through the above comparison, the IPv4 address and the IPv6 address with the same asset fingerprint information can be obtained, and the IPv4 address and the IPv6 address are taken as an IP address pair.
[0162] Step 304: For the IP address pair in the set of IP addresses to be processed, the firewall protection policy corresponding to the IPv4 address in each IP address pair and the firewall protection policy corresponding to the IPv6 address are extracted.
[0163] For example, all corresponding firewall protection policies can be extracted in the firewall. Specifically, the firewall protection policy is recorded in the form of, but not limited to, a policy quintuple [srcIP, srcPort, dstIP, dstPort, Action]. The elements in the policy quintuple represent the source IP address, the source port number, the destination IP address, the destination port number, and the action information, respectively.
[0164] Step 305: The firewall protection policies corresponding to the IPv4 address and the IPv6 address in each IP address pair are compared, and the similarity is calculated.
[0165] The similarity calculation method of the firewall protection policy can be a text similarity calculation method or a graph-based similarity calculation method.
[0166] Specifically, taking the policy quintuple [srcIP, srcPort, dstIP, dstPort, Action] as an example, the text similarity calculation is to take the elements in the policy quintuple as texts, and then compare the corresponding elements to calculate the similarity between the firewall protection policies corresponding to the IPv4 and IPv6 address pairs.
[0167] For the five elements in the policy quintuple, five similarities can be obtained before calculating the similarity of the corresponding elements. Then, in this case, the average of the five similarities can be taken as the final text similarity. Of course, the final text similarity can also be obtained through other ways through the five similarities.
[0168] The graph-based similarity calculation is to convert the policy quintuple [srcIP, srcPort, dstIP, dstPort, Action] corresponding to the IPv4 address and the IPv6 address into a corresponding graph according to a certain rule, and then directly compare the similarity of the graphs.
[0169] Specifically, the elements srcIP and dstIP of the policy quintuple are mapped to the points. The elements srcPort and dstPort of the policy quintuple are mapped to the vertices of the angles, respectively, and the angles are formed. Different ports are mapped to different angles, and the relationship between the ports and the angles can be set by the user. The element Action of the policy quintuple is mapped to the vertices of the angles, and the angles are formed. Different Actions are mapped to different angles, and the specific correspondence between the angles and the Actions can be set by the user. After the graph is obtained, the similarity of the graph can be calculated.
[0170] Step 306, the similarity and the similarity threshold are compared.
[0171] When the similarity is greater than or equal to the similarity threshold m, step 307 is performed; otherwise, step 308 is performed. The similarity threshold m here can be set according to the situation, which can be set to 100%, or can be set to 99%, 95%, etc. according to the situation.
[0172] Step 307, if the similarity is greater than or equal to m, it is determined that the firewall protection policies of the IPv4 address and the IPv6 address in the IP address pair are consistent.
[0173] Step 308, if the similarity is less than m, it is determined that the firewall protection policies of the IPv4 address and the IPv6 address in the IP address pair are inconsistent.
[0174] Step 309, the firewall protection policy reinforcement and improvement strategy is obtained.
[0175] For the firewall protection policies of the IPv4 and IPv6 address pair that are inconsistent, the corresponding firewall protection policy reinforcement and improvement suggestions are given. For example, the firewall protection policy corresponding to the IPv4 address or the firewall protection policy corresponding to the IPv6 address can be used as the firewall protection policy, or other consistent firewall protection policies for the IPv4 address and the IPv6 address can be determined.
[0176] Referring to FIG. 3(b), FIG. 3(b) is a flowchart of the policy analysis method provided by the embodiment of the present application, as shown in FIG. 3(b), including the following steps:
[0177] Steps 3011-3105, the description of steps 3011-3015 can refer to the description of the foregoing steps 301-305.
[0178] The difference is that in step 3105, the firewall protection policy corresponding to the IPv4 address or the IPv6 address in the IP address pair is multiple. Then, for the firewall protection policy corresponding to any one of the IPv4 addresses, the similarity between it and the firewall protection policy corresponding to each of the IPv6 addresses is calculated, so that for an IP address pair, multiple similarities can be obtained in step 3105.
[0179] Step 3016, compare the multiple similarities with the similarity threshold value respectively.
[0180] When the multiple similarities are all greater than or equal to the similarity threshold value m, step 3017 is executed; otherwise, step 3108 is executed. The similarity threshold value m here can be set according to the situation, which can be set to 100%, or can be set to 99%, 95%, etc. according to the situation.
