Method and device for predicting security level of firewall
By matching the firewall's security policy data with the preset audit data, a policy compliance matrix is generated, and the security degree is determined in combination with the preset weight matrix, the problem of inaccurate prediction of the security degree of the firewall is solved, and the effect of early detection of unsafe factors and early warning is achieved.
Patent Information
- Application Number
- CN202111362543.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-17
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-11-17
AI Technical Summary
The prior art has problems of low automation, inaccurate prediction and low efficiency in the security prediction of firewall policies of large-scale private cloud resource pools.
By matching the various security policy data of the firewall at any point in time with the preset audit data according to the preset matching rules, a policy compliance matrix is generated, and the security degree of the firewall is determined in combination with the preset weight matrix.
It realizes accurate prediction of the security of the firewall at any point in time, detects unsafe factors early and provides early warnings, improving the security of the firewall policy configuration.
Smart Images

Figure CN116137600B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network information security technology, and particularly relates to a method and device for predicting the security level of a firewall. Background Art
[0002] To determine the security level of firewall policies in a large-scale private cloud resource pool, manual auditing is usually adopted. However, relying on manual inspection of the firewall underlying configuration has problems such as low automation, inaccurate prediction of the security level of firewall policies, and low prediction efficiency.
[0003] Therefore, in related technologies, professional policy auditing devices can be used to determine the security level of firewall policies. However, the firewall policy auditing devices deployed in the existing network are all single devices, with limited quantification of security policy indicators and trend analysis processing. They often only make a simple judgment on the security level of the firewall when a problem occurs with the firewall, and cannot predict the security level of the firewall policy configuration in advance, resulting in the inability to detect unsafe factors early for warning, thus making the prediction effect of the security level of the firewall poor. Summary of the Invention
[0004] Embodiments of this application provide a method and device for predicting the security level of a firewall, which can predict the security level of the firewall at any time point, so as to give an early warning before the non-compliance of the firewall security policy configuration deteriorates.
[0005] In a first aspect, embodiments of this application provide a method for predicting the security level of a firewall, including:
[0006] Matching each security policy data of the firewall at any time point with each preset audit data corresponding to each security policy data one by one according to a preset matching rule to obtain each matching record;
[0007] Generating a policy compliance matrix according to each of the matching records;
[0008] Determining the security level of the firewall at the time point according to the policy compliance matrix and a preset weight matrix;
[0009] The preset audit data is a firewall security policy with risks.
[0010] In one embodiment, the step of matching each security policy data of the firewall at any time point with each preset audit data corresponding to each security policy data one by one according to a preset matching rule to obtain each matching record includes:
[0011] Obtain the respective second data corresponding one by one to the respective first data from the preset audit data according to the data types of the respective first data in the security policy data;
[0012] Match the second data according to the sub - rule corresponding to the data type of the first data in the preset matching rule to obtain a matching result;
[0013] Generate the matching record corresponding to the security policy data according to the respective matching results.
[0014] In one embodiment, matching the first data and the corresponding preset audit data according to the sub - rule corresponding to the data type of the first data in the preset matching rule to obtain a matching result includes:
[0015] Match the first data and the corresponding second data according to the sub - rule corresponding to the data type of the first data;
[0016] When the first data and the second data conform to the sub - rule, generate a first matching result indicating that the first data and the second data match;
[0017] Otherwise, generate a first matching result indicating that the first data and the second data do not match.
[0018] In one embodiment, the preset weight matrix is determined according to the network environment where the firewall is currently located.
[0019] In one embodiment, it further includes:
[0020] Weight the security degrees of each time point according to the preset weights corresponding to each time point to obtain a predicted value of the security degree at a future time point;
[0021] Wherein, the preset weight corresponding to the time point is inversely proportional to the time difference between the time point and the future time point.
[0022] In one embodiment, the preset weight is determined after being adjusted from an initial weight according to the time difference, and the initial weight is determined according to the fluctuation range of the security degrees of each time point.
