Rule base upgrading method, device, electronic device and storage medium

By determining and upgrading the rule base of the security gateway, the problem that security gateways in the prior art is difficult to accurately identify the user server application type, and the streamlining of the rule base and improving detection efficiency are achieved.

CN116016174BActive Publication Date: 2025-06-06BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211691182.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-27
Publication Date
2025-06-06
Estimated Expiration
2042-12-27

AI Technical Summary

Technical Problem

When detecting and defending against cyber attacks, existing security gateways find it difficult to accurately identify the application types used by the user server, resulting in too large rule bases, degradation in performance, and possible incorrectly intercepting normal traffic.

Method used

By determining the application used by the protected URL and downloading the application list from the rule server based on the preset time, a display interface is generated for the user to select the target application, thereby generating a customized second application list for upgrading the local rule library.

Benefits of technology

It realizes the accurate identification of protected URL applications by the security gateway, reduces the size of the rule base, improves detection efficiency, and avoids the risk of accidentally intercepting normal traffic.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116016174B_ABST
    Figure CN116016174B_ABST
Patent Text Reader

Abstract

The present application provides a rule base upgrade method, device, electronic device and storage medium, wherein the rule base upgrade method includes: determining the application used by the protected website; downloading a first application list from a rule server based on a preset periodic time; detecting the upgrade option selected by the user, wherein when the upgrade option is a customized rule base upgrade option, a display interface is generated based on the first application list, so that the user selects a target application based on the display interface; the application used by the protected website is set to a selected state in the display interface; when the user completes the selection, a second application list is generated; and the local rule base is upgraded based on the second application list. The present application enables the security gateway to have corresponding rules to detect the traffic sent to the application used by the protected website, and improves the detection efficiency of the security gateway.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a rule base upgrading method, device, electronic device and storage medium. Background Art

[0002] The web protection module of the security gateway mainly relies on WAF rules to detect whether there are attacks in the traffic communicating with the web server. WAF rules are divided into general rules and application rules. General rules are used to defend against all types of web applications, and application rules are used to defend against corresponding web applications. The number of WAF rules will affect the attack detection capability and the performance of the firewall device.

[0003] Currently, many security vendors will select all applications and use the most popular rules, and then let users choose the corresponding application rules. In most cases, users do not know which application their web servers are built with, so they do not know which application rules to choose. The following situations will occur: 1. If users select all application rules, device performance will decline, and normal traffic may also be blocked; 2. If users select rules for individual applications, the selected application may be inconsistent with the application corresponding to their own server, resulting in many attacks not being blocked. Summary of the invention

[0004] The purpose of the embodiments of the present application is to provide a rule library upgrade method, device, electronic device and storage medium, so that the security gateway has corresponding rules to detect the traffic sent to the application used by the protected website and improve the detection efficiency of the security gateway.

[0005] In a first aspect, the present invention provides a rule base upgrade method, the method is applied to a security gateway, the method comprising:

[0006] Determine the application used by the protected URL;

[0007] Downloading a first application list from a rule server based on a preset periodic time;

[0008] detecting an upgrade option selected by a user, wherein when the upgrade option is a customized rule base upgrade option, generating a display interface based on the first application list, so that the user selects a target application based on the display interface;

[0009] Setting the application used by the protected website to a selected state in the display interface;

[0010] When the user has completed the selection, generating a second application list;

[0011] The local rule base is updated based on the second application list.

[0012] In the first aspect of the present application, by determining the applications used by the protected URL, downloading a first application list from a rule server based on a preset periodic time, and detecting the upgrade option selected by the user, when the upgrade option is a customized rule library upgrade option, a display interface is generated based on the first application list, so that the user can select the target application based on the display interface, and the application used by the protected URL can be set to a selected state in the display interface. When the user has completed the selection, a second application list can be generated, so that the local rule library can be upgraded based on the second application list.

[0013] Compared with the prior art, since the second application list includes the applications used by the protected website, the gateway can have corresponding rules to detect the traffic sent to the applications used by the protected website. At the same time, through the display interface, the user can customize the rule base used by the gateway, so as to avoid the gateway downloading all the rules to meet the user's needs, thereby reducing the size of the rule base in the gateway and improving the detection efficiency of the gateway.

[0014] In an optional implementation manner, the updating of the local rule base based on the second application list includes:

[0015] Sending the second application list to the rule server, so that the rule server aggregates all rules based on the second application list and generates a rule package;

[0016] The rule package sent by the rule server is received, and the local rule base is updated based on the rule package.

