Firewall policy management method and apparatus, computer device and storage medium
By acquiring new policies from firewall devices and using high-risk rules and authorization tickets for screening and approval processes, the problem of unauthorized firewall policy activation is solved, improving the security of firewall configuration and policy deployment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- INDUSTRIAL AND COMMERCIAL BANK OF CHINA
- Filing Date
- 2023-02-27
- Publication Date
- 2026-04-17
AI Technical Summary
In existing technologies, automated management systems for firewall policies may lead to unauthorized policy activation due to logical misjudgments, manual configuration errors, or unauthorized policy additions, resulting in data leakage or security attacks and reducing the security of firewall configurations.
By acquiring new policies from firewall devices, and using pre-defined high-risk rules and authorization work orders, preliminary and secondary screenings are conducted to establish a targeted approval process. High-risk and unauthorized policies undergo a third approval process to ensure their security.
It improves the security of firewall policy deployment, provides early detection and remediation mechanisms, enhances security checks on unauthorized policies, and reduces the risk of data breaches and security attacks.
Smart Images

Figure CN116248387B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular to a firewall policy management method, apparatus, computer device, and storage medium. Background Technology
[0002] Currently, firewall policies in large enterprise internal networks are mainly managed by firewall automation systems, combined with manual configuration of some complex policies.
[0003] However, in cases where the automated management system makes logical errors, or where manual configuration is flawed, or where policies are added without authorization, unauthorized policies may be enabled on the firewall device. The enabling of unauthorized policies may cause serious data leaks or security attacks, reducing the security of the firewall configuration. Therefore, improvements are urgently needed. Summary of the Invention
[0004] Therefore, it is necessary to provide a firewall policy management method, apparatus, computer equipment, and storage medium that can improve the security of firewall policy opening, in order to address the above-mentioned technical problems.
[0005] Firstly, this application provides a firewall policy management method, which includes:
[0006] Retrieve the newly added firewall policy corresponding to the firewall device;
[0007] If a new firewall policy is determined to be a high-risk policy based on the preset high-risk rules and whether the new firewall policy has an authorized work order, an approval process corresponding to the new firewall policy is established and the approval process is sent to the approver.
[0008] Obtain the approval result from the approver, and determine the usage status of the newly added firewall policy based on the approval result.
[0009] In one embodiment, the newly added firewall policy is determined to be a high-risk policy based on preset high-risk rules and whether the newly added firewall policy has an authorized work order, including:
[0010] If the newly added firewall policy is found to match the preset high-risk rules, determine whether the newly added firewall policy has an authorized work order.
[0011] If not, the newly added firewall policy is identified as a high-risk policy.
[0012] In one embodiment, an approval process is established for adding new firewall policies, including:
[0013] Based on the initiator information corresponding to the newly added firewall policy, determine at least one approver and the flow relationship between each approver;
[0014] Based on the approval parties, the workflow between them, and the approval content for new firewall policies, establish an approval process for new firewall policies.
[0015] In one embodiment, based on the initiator information corresponding to the newly added firewall policy, at least one approver and the flow relationship between each approver are determined, including:
[0016] Based on the source address in the newly added firewall policy, obtain the initiator information corresponding to the newly added firewall policy from the personnel access control system;
[0017] Based on the initiator information, determine at least one approver and the flow relationship between each approver.
[0018] In one embodiment, determining the flow relationship between at least one approver and each approver based on the initiator information includes:
[0019] Based on the initiator's security level and / or the departmental organizational relationship of the initiator's department, determine at least one approver and the flow relationship between the approvers.
[0020] In one embodiment, obtaining the newly added firewall policy corresponding to the firewall device includes:
[0021] Based on the current and historical firewall policies of the firewall device, determine the new firewall policy corresponding to the firewall device.
[0022] In one embodiment, the detection that a newly added firewall policy successfully matches a preset high-risk rule includes:
[0023] Extract the new policy element from the newly added firewall policy and match the new policy element with the preset high-risk rules; the policy element shall include at least the source address, destination address, source port, destination port and protocol type;
[0024] If the newly added policy element is matched with a high-risk rule, it is confirmed that the newly added firewall policy has successfully matched the preset high-risk rule.
[0025] Secondly, this application also provides a firewall policy management device, which includes:
[0026] The acquisition module is used to acquire newly added firewall policies corresponding to the firewall device.
[0027] Create a module to establish an approval process for the new firewall policy when it is determined to be a high-risk policy based on preset high-risk rules and whether the new firewall policy has an authorized work order, and send the approval process to the approver.
[0028] The approval module is used to obtain the approval result from the approver and, based on the approval result, determine the usage status of the newly added firewall policy.
[0029] Thirdly, this application also provides a computer device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0030] Retrieve the newly added firewall policy corresponding to the firewall device;
[0031] If a new firewall policy is determined to be a high-risk policy based on the preset high-risk rules and whether the new firewall policy has an authorized work order, an approval process corresponding to the new firewall policy is established and the approval process is sent to the approver.