[0023] In one embodiment, before matching each security policy data of the firewall at any time point with the respective preset audit data corresponding one by one to each security policy data according to the preset matching rule to obtain each matching record, it further includes:
[0024] Perform conflict detection on each of the security policy data;
[0025] When a conflict is detected, generate a warning message;
[0026] Otherwise, perform the step of matching the security policy data of the firewall at any time point with the preset audit data according to the preset matching rules.
[0027] In a second aspect, an embodiment of the present application provides a security degree prediction device for a firewall, including:
[0028] A data matching module, configured to match the security policy data of the firewall at any time point with the respective preset audit data corresponding to the security policy data one by one according to the preset matching rules, and obtain respective matching records;
[0029] A matrix generation module, configured to generate a policy compliance matrix according to the respective matching records;
[0030] A security degree prediction module, configured to determine the security degree of the firewall at the time point according to the policy compliance matrix and the preset weight matrix;
[0031] The preset audit data is a firewall security policy with risks.
[0032] In a third aspect, an embodiment of the present application provides an electronic device, including a processor and a memory storing a computer program, and when the processor executes the program, the steps of the security degree prediction method of the firewall described in the first aspect are implemented.
[0033] In a fourth aspect, an embodiment of the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the security degree prediction method of the firewall described in the first aspect are implemented.
[0034] The security degree prediction method and device for a firewall provided by the embodiments of the present application, by matching the security policy data of the firewall at any time point with the preset audit data according to the preset matching rules, obtaining respective matching records, and then determining the security degree of the firewall at this time point according to the policy compliance matrix generated from the respective matching records and the preset weight matrix, can quantify the security policy of the firewall at any time point through an automated prediction process, predict the security degree of the firewall policy, and avoid the situation where the security degree of the firewall policy configuration cannot be predicted early when problems occur in the firewall, so as to be able to give an early warning before the non-compliance of the firewall security policy configuration tends to deteriorate. Description of the Drawings
[0035] To more clearly illustrate the technical solutions in the present application or the prior art, the following briefly introduces the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0036] Figure 1 is a schematic flowchart of a method for predicting the security level of a firewall provided by an embodiment of the present invention;
[0037] Figure 2 is a schematic structural diagram of a device for predicting the security level of a firewall provided by the present invention;
[0038] Figure 3 is a schematic structural diagram of an electronic device provided by the present invention. Detailed Embodiments
[0039] To make the objectives, technical solutions, and advantages of the present application clearer, the following will clearly and completely describe the technical solutions in the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments in the present application belong to the scope of protection of the present application.
[0040] The following elaborates on the embodiments of the present application in detail with reference to the accompanying drawings.
[0041] Refer to Figure 1 , which is one of the schematic flowcharts of a method for predicting the security level of a firewall provided by an embodiment of the present invention. This method is applied to an electronic device, where the electronic device can specifically be a server or a terminal device and is used to predict the security level of firewall policies. As Figure 1 shown, a method for predicting the security level of a firewall provided in this embodiment includes:
[0042] Step 101: Match each security policy data of the firewall at any time point with each preset audit data corresponding to each security policy data one by one according to a preset matching rule, and obtain each matching record;
[0043] Step 102: Generate a policy compliance matrix according to each of the matching records;
[0044] Step 103: Determine the security level of the firewall at the time point according to the policy compliance matrix and a preset weight matrix;
[0045] The preset audit data are firewall security policies with risks.
[0046] By matching the security policy data of the firewall at any point in time with the preset audit data according to the preset matching rules, after obtaining each matching record, the security level of the firewall at this time point is determined based on the policy compliance matrix generated from each matching record and the preset weight matrix. Thus, through an automated prediction process, the security policy of the firewall can be quantified at any point in time, predicting the security level of the firewall policy, avoiding the situation where the security level of the firewall policy configuration is predicted only when there is a problem with the firewall, resulting in the inability to detect unsafe factors early. Furthermore, early warning can be given before the non-compliance of the firewall security policy configuration tends to deteriorate.
