A database audit method and device based on multiple firewalls

By sending session information in a multi-firewall configuration to ensure that data packets are routed to the correct firewall, the problem of incomplete audit results caused by dispersed database access traffic is solved, and a more complete database audit results are achieved.

CN116192921BActive Publication Date: 2025-05-13BEIJING ANHUA JINHE TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310199274.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-28
Publication Date
2025-05-13
Estimated Expiration
2043-02-28

AI Technical Summary

Technical Problem

In a multi-firewall configuration, database access traffic may be spread to different firewalls for auditing, resulting in the inability to obtain complete audit results.

Method used

Each firewall sends session information for the session established through the firewall to other firewalls, ensuring that packets can be correctly routed to the firewall where the session resides, and thus auditing on the same firewall.

Benefits of technology

Through this method, ensuring that all packets of the same session are audited on the same firewall, solving the problem of decentralized audits and improving the integrity of database audit results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116192921B_ABST
    Figure CN116192921B_ABST
Patent Text Reader

Abstract

The present application discloses a database audit method and device based on multiple firewalls, the method comprising: each of the multiple firewalls sends the session information of the session established through the firewall to other firewalls in the multiple firewalls; the first firewall receives the data packet exchanged between the database client and the database; determines whether the session to which the data packet belongs is established through the first firewall, if so, sends the data packet to the audit program set on the first firewall for audit; if not, obtains the second firewall that established the session to which the data packet belongs, and sends the data packet to the second firewall. The present application solves the problem in the prior art that the traffic accessing the database is dispersed to different firewalls for auditing, resulting in the inability to obtain a complete audit result, and can ensure the integrity of the database audit result to a certain extent.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of database auditing, and in particular, to a database auditing method and device based on multiple firewalls. Background Art

[0002] Database audit (DBAudit for short) is centered on security events, based on comprehensive and precise audits, and records database activities on the network in real time, performs fine-grained audit compliance management on database operations, and issues real-time alerts for risky behaviors encountered by the database. It helps users generate compliance reports and trace the source of accidents after the fact by recording, analyzing, and reporting on user access to the database. At the same time, it provides efficient query audit reports through big data search technology, locates the cause of the event, and facilitates future query, analysis, and filtering, thereby strengthening the monitoring and auditing of internal and external database network behaviors and improving data asset security.

[0003] When auditing a database, it is usually necessary to obtain the traffic that accesses the database and audit the traffic. In order to ensure the security of the database, a firewall (or firewall) will be set up to protect the database. A network firewall is a special network interconnection device used to strengthen access control between networks. All network communications flowing in and out of the computer must pass through this firewall. The firewall scans the network communications that pass through it, which can filter out some attacks to prevent them from being executed on the target computer. The firewall can also close unused ports. It can also prohibit outgoing communications from specific ports and block Trojans. Finally, it can prohibit access from special sites, thereby preventing all communications from unknown intruders.

[0004] When the database is located behind a firewall, the traffic accessing the database can be sent through the firewall to an auditing program for auditing. The auditing program can be located on the firewall or on other devices connected to the firewall.

[0005] Considering that firewalls may fail, there will be security risks when firewalls fail. In order to solve this problem, two or more firewalls are used before the database. On the one hand, these firewalls increase the number of available firewalls and avoid security risks when a firewall fails; on the other hand, multiple firewalls can also play a role in diversion and achieve firewall load balancing. However, this is problematic for database auditing. For example, the access to the database by the same database session may be scattered on different firewalls, so there will be different audit programs to conduct audits, and it is impossible to obtain a complete audit result. Summary of the invention

[0006] The embodiments of the present application provide a database audit method and device based on multiple firewalls to at least solve the problem in the prior art that the traffic accessing the database is dispersed to different firewalls for auditing, resulting in the inability to obtain complete audit results.