[0032] Obtain the approval result from the approver, and determine the usage status of the newly added firewall policy based on the approval result.
[0033] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the following steps:
[0034] Retrieve the newly added firewall policy corresponding to the firewall device;
[0035] If a new firewall policy is determined to be a high-risk policy based on the preset high-risk rules and whether the new firewall policy has an authorized work order, an approval process corresponding to the new firewall policy is established and the approval process is sent to the approver.
[0036] Obtain the approval result from the approver, and determine the usage status of the newly added firewall policy based on the approval result.
[0037] Fifthly, this application also provides a computer program product comprising a computer program that, when executed by a processor, performs the following steps:
[0038] Retrieve the newly added firewall policy corresponding to the firewall device;
[0039] If a new firewall policy is determined to be a high-risk policy based on the preset high-risk rules and whether the new firewall policy has an authorized work order, an approval process corresponding to the new firewall policy is established and the approval process is sent to the approver.
[0040] Obtain the approval result from the approver, and determine the usage status of the newly added firewall policy based on the approval result.
[0041] The aforementioned firewall policy management method, device, computer equipment, and storage medium can perform timely security checks on firewall policies on firewall devices by inspecting newly added firewall policies. During the security check, new firewall policies are initially screened (first screening) using high-risk rules, and then screened a second time based on whether an authorization work order is available. Both the first and second screenings are automatic screening steps within the firewall automation management system. After the first and second screenings, if a new firewall policy is determined to be a high-risk policy, an approval process is established for the new firewall policy. Based on this approval process, a third approval is conducted for the new firewall policy. The purpose of the third approval is to conduct targeted approval for firewall policies that are high-risk (i.e., meet high-risk rules) and do not have an authorization work order, and to determine the usage status of the new firewall policy based on the approval result. The third approval, as an external approval step independent of the firewall automation management system, can supplement the automatic screening steps in the firewall automation management system. That is, it provides an early detection mechanism and a post-event remediation mechanism for policy opening scenarios in the firewall automation management system. Compared with traditional technologies, it improves the security of firewall policy deployment without requiring significant adjustments to the entire firewall automation management system. Attached Figure Description
[0042] Figure 1 This is an application environment diagram of a firewall policy management method in one embodiment;
[0043] Figure 2 This is a flowchart illustrating a firewall policy management method in one embodiment;
[0044] Figure 3 This is a schematic diagram of the firewall policy parsing module and the high-risk rule management module in one embodiment;
[0045] Figure 4 This is a flowchart illustrating the process of determining a newly added firewall policy as a high-risk policy in one embodiment.
[0046] Figure 5 This is a schematic diagram of the firewall policy parsing module and the high-risk rule management module in another embodiment;
[0047] Figure 6 This is a flowchart illustrating the workflow between the approving party and the various approving parties in one embodiment.
[0048] Figure 7This is a flowchart illustrating a firewall policy management method in another embodiment;
[0049] Figure 8 This is a structural block diagram of a firewall policy management device in one embodiment;
[0050] Figure 9 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0051] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0052] Currently, firewall policies in large enterprise internal networks are primarily configured through firewall automation management systems, supplemented by manual configuration for some complex policies. Specifically, the firewall policy activation process within an enterprise is as follows: 1. The user submits a firewall access request through the enterprise's work order system; 2. After the request is authorized and approved, the firewall automation management system determines whether the policy can be implemented automatically. If it is determined to be automatically implementable, the firewall automation management system completes the activation of the firewall policy according to the work order request; 3. If it is determined that it cannot be automatically implemented, the manual processing procedure for the request is triggered, and the operations and maintenance personnel directly activate the firewall policy on the firewall device according to the request content.
[0053] In the aforementioned traditional technologies, if the automated management system makes a logical error, or if manual configuration is flawed, or if policies are added without authorization, unauthorized policies may be enabled on the firewall device. The enabling of unauthorized policies may cause serious data leakage or security attacks, reducing the security of the firewall configuration.
[0054] This application provides a firewall policy management method, which is executed by a computer device, such as a terminal, server, or cloud platform. Figure 1 As shown, computer device 10 is connected to each firewall device and is used to manage the firewall policies deployed on the firewall devices.
[0055] In one embodiment, such as Figure 2 As shown, a firewall policy management method is provided, which can be applied to... Figure 1 Taking computer device 10 as an example, the following steps are included:
[0056] S201, retrieve the newly added firewall policy corresponding to the firewall device.
[0057] A firewall can be viewed as an IP packet filter, operating on the underlying TCP / IP protocol stack. A firewall can enumerate packets, allowing only those matching specific rules to pass through, while blocking all others (except viruses, which firewalls cannot prevent). In other words, a firewall allows source IP addresses matching specific rules to access destination IP addresses, while blocking source IP addresses that cannot access the destination IP address, thus preventing malicious source IP addresses from accessing the destination IP address.