[0047] In step 101, a security policy of the firewall is the security policy data. Each piece of security policy data has a corresponding preset audit data. The preset audit data is the audit rule for security policy inspection, and this audit rule is used to perform predictive analysis on the security policy data of the firewall. When the parameters in the security policy data match the parameters set in the preset audit data according to the preset matching rules, it indicates that the firewall may have risks corresponding to this preset rule. For example, if the address port information in the security policy is tcp 20,21 and the file transfer protocol is FTP, which is the same as the address port information and file transfer protocol in the corresponding preset audit data, then it has risks such as "allowing anonymous upload and download, blasting, sniffing, win privilege escalation, remote execution (proftpd 1.3.5), various backdoors (proftpd, vsftp 2.3.4)".
[0048] Exemplarily, the corresponding relationship between the preset audit data and the possible risks can be shown in the following table:
[0049]
[0050]
[0051] Among them, the address port information and service are the preset audit data, and the risk description is the risk information corresponding to this preset audit data.
[0052] In an embodiment, the preset matching rule can be to match whether the security policy data is the same as the preset audit data, or to match whether the security policy data belongs to the preset audit data. If so, it is determined that the security policy data matches the preset audit data, and its matching degree is recorded; otherwise, it is determined that the security policy data does not match the preset audit data.
[0053] Due to a security policy data on the firewall, its essential factors usually include: dir - direction (in / out), IP address range (source / destination), port number range (source / destination), protocal - type of transport protocol, action - action (allow / deny), creattime - policy creation time. That is, a security policy data is an 8 - dimensional vector:
[0054] p=(dir p ,ipStart p ,ipEnd p ,portStart p ,portEnd p ,protocal p ,action p ,creattime p )
[0055] Therefore, in order to make the subsequent security prediction more accurate, it is necessary to match the data of each dimension in the security policy data with the preset audit data. Specifically, matching each security policy data of the firewall at any time point with the corresponding preset audit data of each security policy data one by one according to the preset matching rules to obtain each matching record, including:
[0056] According to the data types of the first data in the security policy data, obtain the corresponding first data in the preset audit data one by one;
[0057] Match the second data according to the sub - rules corresponding to the data type of the first data in the preset matching rules to obtain the matching result;
[0058] Generate the matching record corresponding to the security policy data according to each matching result.
[0059] In an embodiment, each first data is the vector of the security policy data in each dimension, such as:
[0060] dir p ,ipStart p ,ipEnd p ,portStart p ,portEnd p ,protocal p ,action p ,creattime p
[0061] After obtaining each first piece of data from the security policy data, the respective first pieces of data can first be quantized according to the corresponding data types as shown in the following table:
[0062]
[0063] If there are n pieces of security policy data on a firewall, the set of all security policy data can be represented as an n×8 security policy matrix:
[0064]
[0065] Similarly, each second piece of data for auditing each first piece of data also exists in each piece of preset audit data. When the types of the first pieces of data include the data types of the above 8 dimensions, the second pieces of data of the above 8 dimensions are obtained from the preset audit data, that is, the preset audit data is:
[0066] r = (dir r , ipStart r , ipEnd r , portStart r , portEnd r , protocal r , action r , nowtime r )
[0067] Similarly, for the convenience of calculation, after obtaining each second piece of data, it can also be quantized according to the corresponding data types as shown in the following table:
[0068]
[0069] Among them, the data type of the policy creation time in the first data corresponds to the data type of the current audit time in the second data.
[0070] Assume there are m pieces of preset audit data, then all the preset audit data can also be represented as an M×8 canonical matrix:
[0071]
[0072] In one embodiment, after obtaining the second pieces of data corresponding one by one to the first pieces of data in a piece of security policy data according to the data types of the first pieces of data from the preset audit data, the first pieces of data and the second pieces of data can be matched according to the respective sub-rules corresponding to the data types in the preset matching rules. Specifically, the first data and the corresponding preset audit data are matched according to the sub-rules corresponding to the data type of the first data in the preset matching rules to obtain a matching result, including:
[0073] Match the first data with the corresponding second data according to the sub - rules corresponding to the data type of the first data;
[0074] When the first data and the second data conform to the sub - rules, generate a first matching result indicating that the first data and the second data match;
[0075] Otherwise, generate a first matching result indicating that the first data and the second data do not match.
