Method, System, Storage Medium and Electronic Device for Processing Network Access Relationship

By automatically processing the network access relationship requirements table and pre-built information table, and generating and issuing configuration commands, the problem of low efficiency and accuracy of network access relationship implementation in large enterprises is solved, and automated implementation is achieved and accuracy is improved.

CN115941463BActive Publication Date: 2025-05-27CHINA CONSTRUCTION BANK
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211647257.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-21
Publication Date
2025-05-27
Estimated Expiration
2042-12-21

AI Technical Summary

Technical Problem

Large enterprises have many network access relationship requirements and complex links, resulting in large-scale inspection and configuration implementation of network access relationships with high error rates, which in turn reduces implementation efficiency and accuracy.

Method used

By obtaining the network access relationship requirements table, using the pre-constructed network area information table, access relationship control matrix and network device configuration information table, a formatted parameter table is generated, and a target command line is generated based on the network device model and parameter table information, and the configuration is automatically issued to establish a network access relationship.

Benefits of technology

The network access relationship can be automatically implemented without manual configuration checking, improving implementation accuracy and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115941463B_ABST
    Figure CN115941463B_ABST
Patent Text Reader

Abstract

The present application discloses a method, a system, a storage medium, and an electronic device for processing network access relationships. A formatted parameter table is generated through a network area information table, an access relationship control matrix, a network device configuration information table, and a network access relationship requirement table. The network device model corresponding to the device name information in the parameter table is obtained through a network device information table. A script is generated according to the network device model, the record information of the parameter table, and a preset command line. The parameter table is converted into a target command line through the script for a distribution operation, and the distribution operation is used to implement an update of the network device configuration to establish a network access relationship for a requester to access a destination host from a source host. There is no need for manual inspection to implement the network access relationship. By simply obtaining and formatting the network access relationship, checking the control device configuration to generate a parameter table, using the command line to generate a script to generate commands and distribute the configuration, the network access relationship implementation is automated, improving the implementation accuracy and implementation efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and more specifically, to a method, system, storage medium and electronic device for processing network access relations. Background Art

[0002] For large enterprises, a wide variety of office and business systems support the efficient operation of the enterprise. The interaction of office and business system data is inseparable from the network. Usually, large enterprises divide the network into different logical areas, and different logical network areas are usually isolated by default. When a new business is launched, it is necessary to open up the network between the client and the server or between the servers, which is called the implementation of the network access relationship.

[0003] However, due to the numerous requirements and complex links of large-scale enterprise network access relationships, manual inspection and configuration of network access relationship implementation is labor-intensive and has a high error rate, resulting in low efficiency and accuracy in the implementation of network access relationships. Summary of the invention

[0004] In view of this, the present application discloses a method, system, storage medium and electronic device for processing network access relationships, aiming to automatically implement network access relationships and improve implementation accuracy and efficiency.

[0005] In order to achieve the above purpose, the disclosed technical solution is as follows:

[0006] In a first aspect, the present application discloses a method for processing a network access relationship, the method comprising:

[0007] Obtaining a network access relationship requirement table; the network access relationship requirement is an access requirement of a demander to access a port of a destination host from a source host;

[0008] Generate a formatted parameter table through a pre-built network area information table, a pre-built access relationship control matrix, a pre-built network device configuration information table and the network access relationship requirement table;

[0009] Obtain device name information in the parameter table;

[0010] Obtain the network device model corresponding to the device name information through a predefined network device information table;

[0011] Generate a script according to the network device model, the record information in the parameter table and a preset command line, and convert the parameter table into a target command line through the script; the target command line is a command line that matches the network device model;

[0012] Perform the operation of issuing the target command line; the issuing operation is used to update the configuration of the network device to establish a network access relationship for the requester to access the destination host from the source host.

[0013] Preferably, the obtaining of the network access relationship requirement table includes:

[0014] Obtain the network access relationship requirements and format them to generate a network access relationship requirement table.

[0015] Preferably, the network devices include switches, firewalls, and routers. The process of constructing the configuration information table of the network devices includes:

[0016] When the network device is a switch, collect the control status and routing configuration of the policy routing of the production plane and the out-of-band plane of the switch respectively; the control status of the policy routing of the out-of-band plane respectively characterizes the policy routing of the switch and the interface direction to which it is bound;

[0017] Construct a switch configuration information table based on the control status of the policy routing of the production plane and the out-of-band plane of the switch respectively and the routing configuration;

[0018] When the network device is a firewall, construct the correspondence between the name of the network area and the address set of the network area, and construct a firewall configuration information table according to the correspondence;

[0019] When the network device is a router, construct a router configuration information table; the router configuration information table includes at least a routing table and dedicated line channel configuration information.

