A firewall security policy optimization method and related equipment

By obtaining the firewall's five-tuple information and network architecture relationships, firewall policies are optimized, solving the problem of policy cleanup affecting network services in existing technologies, and realizing automated optimization of security policies and stability of network services.

CN115987561BActive Publication Date: 2026-03-10WUHAN SIPU TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-30
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

Existing technologies cannot effectively avoid the impact of the cleanup process on network traffic when optimizing firewall policies, resulting in low administrator efficiency and security risks.

Method used

By obtaining the five-tuple information of security update policies and combining it with network architecture relationships, we can determine the historical security policies associated with them, and optimize firewall policies through network session monitoring information to ensure that network service access is not affected while slimming down the firewall.

Benefits of technology

This technology enables the automatic identification and removal of historical policies that do not affect network services when optimizing firewall policies, thereby avoiding network security risks and improving the operating efficiency and security of the firewall.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115987561B_ABST
    Figure CN115987561B_ABST
Patent Text Reader

Abstract

This application discloses a firewall security policy optimization method and related equipment. The method includes: obtaining five-tuple information corresponding to a security update policy; determining a historical security policy corresponding to the security update policy based on the five-tuple information and network architecture, wherein the historical security policy is the security policy corresponding to a situation where at least one element of the five-tuple information of the security update policy is identical; reducing the historical security policy to obtain network session monitoring information; and determining an optimization scheme for the firewall security policy based on the network session monitoring information. The firewall security policy optimization method provided in this application can automatically determine whether the cleanup of historical firewall security policies will affect access to actual services in the existing network. While slimming down the firewall, it can proactively avoid network security risks arising during the cleanup and optimization of firewall security policies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification pertains to the field of network security, and more specifically, this application relates to a firewall security policy optimization method and related devices. Background Technology

[0002] Existing security policy cleanup and optimization techniques mainly compare the target firewall policy with other firewall policies contained in the target firewall to determine whether the parameter information set of the target firewall policy is included in the parameter information set of other firewall policies contained in the target firewall. If the result is yes, the target firewall policy is determined to be a useless junk policy.

[0003] While this method can effectively solve the problem of existing optimization and inspection methods consuming a lot of time and effort for administrators, it cannot guarantee that the cleanup and optimization of firewall junk policies will not affect the access of actual business traffic in the network. Summary of the Invention

[0004] The summary section introduces a series of simplified concepts, which will be further explained in detail in the detailed description section. This summary section is not intended to limit the key and essential technical features of the claimed technical solution, nor is it intended to determine the scope of protection of the claimed technical solution.

[0005] Firstly, this application proposes a firewall security policy optimization method, the method comprising:

[0006] Retrieve the quintuple information corresponding to the security update policy;

[0007] Based on the above five-tuple information and network architecture relationship, determine the historical security policy corresponding to the above security update policy, wherein the above historical security policy is the security policy corresponding to the case where at least one element of the five-tuple information of the above security update policy is the same.

[0008] The aforementioned historical security policies were reduced to obtain network session monitoring information;

[0009] Based on the network session monitoring information mentioned above, an optimization scheme for the firewall security policy will be determined.

[0010] Optionally, the above methods also include:

[0011] Obtain configuration information for the target firewall and target interactive network devices;

[0012] Obtain service traffic information of the target interactive network;

[0013] The above network architecture relationship is constructed based on the configuration information and service traffic information.

[0014] Optionally, the aforementioned network session monitoring information includes information on the number of network sessions;

[0015] The optimization scheme for firewall security policies determined based on the aforementioned network session monitoring information includes:

[0016] If the number of network sessions remains unchanged after the aforementioned historical security policies are removed, the aforementioned historical security policies will be removed to optimize the firewall security policy.