[0076] For example, for the first data dir with the data type of dir p and the second data dir r , the corresponding sub - rule is to determine whether the first data dir p belongs to the second data dir r . If so, determine that the matching result is the first matching result that the first data dir p matches the second data dir r , and parameterize the first matching result and record it as 1; otherwise, determine that the matching result is the second matching result that the first data dir p does not match the second data dir r , and parameterize the second matching result and record it as 0.
[0077] For the first data ipStart and ipEnd with the data types of ipStart and ipEnd p , the first data ipEnd p , as well as the second data ipStart r , the second data ipEnd r , the corresponding sub - rule is to determine whether the IP range between the first data ipStart p and the first data ipEnd p has an intersection with the IP range between the second data ipStart r and the second data ipEnd r ; if there is an intersection, generate a first matching result indicating that the first data ipStart p matches the second data ipStart r , and at the same time the first data ipEnd p matches the second data ipEndr, and record the intersection of the two IP ranges in the first matching result; otherwise, generate a second matching result and parameterize the second matching result and record it as 0.
[0078] For the first data portStart with the data types of portStart and portEnd p, the first data portEnd p , and the second data portStart r , the second data portEnd r , the corresponding sub - rule is to judge whether the port range between the first data portStart p and the first data portEnd p has an intersection with the IP range between the second data portStart r and the second data portEnd r ; if there is an intersection, generate a first matching result indicating that the first data portStart p matches the second data portStart r , and at the same time the first data portEnd p matches the second data portStart r , and record the intersection of the two port ranges in the first matching result; otherwise, generate a second matching result, parameterize the second matching result, and record it as 0.
[0079] For the first data protocal p and the second data protocal r of the data type protocal, the corresponding sub - rule is to judge whether the first data protocal p belongs to the second data protocal r . If so, judge that the matching result is the first matching result that the first data protocal p matches the second data protocal r , and parameterize the first matching result and record it as 1; otherwise, judge that the matching result is the second matching result that the first data protocal p does not match the second data protocal r , and parameterize the second matching result and record it as 0.
[0080] For the first data action p and the second data action r of the data type action, the corresponding sub - rule is to judge whether the first data action p is the same as the second data action r . If so, judge that the matching result is the first matching result that the first data action p matches the second data action r , and parameterize the first matching result and record it as 1; otherwise, judge that the matching result is the first data actionp The second data action r The second matching result that does not match, and parameterize the second matching result, and record it as 0.
[0081] For the first data creatime with the data type of creatime p , and the second data nowtime with the data type of nowtime corresponding to creatime r , it is different from other data types, and its corresponding sub-rule is to detect the second data nowtime r and the first data creatime p The time difference t between them, and record the matching result as:
[0082]
[0083] In one embodiment, after obtaining the matching results of each first data and each second data, the parameters corresponding to each matching result can be multiplied, and the product of the parameters corresponding to each matching result is the parameterized matching record M corresponding to the security policy data ij .
[0084] By matching all dimensions of data in the security policy data, when matching with the preset audit data, the influencing factors of all data constituting the firewall are considered, so that the obtained matching result more comprehensively reflects the security audit result of the firewall at this time point, and further improves the accuracy when predicting the firewall security degree subsequently.
[0085] In step 102, after obtaining each matching record M corresponding to each security policy data ij , all the matching records can be integrated to obtain a policy compliance matrix Match.
[0086] In step 103, for the data types of different security policy data, different weight scores can be configured in the preset weight matrix. The specific setting of the weight score value can be determined according to the actual situation.
[0087] In one embodiment, after generating the policy compliance matrix Match, it can be multiplied by the preset weight matrix W to obtain a security degree matrix formed by the scores of each security policy data:
[0088]
[0089] After obtaining the security degree matrix formed by the scores of each security policy data, add up the scores in the security degree matrix to determine the security degree of the firewall at the corresponding time point as:
[0090]
[0091] This value represents a comprehensive score of the security policy configuration of a firewall in a specific network environment, which can reflect the security situation of the firewall policy. If the value of the security level is higher, it means it is less secure. When the value is 0, it means that all the security policies corresponding to the security policy data comply with the audit rules.