[0020] Preferably, the generating of the formatted parameter table through the pre-constructed network area information table, the pre-constructed access relationship control matrix, the pre-constructed network device configuration information table, and the network access relationship requirement table includes:

[0021] Initialize the pre-constructed network area information table, the pre-constructed network access relationship control matrix, and the pre-constructed network device configuration information table;

[0022] According to the initialized network area information table, divide all the IP addresses in the network access relationship requirement table to obtain the network types of all the IP addresses and the logical network areas to which all the IP addresses belong;

[0023] Group all the IP addresses according to the network type, the logical network area, and the access relationship requirement behavior unit to obtain the grouped source IP addresses and the grouped destination IP addresses; the source IP address is the source host IP address of the access relationship applied by the requester; the destination IP address is the destination host IP address of the access relationship applied by the requester;

[0024] Taking the grouped source IP address and the grouped destination IP address as a Cartesian product;

[0025] Through the entries of the Cartesian product, query the initialized network access relationship control matrix to determine the intermediate control network device and control method for access control that exist in the entries of the Cartesian product;

[0026] According to the initialized network device configuration information table, the control status of the network devices related to the source and destination areas and the intermediate control network devices and control methods for which access control exists in the entries of the Cartesian product are checked to obtain a check result; the check result represents the check result of whether the configuration information of the intermediate control network device or the network devices related to the source and destination areas releases the access relationship corresponding to the entries of the Cartesian product;

[0027] When the inspection result is that the configuration information of the intermediate control network device or the source-destination area-related network device does not allow the network access relationship, a parameter table is generated; the parameter table at least includes a firewall parameter table, a switch policy routing parameter table and a routing parameter table;

[0028] The parameter tables are merged and deduplicated to generate a formatted parameter table.

[0029] Preferably, the process of issuing the target command line includes:

[0030] Log in to the network device through the preset login method;

[0031] The target command line is issued through the network device to update the configuration of the network device and to establish a network access relationship for the demander to access the destination host from the source host.

[0032] A second aspect of the present application discloses a system for processing network access relations, the system comprising:

[0033] A first acquisition unit is used to acquire a network access relationship requirement table; the network access relationship requirement is an access requirement of a demander to access a port of a destination host from a source host;

[0034] A first generating unit, configured to generate a formatted parameter table by using a pre-built network area information table, a pre-built access relationship control matrix, a pre-built network device configuration information table and the network access relationship requirement table;

[0035] A second acquisition unit, used to acquire device name information in the parameter table;

[0036] A third acquisition unit, configured to obtain the network device model corresponding to the device name information through a predefined network device information table;

[0037] A second generation unit, configured to generate a script according to the network device model, the record information in the parameter table, and a preset command line, and convert the parameter table into a target command line through the script; the target command line is a command line that matches the network device model.

[0038] A sending unit, configured to perform a sending operation on the target command line; the sending operation is used to update the configuration of the network device to establish a network access relationship for a requester to access a destination host from a source host.

[0039] Preferably, the first obtaining unit is specifically configured to:

[0040] Obtain and format the network access relationship requirements to generate a network access relationship requirements table.

[0041] Preferably, the first generation unit for constructing the configuration information table of the network device includes:

[0042] A first construction module, configured to collect the control situation and routing configuration of the policy routing of the production plane and the out-of-band plane of the switch when the network device is a switch; the control situation of the policy routing of the out-of-band plane respectively represents the policy routing of the switch and the interface direction to which it is bound; construct a switch configuration information table through the control situation of the policy routing of the production plane and the out-of-band plane of the switch and the routing configuration.

[0043] A second construction module, configured to construct the correspondence between the name of the network area and the address set of the network area when the network device is a firewall, and construct a firewall configuration information table according to the correspondence.

[0044] A third construction module, configured to construct a router configuration information table when the network device is a router; the router configuration information table includes at least a routing table and dedicated line channel configuration information.

[0045] A third aspect of the present application discloses a storage medium, where the storage medium includes stored instructions, and when the instructions run, the device where the storage medium is located is controlled to execute the network access relationship processing method according to any one of the first aspects.

[0046] A fourth aspect of the present application discloses an electronic device, including a memory, and one or more instructions, where one or more instructions are stored in the memory and are configured to be executed by one or more processors to execute the network access relationship processing method according to any one of the first aspects.

[0047] As can be seen from the above technical solutions, the present application discloses a method, a system, a storage medium, and an electronic device for processing network access relationships. A network access relationship requirement table is obtained; the network access relationship requirement is the access requirement for the requester to access the port of the destination host from the source host. By using a pre-constructed network area information table, an access relationship control matrix, a pre-constructed configuration information table of network devices, and the network access relationship requirement table, a formatted parameter table is generated. The device name information in the parameter table is obtained, and through a predefined network device information table, the network device model corresponding to the device name information is obtained. A script is generated according to the network device model, the record information in the parameter table, and a preset command line, and through the script, the parameter table is converted into a target command line, where the target command line is a command line that matches the network device model. The target command line is issued for the purpose of updating the configuration of the network device to establish the network access relationship for the requester to access the destination host from the source host. Through the above solution, there is no need to manually check the configuration to implement the network access relationship. Only by obtaining and formatting the network access relationship, checking the control device configuration to generate a parameter table, using the command line to generate a script to generate a command and issue the configuration, the network access relationship is implemented automatically, improving the implementation accuracy and efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained according to the provided drawings.

[0049] Figure 1 It is a schematic flowchart of a method for processing a network access relationship disclosed in an embodiment of the present application;

[0050] Figure 2 It is a schematic structural diagram of a system for processing a network access relationship disclosed in an embodiment of the present application;

[0051] Figure 3 It is a schematic structural diagram of an electronic device disclosed in an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0052] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.

[0053] In this application, the terms "comprises", "comprising" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprising a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element.