[0058] When using a firewall to ensure network security, it is necessary to first know which source IP addresses are allowed to access the destination IP address through the firewall, and secondly, to know which service port number the firewall allows the source IP addresses to access the destination IP address. These source IP addresses, destination IP addresses, and port numbers constitute the firewall policy. Correspondingly, a firewall device refers to the physical device used to implement firewall functions. In this embodiment, the firewall device can be a single device (e.g., a server) or various devices within a group of devices.
[0059] It is understood that firewall policies on a firewall device can be deployed (enabled), updated, modified, or deleted according to firewall configuration instructions. In this embodiment, by checking for updates to the firewall policies on the firewall device, the newly added firewall policies corresponding to the firewall device can be obtained; wherein, the newly added firewall policy refers to the firewall policy currently deployed on the firewall device that has changed compared to the previous deployment. The newly added firewall policy may include the modified firewall policy or the newly deployed firewall policy.
[0060] S202: If the newly added firewall policy is determined to be a high-risk policy based on the preset high-risk rules and whether the newly added firewall policy has an authorized work order, an approval process corresponding to the newly added firewall policy is established and the approval process is sent to the approver.
[0061] Among them, the preset high-risk rules refer to the definition of high-risk firewall policies.
[0062] Specifically, when the firewall automation management system performs automated verification on any firewall policy, it can compare the firewall policy with high-risk rules to filter out firewall policies that pose a risk. For example, the preset high-risk rule is: IP address 1.1.1.1, where within the enterprise, IP address 1.1.1.1 belongs to the internal financial system and is defined as a high-risk system; then, if the source IP address or destination IP address of any of the above firewall policies is 1.1.1.1 or 1.1.1.1, it can be determined that the firewall policy successfully matches the high-risk rule.
[0063] An authorized work order refers to a record form submitted by the applicant when requesting a firewall policy, which has been authorized and approved. The opposite of an authorized work order is an unauthorized work order or a work order not requested. An unauthorized work order refers to a record form that has been approved without authorization.
[0064] It is understandable that the automatic deployment process of the firewall corresponding to the firewall automation management system includes three parts: application, activation, and verification. Among them, the firewall application can be carried out by the applicant submitting a work order. The firewall application can be authorized after being reviewed and verified by various review parties. Once the authorization is completed, it can be activated (i.e., deployed to the firewall device).
[0065] Specifically, new firewall policies are automatically screened online using preset high-risk rules to initially identify potentially high-risk policies. If a potentially high-risk new firewall policy corresponds to an authorized work order, it is allowed to be (temporarily) enabled. If a potentially high-risk new firewall policy does not correspond to an authorized work order (or corresponds to an unauthorized work order), it is determined to be a high-risk policy, requiring further targeted approval. Therefore, in this embodiment, the purpose of targeted approval is to determine whether high-risk firewall policies not authorized by the firewall automation management system originate from operations outside of security specifications.
[0066] For example, an operation outside of security specifications can be as follows: Within an enterprise system, ordinary employees (the applicants) need to submit a work order to the operations and maintenance personnel, who then review whether to authorize the work order. Therefore, the operations and maintenance personnel have a wider scope of authority than ordinary employees. In this case, the operations and maintenance personnel can enable (authorize) some firewall policies without submitting a work order. Deploying and enabling firewall policies without authorization constitutes an operation outside of security specifications. Therefore, this embodiment establishes a targeted approval process to verify the security of firewall policies enabled by operations and maintenance personnel without authorization.
[0067] Understandably, when determining whether the newly added firewall policy corresponds to an authorized work order, it is necessary to interface with the enterprise's internal work order system. In this embodiment, the computer device 10 is equipped with a work order system interface module. Through this module, authorized and unauthorized work orders within the enterprise over the past N days can be queried. The selectable work order time range of N days can be customized. Enterprises can customize the work order comparison range in the firewall automated management system based on actual environment scale, verification system performance, security check requirements, and actual policy implementation time requirements, thus avoiding overly frequent and large-scale invalid verifications.
[0068] Optionally, when conducting targeted approvals, it is necessary to establish an approval process for the newly added firewall policy and send the approval process to the approver. The approver can be an operations and maintenance personnel or other designated personnel, and the approver may differ for different newly added firewall policies.
[0069] Specifically, establishing an approval process may include: determining at least one approver and the workflow between them based on the new firewall policy; obtaining a workflow template, which includes multiple approval nodes, the approval content corresponding to each node, and the workflow between them; designating each approver as an approval node in the workflow template, the new firewall policy as the approval content of each node, and the workflow between approvers as the workflow between nodes, thus obtaining the approval process corresponding to the new firewall policy. Optionally, the approval process may also include an approval number, approval initiation time, etc.
[0070] Furthermore, the approval process is sent to the terminal devices of each approver, who can view the approval process and fill in the approval results on the page on their terminal.
[0071] S203: Obtain the approval result from the approver and, based on the approval result, determine the usage status of the newly added firewall policy.
