Firewall configuration method and apparatus, computer device and storage medium

By mirroring and analyzing business traffic, site protection and resource configuration rules are generated, and application firewalls are automatically configured, solving the problem of low configuration efficiency in existing technologies and achieving flexible and efficient firewall configuration.

CN116668155BActive Publication Date: 2026-04-14HANGZHOU DBAPPSECURITY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-20
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

The configuration efficiency of existing firewalls is low, especially in large and complex business environments. Pre-configuration and planning are cumbersome and it is easy to overlook protected sites, resulting in high usage costs.

Method used

By receiving and mirroring business traffic, analyzing the network and load information of the site, generating site protection rules and resource configuration rules, and automatically configuring the application firewall, it can adapt to both internal and external network environments without needing to be connected in series with the network.

Benefits of technology

It improves the configuration flexibility and efficiency of application firewalls, adapts to various network environments, ensures that the original network results remain unchanged, and enhances configuration security and system stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116668155B_ABST
    Figure CN116668155B_ABST
Patent Text Reader

Abstract

The application relates to an application firewall configuration method and device, computer equipment and a storage medium. Service traffic obtained by mirroring processing of received traffic from a switch is received, the service traffic is analyzed, network information and load information of a site are obtained, site information for protecting the site is obtained according to the network information, corresponding site protection rules are generated according to the site information for protecting the site, corresponding site resource configuration rules are generated according to the load information, and the application firewall is configured according to the site protection rules and the site resource configuration rules, so that the application firewall does not need to be connected in series to networking, thus the original network result is not changed, and the configuration strategy can be automatically deployed according to the network information and the load condition, so that the flexibility and the configuration efficiency of the application firewall configuration are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of application firewall technology, and in particular to an application firewall configuration method, apparatus, computer device, and storage medium. Background Technology

[0002] Web attacks are attacks targeting users' online behavior or website servers and other devices. They can achieve malicious intrusions through a series of attack methods, such as injecting malicious code, modifying website permissions, and obtaining users' private information. Web application security is an important part of any web-based business, so ensuring the security of web applications is extremely important.

[0003] A Web Application Firewall (WAF) is a product that specifically protects web applications by enforcing a series of security policies targeting HTTP / HTTPS (Hypertext Transfer Protocol). Currently, the common deployment method for WAFs in related technologies is to pre-configure corresponding protection sites to address various web attacks. These sites specify the server information to be protected and the protection detection rules to ensure the web security of the servers. However, when the server services to be protected are too large and complex, pre-configuring and planning for each protection site becomes extremely cumbersome, and it is easy to overlook sites that need protection, resulting in high usage costs and low configuration efficiency.

[0004] Currently, no effective solution has been proposed for the problem of low configuration efficiency of application firewalls in related technologies. Summary of the Invention

[0005] Therefore, it is necessary to provide an application firewall configuration method, apparatus, computer device, and computer-readable storage medium that can improve the configuration efficiency of application firewalls, addressing the aforementioned technical problems.

[0006] Firstly, this application provides an application firewall configuration method. The method includes:

[0007] Receive service traffic, analyze the service traffic to obtain the network information and load information of the site, wherein the service traffic is obtained by mirroring the traffic received by the switch;

[0008] Based on the network information, obtain the site information of the protected site, and generate corresponding site protection rules based on the site information of the protected site;

[0009] Based on the load information, generate corresponding site resource configuration rules;

[0010] Configure the application firewall according to the site protection rules and the site resource configuration rules.

[0011] In one embodiment, when the application firewall is in an intranet environment, obtaining the site information of the protected site based on the network information includes: obtaining a first destination address and a first domain name based on the network information, using the first destination address as the IP address and port of the protected site, and using the first domain name as the domain name of the protected site.

[0012] In one embodiment, when the application firewall is in an external network environment, obtaining the site information of the protected site based on the network information includes: obtaining a second destination address and a second domain name based on the network information, wherein obtaining the second destination address includes: converting the external network address into the second destination address, or resolving the second domain name field, and resolving the external network address into the second destination address based on the resolution result; using the second destination address as the IP address and port of the protected site, and using the second domain name or the second destination address as the domain name of the protected site.