[0017] Optionally, the aforementioned network session monitoring information includes network session traffic information;

[0018] The optimization scheme for firewall security policies determined based on the aforementioned network session monitoring information includes:

[0019] If the change value corresponding to the above network session traffic information is less than a preset threshold after the above historical security policies are removed, the above historical security policies will be removed to optimize the firewall security policy.

[0020] Optionally, the above methods also include:

[0021] When there are at least two historical security policies, the first degree of association between each historical security policy and the security update policy is obtained, wherein the first degree of association is determined based on the overlap of the five-tuple information of the historical security policy and the security update policy.

[0022] Obtain monitoring information for the first network session after deleting a single historical security policy;

[0023] The network impact of deleting each historical security policy is determined based on the aforementioned first degree of correlation and the aforementioned first network session monitoring information.

[0024] Based on the aforementioned network impact level, determine the optimization scheme for firewall security policies.

[0025] Optionally, the above methods also include:

[0026] When there are at least three historical security strategies, obtain the second degree of correlation among multiple historical security strategies;

[0027] Delete the historical security policies corresponding to each second degree of association to obtain the second network session monitoring information;

[0028] The network impact of deleting each group of historical security policies is determined based on the first degree of correlation, the second degree of correlation, and the second network session monitoring information.

[0029] Optionally, the above methods also include:

[0030] The aforementioned second network session monitoring information includes second network session quantity information and second network session traffic information. The aforementioned second network session quantity information corresponds to a first weight, and the aforementioned second network session traffic information corresponds to a second weight. The aforementioned first weight is greater than the aforementioned second weight.

[0031] The above determination of the network impact of deleting each group of historical security policies based on the first degree of correlation, the second degree of correlation, and the second network session monitoring information includes:

[0032] The network impact of deleting each group of historical security policies is determined based on the first degree of association, the second degree of association, the second number of network sessions, the second network session traffic, the first weight, and the second weight.

[0033] Secondly, this application also proposes a firewall security policy optimization device, comprising:

[0034] The first acquisition unit is used to acquire the five-tuple information corresponding to the security update policy;

[0035] The first determining unit is used to determine the historical security policy corresponding to the security update policy based on the above-mentioned five-tuple information and network architecture relationship, wherein the above-mentioned historical security policy is the security policy corresponding to the case where at least one element of the five-tuple information of the above-mentioned security update policy is the same.

[0036] The second acquisition unit is used to remove the aforementioned historical security policies to obtain network session monitoring information;

[0037] The second determining unit is used to determine the optimization scheme of the firewall security policy based on the aforementioned network session monitoring information.

[0038] Thirdly, an electronic device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program stored in the memory to implement the firewall security policy optimization method as described in any of the first aspects above.

[0039] Fourthly, this application also proposes a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the firewall security policy optimization method of any of the above claims in the first aspect.

[0040] In summary, the firewall security policy optimization method of this application includes: obtaining the five-tuple information corresponding to the security update policy; determining the historical security policy corresponding to the security update policy based on the five-tuple information and network architecture relationship, wherein the historical security policy is the security policy corresponding to the security update policy when at least one element of the five-tuple information is the same as that of the security update policy; deleting the historical security policy to obtain network session monitoring information; and determining the optimization scheme of the firewall security policy based on the network session monitoring information. The firewall security policy optimization method provided by this application determines the historical security policy associated with the security update policy through the five-tuple information, deletes the historical security policy, and obtains the access traffic and / or number of conversations of the actual business after deletion. It automatically determines whether the historical security policy of the firewall will affect the access of the actual business in the existing network after being cleaned up. While slimming down the firewall, it can avoid the network security risks generated during the cleanup and optimization of the firewall security policy in advance.

[0041] The firewall security policy optimization method proposed in this application, along with other advantages, objectives, and features of this application, will be partly apparent from the following description and partly understood by those skilled in the art through research and practice of this application. Attached Figure Description

[0042] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit this specification. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:

[0043] Figure 1 This application provides a schematic flowchart of a firewall security policy optimization method.