[0054] As can be seen from the background technology, due to the numerous requirements and complex links of large-scale enterprise network access relationships, manual inspection and configuration of network access relationship implementation is labor-intensive and has a high error rate, resulting in low efficiency and accuracy in the implementation of network access relationships.

[0055] In order to solve the above problems, the present application discloses a method, system, storage medium and electronic device for processing network access relations, which do not require manual inspection and configuration to implement network access relations. Instead, the network access relations can be automatically implemented by obtaining and formatting the network access relations, inspecting and controlling the configuration to generate parameter tables, and using command lines to generate scripts to generate commands and issue configurations, thereby improving the accuracy and efficiency of implementation. The specific implementation method is described in the following embodiments.

[0056] refer to Figure 1 As shown, a method for processing a network access relationship disclosed in an embodiment of the present application is provided. The method for processing a network access relationship mainly includes the following steps:

[0057] S101: Obtain a network access relationship requirement table; the network access relationship requirement is the access requirement of the requester to access the port of the destination host from the source host.

[0058] In S101, network access relationship requirements are obtained and formatted to generate a network access relationship requirement table.

[0059] Among them, the fields included in the network access relationship requirement table are: service request number, source application subsystem, source application deployment unit, source location, source address, source mapping address, destination application subsystem, destination application deployment unit, destination location, destination address, destination mapping address, control point one, control point two, whether the destination end is bypassed, protocol type, connection type, port, timeout, transmission type, transmission time, transmission data volume, purpose, validity period, remarks, etc.

[0060] Network access relationship requirements refer to the protocol that the demander wants to use from the source host to access the port of the destination host and other related access requirements.

[0061] Among them, other related access requirements also include information such as source mapping address, destination address mapping address, time limit, amount of transmitted data, etc. The network protocols include Internet Control Message Protocol (ICMP), User Datagram Protocol (UDP), and Transmission Control Protocol (TCP); the source host is identified by the source IP address, and the destination host is identified by the destination IP address; since there are various application channels for network access relationships and different filling methods for the requester, in order to facilitate data processing, it is necessary to format the network access relationship requirements to generate a network access relationship requirements table; combined with Figure 1 In the shown embodiment, in some optional embodiments, the network access relationship requirements are formatted by integrating the field values of the network access relationship into predefined standard field values: rewriting the IP address according to a custom format, rewriting the port information according to a custom format, rewriting the validity period according to a custom format, etc.

[0062] The network access relationship requirements table can also be a network access relationship requirements table in a custom format.

[0063] The network access relationship requirements table in a custom format integrates the source IP address and the destination IP address into a custom format, uses * to represent the entire address segment, uses - to represent the address range, and uses / to represent discrete addresses with the same previous segment. The examples are as follows:

[0064] For example, writing 192.168.1.0 / 24 as 192.168.1.*; writing 192.168.1.0 / 30 as 192.168.1.0-3; writing 192.168.1.5 and 192.168.1.7 as 192.168.1.5 / 7; writing the discrete addresses 192.168.1.1, 192.168.1.2, and 192.168.1.3 as 192.168.1-3; merging the connection protocol type, port number, and connection type into an integrated port information in a custom format. Specifically, writing the protocol type as TCP, ports 80 and 8080, and the connection type as long connection as TCP / 80 / 8080L; writing the protocol type as UDP, port 53, and no connection type as UDP / 53.

[0065] It should be noted that the custom format of the IP address in this application is different from the standard mask format, and the custom format of the port integrates the protocol type, port number, and connection type information. The above custom format runs through the automated implementation of the network access relationship implemented in the embodiments of this application. The embodiments of this application do not limit the rewriting rules corresponding to the granularity of network area division, and any custom format based on granularity should fall within the protection scope of this application.

[0066] Optionally, a network access relationship application has a work order number as the unique identifier. To obtain the network access relationship, it can be obtained through the application program interface (API) of the network access relationship application system to obtain the network access relationship to which the work order number belongs, or the network access relationship to which the work order number belongs can be obtained through web crawling. This application does not limit this.

[0067] S102: Generate a formatted parameter table through a pre-constructed network area information table, a pre-constructed access relationship control matrix, a pre-constructed network device configuration information table, and a network access relationship requirement table.

[0068] Among them, the process of constructing the network area information table is as follows:

[0069] After the network area is built, according to the network area planning and construction situation, construct the network area information table. The network area information table records the name, address segment, aggregation switch name, associated firewall name, connection method, etc. of the network area.

[0070] The network area information table records information such as the area name, area production network address segment, out-of-band network address segment, area aggregation switch name, area associated firewall, area associated router, etc. of each logical network area.

[0071] The area name of the logical network area is the unique identifier of the network area information.

[0072] The access relationship control matrix records the intermediate control network device name and control method of the network access relationship that may not be allowed between any two logical network areas.

[0073] The network device configuration information records the configuration of all network devices that control the network access relationship. The network device configuration information table includes outbound policy-based routing (PBR), inbound PBR, routing, mapping, etc.

[0074] This application does not make specific restrictions on the data organizational structure and form of the network area information table, the access relationship control matrix, and the network device configuration information table. Any feasible method belongs to the protection scope of this application.

[0075] Network devices include switches, firewalls, routers, etc.