[0013] In one embodiment, generating corresponding site resource configuration rules based on the load information includes: analyzing the load information, wherein the load information includes the number of new connections, throughput, and concurrent connections within a preset time period; and minimizing the reserved address range in the network based on the analysis results to generate recommended access addresses, recommended port number ranges, and recommended outgoing interfaces.

[0014] In one embodiment, after configuring the application firewall, the method further includes: configuring policy routing to redirect the service traffic to the application firewall; wherein, when the application firewall is in an intranet environment, configuring the policy routing includes: specifying the management address of the network firewall through the site resource configuration rules and issuing a first configuration command to configure the policy routing; or, generating a corresponding second configuration command to configure the policy routing based on the network information.

[0015] Secondly, this application also provides an application firewall configuration apparatus. The apparatus includes:

[0016] The receiving and analysis module is used to receive service traffic, analyze the service traffic, and obtain the network information and load information of the site, wherein the service traffic is obtained through switch mirroring;

[0017] The protection rule generation module is used to obtain the site information of the protected site based on the network information, and generate corresponding site protection rules based on the site information of the protected site.

[0018] The resource configuration rule generation module is used to generate corresponding site resource configuration rules based on the load information.

[0019] The configuration module is used to configure the application firewall according to the site protection rules and the site resource configuration rules.

[0020] Thirdly, this application also provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to perform the following steps:

[0021] Receive service traffic, analyze the service traffic to obtain the network information and load information of the site, wherein the service traffic is obtained by mirroring the traffic received by the switch;

[0022] Based on the network information, obtain the site information of the protected site, and generate corresponding site protection rules based on the site information of the protected site;

[0023] Based on the load information, generate corresponding site resource configuration rules;

[0024] Configure the application firewall according to the site protection rules and the site resource configuration rules.

[0025] Fourthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, performs the following steps:

[0026] Receive service traffic, analyze the service traffic to obtain the network information and load information of the site, wherein the service traffic is obtained by mirroring the traffic received by the switch;

[0027] Based on the network information, obtain the site information of the protected site, and generate corresponding site protection rules based on the site information of the protected site;

[0028] Based on the load information, generate corresponding site resource configuration rules;

[0029] Configure the application firewall according to the site protection rules and the site resource configuration rules.

[0030] The aforementioned application firewall configuration method, apparatus, computer equipment, and storage medium receive service traffic from a switch by mirroring the received traffic, analyze the service traffic to obtain network and load information of the sites, obtain site information for protected sites based on the network information, generate corresponding site protection rules based on the site information for protected sites, generate corresponding site resource configuration rules based on the load information, and configure the application firewall based on the site protection rules and site resource configuration rules. This allows the application firewall to be configured without being connected in series with the network, thus not changing the original network structure, and automatically deploying configuration policies based on network information and load conditions, improving the flexibility and efficiency of application firewall configuration. Attached Figure Description

[0031] Figure 1 This is an application environment diagram of a firewall configuration method applied in one embodiment;

[0032] Figure 2 This is a schematic diagram of a network structure in which a firewall configuration method is applied in a related technology in one embodiment.

[0033] Figure 3 This is a schematic diagram of a network structure in another embodiment where a firewall configuration method is applied in the related technology.

[0034] Figure 4 This is a flowchart illustrating the application of a firewall configuration method in one embodiment;

[0035] Figure 5 A network structure diagram illustrating the application of a firewall configuration method in one embodiment;

[0036] Figure 6 This is a schematic diagram of the network structure in an example where the firewall is used in an intranet environment.

[0037] Figure 7 This is a schematic diagram of the network structure in one embodiment where the firewall is located in an external network environment.