[0044] Figure 2 A schematic diagram of a firewall security policy optimization device provided in this application embodiment;

[0045] Figure 3 This is a schematic diagram of an electronic device structure for optimizing firewall security policies, provided in an embodiment of this application. Detailed Implementation

[0046] The firewall security policy optimization method provided in this application determines the historical security policy associated with the security update policy through the five-tuple information, deletes the historical security policy, and obtains the access traffic and / or number of conversations of the actual business after deletion. It automatically determines whether the cleanup of the firewall's historical security policy will affect the access of the actual business in the existing network. While slimming down the firewall, it can avoid the network security risks caused by the cleanup and optimization of firewall security policies in advance.

[0047] The terms "first," "second," "third," "fourth," etc. (if present) in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus. The technical solutions of the embodiments of this application will now be clearly and completely described in conjunction with the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them.

[0048] Please see Figure 1 This is a flowchart illustrating a firewall security policy optimization method provided in an embodiment of this application, which may specifically include:

[0049] S110. Obtain the quintuple information corresponding to the security update policy;

[0050] For example, a security update policy is a newly generated security policy that addresses the current firewall's vulnerabilities and other risks. It is used to fill the gaps in the current firewall. However, after updating the firewall with a security update policy, some of the protection policies may have overlapping protection functions. If the overlapping historical security policies are not cleaned up, the amount of data in the firewall will become extremely large after multiple security policy updates. Therefore, it is necessary to clean up redundant security policies in the firewall after the security policy is updated.

[0051] The method proposed in this application first obtains the five-tuple information corresponding to the security update policy. The five-tuple information includes the source IP address, source port, destination IP address, destination port, and transport layer protocol. The source IP address, source port, destination IP address, destination port, and transport layer protocol form a set. For example, 192.168.1.1 10000TCP 121.14.88.76 80 constitutes a five-tuple. This means that a terminal with IP address 192.168.1.1 connects to a terminal with IP address 121.14.88.76 on port 80 via port 10000 using the TCP protocol.

[0052] S120. Determine the historical security policy corresponding to the security update policy based on the above five-tuple information and network architecture relationship, wherein the above historical security policy is the security policy corresponding to the case where at least one element of the five-tuple information of the above security update policy is the same.

[0053] For example, network architecture relationships refer to the hardware connection relationships between routers corresponding to firewalls and the inherent logical relationships between firewalls. Historical security policies refer to the security policies that, when the firewalls had not updated the aforementioned security update policies, contained at least one element of the five-tuple information identical to the aforementioned security update policies. In other words, at least one of the source IP address, source port, destination IP address, destination port, and transport layer protocol in the historical security policy is identical to the security update policy.

[0054] S130. Reduce the above-mentioned historical security policies to obtain network session monitoring information;

[0055] For example, security policies are reduced, and network session monitoring information is obtained after the reduction. It should be noted that when there are multiple historical security policies, each policy can be reduced individually before obtaining network session monitoring information, or multiple historical security policies can be deleted simultaneously before obtaining network session monitoring information. Network session monitoring information can include the number of network sessions and network session traffic change information. Traffic change information includes changes in total traffic volume and traffic rate. In other words, by monitoring network sessions, it can be determined whether reducing one or more historical security policies will affect network sessions.

[0056] S140. Determine the optimization scheme for the firewall security policy based on the above network session monitoring information.

[0057] For example, when determining an optimization scheme for firewall policies based on network session monitoring information, if the network session monitoring information does not change after deleting certain historical security policies, then these historical security policies can be deleted after loading the security update policy. However, if the number of network sessions and / or the network session traffic information changes, then the historical security policy cannot be deleted, otherwise it will affect normal network sessions.

[0058] In summary, the firewall security policy optimization method provided in this application determines the historical security policy associated with the security update policy through the five-tuple information, deletes the historical security policy, and obtains the access traffic and / or number of conversations of the actual business after deletion. It automatically determines whether the cleanup of the firewall's historical security policy will affect the access of the actual business in the existing network. While slimming down the firewall, it can avoid network security risks caused by the cleanup and optimization of firewall security policies in advance.