[0007] According to one aspect of the present application, a database audit method based on multiple firewalls is provided, comprising: each firewall in the multiple firewalls sends session information of a session established through the firewall to other firewalls in the multiple firewalls; wherein the session is established between a database client and a database through at least one of the multiple firewalls, and an audit program is set on each of the firewalls, and the audit program is used to audit data packets exchanged between the database client and the database; a first firewall receives a data packet exchanged between the database client and the database, wherein the first firewall is one of the multiple firewalls; the first firewall determines whether the session to which the data packet belongs is established through the first firewall, and if so, the first firewall sends the data packet to the audit program set on the first firewall for audit; if not, the first firewall obtains a second firewall that establishes the session to which the data packet belongs, and sends the data packet to the second firewall, wherein the second firewall is one of the multiple firewalls; after receiving the data packet, the second firewall sends the data packet to the audit program set on the second firewall for audit.

[0008] According to another aspect of the present application, a database audit device based on multiple firewalls is also provided, which is located in a first firewall and includes: a sending module, which is used to send session information of a session established through the firewall to other firewalls in the multiple firewalls; wherein the session is established between a database client and a database through at least one of the multiple firewalls, and an audit program is set on each of the firewalls, and the audit program is used to audit data packets exchanged between the database client and the database; a receiving module, which is used to receive data packets exchanged between the database client and the database, wherein the first firewall is one of the multiple firewalls; a judging module, which is used to judge whether the session to which the data packet belongs is established through the first firewall, and if so, the first firewall sends the data packet to the audit program set on the first firewall for audit; if not, obtaining a second firewall that establishes the session to which the data packet belongs, and sending the data packet to the second firewall, wherein the second firewall is one of the multiple firewalls; the second firewall is used to send the data packet to the audit program set on the second firewall for audit after receiving the data packet.

[0009] According to another aspect of the present application, an electronic device is also provided, comprising a memory and a processor; wherein the memory is used to store one or more computer instructions, wherein the one or more computer instructions are executed by the processor to implement the above-mentioned method steps.

[0010] According to another aspect of the present application, a readable storage medium is provided, on which computer instructions are stored, wherein the computer instructions implement the above method steps when executed by a processor.

[0011] In an embodiment of the present application, each of the multiple firewalls sends the session information of the session established through the firewall to other firewalls in the multiple firewalls; wherein the session is established between the database client and the database through at least one of the multiple firewalls, and each of the firewalls is provided with an audit program, and the audit program is used to audit the data packets exchanged between the database client and the database; the first firewall receives the data packet exchanged between the database client and the database, wherein the first firewall is one of the multiple firewalls; the first firewall determines whether the session to which the data packet belongs is established through the first firewall, and if so, the first firewall sends the data packet to the audit program set on the first firewall for audit; if not, the first firewall obtains the second firewall that establishes the session to which the data packet belongs, and sends the data packet to the second firewall, wherein the second firewall is one of the multiple firewalls; after receiving the data packet, the second firewall sends the data packet to the audit program set on the second firewall for audit. The present application solves the problem that the traffic accessing the database is dispersed to different firewalls for auditing in the prior art, resulting in the inability to obtain a complete audit result, and can ensure the integrity of the database audit result to a certain extent. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] The drawings constituting a part of the present application are used to provide a further understanding of the present application. The illustrative embodiments and descriptions of the present application are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0013] Figure 1 is a system schematic diagram of database auditing with a firewall according to an embodiment of the present application;

[0014] Figure 2 is a flowchart of a database audit method based on multiple firewalls according to an embodiment of the present application; and,

[0015] Figure 3It is a schematic diagram of sending session information between firewalls according to an embodiment of the present application. DETAILED DESCRIPTION

[0016] It should be noted that, in the absence of conflict, the embodiments and features in the embodiments of the present application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0017] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0018] The following implementation methods involve database auditing, firewalls, etc. The technical terms in the following implementation methods are first explained below.

[0019] TCP

[0020] Transmission Control Protocol (TCP) is a connection-oriented, reliable, byte-stream-based transport layer communication protocol defined by IETF's RFC793. TCP is designed to adapt to a layered protocol hierarchy that supports multiple network applications. Pairs of processes in host computers connected to different but interconnected computer communication networks rely on TCP to provide reliable communication services. TCP assumes that it can obtain simple, possibly unreliable datagram services from lower-level protocols. In principle, TCP should be able to operate on a variety of communication systems from hard-wired connections to packet switching or circuit switching networks.

[0021] TCP Connection

[0022] A TCP connection is a connection established between two communication ends using the TCP protocol. For example, a client and a server can establish a TCP connection using the TCP protocol.