[0092] Considering that the security level of the firewall is affected by the network environment, in order to make the prediction of the firewall's security level more accurate, in one embodiment, the preset weight matrix is determined according to the network environment where the firewall is currently located.
[0093] In one embodiment, the network environment includes an intranet environment and an extranet environment. For different network environments, different weight matrices are preset. Before determining the scores of each security policy data, the network environment where the firewall is currently located is detected in advance. According to the detected network environment, the corresponding weight matrix is obtained, and then according to the obtained weight matrix and the policy compliance matrix, the scores of each security policy data are determined. Thus, it is avoided that the finally predicted security level of the firewall is inaccurate due to the influence of the network environment, and the accuracy of the prediction of the firewall's security level is improved.
[0094] In order to be able to give an early warning, in one embodiment, after determining the security level of the firewall at any time point, it further includes:
[0095] Weight the security levels of each of the time points according to the preset weights corresponding to each of the time points to obtain a predicted value of the security level at a future time point;
[0096] Wherein, the preset weight corresponding to the time point is inversely proportional to the time difference between the time point and the future time point.
[0097] In one embodiment, in the database of the electronic device, a corresponding relationship table between the time difference and the preset weight can be pre-stored. In the corresponding relationship table, if the time difference is larger, the corresponding preset weight is smaller. After obtaining the security level of the firewall corresponding to any time point, the preset weight corresponding to each time point can be obtained from the corresponding relationship table according to the time difference between each time point and the future time point, and then the security level of each time point is weighted according to the preset weight of each time point, and the predicted value of the security level at the future time point can be obtained.
[0098] By obtaining the time series of the firewall security level and using the time series of the firewall security level to perform trend prediction analysis on the trend of the firewall security level, it is possible to predict in advance that the firewall security policy is non-compliant before the non-compliance of the firewall security policy configuration tends to deteriorate, and thus an early warning process can be carried out earlier.
[0099] In order to make the prediction of the security level at future time points more accurate, in one embodiment, the security level at future time points can also be predicted by the exponential smoothing method. The exponential smoothing method is divided into the first-order exponential smoothing method, the second-order exponential smoothing method, the third-order exponential smoothing method, etc. Their basic idea is that the predicted value is the weighted sum of previous observed values, and different weights are given to different data, with larger weights given to new data and smaller weights given to old data. Since there may be situations where the security level changes greatly due to artificial adjustment of security policies, the trend of the firewall security level shows a certain trend and seasonality. The third-order exponential smoothing has a good prediction effect on time series with a certain trend and seasonality. Therefore, the third-order exponential smoothing method can be selected to predict the security level at future time points.
[0100] Exemplarily, for a certain time point t, at the future time point T after it, the mathematical model of the predicted value of the third-order exponential smoothing of its security level is:
[0101]
[0102]
[0103]
[0104]
[0105] Among them, is the predicted value at time t + T, a t , b t , c t are the three coefficients in the prediction formula, are the values of the first-order, second-order, and third-order exponential smoothing at time t respectively; α is the preset weight, and the value range of α is [0 - 1]. Its value is subjectively selected. The larger the value, the greater the weight of the security level corresponding to the time point closer to the future time point in the prediction of the security level of the firewall at future time points.
[0106] To further improve the accuracy of predicting the security level of the firewall at future time points, in one embodiment, the preset weight is determined by adjusting the initial weight according to the time difference, and the initial weight is determined according to the fluctuation range of the security level at each time point.
[0107] Exemplarily, when the security levels corresponding to each time point are relatively stable, that is, the time series of the security levels is relatively stable, a relatively small initial weight can be selected, such as 0.05 - 0.20. When the time series of the security level fluctuates, but the long-term trend does not change significantly, a slightly larger initial weight can be selected, such as 0.10 - 0.40. When the time series of the security level fluctuates greatly and the long-term trend changes significantly with an obvious upward or downward trend, a larger initial weight is selected, such as 0.60 - 0.80. When the time series of the security level is an upward or downward series, that is, the security level rises or falls as the time point increases, a larger initial weight is selected, such as 0.60 - 1.