[0059] In some examples, the above method also includes:

[0060] Obtain configuration information for the target firewall and target interactive network devices;

[0061] Obtain service traffic information of the target interactive network;

[0062] The above network architecture relationship is constructed based on the configuration information and service traffic information.

[0063] For example, a firewall consists of a firewall software system and network interaction devices that support the software system. By obtaining the configuration information of the software system and the interacting network devices, as well as the traffic information in the network, the logical relationships between various network devices and between the firewall software system can be determined, thereby establishing the network architecture relationship.

[0064] In some examples, the network session monitoring information mentioned above includes information on the number of network sessions;

[0065] The optimization scheme for firewall security policies determined based on the aforementioned network session monitoring information includes:

[0066] If the number of network sessions remains unchanged after the aforementioned historical security policies are removed, the aforementioned historical security policies will be removed to optimize the firewall security policy.

[0067] For example, network session monitoring information includes the number of network sessions. Firewall configuration policies may include whitelists for certain network services. Only clients on the whitelist can complete the corresponding network session. If a historical security policy containing this whitelist is removed, and the updated security policy does not include the corresponding whitelist, then clients on the whitelist will be unable to complete the corresponding network session service, thus reducing the number of network sessions. Firewall configuration policies may also include blacklists. When a blacklist in a historical security policy is removed, and the updated security policy does not include this blacklist, it will lead to a significant increase in unauthorized network session access. Only historical security policies that have been removed should be cleaned up when optimizing firewall security policies if the number of network sessions has not changed.

[0068] In summary, the firewall security policy optimization method provided in this application can determine a reasonable firewall security policy by monitoring the number of network sessions and judging whether the deletion of historical security policies is reasonable.

[0069] In some examples, the network session monitoring information mentioned above includes network session traffic information;

[0070] The optimization scheme for firewall security policies determined based on the aforementioned network session monitoring information includes:

[0071] If the change value corresponding to the above network session traffic information is less than a preset threshold after the above historical security policies are removed, the above historical security policies will be removed to optimize the firewall security policy.

[0072] For example, network session monitoring information also includes network session traffic information. If the change in network session traffic is small after a certain historical security policy is deleted, i.e. less than the preset threshold, it means that deleting the historical security policy will not affect the current network switching status, and the deleted historical security policy is reasonable.

[0073] In some examples, the above method also includes:

[0074] When there are at least two historical security policies, the first degree of association between each historical security policy and the security update policy is obtained, wherein the first degree of association is determined based on the overlap of the five-tuple information of the historical security policy and the security update policy.

[0075] Obtain monitoring information for the first network session after deleting a single historical security policy;

[0076] The network impact of deleting each historical security policy is determined based on the aforementioned first degree of correlation and the aforementioned first network session monitoring information.

[0077] Based on the aforementioned network impact level, determine the optimization scheme for firewall security policies.

[0078] For example, in the above embodiments, the historical security policy determined is a security policy that shares at least one of the five-tuple information with the security update policy. There may be multiple five-tuple information entries in the historical security policy that are identical to the security update policy. Therefore, a first degree of association is determined based on the overlap between the historical security policy and the aforementioned security update policy five-tuple information. The higher the degree of association, the lower the risk of network fluctuations after deletion. Then, based on the first degree of association from low to high, the corresponding historical security policies are deleted one by one, and the first network session monitoring information after deletion is obtained. The deletion of historical security policies is stopped when the change in the first network session monitoring information exceeds a preset range. Historical security policies whose changes in the first network session monitoring information do not exceed the preset range are deleted and designated as the current optimization scheme. This will not affect the normal operation of network sessions, and the firewall's security policy has been simplified.