[0038] Figure 8 This is a structural block diagram of an application firewall configuration device in one embodiment;

[0039] Figure 9 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0040] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0041] The application firewall configuration method provided in this application embodiment can be applied to, for example, Figure 1 In the application environment shown, terminal 102 communicates with server 104 via a network. A data storage system can store the data that server 104 needs to process. The data storage system can be integrated onto server 104 or placed on a cloud or other network server. The application firewall configuration method of this embodiment analyzes traffic and recommends the most suitable network deployment scheme for terminal 102 to deploy. Terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, etc., and server 104 can be a standalone server or a server cluster composed of multiple servers.

[0042] In related technologies, the main method for protecting sites is to connect application firewalls in series with the network. Figure 2 This is a network structure diagram illustrating the application of firewall configuration methods in related technologies, such as... Figure 2 As shown, an application firewall is deployed in a transparent proxy network. The application firewall device is transparently connected in series with the network, and its communication interface operates at Layer 2. No IP address or port configuration is required; users can directly access the website using the web server's IP address. The application firewall captures business data packets flowing through the bridge, filters irrelevant requests, extracts relevant fields from the packets as site domain names, and extracts the destination IP as the site address, thereby determining the corresponding site information to be protected. While this method simplifies site deployment, it requires the application firewall to be serially connected to the terminal network and to operate at Layer 2. However, as... Figure 3 As shown, in real-world application environments, when various complex situations arise in the customer network, causing the application firewall to be unable to access the customer network serially or to operate at Layer 2, this method will not be feasible.

[0043] In one embodiment, such as Figure 4 As shown, an application firewall configuration method is provided, which is applied to... Figure 1 Taking the terminal in the example, the explanation includes the following steps:

[0044] Step S402: Receive service traffic, analyze the service traffic, and obtain the network information and load information of the site. The service traffic is obtained by mirroring the traffic received by the switch.

[0045] in, Figure 5 This is a network structure diagram of an application firewall configuration method according to an embodiment of this application, such as... Figure 5As shown, the switch (SW) mirrors the received traffic through the firewall (FW), and then transmits the mirrored service traffic to the application firewall. The application firewall automatically analyzes and identifies the original network traffic pattern, and obtains the network information and load information of the sites that need to be protected based on the analysis results. Since the service traffic analyzed and identified by the application firewall is obtained by mirroring the original traffic, it does not affect the original services themselves.

[0046] Step S404: Obtain the site information of the protected site based on the network information, and generate the corresponding site protection rules based on the site information of the protected site.

[0047] The application firewall analyzes received service traffic to obtain network information. Based on this network information, it generates and records site information for sites that need protection. It then generates corresponding site protection rules and settings based on this recorded site information, and recommends appropriate redirection deployment schemes for users to choose from.

[0048] Step S406: Generate corresponding site resource configuration rules based on load information.

[0049] The application firewall analyzes and records the service load of sites to generate corresponding site resource configuration rules, including how to rationally utilize existing resources to achieve optimal load distribution. These resource configuration rules guide users in selecting network access addresses, port ranges, and outgoing interfaces.

[0050] In the above application firewall configuration method, service traffic is received and analyzed to obtain network and load information of the sites. The service traffic is obtained by mirroring the traffic received by the switch. Based on the network information, the site information of the protected sites is obtained. Based on the site information of the protected sites, corresponding site protection rules are generated. Based on the load information, corresponding site resource configuration rules are generated. This allows the application firewall to be installed in series with the network, thus not changing the original network structure. Furthermore, it can automatically deploy configuration policies based on network information and load conditions, improving the flexibility and efficiency of application firewall configuration.

[0051] In one embodiment, when the application firewall is in an intranet environment, obtaining the site information of the protected site based on network information includes: obtaining a first destination address and a first domain name based on network information, using the first destination address as the IP address and port of the protected site, and using the first domain name as the domain name of the protected site.

[0052] When the application firewall is in an intranet environment, it receives business traffic, extracts the first destination address as the IP and port of the site to be protected based on the network information of the business traffic, and extracts the first domain name as the domain name of the site to be protected, thereby generating and recording the site information to be protected. Based on the recorded site information, the application firewall automatically generates corresponding site protection rules and recommends appropriate redirection deployment solutions to the user according to the site protection rules.