[0108] By detecting the fluctuation amplitude of the security level at each time point, the corresponding initial weight is obtained, and then according to the time difference between each time point and the future time point, the initial weight is adjusted so that the preset weight of the finally determined time point is more consistent with the actual change trend of the security level of the firewall, thereby further improving the accuracy of predicting the security level of the firewall at the future time point.
[0109] In addition to determining the initial weight based on the fluctuation amplitude of the security level at each time point, the initial weight can also be determined by the linear programming optimal solution method. For example, by introducing the concept of the mean square error of prediction to judge whether the initial weight α is accurate, it can be set as:
[0110]
[0111] where S t is the smoothed value at time t, and y t is the predicted value at time t. Then the above formula constitutes a function σ(α′) of the initial weight α′ with respect to σ. Then the confirmation of the optimal α′ becomes the problem of solving the minimum value of the variance function σ(α′). At this time, the linear programming method can be directly used to solve it, which will not be elaborated here.
[0112] Considering that conflicts or omissions often occur between the security policies of the firewall. At this time, even if the security level corresponding to the firewall is determined, the security policy of the firewall may need to be modified due to conflicts, so that the security level obtained in the case of security policy conflicts does not have good reference value, resulting in waste of computing resources in the electronic device and affecting the prediction efficiency of the security level. Therefore, in an embodiment, before matching each security policy data of the firewall at any time point with each preset audit data corresponding to each security policy data one by one according to the preset matching rules to obtain each matching record, it further includes:
[0113] Performing conflict detection on each of the security policy data;
[0114] When a conflict is detected, generating a warning message;
[0115] Otherwise, perform the step of matching the security policy data of the firewall at any time point with the preset audit data according to the preset matching rules.
[0116] In one embodiment, the conflict detection of each security policy data may include three layers: basic compliance detection of a single policy, mid-course detection of policies of a single firewall, and policy conflict detection based on the service path.
[0117] For the basic compliance detection, for each individual security policy data, first judge whether its source / destination address range is compliant according to the first custom rule, whether its source / destination port number range is compliant according to the second custom rule, and whether its transmission protocol is compliant according to the third custom rule; if any one of them is non-compliant, it is judged that the security policy data has a conflict; otherwise, it is judged that the security policy data is compliant.
[0118] For each security policy data that passes the basic compliance detection, perform policy conflict detection based on a single firewall. Specifically, judge whether the actions in the security policy data are consistent with the records in the port list and the records in the port on / off table; if they are consistent, it is judged to be compliant; otherwise, it is judged that the security policy data has a conflict. Exemplarily, if the records in the port list allow the actions in the security policy data to pass, while the records in the port on / off table do not allow the actions in the security policy data to pass, it is determined at this time that the security policy data has a conflict.
[0119] For a business system on the cloud, generally, it will pass through two firewalls, an internal network firewall and an external network firewall, before the service can be distributed. Since the policies of the two firewalls are configured separately, there may sometimes be a possibility of policy conflicts, resulting in service interruption. Therefore, for each security policy data that passes the policy conflict detection based on a single firewall, it is necessary to perform multi-firewall policy conflict detection based on the service path. Specifically, detect whether the security policy data conflicts with the security policy data of another firewall on the service path. If so, it is judged that the security policy data has a conflict; otherwise, it is judged that the security policy data is compliant.
[0120] In the above three-layer policy conflict detection, if a conflict in the security policy data is detected in any layer, a warning message is generated and sent to the specified terminal for alarm. If all the security policy data is compliant after passing the above three-layer policy conflict detection, perform security degree prediction.
[0121] By performing the security degree prediction of the firewall when it is detected that there are no conflicts in each security policy data, the waste of computing resources is avoided, and the prediction efficiency of the firewall security degree is improved.
[0122] The security level prediction device of the firewall provided by the present invention will be described below. The security level prediction device of the firewall described below can be correspondingly referred to the security level prediction method of the firewall described above.