[0181] Step 3017, if the multiple similarities are all greater than or equal to m, it is determined that the firewall protection policies of the IPv4 address and the IPv6 address in the IP address pair are consistent.
[0182] Step 3018, if one or more similarities are less than m, it is determined that the firewall protection policies of the IPv4 address and the IPv6 address in the IP address pair are inconsistent.
[0183] Step 3019, obtain the firewall protection policy reinforcement and improvement strategy.
[0184] For the firewall protection policy of the IPv4 and IPv6 pair, the corresponding firewall protection policy reinforcement and improvement suggestion is given. For example, the firewall protection policy corresponding to the IPv4 address or the firewall protection policy corresponding to the IPv6 address can be used as the firewall protection policy, or other consistent firewall protection policies for the IPv4 address and the IPv6 address can also be determined.
[0185] In the embodiment of the present application, the acquired IPv4 address set and IPv6 address set are analyzed for asset fingerprint information, and a to-be-processed IP address set is acquired. The similarity of the firewall protection policies corresponding to the IPv4 address and the IPv6 address of the IP address pair in the acquired to-be-processed IP address set is calculated, so that the adjustment policy can be determined according to the similarity. Therefore, by using the scheme of the embodiment of the present application, the dual-stack protection policy of the firewall, gateway and other protection devices can be analyzed, and the missing or inconsistent problems in the policy can be found, thereby reducing the risk of security attacks. At the same time, by using the scheme of the embodiment of the present application, the analysis and early warning mechanism for the IPv4 and IPv6 dual-stack protection policy of the firewall and other protection devices can be realized, which is beneficial to timely finding the problems existing in the IPv4 and IPv6 dual-stack protection policy of the firewall and other protection devices, and thus the firewall security protection policy improvement and reinforcement can be better performed, and the risk of security attacks can be reduced.
[0186] The embodiment of the present application further provides a policy analysis device. Referring to Figure 4 , Figure 4 is a structural diagram of the policy analysis device provided by the embodiment of the present application. Since the principle of solving problems of the policy analysis device is similar to that of the policy analysis method in the embodiment of the present application, the implementation of the policy analysis device can be referred to the implementation of the method, and the repeated parts will not be described herein.
[0187] As shown in Figure 4 , the policy analysis device 400 comprises:
[0188] A first acquisition module 401 is configured to acquire an IPv4 address set and an IPv6 address set respectively; a second acquisition module 402 is configured to analyze the IPv4 address set and the IPv6 address set for asset fingerprint information, and obtain a to-be-processed IP address set; wherein the to-be-processed IP address set comprises at least one IP address pair, the IP address pair comprises an IPv4 address and an IPv6 address, and the asset fingerprint information corresponding to the IPv4 address in each IP address pair is completely identical or partially identical to the asset fingerprint information corresponding to the IPv6 address; a third acquisition module 403 is configured to acquire, for any first IP address pair in the IP address pair, a first firewall protection policy corresponding to a first IPv4 address in the first IP address pair and a second firewall protection policy corresponding to a first IPv6 address in the first IP address pair; a first determination module 404 is configured to determine the similarity between the first firewall protection policy and the second firewall protection policy; and a fourth acquisition module 405 is configured to obtain an adjustment policy based on the similarity.
[0189] The second acquisition module comprises:
[0190] The first obtaining sub-module is configured to obtain a first multi-tuple of each IPv4 address in the IPv4 address set and a second multi-tuple of each IPv6 address in the IPv6 address set, respectively;
[0191] The second obtaining sub-module is configured to, for any target IPv4 address, form an IP address pair by using the target IPv4 address and a target IPv6 address when all or part of elements of the first multi-tuple of the target IPv4 address are the same as all or part of elements of the second multi-tuple of the target IPv6 address;
[0192] The third obtaining sub-module is configured to form the to-be-processed IP address set by using the obtained plurality of IP address pairs.
[0193] Each multi-tuple includes operating system (OS) information, a port number, port information, service information, service version information, and host name information.
[0194] Each firewall protection policy can include the following information: a source IP address, a source port number, a destination IP address, a destination port number, and action information; and the first determining module includes:
[0195] The first calculating sub-module is configured to calculate a text similarity between each element in the first firewall policy and a corresponding element in the second firewall policy, respectively, to obtain a plurality of text similarities.
[0196] The first determining sub-module is configured to determine a similarity between the first firewall protection policy and the second firewall protection policy according to the plurality of text similarities.