[0017] In the above optional implementation, by sending the second application list to the rule server, the rule server can summarize all rules and generate a rule package based on the second application list, and then by receiving the rule package sent by the rule server, the local rule base can be upgraded based on the rule package.

[0018] In an optional implementation manner, before sending the second application list to the rule server, the method further includes:

[0019] Get the current system time;

[0020] It is determined whether the current system time is the rule base upgrade time. If the current system time is the rule base upgrade time, the upgrade of the local rule base based on the second application list is triggered.

[0021] In the above optional implementation, by obtaining the current system time, it is possible to determine whether the current system time is the rule base upgrade time, and when the current system time is the rule base upgrade time, the upgrade of the local rule base based on the second application list is triggered.

[0022] In an optional implementation, the rule package includes general rules and application rules, wherein the general rules are rules applicable to all applications, and the application rules are rules applicable to specific applications.

[0023] In an optional implementation, since the rule package includes common rules and application rules, all rules required by the application can be updated.

[0024] In a second aspect, the present invention provides a rule base upgrade device, which is applied to a security gateway, and the device includes:

[0025] A determination module, used for determining an application used by a protected URL;

[0026] A download module, configured to download the first application list from the rule server based on a preset regular time;

[0027] a detection module, configured to detect an upgrade option selected by a user, wherein when the upgrade option is a customized rule base upgrade option, a display interface is generated based on the first application list, so that the user selects a target application based on the display interface;

[0028] A processing module, used for setting the application used by the protected website to a selected state in the display interface;

[0029] A generating module, used for generating a second application list when the user completes the selection;

[0030] An upgrading module is used to upgrade the local rule base based on the second application list.

[0031] The device of the second aspect of the present application can determine the application used by the protected website, download the first application list from the rule server based on a preset periodic time, and detect the upgrade option selected by the user by executing the rule base upgrade method, and then when the upgrade option is a customized rule base upgrade option, a display interface can be generated based on the first application list to enable the user to select the target application based on the display interface, and then the application used by the protected website can be set to a selected state in the display interface, and then when the user has completed the selection, a second application list can be generated, so that the local rule base can be upgraded based on the second application list.

[0032] Compared with the prior art, since the second application list includes the applications used by the protected website, the gateway can have corresponding rules to detect the traffic sent to the applications used by the protected website. At the same time, through the display interface, the user can customize the rule base used by the gateway, so as to avoid the gateway downloading all the rules to meet the user's needs, thereby reducing the size of the rule base in the gateway and improving the detection efficiency of the gateway.

[0033] In an optional implementation, the upgrade module includes:

[0034] a sending submodule, configured to send the second application list to the rule server, so that the rule server aggregates all rules based on the second application list and generates a rule package;

[0035] The receiving submodule is used to receive the rule package sent by the rule server and update the local rule base based on the rule package.

[0036] In the above optional implementation, by sending the second application list to the rule server, the rule server can summarize all rules and generate a rule package based on the second application list, and then by receiving the rule package sent by the rule server, the local rule base can be upgraded based on the rule package.

[0037] In an optional embodiment, the device further comprises:

[0038] an acquisition submodule, configured to acquire the current system time before sending the second application list to the rule server;

[0039] The judgment submodule is used to judge whether the current system time is the rule base upgrade time. If the current system time is the rule base upgrade time, it triggers the execution of the upgrade of the local rule base based on the second application list.

[0040] In the above optional implementation, by obtaining the current system time, it is possible to determine whether the current system time is the rule base upgrade time, and when the current system time is the rule base upgrade time, the upgrade of the local rule base based on the second application list is triggered.

[0041] In an optional implementation, the rule package includes general rules and application rules, wherein the general rules are rules applicable to all applications, and the application rules are rules applicable to specific applications.

[0042] In an optional implementation, since the rule package includes common rules and application rules, all rules required by the application can be updated.

[0043] In a third aspect, the present invention provides an electronic device, comprising:

[0044] Processor; and

[0045] The memory is configured to store machine-readable instructions, and when the instructions are executed by the processor, the rule base upgrading method as described in any one of the aforementioned implementations is executed.

[0046] The electronic device of the third aspect of the present application can determine the application used by the protected website, download the first application list from the rule server based on a preset periodic time, and detect the upgrade option selected by the user by executing the rule base upgrade method, and then, when the upgrade option is a customized rule base upgrade option, generate a display interface based on the first application list, so that the user can select the target application based on the display interface, and then set the application used by the protected website to a selected state in the display interface, and then when the user completes the selection, generate a second application list, so that the local rule base can be upgraded based on the second application list.