[0053] For example, Figure 6 This is a schematic diagram of the network structure when the application firewall of one embodiment of this application is in an intranet environment, as shown below. Figure 6 As shown, before the application firewall is deployed, the destination address of network service requests sent from the user network to the switch is 192.168.27.165:80, the request header is GET / 1.html HTTP / 1.1, and the Host is abc.com. Here, Host is a host table that stores hostnames and IP addresses. After the network traffic is sent, the application firewall is connected to the switch side. The traffic is mirrored to the application firewall on the switch. In this mode, the application firewall only recognizes customer service traffic and has no impact on the customer's original services. The application firewall analyzes the received service traffic, extracts the first destination address 192.168.27.165:80 as the IP address and port of the site to be protected, and the first domain name abc.com as the domain name of the site to be protected, thereby generating and recording the information of the sites to be protected.

[0054] In this embodiment, business traffic is analyzed in an intranet environment to obtain information about protected sites, which facilitates the generation of corresponding protection rules and deployment schemes, thereby improving the configuration efficiency of the application firewall.

[0055] In one embodiment, when the application firewall is in an external network environment, obtaining the site information of the protected site based on network information includes: obtaining a second destination address and a second domain name based on network information. Obtaining the second destination address includes: converting the external network address to a second destination address, or resolving the second domain name field and resolving the external network address to a second destination address based on the resolution result. The second destination address is used as the IP address and port of the protected site, and the second domain name or the second destination address is used as the domain name of the protected site.

[0056] When the application firewall is in an external network environment, network information needs to be processed to provide information for subsequent application firewall deployment. This embodiment uses two methods to translate external network addresses. Method one is through the user firewall device (FW), which translates the external network address into a second destination address via NAT (Network Address Translation) and sends it to the switch (SW). Method two is through a DNS (Domain Name System) server resolving the second domain name field, resolving the requested external network address into a second destination address, and sending it to the switch (SW). The application firewall analyzes the received service traffic, extracts the second destination address as the IP and port of the protected site, and uses the second domain name or second destination address as the domain name of the protected site, thereby generating site information for the protected site. Based on the recorded site information, it automatically recommends and generates corresponding site protection rules and settings, and recommends that the customer adopt a reverse proxy deployment solution.

[0057] For example, Figure 7 This is a schematic diagram of the network structure when the application firewall of one embodiment of this application is in an external network environment, as shown below. Figure 7 As shown, before the application firewall is deployed, the destination address of network service requests sent from the user network to the switch is 202.101.172.35:80, the request header is GET / 1.html HTTP / 1.1, and the Host is www.test.com. In Method 1, the traffic passes through the customer's application firewall device, and the external network address is translated to 192.168.26.81:80 via NAT. Finally, the second destination address of the HTTP service requests sent to the switch SW is 192.168.26.81:80, the request header is GET / 1.html HTTP / 1.1, and the Host is www.test.com. In Method 2, the traffic resolves the www.test.com field through a DNS server, resolving the destination address of the request to 192.168.26.81:80. The final destination address of the HTTP request sent to the switch (SW) is 192.168.26.81:80, with request headers of GET / 1.html HTTP / 1.1 and Host address 192.168.26.81:80. The application firewall (WAF) analyzes the received HTTP traffic, extracting the destination address 192.168.26.81:80 as the IP address and port of the site to be protected, and either www.test.com or 192.168.26.81:80 as the domain name of the site to be protected, thus generating information about the sites to be protected.

[0058] In this embodiment, business traffic is analyzed in an external network environment to obtain information about protected sites, facilitating the generation of corresponding protection rules and deployment schemes, thus improving the configuration efficiency of the application firewall. Furthermore, by employing different configuration methods for internal and external networks, it can adapt to various network environments, offering greater flexibility and configuration efficiency.

[0059] In one embodiment, generating corresponding site resource configuration rules based on load information includes: analyzing the load information, wherein the load information includes the number of new connections, throughput and concurrent connections within a preset time period; minimizing the reserved address range in the network based on the analysis results; and generating recommended access addresses, recommended port number ranges and recommended outgoing interfaces.