[0023] There are multiple states in a TCP connection. The meaning of each state is as follows:

[0024] Closed state (CLOSED): There is no connection state.

[0025] Listening state (LISTEN): Listen for connection requests from remote TCP ports.

[0026] Synchronous packet sending state (SYN-SENT): After sending a connection request, wait for a matching connection request (client).

[0027] Synchronous packet reception state (SYN-RCVD): After receiving and sending a connection request, wait for the other party's confirmation of the connection request (server).

[0028] ESTABLISHED: Indicates an established connection.

[0029] The following is an explanation of the state changes in a TCP connection. At the beginning, before the connection is established, both the server and the client are in the CLOSED state. After the server starts to create a socket, it starts to listen and changes to the LISTEN state. The client requests to establish a connection and sends a synchronize (SYN) message to the server. The client's state changes to SYN_SENT. After receiving the client's message, the server sends an ACK and a SYN message to the client. At this time, the server's state changes to SYN_RCVD. Then, after receiving the ACK and SYN messages, the client sends an ACK to the server. The client's state changes to ESTABLISHED. After receiving the client's ACK, the server also changes to ESTABLISHED. At this point, the three-way handshake is completed and the connection is established.

[0030] The three-way handshake process can be as follows:

[0031] 1. First, the client sends a connection request with SYN=1 to the server, where seq is the packet sequence number.

[0032] 2. After receiving the packet, the server sets ACK to 1 to indicate receipt, and sets the ACK field to x+1 to indicate that the packet with sequence number x has been received, and the next packet to be received is x+1. Then it sends SYN=1 to indicate a request to establish a connection (this ensures full-duplex communication).

[0033] 3. The client sends a message to the server to confirm receipt. ACK=1 indicates confirmation of receipt of the message in process 2. Similarly, ACK is set to y+1, indicating that the next expected packet is y+1, and then the server sends the packet x+1 it expects to send.

[0034] Figure 1 is a schematic diagram of a database audit system with a firewall according to an embodiment of the present application, such as Figure 1 As shown, the system may include multiple firewalls (in Figure 1Two firewalls are shown in the figure, namely, firewall 1 and firewall 2. The database access traffic will pass through the load balancing server. The load balancing server will send the database access traffic to firewall 1 or firewall 2 according to the running status of firewall 1 and firewall 2. Firewall 1 and firewall 2 will send the database access traffic to the database on the one hand, and audit the database access traffic and the access results returned by the database on the other hand. That is, an audit program is set on firewall 1 and firewall 2 (in Figure 1 (not shown in the figure), the access to the database (including the database access traffic and the access results returned by the database) is audited through the audit programs on firewall 1 and firewall 2.

[0035] exist Figure 1 In the example, due to the existence of the load balancing server, the database access traffic of the same session may be sent to firewall 1 and firewall 2 respectively by the load balancing server, which will cause the audit results to be scattered on firewall 1 and firewall 2, making it impossible to obtain complete audit results.

[0036] In order to solve the above problems, in the following implementation, a database audit method based on multiple firewalls is provided. Figure 2 is a flowchart of a database audit method based on multiple firewalls according to an embodiment of the present application, such as Figure 2 As shown below, Figure 2 The steps involved in the method are described.

[0037] Step S202, each of the multiple firewalls sends session information of a session established through the firewall to other firewalls in the multiple firewalls; wherein the session is established between a database client and a database through at least one of the multiple firewalls, and each of the firewalls is provided with an audit program, and the audit program is used to audit data packets interacting between the database client and the database.

[0038] Step S204: a first firewall receives a data packet exchanged between the database client and the database, wherein the first firewall is one of the multiple firewalls.

[0039] Step S206, the first firewall determines whether the session to which the data packet belongs is established through the first firewall. If yes, the first firewall sends the data packet to an audit program set on the first firewall for auditing.

[0040] Step S208: if not, the first firewall obtains a second firewall that establishes a session to which the data packet belongs, and sends the data packet to the second firewall, wherein the second firewall is one of the multiple firewalls.

[0041] Step S210: After receiving the data packet, the second firewall sends the data packet to an audit program set on the second firewall for auditing.