[0072] The approval results from each approving party can include approval passed, approval failed, or approval incomplete. Furthermore, for any approving party, if the approval result is "approval incomplete" within a preset time period, then the approving party's approval result can be determined as approval failed.
[0073] Specifically, based on the approval results of each approving party, the approval status of the approval process is determined, which can include approval passed, approval failed, or approval incomplete. Then, based on the approval status of the approval process, the usage status of the newly added firewall policy is determined; for example, the usage status of the newly added firewall policy can include continuing to enable or disable it.
[0074] In the aforementioned firewall policy management method, security checks can be performed on newly added firewall policies on firewall devices in a timely manner. During the security check, new firewall policies are initially screened using high-risk rules (first screening), and then screened a second time based on whether an authorization work order is available. Both the first and second screenings are automatic screening steps within the firewall automation management system. After the first and second screenings, if a new firewall policy is determined to be a high-risk policy, an approval process is established for the new firewall policy. Based on this approval process, a third approval is conducted for the new firewall policy. The purpose of the third approval is to conduct targeted approval for firewall policies that are high-risk (i.e., meet high-risk rules) and do not have an authorization work order, and to determine the usage status of the new firewall policy based on the approval result. The third approval, as an external approval step independent of the firewall automation management system, can supplement the automatic screening steps in the firewall automation management system. That is, it provides an early detection mechanism and a post-event remediation mechanism for policy opening scenarios in the firewall automation management system. Compared with traditional technologies, this improves the security of firewall policy deployment without requiring significant adjustments to the entire firewall automation management system.
[0075] In one embodiment, this embodiment provides an optional method for obtaining the newly added firewall policy corresponding to the firewall device, that is, a method for refining S201. The specific implementation process may include: determining the newly added firewall policy corresponding to the firewall device based on the current firewall policy and historical firewall policies corresponding to the firewall device.
[0076] Among them, such as Figure 3 As shown, the computer device 10 in this embodiment includes a firewall policy parsing module 30, which further includes a firewall incremental configuration comparison unit 31. The firewall incremental configuration comparison unit 31 is used to provide firewall policy acquisition service and firewall policy incremental comparison service. When the firewall policy acquisition service is invoked, it will retrieve the full configuration of the current firewall device and store the full configuration (i.e., all configured firewall policies) in text format. Then, it will compare the full configuration retrieved this time with the previous full configuration most recent in time to obtain the new firewall policy.
[0077] It is understandable that the full configuration of the current firewall device mentioned above is the current firewall policy, and the most recent full configuration is the historical firewall policy; firewall policies that have changed or been added in the current firewall policy compared to the historical firewall policy are identified as new firewall policies.
[0078] In this embodiment, by periodically checking for updates, newly added firewall policies on the firewall device can be detected in a timely manner, thus improving the timeliness of firewall policy security checks.
[0079] In one embodiment, this embodiment provides an optional method to determine whether a newly added firewall policy is a high-risk policy based on preset high-risk rules and whether the newly added firewall policy has an authorized work order, that is, to provide a way to refine S202. The specific implementation process may include: if it is detected that the newly added firewall policy successfully matches the preset high-risk rules, then determine whether the newly added firewall policy has an authorized work order. If not, then determine that the newly added firewall policy is a high-risk policy.
[0080] Among them, such as Figure 3 As shown, the computer device 10 in this embodiment includes a high-risk rule management module 20, which includes a high-risk rule maintenance unit 21 for defining high-risk rules. The high-risk rule maintenance unit 21 can provide maintenance personnel with high-risk rule creation services through a webpage display. Maintenance personnel can define high-risk rules according to the enterprise's internal security review requirements and actual address usage. Optionally, high-risk rules can be used to limit elements such as source address, source port, destination address, destination port, and protocol in firewall policies.
[0081] Furthermore, such as Figure 4 As shown, this embodiment provides an optional method for identifying a newly added firewall policy that successfully matches a preset high-risk rule, which may specifically include:
[0082] S401: Extract the new policy element from the newly added firewall policy and match the new policy element with the preset high-risk rules.
[0083] The newly added policy elements include at least the source address, destination address, source port, destination port, and protocol type.
[0084] Specifically, such as Figure 5 As shown, the firewall policy parsing module 30 in this embodiment also includes a firewall policy parsing query unit 32. The firewall policy parsing query unit 32 is used to receive the newly added firewall policy sent by the firewall incremental configuration comparison unit 31, and parse the newly added firewall policy to obtain the new policy element in the form of a five-tuple. Optionally, the final storage format of the newly added firewall policy may include policy number, etc., in addition to the five-tuple information.
[0085] S402 If the newly added policy element is matched with a high-risk rule, it is confirmed that the newly added firewall policy has successfully matched the preset high-risk rule.
[0086] Among them, such as Figure 5 As shown, the risk rule management module 20 in this embodiment includes a high-risk policy comparison unit 22 for defining comparison rules between newly added firewall policies and high-risk rules. The high-risk policy comparison unit 22 provides a service to compare whether a five-tuple of data conforms to a high-risk rule through an interface. Corresponding to the newly added policy element, the interface parameters of the high-risk policy comparison unit 22 include source address, source port, destination address, destination port, protocol, etc.