[0197] Each firewall protection policy can include the following information: a source IP address, a source port number, a destination IP address, a destination port number, and action information; and the first determining module includes:
[0198] The first obtaining sub-module is configured to form a first policy graph according to the first firewall protection policy.
[0199] The second obtaining sub-module is configured to form a second policy graph according to the second firewall protection policy.
[0200] The first determining sub-module is configured to take a similarity between the first policy graph and the second policy graph as a similarity between the first firewall protection policy and the second firewall protection policy.
[0201] The policy graph is formed in the following manner:
[0202] The source IP address and the destination IP address in the firewall protection policy are taken as different points, respectively.
[0203] a first angle is formed by taking the source port number in the firewall protection policy as a vertex of an angle; a second angle is formed by taking the destination port number in the firewall protection policy as a vertex of an angle, wherein different port numbers correspond to different angles;
[0204] a third angle is formed by taking the action information in the firewall protection policy as a vertex of an angle;
[0205] The policy graph is formed by using the point, the first angle, the second angle and the third angle.
[0206] The fourth obtaining module comprises:
[0207] The first obtaining sub-module is configured to, when the first firewall protection policy and the second firewall protection policy are one, if the similarity is greater than or equal to a similarity threshold, determine that the first firewall protection policy and the second firewall protection policy are consistent, and no policy adjustment is needed.
[0208] The second obtaining sub-module is configured to, when the similarity is less than the similarity threshold, determine that the first firewall protection policy and the second firewall protection policy are inconsistent, and adjust the first firewall protection policy and the second firewall protection policy to be consistent.
[0209] The first determining module is configured to, when the first firewall protection policy is multiple or the second firewall protection policy is multiple, for any first firewall protection policy in the multiple first firewall protection policies, determine the similarity between the first firewall protection policy and each second firewall protection policy, and obtain multiple similarities.
[0210] The third obtaining sub-module is configured to, when the first firewall protection policy is multiple or the second firewall protection policy is multiple, if the multiple similarities are all greater than or equal to a similarity threshold, determine that the first firewall protection policy and the second firewall protection policy are consistent, and no policy adjustment is needed.
[0211] The fourth obtaining sub-module is configured to, when one or more of the multiple similarities is less than the similarity threshold, determine that the first firewall protection policy and the second firewall protection policy are inconsistent, and adjust the first firewall protection policy and the second firewall protection policy to be consistent.
[0212] The apparatus provided in the embodiments of the present application can execute the method embodiments, and the implementation principles and technical effects are similar, and thus will not be described here.
[0213] As Figure 5As shown, the policy analysis device 500 comprises: an IPv6 address and IPv4 address input module 501, an asset fingerprint analysis module 502, a firewall protection policy extraction module 503, a firewall protection policy detection module 504, and a firewall protection policy reinforcement and improvement module 505.
[0214] The IPv6 address and IPv4 address input module 501 is configured to obtain an IPv4 address set and an IPv6 address set.
[0215] The asset fingerprint analysis module 502 is configured to obtain, extract, and compare asset fingerprint information of the IPv4 address set and the IPv6 address set, and obtain an IPv4 and IPv6 pair with the same asset fingerprint information.
[0216] The firewall protection policy extraction module 503 is configured to extract all corresponding firewall protection policies in the firewall for the IPv4 and IPv6 addresses corresponding to the IPv4 and IPv6 pair with the same asset fingerprint information.
[0217] The firewall protection policy detection module 504 is configured to compare the firewall protection policies corresponding to the IPv4 and IPv6 pair, calculate the similarity of the protection policies, compare the similarity in size, and determine the consistency of the firewall protection policies of the IPv4 and IPv6 pair.
[0218] The firewall protection policy reinforcement and improvement module 505 is configured to reinforce and improve the firewall protection policies for the IPv4 and IPv6 pair with inconsistent firewall protection policies.
[0219] The device provided in the embodiment of the application can execute the method embodiments described above, and has similar implementation principles and technical effects, which will not be described here again in the embodiment.
[0220] As shown in the method embodiment, the policy analysis device comprises: Figure 6 A processor 601 and a transceiver 602.
[0221] The processor 601 is configured to:
[0222] obtain an IPv4 address set and an IPv6 address set, respectively;
[0223] perform asset fingerprint information analysis on the IPv4 address set and the IPv6 address set to obtain a to-be-processed IP address set, wherein the to-be-processed IP address set comprises at least one IP address pair, the IP address pair comprises an IPv4 address and an IPv6 address, asset fingerprint information corresponding to the IPv4 address in each IP address pair is completely identical or partially identical to asset fingerprint information corresponding to the IPv6 address.