[0079] In some examples, the above method also includes:

[0080] When there are at least three historical security strategies, obtain the second degree of correlation among multiple historical security strategies;

[0081] Delete the historical security policies corresponding to each second degree of association to obtain the second network session monitoring information;

[0082] The network impact of deleting each group of historical security policies is determined based on the first degree of correlation, the second degree of correlation, and the second network session monitoring information.

[0083] For example, when there are multiple historical security policies, there will be a second degree of correlation between them, that is, the relationship between the five-tuple information of multiple historical security policies. The higher the degree of correlation, the greater the impact on the network when deleting multiple historical security policies together. As can be seen from the above embodiments, the degree of overlap between the historical security policies and the five-tuple information of the security update policies determines the first degree of correlation. The higher the degree of correlation, the lower the risk of network fluctuations after deletion. Therefore, when deleting historical security policies, multiple historical security policies are deleted according to the first degree of correlation from low to high and the second degree of correlation from high to low to obtain second network session monitoring information. The second network session monitoring information after deletion is obtained until the change of the second network session monitoring information exceeds a preset range. Then, the deletion of historical security policies is stopped, and the historical security policies whose changes of the second network session monitoring information do not exceed the preset range are deleted. This is defined as the current optimization scheme.

[0084] In some examples, the above method also includes:

[0085] The aforementioned second network session monitoring information includes second network session quantity information and second network session traffic information. The aforementioned second network session quantity information corresponds to a first weight, and the aforementioned second network session traffic information corresponds to a second weight. The aforementioned first weight is greater than the aforementioned second weight.

[0086] The above determination of the network impact of deleting each group of historical security policies based on the first degree of correlation, the second degree of correlation, and the second network session monitoring information includes:

[0087] The network impact of deleting each group of historical security policies is determined based on the first degree of association, the second degree of association, the second number of network sessions, the second network session traffic, the first weight, and the second weight.

[0088] For example, the second network session monitoring information includes the number of second network sessions and the traffic information of second network sessions, ensuring that the importance of the number of sessions is higher than that of the traffic. In this embodiment, when obtaining the second network session monitoring information by deleting multiple historical security policies according to a first correlation degree from low to high and a second correlation degree from high to low, the second network session monitoring information is weighted and scored using a first weight corresponding to the number of second network sessions and a second weight corresponding to the traffic information of the second network sessions.

[0089] This allows us to obtain the combined impact of deleting multiple historical security policies on the number of network sessions and network session traffic, resulting in a more objective and accurate assessment of the network impact of deleting each set of historical security policies.

[0090] Please see Figure 2 One embodiment of the firewall security policy optimization device in this application may include:

[0091] The first acquisition unit 21 is used to acquire the five-tuple information corresponding to the security update policy;

[0092] The first determining unit 22 is used to determine the historical security policy corresponding to the security update policy based on the above-mentioned five-tuple information and network architecture relationship, wherein the above-mentioned historical security policy is the security policy corresponding to the case where at least one element of the five-tuple information of the security update policy is the same as that of the security update policy.

[0093] The second acquisition unit 23 is used to delete the above-mentioned historical security policies to obtain network session monitoring information.

[0094] The second determining unit 24 is used to determine the optimization scheme of the firewall security policy based on the above network session monitoring information.

[0095] like Figure 3 As shown, this application embodiment also provides an electronic device 300, including a memory 310, a processor 320, and a computer program 311 stored in the memory 320 and executable on the processor. When the processor 320 executes the computer program 311, it implements the steps of any of the above-mentioned firewall security policy optimization methods.

[0096] Since the electronic device described in this embodiment is the device used to implement the firewall security policy optimization device in the embodiments of this application, the art can be applied based on the method described in the embodiments of this application.

[0097] Those skilled in the art can understand the specific implementation methods and various variations of the electronic device in this embodiment. Therefore, 5 will not describe in detail how the electronic device implements the method in this application embodiment. Any equipment used by those skilled in the art to implement the method in this application embodiment is within the scope of protection of this application.