[0042] In the above steps, each firewall records all the sessions created by the firewall, so that each firewall can clearly know the firewall where the session to which a data packet belongs is located, so that the data packet can be sent to the firewall where the session is located, and the data packets of the same session can be guaranteed to be audited by the same firewall. The above steps solve the problem of not being able to obtain complete audit results due to the traffic accessing the database being dispersed to different firewalls for auditing in the prior art, and can ensure the integrity of the database audit results to a certain extent.

[0043] Figure 3 is a schematic diagram of sending session information between firewalls according to an embodiment of the present application, Figure 3 The system shown in Figure 1 Basically the same, both include multiple firewalls. Database access traffic will pass through the load balancing server. The load balancing server will send the database access traffic to firewall 1 or firewall 2 according to the running status of firewall 1 and firewall 2. Firewall 1 and firewall 2 will send the database access traffic to the database on the one hand, and audit the database access traffic and the access results returned by the database on the other hand. That is, an audit program is set on firewall 1 and firewall 2, and the access to the database is audited through the audit program on firewall 1 and firewall 2. Figure 1 The difference is that in Figure 3 In the process, firewall 1 and firewall 2 will exchange information. Firewall 1 will send session information of the session established on it to firewall 2, and firewall 2 will send session information of the session established on the firewall to firewall 1.

[0044] As an optional implementation, since the load balancing server is connected to multiple firewalls, when the load balancing server receives the first synchronization message from the database client for establishing a TCP connection, the load balancing server obtains the load of the audit programs on all firewalls or the number of data packets that have been audited by the audit programs on all firewalls, and the load balancing server selects the firewall where the audit program with the smallest load is located or the firewall where the audit program with the smallest number of audit packets is located, and the load balancing server sends the first synchronization message to the selected firewall.

[0045] When the selected firewall receives the first synchronization message, it determines whether the number of data packets that have not been audited by the audit program on the firewall exceeds the threshold. If it exceeds the threshold, the first synchronization message is forwarded to the database. If it exceeds the threshold, the selected firewall resends the first synchronization message to the load balancing server. The load balancing server reselects a firewall and sends the first synchronization message to the reselected firewall.

[0046] The session information may include: the network address of the database client, the port number of the database client, the network address of the database, and the port number of the database. In this case, the connections established between different database clients and the same database belong to different sessions, and the connections between the same database client and different databases also belong to different sessions. In an optional implementation, the first firewall determines whether the session to which the data packet belongs is established through the first firewall, including: the first firewall searches the session information already recorded in the first firewall according to the source network address and port number and the destination network address and port number of the data packet, wherein the session information includes: the network address of the database client, the port number of the database client, the network address of the database, and the port number of the database; if the first firewall can find the session information matching the source network address and port number and the destination network address and port number of the data packet, then it is determined whether the session corresponding to the matching session information is established in the first firewall.

[0047] For the second firewall, it can also distinguish whether the data packet comes from other firewalls, so as to perform different processing, that is, the second firewall determines whether the data packet comes from other firewalls; after the second firewall determines that the data packet comes from other firewalls, the second firewall sends the data packet to the audit program set on the second firewall for auditing.

[0048] As an optional implementation, if the second firewall determines that the data packet originates from other firewalls, on the one hand, it sends the data packet to the audit program set on the second firewall for auditing, and on the other hand, it also obtains the source network address, port number, destination network address and port number of the data packet, and sends the obtained network address and port number as session information to other firewalls, which is used to indicate to other firewalls that the session to which the data packet belongs is located in the second firewall.

[0049] When the second firewall determines that the data packet originates from the database client or the database, the second firewall searches for the session to which the data packet belongs in the locally recorded session information. When the session to which the data packet belongs is established on the second firewall, the second firewall sends the data packet to an audit program set on the second firewall for auditing.

[0050] After the data packet reaches the firewall, it is first determined whether it is a packet to a database protected by the firewall. Only packets accessing the protected database enter the following processing flow. For packets not accessing the protected database, the firewall does not need to perform any processing on the packet and can simply transfer the packet away.