[0224] For any first IP address pair in the IP address pairs, a first firewall protection policy corresponding to a first IPv4 address in the first IP address pair and a second firewall protection policy corresponding to a first IPv6 address in the first IP address pair are obtained;
[0225] Similarity between the first firewall protection policy and the second firewall protection policy is determined;
[0226] Based on the similarity, an adjustment policy is obtained.
[0227] The processor 601 is configured to:
[0228] A first multi-tuple of each IPv4 address in the set of IPv4 addresses and a second multi-tuple of each IPv6 address in the set of IPv6 addresses are obtained respectively;
[0229] For any target IPv4 address, when all or part of elements of the first multi-tuple of the target IPv4 address are the same as all or part of elements of the second multi-tuple of a target IPv6 address, an IP address pair is formed by the target IPv4 address and the target IPv6 address;
[0230] The set of IP addresses to be processed is formed by using the obtained plurality of IP address pairs;
[0231] The multi-tuple includes operating system (OS) information, port number, port information, service information, service version information, and host name information.
[0232] Each firewall protection policy can include the following information: source IP address, source port number, destination IP address, destination port number, and action information; and the processor 601 is configured to:
[0233] Text similarity between each element in the first firewall policy and a corresponding element in the second firewall policy is calculated respectively to obtain a plurality of text similarities;
[0234] Similarity between the first firewall protection policy and the second firewall protection policy is determined according to the plurality of text similarities.
[0235] Each firewall protection policy can include the following information: source IP address, source port number, destination IP address, destination port number, and action information; and the processor 601 is configured to:
[0236] A first strategy graph is formed according to the first firewall protection policy;
[0237] A second strategy graph is formed according to the second firewall protection policy;
[0238] The similarity between the first policy graph and the second policy graph is taken as the similarity between the first firewall protection policy and the second firewall protection policy.
[0239] The processor 601 is configured to form a policy graph in the following manner:
[0240] The source IP address and the destination IP address in the firewall protection policy are taken as different points respectively.
[0241] The source port number in the firewall protection policy is taken as the vertex of a first angle, and the destination port number in the firewall protection policy is taken as the vertex of a second angle, wherein different port numbers correspond to different angles.
[0242] The action information in the firewall protection policy is taken as the vertex of a third angle.
[0243] The points, the first angle, the second angle and the third angle are used to form a policy graph.
[0244] The processor 601 is configured to:
[0245] When the first firewall protection policy and the second firewall protection policy are one, if the similarity is greater than or equal to a similarity threshold, it is determined that the first firewall protection policy and the second firewall protection policy are consistent, and no policy adjustment is needed.
[0246] When the similarity is less than the similarity threshold, it is determined that the first firewall protection policy and the second firewall protection policy are inconsistent, and the first firewall protection policy and the second firewall protection policy are adjusted to be consistent.
[0247] The processor 601 is configured to:
[0248] When the first firewall protection policy is multiple or the second firewall protection policy is multiple, for any first firewall protection policy in the multiple first firewall protection policies, the similarity between the first firewall protection policy and each second firewall protection policy is determined, and multiple similarities are obtained.
[0249] When the first firewall protection policy is multiple or the second firewall protection policy is multiple, if the multiple similarities are all greater than or equal to a similarity threshold, it is determined that the first firewall protection policy and the second firewall protection policy are consistent, and no policy adjustment is needed.
[0250] When one or more of the plurality of similarities is less than the similarity threshold, it is determined that the first firewall protection policy and the second firewall protection policy are inconsistent, and the first firewall protection policy and the second firewall protection policy are adjusted to be consistent.
[0251] The apparatus provided by the embodiments of the present application can execute the method embodiments described above, and has similar implementation principles and technical effects. Therefore, the apparatus will not be described here again.
[0252] It should be noted that the division of units in the embodiments of the present application is illustrative, and is only a logical function division. In actual implementation, another division manner can be used. In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0253] When the integrated unit is realized in the form of a software functional unit and sold or used as an independent product, the integrated unit can be stored in a processor-readable storage medium. Based on this understanding, the technical solutions of the present application, essentially or in part, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, and various other media that can store program codes.
[0254] The embodiments of the present application also provide a communication device, including a memory, a processor, and a program stored in the memory and executable on the processor, and the processor implements the steps in the policy analysis method when executing the program.