[0087] Specifically, after the parameters of the newly added policy element are input into the interface of the high-risk policy comparison unit 22, the high-risk policy comparison unit 22 compares each parameter of the newly added policy element with each high-risk rule in the high-risk rule maintenance unit 201, and determines whether the newly added firewall policy conforms to the high-risk rules based on the comparison results. It can be understood that as long as it is determined that the parameters corresponding to the newly added firewall policy conform to any one of the high-risk rules, there is no need to compare the remaining high-risk rules.
[0088] In this embodiment, the customization of high-risk rules allows enterprises to customize the scope of high-risk firewall policies according to their internal security requirements, avoiding the consumption of verification of a large number of invalid low-risk policies.
[0089] like Figure 6 As shown, this embodiment provides an optional method for establishing an approval process corresponding to a newly added firewall policy, that is, a way to refine S203. The specific implementation process may include:
[0090] S601, based on the initiator information corresponding to the newly added firewall policy, determines at least one approver and the flow relationship between each approver.
[0091] The information for the initiator of the newly added firewall policy includes the information of the person who initiated the policy and the purpose of the policy. The information of the person who initiated the policy may include the person ID, the department to which the person who initiated the policy belongs, the organizational structure of the department to which the person who initiated the policy, and the permission level of the person who initiated the policy.
[0092] It is understandable that the approvers may differ depending on the initiator. For example, if the initiator is maintenance personnel 1, the approvers could be maintenance personnel 2, maintenance personnel 3, and so on. If the initiator is ordinary employee 1, the approvers could be maintenance personnel 1, maintenance personnel 2, maintenance personnel 3, and so on.
[0093] Specifically, based on the initiator information corresponding to the newly added firewall policy, determine at least one approver and the flow relationship between each approver, including: obtaining the initiator information corresponding to the newly added firewall policy from the personnel access control system based on the source address in the newly added firewall policy; and determining at least one approver and the flow relationship between each approver based on the initiator information.
[0094] Optionally, the source address in the newly added firewall policy can be resolved and connected to the personnel access control system. The personnel access control system stores the information of each IP address in the enterprise system, the personnel who use each IP address, and the purpose of use. Therefore, the initiator information corresponding to the newly added firewall policy can be queried through the source address.
[0095] Specifically, based on the initiator information, determine at least one approver and the flow relationship between each approver, including: based on the initiator's security level and / or the departmental organizational relationship of the initiator's department in the initiator information, determine at least one approver and the flow relationship between each approver.
[0096] In one possible implementation, the initiator can be assigned a corresponding approver based on the initiator's security level in the initiator information and a preset level lookup table. The level lookup table stores the reviewers corresponding to different security levels and the flow relationships between the approvers.
[0097] In another possible approach, the superiors of the initiator can be determined based on the departmental organizational relationship of the initiator's department, and each superior and maintenance personnel can be used as the approver of the initiator and the flow relationship between each approver.
[0098] Furthermore, in another possible approach, maintenance personnel can be determined based on the security level of the initiator in the initiator information, and the superior personnel corresponding to the initiator can be determined based on the departmental organizational relationship of the department to which the initiator belongs; from each superior personnel and maintenance personnel, the approver corresponding to the initiator and the flow relationship between each approver can be obtained.
[0099] S602 establishes an approval process for new firewall policies based on the approval parties, the workflow between them, and the approval content of the new firewall policies.
[0100] In one possible implementation, the approval content for the new firewall policy can be the same for each approver, that is, the entire new firewall policy is distributed to each approver as the approval content; in another possible implementation, the approval content for the new firewall policy can also be different for each approver.
[0101] Specifically, by adding the approval parties, the workflow between them, and the approval content for the new firewall policy to the approval template, an approval process for the new firewall policy can be established.
[0102] In this embodiment, by matching approvers to different initiators and setting up approval processes in a differentiated and refined manner, targeted manual security verification can be achieved, further improving the security of firewall policy deployment.
[0103] For example, based on the above embodiments, this embodiment provides an optional example of a firewall policy management method. For instance... Figure 7 As shown, the specific implementation process includes:
[0104] S701 determines the new firewall policy for the firewall device based on the current and historical firewall policies.
[0105] S702 If it is found that the newly added firewall policy matches the preset high-risk rule, it is determined whether the newly added firewall policy has an authorized work order.
[0106] Specifically, the newly added policy element is extracted from the newly added firewall policy, and the newly added policy element is matched with the preset high-risk rules. The policy element includes at least the source address, destination address, source port, destination port, and protocol type. If the newly added policy element matches the high-risk rule, it is determined that the newly added firewall policy has successfully matched the preset high-risk rule.
[0107] If S703 is not available, then the newly added firewall policy is determined to be a high-risk policy.