[0047] Compared with the prior art, since the second application list includes the applications used by the protected website, the gateway can have corresponding rules to detect the traffic sent to the applications used by the protected website. At the same time, through the display interface, the user can customize the rule base used by the gateway, so as to avoid the gateway downloading all the rules to meet the user's needs, thereby reducing the size of the rule base in the gateway and improving the detection efficiency of the gateway.

[0048] In a fourth aspect, the present invention provides a storage medium storing a computer program, wherein the computer program is executed by a processor to perform a rule base upgrading method as described in any one of the aforementioned implementations.

[0049] The storage medium of the fourth aspect of the present application can determine the application used by the protected website by executing the rule base upgrade method, download the first application from the rule server based on the preset regular time,

[0050] list and detect the upgrade option selected by the user, and then when the upgrade option is a customized rule base 5 upgrade option, a display interface is generated based on the first application list, so that the user can

[0051] The display interface selects the target application, and then the application used by the protected website can be set to a selected state in the display interface. When the user completes the selection, a second application list can be generated, so that the local rule library can be updated based on the second application list.

[0052] Compared with the prior art, since the second application list includes the applications used by the protected website, the gateway can have corresponding rules to detect the traffic sent to the applications used by the protected website. At the same time, through the display interface, the user can customize the rule base used by the gateway, so that the gateway can avoid downloading all the rules to meet user needs, thereby reducing the size of the rule base in the gateway and improving the detection efficiency of the gateway. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] In order to more clearly illustrate the technical solution of the embodiment of the present application, the following is a description of the embodiment of the present application.

[0054] The accompanying drawings required for use are briefly introduced. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0055] Figure 1 It is a flowchart of a rule base upgrade method disclosed in an embodiment of the present application;

[0056] Figure 2 It is a structural schematic diagram of a rule base upgrading device disclosed in an embodiment of the present application;

[0057] Figure 3 It is a structural schematic diagram of an electronic device disclosed in an embodiment of the present application. DETAILED DESCRIPTION

[0058] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0059] Embodiment 1

[0060] See also Figure 1 , Figure 1 1 is a flow chart of a rule base upgrade method disclosed in an embodiment of the present application, wherein the method of the embodiment of the present application is applied to a security gateway. Figure 1 As shown, the method of the embodiment of the present application includes the following steps:

[0061] 101. Determine the application used by the protected URL;

[0062] 102. Downloading a first application list from a rule server based on a preset regular time;

[0063] 103. Detecting an upgrade option selected by the user, wherein when the upgrade option is a customized rule base upgrade option, generating a display interface based on the first application list, so that the user selects a target application based on the display interface;

[0064] 104. In the display interface, set the application used by the protected URL to a selected state;

[0065] 105. When the user completes the selection, a second application list is generated;

[0066] 106. Update the local rule base based on the second application list.

[0067] In an embodiment of the present application, by determining the application used by the protected URL, downloading the first application list from the rule server based on a preset periodic time, and detecting the upgrade option selected by the user, when the upgrade option is a customized rule base upgrade option, a display interface is generated based on the first application list, so that the user can select the target application based on the display interface, and then the application used by the protected URL can be set to a selected state in the display interface, and then when the user has completed the selection, a second application list can be generated, so that the local rule base can be upgraded based on the second application list.

[0068] Compared with the prior art, since the second application list includes the applications used by the protected website, the gateway can have corresponding rules to detect the traffic sent to the applications used by the protected website. At the same time, through the display interface, the user can customize the rule base used by the gateway, so as to avoid the gateway downloading all the rules to meet the user's needs, thereby reducing the size of the rule base in the gateway and improving the detection efficiency of the gateway.

[0069] In the embodiment of the present application, as an example, it is assumed that there are rules for different applications such as application A, application B, and application N on the rule server, and it is assumed that the user uses application A to build a web server. At this time, if the rule base of all applications provided to the user is a "standard rule base", since the user himself does not know which application the web server uses, the user may select all applications or some applications. Among them, if the user selects all applications, the number of rules loaded by the security gateway will increase, resulting in a decrease in the performance of the security gateway. At the same time, some types of application rules do not match the application corresponding to the current server, and some normal traffic of the application may be mistakenly matched; if the user selects some types of applications, the application of the web server itself may not match the selected application rules, resulting in the risk of missing the interception of attacks of this type of application.