[0076] The specific process of constructing the network device configuration information table is as follows:

[0077] After the network device goes online, synchronize the running configuration of the network device, record it separately according to different configuration items, and construct a network device configuration information table, which includes routing, outbound PBR, inbound PBR, anti-virus PBR, mapping, etc. Specifically, the process of constructing the network device information table includes, after the network device goes online, constructing the network device information table according to information such as the model, name, management address, and administrator account of the network device. The network device information table records the model, name, management address, administrator account, etc. of the network device.

[0078] The specific process of constructing the configuration information table of the network device is shown in A1 - A4.

[0079] A1: When the network device is a switch, collect the control status and routing configuration of the policy routing of the production plane and the out-of-band plane of the switch respectively; the control status of the policy routing of the out-of-band plane respectively characterizes the policy routing of the switch and the interface direction to which it is bound.

[0080] Among them, the bound interface direction is the interface direction to which the policy routing of the switch is bound.

[0081] A2: Construct a switch configuration information table through the control status of the policy routing of the production plane and the out-of-band plane of the switch respectively and the routing configuration.

[0082] Among them, the production plane and the out-of-band plane of the switch separate the production data stream and the management data stream and have non-interfering forwarding rules and routing controls; the control status of the policy routing includes using Access Control Lists (ACLs) for traffic filtering and using redirection to forward traffic to a specified device; the switch routing configuration includes static routing configuration and dynamic routing configuration.

[0083] A3: When the network device is a firewall, construct the correspondence between the name of the network zone (ZONE) and the address set of the network zone, and construct a firewall configuration information table according to the correspondence.

[0084] To facilitate understanding of constructing the correspondence between the name of the network zone and the address set of the network zone when the network device is a firewall, and constructing a firewall configuration information table according to the correspondence, an example is given here for illustration:

[0085] For example, taking the external firewall as an example, it is connected to 4 pairs of different network devices, corresponding to 4 network zones, namely trust, untrust, tg, and dmz. It is necessary to enumerate all the address segments coming from the directions of trust, untrust, tg, and dmz, that is, the address set corresponding to the network zone. When defining an address, the firewall needs to define the zone of the address, and when customizing a policy, it also needs the zone information corresponding to the address.

[0086] A4: When the network device is a router, construct a router configuration information table; the router configuration information table includes at least a routing table and dedicated line channel configuration information.

[0087] The process of constructing an access relationship control matrix is as follows:

[0088] After the enterprise network is constructed, construct a network access relationship control matrix according to the network planning and construction situation. The network access relationship control matrix records the names of intermediate network devices that may not be released and the control methods between any two logical network regions. Among them, the intermediate network device is a network device that controls the network access relationship except for the source and destination area devices.

[0089] The process of generating a formatted parameter table through a pre-constructed network area information table, a pre-constructed access relationship control matrix, a pre-constructed network device configuration information table, and a network access relationship requirement table is as shown in B1 - B8.

[0090] B1: Initialize the pre-constructed network area information table, the pre-constructed network access relationship control matrix, and the pre-constructed network device configuration information table.

[0091] Among them, since the pre-constructed network area information table, the pre-constructed network access relationship control matrix, and the network device configuration information table are all tables (Excel), the program needs to read them into memory. Therefore, these tables need to be initialized to enable the program to read them into memory.

[0092] B2: According to the initialized network area information table, divide all the IP addresses in the network access relationship requirement table to obtain the network types of all the IP addresses and the logical network regions to which all the IP addresses belong.

[0093] Among them, divide the source IP address and the destination IP address in the network access relationship requirement table into network types and the logical network regions to which they belong according to the network area information table.

[0094] The network types include production network, out-of-band network, test network, etc., which are network separation or plane separation networks. Device separation means that different network types use different network devices for networking; plane separation means that different network types use the same network device for networking and use the plane technology of the network device itself to isolate different networks.

[0095] The expression format of the logical network area address range in the network area information table is the same as the custom IP address format in the above network access relationship requirement table, for reference.

[0096] The matching scheme for determining whether a custom-formatted IP address belongs to a certain logical network area is as follows:

[0097] Organize the IP addresses in the network access relationship requirement table and the network area information table by separating them into A-segment, B-segment, C-segment, and D-segment addresses, and record the start and end values for each segment. Examples include:

[0098] First, organize 192.168.1.0 - 3 such that the start and end values of the A-segment are 192 to 192, the start and end values of the B-segment are 168 - 168, the start and end values of the C-segment are 1 to 1, and the start and end values of the D-segment are 0 to 3.

[0099] Then, compare the IP addresses in the network access relationship requirements with the address segments of each logical network area. If the A-segment, B-segment, C-segment, and D-segment addresses of the IP address in the network access relationship requirements are all within the A-segment, B-segment, C-segment, and D-segment address ranges of a certain logical network area address segment, then the current network access relationship IP address belongs to that logical network area.

[0100] Among them, obtain the network access relationship requirements submitted by the requester through the access network access relationship application system interface or crawler, integrate the network access relationship requirements in a custom format to generate a formatted network access relationship requirement table. The formatted network access relationship requirement table records the access relationship information from the source IP address to the destination IP address that the requester wants to establish, and is formatted in a custom format.

[0101] The embodiments of this application mainly implement network area matching for the IPv4 address format. For network area matching of the IPv6 address format, the above ideas can also be used to implement it, and this application does not limit this.