[0108] S704 If it is determined that the newly added firewall policy is a high-risk policy, the initiator information corresponding to the newly added firewall policy is obtained from the personnel access control system based on the source address in the newly added firewall policy.
[0109] S705, based on the initiator's security level and / or the departmental organizational relationship of the initiator's department in the initiator information, determine at least one approver and the flow relationship between the approvers.
[0110] S706 establishes an approval process for new firewall policies based on the approval parties, the workflow between them, and the approval content of the new firewall policies.
[0111] S707: Obtain the approval result from the approver and, based on the approval result, determine the usage status of the newly added firewall policy.
[0112] The specific processes of S701-S707 described above can be found in the description of the above method embodiments. Their implementation principles and technical effects are similar, and will not be repeated here.
[0113] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps.
[0114] Based on the same inventive concept, this application also provides a firewall policy management device for implementing the firewall policy management method described above. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more firewall policy management device embodiments provided below can be found in the limitations of the firewall policy management method described above, and will not be repeated here.
[0115] In one embodiment, such as Figure 8 As shown, a firewall policy management device 1 is provided, including: an acquisition module 11, a creation module 12, and an approval module 13, wherein:
[0116] Module 11 is used to obtain newly added firewall policies corresponding to the firewall device;
[0117] Create module 12, which is used to establish an approval process for the new firewall policy when the new firewall policy is determined to be a high-risk policy based on the preset high-risk rules and whether the new firewall policy has an authorized work order, and send the approval process to the approver.
[0118] Approval module 13 is used to obtain the approval result from the approver and, based on the approval result, determine the usage status of the newly added firewall policy.
[0119] In one embodiment, the firewall policy management device 1 further includes a secondary judgment module, used to: if it is found that the newly added firewall policy matches the preset high-risk rule successfully, determine whether the newly added firewall policy has an authorized work order;
[0120] If not, the newly added firewall policy is identified as a high-risk policy.
[0121] In one embodiment, module 12 is created, including:
[0122] The node construction submodule is used to determine at least one approver and the flow relationship between each approver based on the initiator information corresponding to the newly added firewall policy.
[0123] The workflow submodule is used to establish the approval workflow for new firewall policies based on the approval parties, the flow relationships between them, and the approval content of the new firewall policies.
[0124] In one embodiment, the node construction submodule includes:
[0125] The addressing module is used to obtain the initiator information corresponding to the newly added firewall policy from the personnel access control system based on the source address in the newly added firewall policy.
[0126] The module is used to determine the flow relationship between at least one approver and each approver based on the initiator information.
[0127] In one embodiment, the determination module is specifically used to: determine at least one approver and the flow relationship between the approvers based on the security level of the initiator and / or the departmental organizational relationship of the department to which the initiator belongs in the initiator information.
[0128] In one embodiment, the acquisition module 12 is specifically used to: determine the new firewall policy corresponding to the firewall device based on the current firewall policy and historical firewall policy corresponding to the firewall device.
[0129] In one embodiment, the firewall policy management device 1 further includes a comparison and judgment module, used to: extract the new policy element from the new firewall policy and match the new policy element with the preset high-risk rules; wherein, the policy element includes at least source address, destination address, source port, destination port and protocol type;
[0130] If the newly added policy element is matched with a high-risk rule, it is confirmed that the newly added firewall policy has successfully matched the preset high-risk rule.
[0131] The modules in the aforementioned firewall policy management can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the computer device's memory as software, so that the processor can invoke and execute the corresponding operations of each module.
[0132] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 9As shown, the computer device includes a processor, memory, communication interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a firewall policy management method. The display screen can be an LCD screen or an e-ink screen. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad mounted on the computer device casing, or an external keyboard, touchpad, or mouse.
[0133] Those skilled in the art will understand that Figure 9 The structure shown is merely a block diagram of a portion of the structure related to this invention and does not constitute a limitation on the computer equipment on which this invention is applied. Specific computer equipment may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.
[0134] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0135] Retrieve the newly added firewall policy corresponding to the firewall device;
[0136] If a new firewall policy is determined to be a high-risk policy based on the preset high-risk rules and whether the new firewall policy has an authorized work order, an approval process corresponding to the new firewall policy is established and the approval process is sent to the approver.
[0137] Obtain the approval result from the approver, and determine the usage status of the newly added firewall policy based on the approval result.
[0138] In one embodiment, when the processor executes a computer program to determine that a newly added firewall policy is a high-risk policy based on preset high-risk rules and whether the newly added firewall policy has an authorized work order, the following steps are specifically implemented: if it is found that the newly added firewall policy matches the preset high-risk rules, then it is determined whether the newly added firewall policy has an authorized work order; if it does not, then the newly added firewall policy is determined to be a high-risk policy.
[0139] In one embodiment, when the processor executes the logic of the computer program to establish the approval process corresponding to the new firewall policy, the following steps are specifically implemented: based on the initiator information corresponding to the new firewall policy, determine at least one approver and the flow relationship between each approver; based on each approver, the flow relationship between each approver, and the approval content of the new firewall policy, establish the approval process corresponding to the new firewall policy.