[0051] In the case of two firewalls, the first firewall (i.e., firewall 1) receives a SYN+ACK packet (or message) of a session. Since the received data packets are SYN messages and ACK messages, it means that a database client has sent the first SYN packet to the database. In this case, the first firewall records the sequence number (seq) and ACK information carried in the SYN message and ACK message. After the first firewall records the SYN message and ACK message, it forwards the SYN message and ACK message to the second firewall (i.e., firewall 2). After the second firewall receives the SYN message and ACK message, it records the seq and ACK information and forwards it to the first firewall (receives the SYNACK packet). Through such forwarding operations, the first firewall informs the second firewall that the sessions established through the SYN message and ACK message are all processed by the first firewall.

[0052] When the first firewall receives a non-SYN request packet of a session, a session is created. At this time, if the first firewall has recorded the SYN packet and ACK packet of the session, it is determined that the data packet of the session is processed by the first firewall, and then the non-SYN request packet is sent to the protocol parsing process (NPP), and the protocol parsing process directly transfers the data packet to the audit program for auditing.

[0053] If the second firewall receives the response packet of this session, since the second firewall also records that the session is processed by the first firewall, the response packet of the session will be directly transferred to the first firewall. The first firewall determines that the session has been created, and then puts it in the first firewall for audit. After the audit, the response packet will be transferred according to the port record of the session. If the first firewall does not create this session, it will be transferred back to the second firewall. After receiving the response packet, the second firewall determines whether it is processed on the second firewall. If so, it can be processed on the second firewall. If not, it will be forwarded to another firewall for processing.

[0054] In an optional implementation, in order to prevent the data packet from being forwarded continuously between the first firewall and the second firewall, at this time, after the first firewall receives the data packet sent by the second firewall, if the first firewall finds that the session corresponding to the data packet is not processed on the first firewall, the first firewall records the data packet, and the record is used to indicate that the first firewall forwards the received data packet to the second firewall. If the first firewall receives the data packet again, the first firewall determines that the data packet has been forwarded to the second firewall once, and the first firewall forwards the data packet to other firewalls other than the second firewall. If the data packet has been forwarded to all firewalls, the first firewall audits the data packet and records the session information corresponding to the data packet. In the future, all data packets of the session will be processed by the first firewall.

[0055] Through the above implementation, it can be determined which firewall a session is created through, and all data packets of the session are audited on the firewall where the session is created. This ensures that the database access traffic of a session is audited on the same firewall.

[0056] In this embodiment, an electronic device is provided, including a memory and a processor. The memory stores a computer program, and the processor is configured to run the computer program to execute the method in the above embodiment.

[0057] The above program can be run in the processor, or it can also be stored in the memory (or computer-readable medium), which includes permanent and non-permanent, removable and non-removable media. Information storage can be achieved by any method or technology. Information can be computer-readable instructions, data structures, modules of programs or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.

[0058] These computer programs can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps of the functions specified in one or more blocks can be implemented by different modules corresponding to different steps.

[0059] Such a device or system is provided in this embodiment. The device is called a database audit device based on multiple firewalls, located in the first firewall, and includes: a sending module, used to send the session information of the session established through the firewall to other firewalls in the multiple firewalls; wherein the session is established between the database client and the database through at least one of the multiple firewalls, and each of the firewalls is provided with an audit program, and the audit program is used to audit the data packets exchanged between the database client and the database; a receiving module, used to receive the data packets exchanged between the database client and the database, wherein the first firewall is one of the multiple firewalls; a judging module, used to judge whether the session to which the data packet belongs is established through the first firewall, if so, the first firewall sends the data packet to the audit program set on the first firewall for audit; if not, obtain the second firewall that establishes the session to which the data packet belongs, and send the data packet to the second firewall, wherein the second firewall is one of the multiple firewalls; the second firewall is used to send the data packet to the audit program set on the second firewall for audit after receiving the data packet.

[0060] The system or device is used to implement the functions of the method in the above-mentioned embodiment. Each module in the system or device corresponds to each step in the method, which has been explained in the method and will not be repeated here.

[0061] Optionally, the judgment module is used to: search in session information already recorded in the first firewall according to the source network address and port number and the destination network address and port number of the data packet, wherein the session information includes: the network address of the database client, the port number of the database client, the network address of the database, and the port number of the database; if session information matching the source network address and port number and the destination network address and port number of the data packet can be found, then determine whether the session corresponding to the matching session information is established in the first firewall.