[0070] In comparison, if the method of the embodiment of the present application is adopted, first, the security gateway can discover the applications existing in the protected website, and then help the user to understand the applications used by the web server used by the user, so as to avoid the user missing the rules for selecting necessary applications. Second, the user can choose "custom rule library", that is, choose to upgrade the custom rule library. The security gateway can recommend which applications the user should select based on the results of identifying the application, and then download the corresponding rules for defense. In this way, the web server used by the user can use the corresponding application type rules for defense, ensuring that all attacks of the application can be intercepted and no false alarms will be generated. In addition, the waf engine loads fewer rules, and the performance of the waf engine will be significantly improved.

[0071] In the embodiment of the present application, with respect to step 101, the protected website refers to the address of the protected web server, and accordingly, the application used by the protected website is the application used by the web server. On the other hand, the application may refer to a web application.

[0072] In the embodiment of the present application, with respect to step 101, a specific method of determining the application used by the protected website is to analyze the message of the web application to know the application used by the web server.

[0073] In the embodiment of the present application, for step 102, the preset regular time may be once a week or once a day, and the embodiment of the present application does not limit this.

[0074] In the embodiment of the present application, with respect to 102, the first application list includes the names of multiple applications, for example, the name of application A and the name of application B. Accordingly, there are options for application A and application B in the display page.

[0075] In the embodiment of the present application, for step 103, the upgrade options include a customized rule base upgrade option and a table standard upgrade option, wherein the standard upgrade option indicates downloading all rules.

[0076] In the embodiment of the present application, with respect to step 104, in the display interface, the state of each application includes an unselected state and a selected state. For example, when the check box where the application is located is checked, the application is in the selected state.

[0077] In the embodiment of the present application, with respect to step 105 , the second application list is composed of the names of all applications selected by the user. For example, when the user selects application A and application B, the second application list includes the names of application A and application B.

[0078] It should be noted that the rules of the embodiment of the present application are security policy information for detecting traffic. In addition, the application of the embodiment of the present application may refer to a web application.

[0079] In an optional implementation, step 106: Updating the local rule base based on the second application list includes the following sub-steps:

[0080] Sending the second application list to the rule server, so that the rule server aggregates all rules based on the second application list and generates a rule package;

[0081] Receive the rule package sent by the rule server and update the local rule base based on the rule package.

[0082] In the above optional implementation, by sending the second application list to the rule server, the rule server can summarize all rules based on the second application list and generate a rule package, and then by receiving the rule package sent by the rule server, the local rule base can be upgraded based on the rule package.

[0083] In an optional implementation manner, before the step of sending the second application list to the rule server, the method of the embodiment of the present application further includes the following steps:

[0084] Get the current system time;

[0085] It is determined whether the current system time is the rule base upgrade time. If the current system time is the rule base upgrade time, the upgrade of the local rule base based on the second application list is triggered.

[0086] In the above optional implementation, by obtaining the current system time, it is possible to determine whether the current system time is the rule base upgrade time, and when the current system time is the rule base upgrade time, it triggers the execution of upgrading the local rule base based on the second application list.

[0087] In an optional implementation, the rule package includes general rules and application rules, wherein the general rules are rules applicable to all applications, and the application rules are rules applicable to specific applications.

[0088] In an optional implementation, since the rule package includes common rules and application rules, all rules required by the application can be updated.

[0089] Embodiment 2

[0090] See also Figure 2 , Figure 2 is a schematic diagram of a structure of a rule base upgrade device disclosed in an embodiment of the present application, wherein the device is applied to a security gateway, such as Figure 2 As shown, the device of the embodiment of the present application includes the following functional modules:

[0091] A determination module 201 is used to determine the application used by the protected website;

[0092] A download module 202, configured to download a first application list from a rule server based on a preset periodic time;

[0093] A detection module 203 is used to detect the upgrade option selected by the user, wherein when the upgrade option is a customized rule base upgrade option, a display interface is generated based on the first application list, so that the user selects a target application based on the display interface;

[0094] Processing module 204, used to set the application used by the protected website to a selected state in the display interface;

[0095] A generating module 205, used for generating a second application list when the user has completed the selection;

[0096] The upgrading module 206 is configured to upgrade the local rule base based on the second application list.