[0123] In one embodiment, as Figure 2 shown, a security level prediction device of a firewall is provided, including:
[0124] A data matching module 210, configured to match each security policy data of the firewall at any time point with each preset audit data corresponding to each security policy data one by one according to a preset matching rule, and obtain each matching record;
[0125] A matrix generation module 220, configured to generate a policy compliance matrix according to each of the matching records;
[0126] A security level prediction module 230, configured to determine the security level of the firewall at the time point according to the policy compliance matrix and a preset weight matrix;
[0127] The preset audit data is a firewall security policy with risks.
[0128] In one embodiment, the data matching module 210 is specifically configured to:
[0129] According to the data types of each first data in the security policy data, obtain each second data corresponding to each first data from the preset audit data;
[0130] Match the second data according to the sub-rule corresponding to the data type of the first data in the preset matching rule to obtain a matching result;
[0131] Generate the matching record corresponding to the security policy data according to each of the matching results.
[0132] In one embodiment, the data matching module 210 is specifically configured to:
[0133] Match the first data with the corresponding second data according to the sub-rule corresponding to the data type of the first data;
[0134] When the first data and the second data conform to the sub-rule, generate a first matching result indicating that the first data and the second data match;
[0135] Otherwise, generate a first matching result indicating that the first data and the second data do not match.
[0136] In one embodiment, the preset weight matrix is determined according to the network environment where the firewall is currently located.
[0137] In one embodiment, the safety degree prediction module 230 is further configured to:
[0138] Weight the safety degrees at each of the time points according to the preset weights corresponding to each of the time points to obtain a predicted value of the safety degree at a future time point;
[0139] Wherein, the preset weight corresponding to the time point is inversely proportional to the time difference between the time point and the future time point.
[0140] In one embodiment, the preset weight is determined after being adjusted from an initial weight according to the time difference, and the initial weight is determined according to the fluctuation range of the safety degree at each of the time points.
[0141] In one embodiment, the data matching module 210 is further configured to:
[0142] Perform conflict detection on each of the security policy data;
[0143] When a conflict is detected, generate a warning message;
[0144] Otherwise, perform the step of matching each security policy data of the firewall at any time point with the preset audit data according to the preset matching rules.
[0145] Figure 3 Illustrates a schematic physical structure diagram of an electronic device, as Figure 3 shown, the electronic device may include: a processor 810, a communication interface 820, a memory 830, and a communication bus 840. Among them, the processor 810, the communication interface 820, and the memory 830 communicate with each other through the communication bus 840. The processor 810 can call a computer program in the memory 830 to execute the steps of the safety degree prediction method of the firewall, for example, including:
[0146] Match each security policy data of the firewall at any time point with each preset audit data corresponding to each security policy data one by one according to the preset matching rules to obtain each matching record;
[0147] Generate a policy compliance matrix according to each of the matching records;
[0148] Determine the safety degree of the firewall at the time point according to the policy compliance matrix and the preset weight matrix;
[0149] The preset audit data is a firewall security policy with risks.
[0150] In addition, when the logical instructions in the above-mentioned memory 830 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.
[0151] On the other hand, an embodiment of this application also provides a computer program product. The computer program product includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the steps of the security degree prediction method of the firewall provided in the above-mentioned various embodiments, for example, including:
[0152] Match each security policy data of the firewall at any time point with each preset audit data corresponding to each security policy data one by one according to a preset matching rule, and obtain each matching record;
[0153] Generate a policy compliance matrix according to each of the matching records;
[0154] Determine the security degree of the firewall at the time point according to the policy compliance matrix and a preset weight matrix;
[0155] The preset audit data is a firewall security policy with risks.
[0156] On the other hand, an embodiment of this application also provides a processor-readable storage medium. The processor-readable storage medium stores a computer program. The computer program is used to cause a processor to execute the steps of the methods provided in the above-mentioned various embodiments, for example, including:
[0157] Match each security policy data of the firewall at any time point with each preset audit data corresponding to each security policy data one by one according to a preset matching rule, and obtain each matching record;
[0158] Generate a policy compliance matrix according to each of the matching records;
[0159] Determine the security level of the firewall at the time point according to the policy compliance matrix and the preset weight matrix;
[0160] The preset audit data is the firewall security policy with risks.