[0062] Optionally, it also includes: a second judgment module and a second sending module, the second judgment module and the second sending module are located in the second firewall, wherein the second judgment module is used to judge whether the data packet originates from other firewalls; the second sending module is used to send the data packet to the audit program set on the second firewall for audit after determining that the data packet originates from other firewalls.

[0063] Optionally, the second sending module is used to, when it is determined that the data packet originates from the database client or the database, search the locally recorded session information for the session to which the data packet belongs by the second firewall; when the session to which the data packet belongs is established on the second firewall, the second firewall sends the data packet to an audit program set on the second firewall for auditing.

[0064] The above optional implementation solves the problem in the prior art that the traffic accessing the database is dispersed to different firewalls for auditing, resulting in inability to obtain complete audit results, and can ensure the integrity of the database audit results to a certain extent.

[0065] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.

Claims

1. A database audit method based on multiple firewalls, characterized in that: include: Each of the multiple firewalls sends session information of a session established through the firewall to other firewalls in the multiple firewalls; wherein the session is established between a database client and a database through at least one of the multiple firewalls, and each of the firewalls is provided with an audit program, and the audit program is used to audit data packets exchanged between the database client and the database; A first firewall receives a data packet exchanged between the database client and the database, wherein the first firewall is one of the multiple firewalls; The first firewall determines whether the session to which the data packet belongs is established through the first firewall. If so, the first firewall sends the data packet to an audit program set on the first firewall for auditing; wherein the first firewall searches the session information recorded in the first firewall according to the source network address and port number and the destination network address and port number of the data packet, wherein the session information includes: the network address of the database client, the port number of the database client, the network address of the database, and the port number of the database; if the first firewall can find the session information matching the source network address and port number and the destination network address and port number of the data packet, then it is determined whether the session corresponding to the matching session information is established in the first firewall; If not, the first firewall acquires a second firewall that establishes the session to which the data packet belongs, and sends the data packet to the second firewall, wherein the second firewall is one of the multiple firewalls; After receiving the data packet, the second firewall sends the data packet to an audit program set on the second firewall for audit; wherein the second firewall determines whether the data packet originates from other firewalls; after determining that the data packet originates from other firewalls, the second firewall sends the data packet to an audit program set on the second firewall for audit; wherein, when the second firewall determines that the data packet originates from the database client or the database, the second firewall searches for the session to which the data packet belongs in the locally recorded session information, and when the session to which the data packet belongs is established on the second firewall, the second firewall sends the data packet to the audit program set on the second firewall for audit.

2. A database audit device based on multiple firewalls, characterized in that: Located in the first firewall, including: A sending module, used to send session information of a session established through the firewall to other firewalls among the multiple firewalls; wherein the session is established between a database client and a database through at least one of the multiple firewalls, and each firewall is provided with an audit program, and the audit program is used to audit data packets exchanged between the database client and the database; A receiving module, configured to receive a data packet exchanged between the database client and the database, wherein the first firewall is one of the multiple firewalls; a judgment module, used to judge whether the session to which the data packet belongs is established through the first firewall, and if so, the first firewall sends the data packet to the audit program set on the first firewall for audit; if not, obtain a second firewall that establishes the session to which the data packet belongs, and send the data packet to the second firewall, wherein the second firewall is one of the multiple firewalls; the second firewall is used to send the data packet to the audit program set on the second firewall for audit after receiving the data packet; wherein the first firewall searches the session information already recorded in the first firewall according to the source network address and port number and the destination network address and port number of the data packet, wherein the session information includes: the network address of the database client, the port number of the database client, the network address of the database and the the port number of the database; if the first firewall can find the session information matching the source network address and port number and the destination network address and port number of the data packet, then determine whether the session corresponding to the matching session information is established in the first firewall; wherein, the second firewall determines whether the data packet originates from other firewalls; after determining that the data packet originates from other firewalls, the second firewall sends the data packet to the audit program set on the second firewall for audit; wherein, when the second firewall determines that the data packet originates from the database client or the database, the second firewall searches the locally recorded session information for the session to which the data packet belongs, and when the session to which the data packet belongs is established in the second firewall, the second firewall sends the data packet to the audit program set on the second firewall for audit.

Citation Information

Patent Citations

  • Firewall policy processing method and device

    CN104135461A

  • Network policy audit method, device, and computer-readable storage medium

    CN109040089A