[0255] The embodiment of the present application further provides a readable storage medium, and a program is stored on the readable storage medium. The program is executed by a processor to implement each process of the above policy analysis method embodiment and achieve the same technical effects. To avoid repetition, details are not described herein. The readable storage medium can be any available medium or data storage device accessible by the processor, including but not limited to a magnetic memory (for example, a floppy disk, a hard disk, a magnetic tape, a magneto-optical disk (MO), etc.), an optical memory (for example, a CD, a DVD, a BD, a HVD, etc.), and a semiconductor memory (for example, a ROM, an EPROM, an EEPROM, a nonvolatile memory (NAND FLASH), a solid-state disk (SSD), etc.).
[0256] It should be noted that in this document, the term "comprising" or "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such a process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of additional identical elements in the process, method, article or device including the element.
[0257] From the above description of the embodiments, those skilled in the art can clearly understand that the above embodiment methods can be realized by means of software and a necessary general hardware platform, and of course, they can also be realized by hardware, but in many cases, the former is a better embodiment. According to such understanding, the technical solutions of the present application can be embodied in the form of a software product, which is stored in a storage medium (such as a ROM / RAM, a magnetic disk, an optical disk), and includes a plurality of instructions for causing a terminal (which can be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in the various embodiments of the present application.
[0258] The embodiments of the present application are described above in combination with the drawings, but the present application is not limited to the above specific embodiments, and the above specific embodiments are only illustrative and not limiting. Those skilled in the art can make many forms under the inspiration of the present application without departing from the scope of the present application and the protection scope of the claims.
Claims
1. A method of policy analysis, characterized by, The method comprises the following steps: respectively acquiring an IPv4 address set and an IPv6 address set; performing asset fingerprint information analysis on the IPv4 address set and the IPv6 address set to obtain a to-be-processed IP address set; wherein the to-be-processed IP address set comprises at least one IP address pair, the IP address pair comprises an IPv4 address and an IPv6 address, and the asset fingerprint information corresponding to the IPv4 address in each IP address pair is completely identical or partially identical to the asset fingerprint information corresponding to the IPv6 address; for any first IP address pair in the IP address pair, acquiring a first firewall protection policy corresponding to a first IPv4 address in the first IP address pair and a second firewall protection policy corresponding to a first IPv6 address in the first IP address pair; determining the similarity between the first firewall protection policy and the second firewall protection policy; based on the similarity, obtaining an adjustment policy; when the first firewall protection policy and the second firewall protection policy are one, the adjustment policy is obtained based on the similarity, comprising: when the similarity is greater than or equal to a similarity threshold, it is determined that the first firewall protection policy and the second firewall protection policy are consistent, and no policy adjustment is needed; when the similarity is less than the similarity threshold, it is determined that the first firewall protection policy and the second firewall protection policy are inconsistent, and the first firewall protection policy and the second firewall protection policy are adjusted to be consistent.
2. The method of claim 1, wherein, The asset fingerprint information analysis on the IPv4 address set and the IPv6 address set to obtain the to-be-processed IP address set comprises: respectively acquiring a first multi-tuple of each IPv4 address in the IPv4 address set and a second multi-tuple of each IPv6 address in the IPv6 address set; for any target IPv4 address, when all or part of the elements of the first multi-tuple of the target IPv4 address are identical to all or part of the elements of the second multi-tuple of a target IPv6 address, an IP address pair is formed by using the target IPv4 address and the target IPv6 address; using the obtained multiple IP address pairs to form the to-be-processed IP address set; wherein the multi-tuple comprises operating system (OS) information, port number, port information, service information, service version information, and host name information.
3. The method of claim 1 or 2, wherein the firewall protection policy comprises the following information: source IP address, source port number, destination IP address, destination port number, and action information; the determination of the similarity between the first firewall protection policy and the second firewall protection policy comprises: respectively calculating the text similarity between each element in the first firewall protection policy and the corresponding element in the second firewall protection policy to obtain multiple text similarities; determining the similarity between the first firewall protection policy and the second firewall protection policy according to the multiple text similarities.
4. The method according to claim 1 or 2, characterized in that, The firewall protection policy includes the following information: source IP address, source port number, destination IP address, destination port number, and action information; The similarity between the first firewall protection policy and the second firewall protection policy is determined by: forming a first strategy graph according to the first firewall protection policy; forming a second strategy graph according to the second firewall protection policy; the similarity between the first strategy graph and the second strategy graph is taken as the similarity between the first firewall protection policy and the second firewall protection policy.