[0097] The device of the embodiment of the present application can determine the application used by the protected website, download the first application list from the rule server based on a preset periodic time, and detect the upgrade option selected by the user by executing the rule base upgrade method, and then, when the upgrade option is a customized rule base upgrade option, generate a display interface based on the first application list, so that the user can select the target application based on the display interface, and then set the application used by the protected website to a selected state in the display interface, and then when the user completes the selection, generate a second application list, so that the local rule base can be upgraded based on the second application list.

[0098] Compared with the prior art, since the second application list includes the applications used by the protected website, the gateway can have corresponding rules to detect the traffic sent to the applications used by the protected website. At the same time, through the display interface, the user can customize the rule base used by the gateway, so as to avoid the gateway downloading all the rules to meet the user's needs, thereby reducing the size of the rule base in the gateway and improving the detection efficiency of the gateway.

[0099] In an optional implementation manner, the upgrade module of the embodiment of the present application includes the following sub-functional modules:

[0100] A sending submodule, used for sending the second application list to the rule server, so that the rule server aggregates all rules based on the second application list and generates a rule package;

[0101] The receiving submodule is used to receive the rule package sent by the rule server and upgrade the local rule base based on the rule package.

[0102] In the above optional implementation, by sending the second application list to the rule server, the rule server can summarize all rules based on the second application list and generate a rule package, and then by receiving the rule package sent by the rule server, the local rule base can be upgraded based on the rule package.

[0103] In an optional implementation manner, the device of the embodiment of the present application further includes the following functional modules:

[0104] An acquisition submodule, used for acquiring the current system time before sending the second application list to the rule server;

[0105] The judgment submodule is used to judge whether the current system time is the rule base upgrade time. If the current system time is the rule base upgrade time, it triggers the execution of upgrading the local rule base based on the second application list.

[0106] In the above optional implementation, by obtaining the current system time, it is possible to determine whether the current system time is the rule base upgrade time, and when the current system time is the rule base upgrade time, it triggers the execution of upgrading the local rule base based on the second application list.

[0107] In an optional implementation, the rule package includes general rules and application rules, wherein the general rules are rules applicable to all applications, and the application rules are rules applicable to specific applications.

[0108] In an optional implementation, since the rule package includes common rules and application rules, all rules required by the application can be updated.

[0109] Embodiment 3

[0110] See also Figure 3 , Figure 3 is a schematic diagram of the structure of an electronic device disclosed in an embodiment of the present application, such as Figure 3 As shown, the electronic device of the embodiment of the present application includes:

[0111] Processor 301; and

[0112] The memory 302 is configured to store machine-readable instructions, and when the instructions are executed by the processor, the rule base updating method as described in any of the aforementioned implementations is executed.

[0113] The electronic device of the embodiment of the present application can determine the application used by the protected website, download the first application list from the rule server based on a preset periodic time, and detect the upgrade option selected by the user by executing the rule base upgrade method, and then, when the upgrade option is a customized rule base upgrade option, generate a display interface based on the first application list, so that the user can select the target application based on the display interface, and then set the application used by the protected website to a selected state in the display interface, and then when the user completes the selection, generate a second application list, so that the local rule base can be upgraded based on the second application list.

[0114] Compared with the prior art, since the second application list includes the applications used by the protected website, the gateway can have corresponding rules to detect the traffic sent to the applications used by the protected website. At the same time, through the display interface, the user can customize the rule base used by the gateway, so as to avoid the gateway downloading all the rules to meet the user's needs, thereby reducing the size of the rule base in the gateway and improving the detection efficiency of the gateway.

[0115] Embodiment 4

[0116] An embodiment of the present application provides a storage medium, wherein the storage medium stores a computer program, and the computer program is executed by a processor as a rule base upgrade method as described in any of the aforementioned implementations.

[0117] The storage medium of the embodiment of the present application can determine the application used by the protected website by executing the rule base upgrade method, download the first application list from the rule server based on the preset periodic time, and detect the upgrade option selected by the user, so as to be able to upgrade the application when the upgrade option is the customized rule base upgrade option.

[0118] When the first application list is selected, a display interface is generated based on the first application list, so that the user can select the target application based on the display interface, and then the application used by the protected website can be set to the selected state in the display interface.

[0119] state, and then when the user completes the selection, a second application list can be generated, so that the local rule base can be updated based on the second application list.