[0140] In one embodiment, when the processor executes the logic of a computer program to determine at least one approver and the flow relationship between each approver based on the initiator information corresponding to the newly added firewall policy, the specific steps are as follows: obtain the initiator information corresponding to the newly added firewall policy from the personnel access control system based on the source address in the newly added firewall policy; determine the flow relationship between at least one approver and each approver based on the initiator information.
[0141] In one embodiment, when the processor executes the logic of a computer program to determine at least one approver and the flow relationship between each approver based on the initiator information, the specific steps are as follows: determine at least one approver and the flow relationship between each approver based on the security level of the initiator and / or the departmental organizational relationship of the department to which the initiator belongs in the initiator information.
[0142] In one embodiment, when the processor executes the logic of the computer program to obtain the new firewall policy corresponding to the firewall device, the following steps are specifically implemented: based on the current firewall policy and historical firewall policy corresponding to the firewall device, determine the new firewall policy corresponding to the firewall device.
[0143] In one embodiment, when the processor executes the logic that the computer program recognizes that the newly added firewall policy has successfully matched the preset high-risk rule, the following steps are specifically implemented: extracting the newly added policy element from the newly added firewall policy and matching the newly added policy element with the preset high-risk rule; wherein, the policy element includes at least the source address, destination address, source port, destination port and protocol type; if the newly added policy element matches the high-risk rule, it is determined that the newly added firewall policy has successfully matched the preset high-risk rule.
[0144] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor:
[0145] Retrieve the newly added firewall policy corresponding to the firewall device;
[0146] If a new firewall policy is determined to be a high-risk policy based on the preset high-risk rules and whether the new firewall policy has an authorized work order, an approval process corresponding to the new firewall policy is established and the approval process is sent to the approver.
[0147] Obtain the approval result from the approver, and determine the usage status of the newly added firewall policy based on the approval result.
[0148] In one embodiment, when the logic of determining that a newly added firewall policy is a high-risk policy based on preset high-risk rules and whether the newly added firewall policy has an authorized work order is executed by the processor, the following steps are specifically implemented: if it is found that the newly added firewall policy matches the preset high-risk rules, then it is determined whether the newly added firewall policy has an authorized work order; if it does not, then the newly added firewall policy is determined to be a high-risk policy.
[0149] In one embodiment, when the logic of the computer program establishing the approval process corresponding to the new firewall policy is executed by the processor, the following steps are specifically implemented: based on the initiator information corresponding to the new firewall policy, determine at least one approver and the flow relationship between each approver; based on each approver, the flow relationship between each approver, and the approval content of the new firewall policy, establish the approval process corresponding to the new firewall policy.
[0150] In one embodiment, when the logic of determining at least one approver and the flow relationship between each approver based on the initiator information corresponding to the newly added firewall policy is executed by the processor, the following steps are specifically implemented: obtaining the initiator information corresponding to the newly added firewall policy from the personnel access control system based on the source address in the newly added firewall policy; determining the flow relationship between at least one approver and each approver based on the initiator information.
[0151] In one embodiment, when the logic of a computer program determining at least one approver and the flow relationship between each approver based on the initiator information is executed by the processor, the following steps are specifically implemented: determining at least one approver and the flow relationship between each approver based on the security level of the initiator and / or the departmental organizational relationship of the department to which the initiator belongs in the initiator information.
[0152] In one embodiment, when the logic of the computer program to obtain the new firewall policy corresponding to the firewall device is executed by the processor, the following steps are specifically implemented: based on the current firewall policy and the historical firewall policy corresponding to the firewall device, determine the new firewall policy corresponding to the firewall device.
[0153] In one embodiment, when the logic that the computer program recognizes that the newly added firewall policy matches the preset high-risk rule is executed by the processor, the following steps are specifically implemented: extract the newly added policy element from the newly added firewall policy and match the newly added policy element with the preset high-risk rule; wherein, the policy element includes at least the source address, destination address, source port, destination port and protocol type; if the newly added policy element matches the high-risk rule, it is determined that the newly added firewall policy has been recognized as matching the preset high-risk rule.
[0154] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps:
[0155] Retrieve the newly added firewall policy corresponding to the firewall device;
[0156] If a new firewall policy is determined to be a high-risk policy based on the preset high-risk rules and whether the new firewall policy has an authorized work order, an approval process corresponding to the new firewall policy is established and the approval process is sent to the approver.
[0157] Obtain the approval result from the approver, and determine the usage status of the newly added firewall policy based on the approval result.
[0158] In one embodiment, when the logic of determining that a newly added firewall policy is a high-risk policy based on preset high-risk rules and whether the newly added firewall policy has an authorized work order is executed by the processor, the following steps are specifically implemented: if it is found that the newly added firewall policy matches the preset high-risk rules, then it is determined whether the newly added firewall policy has an authorized work order; if it does not, then the newly added firewall policy is determined to be a high-risk policy.