[0102] B3: Group all IP addresses according to the network type, logical network area, and access relationship requirement behavior unit to obtain the grouped source IP addresses and grouped destination IP addresses; the source IP address is the source host IP address of the access relationship applied by the requester; the destination IP address is the destination host IP address of the access relationship applied by the requester.

[0103] B4: Use the grouped source IP addresses and grouped destination IP addresses as the Cartesian product.

[0104] Among them, group the source IP address and destination IP address in a network access relationship requirement of the same network type by region and perform the Cartesian product.

[0105] The basis for grouping the source IP address and destination IP address in the network access relationship requirements by the logical network area they belong to is that the change of the network access relationship is released on the same network device in the same logical network area.

[0106] It should be noted that the Cartesian product is the same as the mathematical Cartesian product concept and will not be elaborated here.

[0107] Group the source IP address and destination IP address in the network access relationship requirement table according to the network type and network area based on the pre-constructed network area information table, and perform a Cartesian product on the network access relationships of the same network type according to the areas to which the source IP address and destination IP address belong.

[0108] B5: Query the initialized network access relationship control matrix through the entries of the Cartesian product to determine the intermediate control network devices and control methods for which access control exists for the entries of the Cartesian product.

[0109] Among them, for the Cartesian product entries, query the network access relationship control matrix to determine the intermediate control network devices and control methods for which access control may exist for the Cartesian product entries, check whether the configuration information of the intermediate control network devices and the network devices related to the source and destination areas allows the network access relationship, and for those that are not allowed, generate a parameter table.

[0110] The intermediate control network device refers to a network device that is not a network device related to the logical network area to which the source host belongs or a network device related to the logical network area to which the destination host belongs among the network devices passed through in the network connection from the source host to the destination host, and is a network device that controls the connection from the source host to the destination host. The intermediate control network device is a switch, a firewall, or a router, and the number of intermediate control network devices is zero, one, or more.

[0111] The network access relationship control network devices include switches, routers, firewalls, etc.

[0112] According to the network device names for which access control may exist and the network types for which the network access relationship needs to be established, a parameter table can be generated by distinguishing the control types of the control network devices. Among them, the control types include switch PBR control, firewall control, and routing control.

[0113] The switch PBR control includes checking the anti-virus port PBR of the network area aggregation switch. Among them, the anti-virus PBR is used to block common virus attack ports. For the case of a side-mounted firewall, check the outbound PBR and inbound PBR. Among them, the outbound PBR is generally mounted on the inbound direction of the switch's downlink port, and the inbound PBR is generally mounted on the inbound direction of the switch's uplink port. When the outbound PBR and inbound PBR do not allow the access relationship and there is no side-mounted firewall, it belongs to the switch PBR control, and to allow the access relationship, the PBR needs to be adjusted.

[0114] Firewall control includes the case of a side-mounted firewall. A side-mounted firewall refers to a connection method where the firewall is only connected to the same stack of switches. Usually, the outgoing PBR and incoming PBR redirect the access relationship traffic to be allowed to the side-mounted firewall. When the outgoing PBR and incoming PBR do not allow the network relationship, it belongs to firewall control. To allow the access relationship, a new policy needs to be added to the firewall; in the case of a series-connected firewall, it belongs to firewall control. To allow the access relationship, a new policy must be added to the firewall; among them, if there is a mapping for the access relationship, the corresponding firewall nat configuration needs to be checked. For existing mappings, only a firewall policy needs to be added. Otherwise, both a firewall policy and a firewall mapping need to be added; among them, the inspection of the firewall nat configuration includes the inspection of one-to-one static mappings, and the inspection of many-to-one and many-to-many source mappings. Among them, the inspection of the firewall nat configuration in the embodiments of the present application adopts a method of discretizing the integrated IP address into individual addresses for inspection.

[0115] Routing control includes router routing and firewall routing. Router routing is mainly the network boundary router. When the router does not add a route to allow network access relationships, it is router control. The network devices with routing control include routers and firewalls.

[0116] B6: According to the initialized network device configuration information table, check the control status of the network devices related to the source and destination regions and the intermediate control network devices and control methods for which there is access control for the entries of the Cartesian product, and obtain the inspection results; the inspection results represent the inspection results of whether the configuration information of the intermediate control network device or the network devices related to the source and destination regions allows the access relationships corresponding to the entries of the Cartesian product.

[0117] Among them, when the control network device does not allow the access relationship corresponding to the entry of the Cartesian product, a parameter table is generated and the control type is recorded, including switch PBR control, firewall control, and routing control. The parameter table records the information related to the network access relationships that need to be allowed on the control network device and the change-related information.

[0118] The parameter table includes a firewall parameter table, a switch packet filtering mechanism (Access Control Lists, ACL) parameter table, a new routing parameter table, etc. Specifically as follows:

[0119] The fields included in the firewall parameter table are: device name, policy ID, source region, source address, source location, Network Address Translation (NAT) address, source interface, source port, destination region, destination address, destination address mapping type, destination address, destination interface, service port, action, whether to record logs, time period limit, move before a certain policy, description, etc.

[0120] The fields included in the switch ACL parameter table are: device name, ACL number, rule number, Virtual Private Network (VPN) instance name, source address, destination address, action, move before a certain rule, description, requirement order number, etc.