[0098] In practical implementation, when the computer program 311 is executed by the processor, it can achieve the following: Figure 1 Any of the corresponding implementation methods in the embodiments.

[0099] It should be noted that in the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0100] Those skilled in the art will understand that the embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can be implemented as a completely hardware embodiment, a completely software embodiment, or a combination of hardware and software.

[0101] The application can take the form of embodiments in terms of components and hardware. Furthermore, it can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0102] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create a machine for implementing the flowchart illustrations. Figure 1One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0103] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to operate in a specific manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0104] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0105] This application also provides a computer program product, which includes computer software instructions. When the computer software instructions are executed on a processing device, the processing device performs the firewall security policy optimization process in the corresponding embodiment, including:

[0106] Retrieve the quintuple information corresponding to the security update policy;

[0107] Based on the above five-tuple information and network architecture relationship, determine the historical security policy corresponding to the above security update policy, wherein the above historical security policy is the security policy corresponding to the case where at least one element of the five-tuple information of the above security update policy is the same.

[0108] The aforementioned historical security policies were reduced to obtain network session monitoring information;

[0109] Based on the network session monitoring information mentioned above, an optimization scheme for the firewall security policy will be determined.

[0110] In some embodiments, the above method further includes:

[0111] Obtain configuration information for the target firewall and target interactive network devices;

[0112] Obtain service traffic information of the target interactive network;

[0113] The above network architecture relationship is constructed based on the configuration information and service traffic information.

[0114] In some implementations, the network session monitoring information mentioned above includes network session quantity information;

[0115] The optimization scheme for firewall security policies determined based on the aforementioned network session monitoring information includes:

[0116] If the number of network sessions remains unchanged after the aforementioned historical security policies are removed, the aforementioned historical security policies will be removed to optimize the firewall security policy.

[0117] In some implementations, the aforementioned network session monitoring information includes network session traffic information;

[0118] The optimization scheme for firewall security policies determined based on the aforementioned network session monitoring information includes:

[0119] If the change value corresponding to the above network session traffic information is less than a preset threshold after the above historical security policies are removed, the above historical security policies will be removed to optimize the firewall security policy.

[0120] In some embodiments, the above method further includes:

[0121] When there are at least two historical security policies, the first degree of association between each historical security policy and the security update policy is obtained, wherein the first degree of association is determined based on the overlap of the five-tuple information of the historical security policy and the security update policy.

[0122] Obtain monitoring information for the first network session after deleting a single historical security policy;

[0123] The network impact of deleting each historical security policy is determined based on the aforementioned first degree of correlation and the aforementioned first network session monitoring information.

[0124] Based on the aforementioned network impact level, determine the optimization scheme for firewall security policies.

[0125] In some embodiments, the above method further includes:

[0126] When there are at least three historical security strategies, obtain the second degree of correlation among multiple historical security strategies;

[0127] Delete the historical security policies corresponding to each second degree of association to obtain the second network session monitoring information;

[0128] The network impact of deleting each group of historical security policies is determined based on the first degree of correlation, the second degree of correlation, and the second network session monitoring information.

[0129] In some embodiments, the above method further includes:

[0130] The aforementioned second network session monitoring information includes second network session quantity information and second network session traffic information. The aforementioned second network session quantity information corresponds to a first weight, and the aforementioned second network session traffic information corresponds to a second weight. The aforementioned first weight is greater than the aforementioned second weight.

[0131] The above determination of the network impact of deleting each group of historical security policies based on the first degree of correlation, the second degree of correlation, and the second network session monitoring information includes:

[0132] The network impact of deleting each group of historical security policies is determined based on the first degree of association, the second degree of association, the second number of network sessions, the second network session traffic, the first weight, and the second weight.

[0133] A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium that a computer can store or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).

[0134] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0135] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, or indirect coupling or communication connection between apparatuses or units, and may be electrical, mechanical, or other forms.