5. The method of claim 4, wherein, The strategy graph is formed in the following way: the source IP address and the destination IP address in the firewall protection policy are taken as different points respectively; the source port number in the firewall protection policy is taken as the vertex of a first angle, and the destination port number in the firewall protection policy is taken as the vertex of a second angle, wherein different port numbers correspond to different angles; the action information in the firewall protection policy is taken as the vertex of a third angle; the points, the first angle, the second angle, and the third angle are used to form a strategy graph.
6. The method of claim 1, wherein, When the first firewall protection policy is multiple, or the second firewall protection policy is multiple, the similarity between the first firewall protection policy and the second firewall protection policy is determined by: for any first firewall protection policy in the multiple first firewall protection policies, the similarity between the first firewall protection policy and each second firewall protection policy is determined, obtaining multiple similarities; the adjustment strategy is obtained based on the similarity, including: when all the multiple similarities are greater than or equal to a similarity threshold, it is determined that the first firewall protection policy and the second firewall protection policy are consistent, and no policy adjustment is needed; when one or more of the multiple similarities are less than the similarity threshold, it is determined that the first firewall protection policy and the second firewall protection policy are inconsistent, and the first firewall protection policy and the second firewall protection policy are adjusted to be consistent.
7. A policy analysis apparatus characterized by comprising: including: a first acquisition module for acquiring an IPv4 address set and an IPv6 address set respectively; a second acquisition module for performing asset fingerprint information analysis on the IPv4 address set and the IPv6 address set to obtain a set of IP addresses to be processed; wherein the set of IP addresses to be processed includes at least one IP address pair, the IP address pair includes an IPv4 address and an IPv6 address, and the asset fingerprint information corresponding to the IPv4 address in each IP address pair is completely the same or partially the same as the asset fingerprint information corresponding to the IPv6 address; a third acquisition module for, for any first IP address pair in the IP address pair, acquiring a first firewall protection policy corresponding to a first IPv4 address in the first IP address pair and a second firewall protection policy corresponding to a first IPv6 address in the first IP address pair; a first determination module for determining the similarity between the first firewall protection policy and the second firewall protection policy; a fourth acquisition module for obtaining an adjustment strategy based on the similarity; The fourth obtaining module comprises: The first obtaining submodule is configured to, when the first firewall protection policy and the second firewall protection policy are one, if the similarity is greater than or equal to a similarity threshold, determine that the first firewall protection policy and the second firewall protection policy are consistent, and no policy adjustment is needed; The second obtaining submodule is configured to, when the similarity is less than the similarity threshold, determine that the first firewall protection policy and the second firewall protection policy are inconsistent, and adjust the first firewall protection policy and the second firewall protection policy to be consistent.
8. A policy analysis apparatus characterized by comprising: Comprise: A processor and a transceiver; The processor is configured to: Obtain an IPv4 address set and an IPv6 address set respectively; Perform asset fingerprint information analysis on the IPv4 address set and the IPv6 address set to obtain a to-be-processed IP address set; the to-be-processed IP address set comprises at least one IP address pair, the IP address pair comprises an IPv4 address and an IPv6 address, and asset fingerprint information corresponding to the IPv4 address in each IP address pair is completely identical or partially identical to asset fingerprint information corresponding to the IPv6 address; For any first IP address pair in the IP address pair, obtain a first firewall protection policy corresponding to a first IPv4 address in the first IP address pair and a second firewall protection policy corresponding to a first IPv6 address in the first IP address pair; Determine a similarity between the first firewall protection policy and the second firewall protection policy; Based on the similarity, obtain an adjustment policy; When the first firewall protection policy and the second firewall protection policy are one, the obtaining of the adjustment policy based on the similarity comprises: When the similarity is greater than or equal to a similarity threshold, determine that the first firewall protection policy and the second firewall protection policy are consistent, and no policy adjustment is needed; When the similarity is less than the similarity threshold, determine that the first firewall protection policy and the second firewall protection policy are inconsistent, and adjust the first firewall protection policy and the second firewall protection policy to be consistent.
9. A communication device comprising: A memory, a processor, and a program stored in the memory and capable of running on the processor; the program comprises the steps of the method according to any one of claims 1 to 6. The program is executed by the processor to implement the steps of the method according to any one of claims 1 to 6.
10. A readable storage medium for storing a program, characterized in that,
Citation Information
Patent Citations
Credible strategy updating method and device
CN110363007A
Method and device for determining risk of IPv6 address
CN111343295A