[0121] The fields included in the newly added routing parameter table are: device name, routing type, destination address, next-hop address, Open Shortest Path First (OSPF) number, OSPF published network segment, Border Gateway Protocol (BGP) number, BGP published network segment, description, requirement order number, etc.

[0122] B7: When the inspection result is that the configuration information of the intermediate control network device or the network devices related to the source and destination regions does not allow the inspection result of the network access relationship, generate a parameter table; the parameter table includes at least a firewall parameter table, a switch policy routing parameter table, and a routing parameter table.

[0123] B8: Merge and deduplicate the parameter table to generate a formatted parameter table.

[0124] The specific process of merging and deduplicating the parameter table is shown in C1 - C3.

[0125] C1: For the firewall parameter table, only keep one entry with all fields the same; for those with other fields being the same but different source IP addresses, merge the source IP addresses together to become one record; for those with other fields being the same but different destination IP addresses, merge the destination IP addresses together to become one record; for those with other fields being the same but different ports, merge the ports together to become one record.

[0126] C2: For the switch PBR parameter table, only keep one entry with all fields the same.

[0127] C3: For the routing parameter table, only keep one entry with all fields the same.

[0128] S103: Obtain the device name information in the parameter table.

[0129] Among them, the device name information in the parameter table includes information such as network device model, management address, administrator account, etc.

[0130] S104: Through the predefined network device information table, obtain the network device model corresponding to the device name information.

[0131] Among them, based on the device name information in the formatted parameter table and the predefined network device information table, obtain information such as the network device model, management address, administrator account, etc.

[0132] The network device information table records information such as the network device name, network device model, management address, administrator account password, etc. of the network device.

[0133] S105: Generate a script based on the network device model, the recorded information in the parameter table, and a preset command line, and through the script, convert the parameter table into a target command line; the target command line is a command line that matches the network device model.

[0134] Among them, the preset command line can generate a corresponding command line according to the network device model and the change type.

[0135] Among them, the script is a command line generation script. The command line generation script is a program that can convert the parameter table into commands, and the command line is a command that can be executed on the network device.

[0136] Call the pre-established command line generation script according to the device model and change type of the network device name in the parameter table to generate a corresponding command set that the network device can execute.

[0137] According to the network device model and the recorded information in the parameter table, call the corresponding command line generation script to convert the parameter table into a command line that matches the device model.

[0138] The command line generation script is a program that converts the parameter table into commands that the network device can execute according to different network device models and change types. The command line is a command set that the network device can execute. It should be noted that the script is strictly related to the format of the parameter table, and the custom addresses and ports, etc. throughout this application determine the conversion logic of the command line generation script.

[0139] S106: Perform a distribution operation on the target command line; the distribution operation is used to update the configuration of the network device to establish a network access relationship for the requester to access the destination host from the source host.

[0140] In S106, log in to the network device through a preset login method, and through this network device, perform a distribution operation on the target command line to update the configuration of the network device to establish a network access relationship for the requester to access the destination host from the source host.

[0141] The preset login method can be a method of remotely logging in to the network device based on the network device management address and the administrator account, or it can be other login methods. The specific determination of the preset login method is not specifically limited in this application. The preset login method of this solution is preferably a method of remotely logging in to the network device based on the network device management address and the administrator account.

[0142] Based on the management address of the network device and the administrator account, the command line is issued remotely to log in to the network device, so as to update the configuration of the network device and establish the network access relationship.

[0143] According to the obtained management address of the network device and the administrator account, remotely connect to the network device through a remote connection tool. By executing commands line by line and saving them, the configuration of the network device is changed to allow the network access relationship. The management address of the network device is the out-of-band address of the network device that allows remote login, and the remote connection tool can remotely connect to the network device.

[0144] Among them, the target command line issuance is the process of completely executing each command after logging in to the network device through the administrator account, and the configuration of the network device is updated by saving the configuration.

[0145] In the embodiment of the present application, there is no need to manually check the configuration to implement the network access relationship. Only by obtaining and formatting the network access relationship, checking the control device configuration to generate a parameter table, using the command line to generate a script to generate commands and issue the configuration, the network access relationship is implemented automatically, improving the implementation accuracy and efficiency.

[0146] Based on the above embodiment Figure 1 A method for processing a network access relationship is disclosed. The embodiment of the present application also correspondingly discloses a system for processing a network access relationship, as Figure 2 shown. The system for processing the network access relationship includes a first acquisition unit 201, a first generation unit 202, a second acquisition unit 203, a third acquisition unit 204, a second generation unit 205, and a distribution unit 206.

[0147] The first acquisition unit 201 is used to acquire a network access relationship requirement table; the network access relationship requirement is the access requirement of the requester to access the port of the destination host from the source host.

[0148] The first generation unit 202 is used to generate a formatted parameter table through a pre-constructed network area information table, a pre-constructed access relationship control matrix, a pre-constructed configuration information table of the network device, and the network access relationship requirement table.

[0149] The second acquisition unit 203 is used to acquire the device name information in the parameter table.

[0150] The third acquisition unit 204 is used to obtain the network device model corresponding to the device name information through a predefined network device information table.

[0151] A second generation unit 205, configured to generate a script according to the network device model, the record information in the parameter table, and a preset command line, and convert the parameter table into a target command line through the script; the target command line is a command line matching the network device model.