[0159] In one embodiment, when the logic of the computer program establishing the approval process corresponding to the new firewall policy is executed by the processor, the following steps are specifically implemented: based on the initiator information corresponding to the new firewall policy, determine at least one approver and the flow relationship between each approver; based on each approver, the flow relationship between each approver, and the approval content of the new firewall policy, establish the approval process corresponding to the new firewall policy.
[0160] In one embodiment, when the logic of determining at least one approver and the flow relationship between each approver based on the initiator information corresponding to the newly added firewall policy is executed by the processor, the following steps are specifically implemented: obtaining the initiator information corresponding to the newly added firewall policy from the personnel access control system based on the source address in the newly added firewall policy; determining the flow relationship between at least one approver and each approver based on the initiator information.
[0161] In one embodiment, when the logic of a computer program determining at least one approver and the flow relationship between each approver based on the initiator information is executed by the processor, the following steps are specifically implemented: determining at least one approver and the flow relationship between each approver based on the security level of the initiator and / or the departmental organizational relationship of the department to which the initiator belongs in the initiator information.
[0162] In one embodiment, when the logic of the computer program to obtain the new firewall policy corresponding to the firewall device is executed by the processor, the following steps are specifically implemented: based on the current firewall policy and the historical firewall policy corresponding to the firewall device, determine the new firewall policy corresponding to the firewall device.
[0163] In one embodiment, when the logic that the computer program recognizes that the newly added firewall policy matches the preset high-risk rule is executed by the processor, the following steps are specifically implemented: extract the newly added policy element from the newly added firewall policy and match the newly added policy element with the preset high-risk rule; wherein, the policy element includes at least the source address, destination address, source port, destination port and protocol type; if the newly added policy element matches the high-risk rule, it is determined that the newly added firewall policy has been recognized as matching the preset high-risk rule.
[0164] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0165] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0166] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0167] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A firewall policy management method characterized by, The method includes: Retrieve the newly added firewall policy corresponding to the firewall device; If the newly added firewall policy is found to match the preset high-risk rule, it is determined whether the newly added firewall policy has an authorized work order. The authorized work order refers to the record form submitted by the applicant when applying for the firewall policy and which has been authorized and approved. If not, the newly added firewall policy is determined to be a high-risk policy; If the newly added firewall policy is determined to be a high-risk policy, at least one approver and the flow relationship between each approver shall be determined based on the initiator information corresponding to the newly added firewall policy. Based on the approval parties, the workflow between them, and the approval content of the new firewall policy, an approval process corresponding to the new firewall policy is established, and the approval process is sent to the approval parties. Obtain the approval result from the approver, and determine the usage status of the newly added firewall policy based on the approval result.
2. The method of claim 1, wherein, The step of determining at least one approver and the flow relationship between each approver based on the initiator information corresponding to the newly added firewall policy includes: Based on the source address in the newly added firewall policy, obtain the initiator information corresponding to the newly added firewall policy from the personnel access control system; Based on the initiator information, determine at least one approver and the flow relationship between each approver.
3. The method of claim 2, wherein, The step of determining at least one approver and the flow relationship between each approver based on the initiator information includes: Based on the initiator's security level and / or the departmental organizational relationship of the initiator's department in the initiator's information, determine at least one approver and the flow relationship between the approvers.
4. The method of claim 1, wherein, The process of obtaining the newly added firewall policy corresponding to the firewall device includes: Based on the current and historical firewall policies of the firewall device, determine the new firewall policy corresponding to the firewall device.
5. The method of claim 1, wherein, The newly added firewall policy was found to have successfully matched a preset high-risk rule, including: Extract the new policy element from the newly added firewall policy and match the new policy element with preset high-risk rules; wherein, the new policy element includes at least source address, destination address, source port, destination port and protocol type; If the newly added policy element matches a preset high-risk rule, it is determined that the newly added firewall policy has successfully matched the preset high-risk rule.
6. A firewall policy management apparatus characterized by comprising: The device includes: The acquisition module is used to acquire newly added firewall policies corresponding to the firewall device. A module is created to determine whether the newly added firewall policy has an authorized work order if it is found that the newly added firewall policy matches the preset high-risk rule. The authorized work order refers to the record form submitted by the applicant when applying for the firewall policy and which has been authorized and approved. If not, the newly added firewall policy is determined to be a high-risk policy; If the newly added firewall policy is determined to be a high-risk policy, an approval process corresponding to the newly added firewall policy is established, and the approval process is sent to the approver. The approval module is used to obtain the approval result from the approver and, based on the approval result, determine the usage status of the newly added firewall policy. 7.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-6 when the computer program is executed by the processor. When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 5.
8. A computer-readable storage medium having stored thereon a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5.
9. A computer program product comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Firewall security policy automatic adaptation system and method
CN111786949A
Firewall rule dynamic configuration method
CN113992422A