[0136] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0137] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0138] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0139] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A method of firewall security policy optimization, characterized by, The method comprises: obtaining five-tuple information corresponding to a security update policy; determining a historical security policy corresponding to the security update policy according to the five-tuple information and a network architecture relationship, wherein the historical security policy is a security policy corresponding to a case where at least one element information of the five-tuple information of the security update policy is the same; pruning the historical security policy to obtain network session monitoring information; determining an optimization scheme of a firewall security policy according to the network session monitoring information; in a case where there are at least two historical security policies, obtaining a first correlation degree of each historical security policy with the security update policy, wherein the first correlation degree is determined based on a coincidence degree of the five-tuple information of the historical security policy and the security update policy; obtaining first network session monitoring information after a single historical security policy is deleted; determining a network impact degree after deletion of each historical security policy according to the first correlation degree and the first network session monitoring information; determining an optimization scheme of a firewall security policy according to the network impact degree; in a case where there are at least three historical security policies, obtaining a second correlation degree between a plurality of historical security policies; deleting the historical security policy corresponding to each second correlation degree to obtain second network session monitoring information; determining a network impact degree after deletion of each group of historical security policies according to the first correlation degree, the second correlation degree and the second network session monitoring information; wherein the plurality of historical security policies are deleted according to the first correlation degree from low to high and the second correlation degree from high to low.

2. The method of claim 1, wherein, The method further comprises: obtaining configuration information of a target firewall and a target interactive network device; obtaining service traffic information of a target interactive network; constructing the network architecture relationship according to the configuration information and the service traffic information.

3. The method of claim 1, wherein, The network session monitoring information comprises network session quantity information. The method of determining an optimization scheme of a firewall security policy according to the network session monitoring information comprises: in a case where the network session quantity information does not change after the historical security policy is pruned, the historical security policy is pruned to optimize the firewall security policy.

4. The method of claim 3, wherein, The network session monitoring information comprises network session traffic information. The method of determining an optimization scheme of a firewall security policy according to the network session monitoring information comprises: in a case where a change value corresponding to the network session traffic information is less than a preset threshold after the historical security policy is pruned, the historical security policy is pruned to optimize the firewall security policy.

5. The method of claim 1, wherein, The method further comprises: the second network session monitoring information comprises second network session quantity information and second network session traffic information, the second network session quantity information corresponds to a first weight, the second network session traffic information corresponds to a second weight, and the first weight is greater than the second weight; the method of determining a network impact degree after deletion of each group of historical security policies according to the first correlation degree, the second correlation degree and the second network session monitoring information comprises: The network influence degree after each group of historical security policies is deleted is determined according to the first correlation degree, the second correlation degree, the second network session quantity information, the second network session traffic information, the first weight and the second weight.

6. A firewall security policy optimization apparatus for implementing the firewall security policy optimization method according to any one of claims 1 to 5, characterized by, Comprise: A first obtaining unit, configured to obtain five-tuple information corresponding to a security update policy; A first determining unit, configured to determine a historical security policy corresponding to the security update policy according to the five-tuple information and a network architecture relationship, wherein the historical security policy is a security policy corresponding to a case in which at least one element information of the five-tuple information of the security update policy is the same; A second obtaining unit, configured to obtain network session monitoring information by pruning the historical security policy; A second determining unit, configured to determine an optimization scheme of a firewall security policy according to the network session monitoring information.

7. An electronic device comprising: A memory and a processor, wherein the processor is configured to implement the steps of the firewall security policy optimization method according to any one of claims 1-5 when executing a computer program stored in the memory.

8. A computer readable storage medium having stored thereon a computer program, characterized in that: The computer program is executed by the processor to implement the firewall security policy optimization method according to any one of claims 1-5.

Citation Information

Patent Citations

  • Security strategy control method and device

    CN104735026A

  • Network safety management method and system based on firewall

    CN105471618A