[0152] A distribution unit 206, configured to perform a distribution operation on the target command line; the distribution operation is used to update the configuration of the network device to establish a network access relationship for the requester to access the destination host from the source host.

[0153] Furthermore, the first acquisition unit 201 is specifically configured to acquire and format the network access relationship requirements to generate a network access relationship requirements table.

[0154] Furthermore, the first generation unit 202 for constructing the configuration information table of the network device includes a first construction module, a second construction module, a third construction module, and a fourth construction module.

[0155] The first construction module is configured to, when the network device is a switch, collect the control situation and routing configuration of the policy routing of the production plane and the out-of-band plane of the switch respectively; the control situation of the policy routing of the out-of-band plane respectively characterizes the policy routing of the switch and the interface direction to which it is bound; construct a switch configuration information table through the control situation and routing configuration of the policy routing of the production plane and the out-of-band plane of the switch respectively.

[0156] The second construction module is configured to, when the network device is a firewall, construct the correspondence between the name of the network area and the address set of the network area, and construct a firewall configuration information table according to the correspondence.

[0157] The third construction module is configured to, when the network device is a router, construct a router configuration information table; the router configuration information table includes at least a routing table and dedicated line channel configuration information.

[0158] Furthermore, the first generation unit 202 includes an initialization module, a partitioning module, a grouping module, a first determination module, a second determination module, an inspection module, a generation module, and a duplicate removal module.

[0159] The initialization module is configured to initialize a pre-constructed network area information table, a pre-constructed network access relationship control matrix, and a pre-constructed network device configuration information table.

[0160] The partitioning module is configured to partition all the IP addresses in the network access relationship requirements table according to the initialized network area information table to obtain the network types of all the IP addresses and the logical network areas to which all the IP addresses belong.

[0161] A grouping module, which is used to group all IP addresses according to network type, logical network area, and access relationship requirement behavior unit, so as to obtain the grouped source IP addresses and grouped destination IP addresses; the source IP address is the source host IP address of the access relationship applied by the requester; the destination IP address is the destination host IP address of the access relationship applied by the requester.

[0162] A first determination module, which is used to take the grouped source IP addresses and grouped destination IP addresses as the Cartesian product.

[0163] A second determination module, which is used to query the initialized network access relationship control matrix through the entries of the Cartesian product, and determine the intermediate control network devices with access control and the control methods in the entries of the Cartesian product.

[0164] An inspection module, which is used to inspect the control situation of the source-destination area related network devices and the intermediate control network devices with access control and the control methods in the entries of the Cartesian product according to the initialized network device configuration information table, so as to obtain an inspection result; the inspection result represents the inspection result of whether the configuration information of the intermediate control network device or the source-destination area related network device allows the access relationship corresponding to the entry of the Cartesian product.

[0165] A generation module, which is used to generate a parameter table when the inspection result is that the configuration information of the intermediate control network device or the source-destination area related network device does not allow the inspection result of the network access relationship; the parameter table at least includes a firewall parameter table, a switch policy routing parameter table, and a routing parameter table.

[0166] A deduplication module, which is used to merge and deduplicate the parameter table to generate a formatted parameter table.

[0167] Further, a distribution unit 207 for distributing the target command line includes a login module and an operation module.

[0168] The login module is used to log in to the network device through a preset login method.

[0169] The operation module is used to distribute the target command line through the network device to implement the update of the network device configuration, so as to establish the network access relationship for the requester to access the destination host from the source host.

[0170] In the embodiment of the present application, there is no need to manually check the configuration to implement the network access relationship. Only by obtaining and formatting the network access relationship, checking the control device configuration to generate a parameter table, using the command line to generate a script to generate commands and distribute the configuration, the network access relationship is implemented automatically, improving the implementation accuracy and implementation efficiency.

[0171] An embodiment of the present application further provides a storage medium, which includes stored instructions. When the instructions run, they control the device where the storage medium is located to execute the above-mentioned method for processing network access relationships.

[0172] An embodiment of the present application further provides an electronic device. The schematic structural diagram is as Figure 3 shown, and specifically includes a memory 301 and one or more instructions 302. One or more of the instructions 302 are stored in the memory 301 and are configured to be executed by one or more processors 303 to execute the above-mentioned method for processing network access relationships.

[0173] The specific implementation processes and their derivative methods of the above-mentioned various embodiments are all within the protection scope of the present application.

[0174] Each embodiment in this specification is described in a progressive manner. The same or similar parts among the various embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system or system embodiment, since it is basically similar to the method embodiment, it is described relatively simply. For the relevant parts, refer to the partial description of the method embodiment. The systems and system embodiments described above are only illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative work.

[0175] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0176] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.

[0177] The above are only the preferred embodiments of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.

Claims

1. A method for processing network access relationships, characterized in that, the method includes: Obtaining a network access relationship requirements table; the network access relationship requirement is the access requirement of the requester to access the port of the destination host from the source host; Generating a formatted parameter table through a pre-constructed network area information table, a pre-constructed access relationship control matrix, a pre-constructed network device configuration information table, and the network access relationship requirements table; Obtaining the device name information in the parameter table; Obtaining the network device model corresponding to the device name information through a predefined network device information table; Generating a script based on the network device model, the record information in the parameter table, and a preset command line, and converting the parameter table into a target command line through the script; the target command line is a command line that matches the network device model; Performing a distribution operation on the target command line; the distribution operation is used to update the configuration of the network device to establish a network access relationship for the requester to access the destination host from the source host.