[0161] The processor-readable storage medium can be any available medium or data storage device accessible by the processor, including but not limited to magnetic memories (such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), etc.), optical memories (such as CDs, DVDs, BDs, HVDs, etc.), and semiconductor memories (such as ROM, EPROM, EEPROM, non-volatile memories (NANDFLASH), solid-state drives (SSD)), etc.
[0162] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0163] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disks, optical disks, etc., including several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0164] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of each embodiment of the present application.
Claims
1. A method for predicting the security level of a firewall, characterized in that, it includes: Matching each security policy data of the firewall at any time point with each preset audit data corresponding to each security policy data one by one according to a preset matching rule to obtain each matching record; Generating a policy compliance matrix according to each of the matching records; Determining the security level of the firewall at the time point according to the policy compliance matrix and a preset weight matrix; The preset audit data is a firewall security policy with risks; Weighting the security levels of each of the time points according to the preset weights corresponding to each of the time points to obtain a predicted value of the security level at a future time point; wherein, the preset weight corresponding to the time point is inversely proportional to the time difference between the time point and the future time point.
2. The method for predicting the security level of a firewall according to claim 1, characterized in that, The step of matching each security policy data of the firewall at any time point with each preset audit data corresponding to each security policy data one by one according to a preset matching rule to obtain each matching record includes: According to the data types of each first data in the security policy data, obtaining each second data corresponding to each of the first data from the preset audit data; Matching the second data according to the sub-rule corresponding to the data type of the first data in the preset matching rule to obtain a matching result; Generating the matching record corresponding to the security policy data according to each of the matching results.
3. The method for predicting the security level of a firewall according to claim 2, characterized in that, The step of matching the first data with the corresponding preset audit data according to the sub-rule corresponding to the data type of the first data in the preset matching rule to obtain a matching result includes: Matching the first data with the corresponding second data according to the sub-rule corresponding to the data type of the first data; When the first data and the second data conform to the sub-rule, generating a first matching result indicating that the first data and the second data match; Otherwise, generating a first matching result indicating that the first data and the second data do not match.
4. The method for predicting the security level of a firewall according to claim 1, characterized in that, The preset weight matrix is determined according to the network environment where the firewall is currently located.
5. The method for predicting the security level of a firewall according to claim 4, characterized in that, The preset weight is determined after adjusting the initial weight according to the time difference, and the initial weight is determined according to the fluctuation range of the security levels of each of the time points.
6. The method for predicting the security level of a firewall according to claim 1, characterized in that, Before matching each security policy data of the firewall at any time point with each preset audit data corresponding to each security policy data one by one according to a preset matching rule to obtain each matching record, it further includes: Performing conflict detection on each of the security policy data; When a conflict is detected, generating a warning message; Otherwise, perform the step of matching the security policy data of the firewall at any time point with the preset audit data according to the preset matching rules.
7. A security level prediction device for a firewall, comprising: a data matching module, configured to match the security policy data of the firewall at any time point with the respective preset audit data corresponding to the security policy data one by one according to the preset matching rules to obtain respective matching records; a matrix generation module, configured to generate a policy compliance matrix according to the respective matching records; a security level prediction module, configured to determine the security level of the firewall at the time point according to the policy compliance matrix and the preset weight matrix; the preset audit data is the firewall security policy with risks; weight the security levels of the respective time points according to the preset weights corresponding to the respective time points to obtain a predicted value of the security level at a future time point; wherein, the preset weight corresponding to the time point is inversely proportional to the time difference between the time point and the future time point.
8. An electronic device, comprising a processor and a memory storing a computer program, wherein, when the processor executes the computer program, the steps of the security level prediction method for the firewall according to any one of claims 1 to 6 are implemented.
9. A computer program product, comprising a computer program, wherein, when the computer program is executed by a processor, the steps of the security level prediction method for the firewall according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Network policy audit method, device, and computer-readable storage medium
CN109040089A
System for checking firewall using harmful information DB
KR101341451B1