[0120] Compared with the prior art, since the second application list includes the applications used by the protected website,

[0121] Therefore, there are corresponding rules in the gateway to detect 0 traffic sent to the application used by the protected website. At the same time, through the display interface, users can customize the rule base used by the gateway, so as to avoid

[0122] The gateway is not required to download all rules to meet user needs, thereby reducing the size of the rule base in the gateway and improving the detection efficiency of the gateway.

[0123] In the embodiments provided in this application, it should be understood that the disclosed devices and methods can be

[0124] The device embodiments described above are merely illustrative. For example, the division of unit 5 is only a logical function division. There may be other divisions in actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed may be through some communication interface, and the indirect coupling or communication connection of the device or unit may be electrical, mechanical or other forms.

[0125] 0 In addition, the units described as separate components may or may not be physically separate.

[0126] The components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0127] Furthermore, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.

[0128] It should be noted that if the function is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can essentially be embodied in the form of a software product, or in other words, the part that contributes to the prior art or the part of the technical solution. The computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM) random access memory (RAM), disk or optical disk, and other media that can store program codes.

[0129] In this document, relational terms such as first and second, etc. are used merely to distinguish one entity or operation from another entity or operation, but do not necessarily require or imply any such actual relationship or order between these entities or operations.

[0130] The above are only embodiments of the present application and are not intended to limit the scope of protection of the present application. For those skilled in the art, the present application may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the scope of protection of the present application.

Claims

1. A rule base upgrade method, It is characterized in that The method is applied to a security gateway, and the method comprises: Determine the application used by the protected URL; Downloading a first application list from a rule server based on a preset periodic time; detecting an upgrade option selected by a user, wherein when the upgrade option is a customized rule base upgrade option, generating a display interface based on the first application list, so that the user selects a target application based on the display interface; Setting the application used by the protected website to a selected state in the display interface; When the user completes the selection, a second application list is generated, wherein the second application list includes all the applications in the selected state; The local rule base is updated based on the second application list.

2. The method according to claim 1, It is characterized in that The updating of the local rule base based on the second application list includes: Sending the second application list to the rule server, so that the rule server aggregates all rules based on the second application list and generates a rule package; The rule package sent by the rule server is received, and the local rule base is updated based on the rule package.

3. The method according to claim 2, It is characterized in that Before sending the second application list to the rule server, the method further includes: Get the current system time; It is determined whether the current system time is the rule base upgrade time. If the current system time is the rule base upgrade time, the upgrade of the local rule base based on the second application list is triggered.

4. The method according to claim 2, It is characterized in that The rule package includes general rules and application rules, wherein the general rules are rules applicable to all applications, and the application rules are rules applicable to specific applications.

5. A rule base upgrade device, It is characterized in that The device is applied to a security gateway, and the device comprises: A determination module, used for determining an application used by a protected URL; A download module, configured to download the first application list from the rule server based on a preset regular time; a detection module, configured to detect an upgrade option selected by a user, wherein when the upgrade option is a customized rule base upgrade option, a display interface is generated based on the first application list, so that the user selects a target application based on the display interface; A processing module, used for setting the application used by the protected website to a selected state in the display interface; A generating module, configured to generate a second application list when the user completes the selection, wherein the second application list includes all the applications in the selected state; An upgrading module is used to upgrade the local rule base based on the second application list.

6. The device as claimed in claim 5, It is characterized in that The upgrade module includes: a sending submodule, configured to send the second application list to the rule server, so that the rule server aggregates all rules based on the second application list and generates a rule package; The receiving submodule is used to receive the rule package sent by the rule server and update the local rule base based on the rule package.

7. The device according to claim 5, It is characterized in that The device also includes: an acquisition submodule, configured to acquire the current system time before sending the second application list to the rule server; The judgment submodule is used to judge whether the current system time is the rule base upgrade time. If the current system time is the rule base upgrade time, it triggers the execution of the upgrade of the local rule base based on the second application list.

8. The device according to claim 6, It is characterized in that The rule package includes general rules and application rules, wherein the general rules are rules applicable to all applications, and the application rules are rules applicable to specific applications.

9. An electronic device, It is characterized in that include: processor; as well as The memory is configured to store machine-readable instructions, and when the instructions are executed by the processor, the rule base upgrading method according to any one of claims 1 to 4 is executed.

10. A storage medium, It is characterized in that The storage medium stores a computer program, and the computer program is executed by a processor to implement the rule base upgrading method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • A application software security detection system and method in an application system

    CN109190374A

  • Request processing method, device and system, storage medium and electronic equipment

    CN112988385A