2. The method according to claim 1, characterized in that, the obtaining of the network access relationship requirements table includes: Obtaining network access relationship requirements and formatting them to generate a network access relationship requirements table.

3. The method according to claim 1, characterized in that, Network devices include switches, firewalls, and routers. The process of constructing a network device configuration information table includes: When the network device is a switch, collecting the control status and routing configuration of the policy routing of the switch production plane and the out-of-band plane respectively; the control status of the policy routing of the out-of-band plane respectively characterizes the policy routing of the switch and the interface direction to which it is bound; Constructing a switch configuration information table through the control status of the policy routing of the switch production plane, the out-of-band plane respectively, and the routing configuration; When the network device is a firewall, constructing the correspondence between the name of the network area and the address set of the network area, and constructing a firewall configuration information table according to the correspondence; When the network device is a router, constructing a router configuration information table; the router configuration information table includes at least a routing table and dedicated line channel configuration information.

4. The method according to claim 1, characterized in that, the generating of a formatted parameter table through a pre-constructed network area information table, a pre-constructed access relationship control matrix, a pre-constructed network device configuration information table, and the network access relationship requirements table includes: Initializing the pre-constructed network area information table, the pre-constructed access relationship control matrix, and the pre-constructed network device configuration information table; Dividing all IP addresses in the network access relationship requirements table according to the initialized network area information table to obtain the network types of all IP addresses and the logical network areas to which all IP addresses belong; Group all IP addresses according to the network type, the logical network area, and the access relationship demand behavior unit, obtaining the grouped source IP addresses and the grouped destination IP addresses; the source IP address is the source host IP address of the access relationship applied by the requester; the destination IP address is the destination host IP address of the access relationship applied by the requester. Use the grouped source IP addresses and the grouped destination IP addresses as the Cartesian product. Query the initialized network access relationship control matrix through the entries of the Cartesian product to determine the intermediate control network devices with access control for the entries of the Cartesian product and the control methods. According to the initialized network device configuration information table, check the control situation of the source-destination area related network devices and the intermediate control network devices with access control for the entries of the Cartesian product and the control methods, obtaining an inspection result; the inspection result represents whether the configuration information of the intermediate control network device or the source-destination area related network device allows the access relationship corresponding to the entry of the Cartesian product. When the inspection result is that the configuration information of the intermediate control network device or the source-destination area related network device does not allow the inspection result of the network access relationship, generate a parameter table; the parameter table at least includes a firewall parameter table, a switch policy routing parameter table, and a routing parameter table. Merge and deduplicate the parameter table to generate a formatted parameter table.

5. The method according to claim 1, wherein, The process of issuing the target command line includes: Log in to the network device through a preset login method. Issue the target command line through the network device to update the configuration of the network device, so as to establish a network access relationship for the requester to access the destination host from the source host.

6. A network access relationship processing system, wherein, The system includes: A first acquisition unit, configured to acquire a network access relationship requirement table; the network access relationship requirement is the access requirement of the requester from the source host to the port of the destination host. A first generation unit, configured to generate a formatted parameter table through a pre-constructed network area information table, a pre-constructed access relationship control matrix, a pre-constructed network device configuration information table, and the network access relationship requirement table. A second acquisition unit, configured to acquire the device name information in the parameter table. A third acquisition unit, configured to obtain the network device model corresponding to the device name information through a predefined network device information table. A second generation unit, configured to generate a script according to the network device model, the record information in the parameter table, and a preset command line, and convert the parameter table into a target command line through the script; the target command line is a command line matching the network device model. An issuing unit, configured to perform an issuing operation on the target command line; the issuing operation is used to update the configuration of the network device to establish a network access relationship for the requester to access the destination host from the source host.

7. The system according to claim 6, wherein, The first acquisition unit is specifically configured to: Obtain the network access relationship requirements and format them to generate a network access relationship requirements table.

8. The system according to claim 6, wherein, The first generation unit for constructing the configuration information table of the network device includes: The first construction module is used to collect the control situation and routing configuration of the policy routing of the production plane and the out-of-band plane of the switch respectively when the network device is a switch; the control situation of the policy routing of the out-of-band plane respectively characterizes the policy routing of the switch and the interface direction to which it is bound; through the control situation of the policy routing of the production plane and the out-of-band plane of the switch and the routing configuration, construct a switch configuration information table; The second construction module is used to construct the correspondence between the name of the network area and the address set of the network area when the network device is a firewall, and construct a firewall configuration information table according to the correspondence; The third construction module is used to construct a router configuration information table when the network device is a router; the router configuration information table includes at least a routing table and dedicated line channel configuration information.

9. A storage medium, wherein, The storage medium includes stored instructions, wherein when the instructions are running, the device where the storage medium is located is controlled to execute the network access relationship processing method according to any one of claims 1 to 5.

10. An electronic device, wherein, It includes a memory, and one or more instructions, wherein one or more instructions are stored in the memory and are configured to be executed by one or more processors to execute the network access relationship processing method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Enterprises network access authority control method and device

    CN106060041A

  • Establishment method and device of network access relationship, storage medium and equipment

    CN112039869A