[0060] The application firewall, based on the analyzed site service load, guides customers to make reasonable use of existing resources, minimize the reserved address range in the specified network, and achieve reasonable allocation of configuration resources, such as recommending specified access addresses, port number ranges, and WAF outgoing interfaces.

[0061] For example, such as Figure 6 As shown, when the application firewall is in an intranet environment, based on the load information, the recommended access address for the WAF is 192.168.2.0-192.168.2.255, the port number range is 8081-8089, and the outgoing interface is ethx. Figure 7 As shown, when the application firewall is in an external network environment, the load on the logged site 1 is high. Therefore, it is recommended to specify the access address as 192.168.2.0-192.168.2.64, the port number range as 8081-8089, and the outgoing interface as ethx. For the logged site 2, the load is low. Therefore, it is recommended to specify the access address as 192.168.2.65-192.168.2.66, the port number as 8081, and the outgoing interface as ethx.

[0062] In this embodiment, resources are configured reasonably for different load conditions, which realizes full utilization and reasonable allocation of load resources and improves the configuration efficiency of application firewall.

[0063] In one embodiment, after configuring the application firewall, the method further includes configuring policy routing to redirect business traffic to the application firewall. When the application firewall is in an intranet environment, configuring policy routing includes: specifying the management address of the network firewall through site resource configuration rules and issuing a first configuration command to configure policy routing, or generating a corresponding second configuration command to configure policy routing based on network information.

[0064] In this deployment scenario, when the application firewall is located within an internal network environment, after the user confirms that the application firewall's generated and recommended configuration policies are correct, the application firewall switches from deployment mode to working mode and begins detecting and protecting the corresponding sites. It automatically selects a suitable address from the user-specified reserved address range to simulate an internal access address and forwards client traffic that passes security checks to the actual web server through the user-specified outgoing interface. The policy routing that needs to be configured on the application firewall can be done by directly specifying the user's network firewall (FW) management address on the application firewall, allowing the application firewall to issue a first configuration command to complete the configuration, or by generating a corresponding network firewall configuration command (i.e., a second configuration command) on the application firewall to assist the user in configuration. Under this deployment scheme, even if the application firewall experiences an abnormal power outage, business traffic can still be forwarded normally to the web server through the switch (SW).

[0065] In this embodiment, business traffic is diverted to the application firewall for security protection, which improves the security of the application firewall configuration. At the same time, when the application firewall experiences an abnormal power failure, business traffic can still be forwarded to the web server normally through the switch (SW), thus improving the stability and reliability of the system.

[0066] In one embodiment, when the application firewall is in an external network environment, configuring policy routing further includes: specifying the management address of the network firewall by configuring a network address translation mapping table, issuing a first configuration command to configure policy routing, or generating a corresponding second configuration command to configure policy routing based on network information.

[0067] When the external network address is translated using the method described above, i.e., the user configures a NAT (Network Address Translation) mapping table on the network firewall (FW) to translate the external network address into an access address generated on the application firewall, and redirects the service traffic matching the access address to the application firewall, the management address of the network firewall can be specified directly on the application firewall, and the application firewall can directly issue the first configuration command to complete the configuration, or the application firewall can generate a corresponding network firewall configuration command (i.e., the second configuration command) to assist the customer in the configuration.

[0068] In this embodiment, business traffic is diverted to the application firewall for security protection, which improves the security of the application firewall configuration. Furthermore, different configuration methods are used for internal and external networks, which can adapt to various network environments and provide greater flexibility and configuration efficiency.

[0069] In one embodiment, when in an external network environment, configuring policy routing further includes: specifying the management address of the domain name server by configuring the resolution field, and issuing a first configuration command to configure policy routing; or, generating a corresponding second configuration command to configure policy routing based on network information.

[0070] When the external network address conversion method is the second method described above, that is, the DNS server configures the resolution field to resolve the second domain name to the access address generated on the application firewall and redirects the business traffic matching the access address to the application firewall, the management address of the network firewall can be specified directly on the application firewall, and the application firewall can directly issue the first configuration command to complete the configuration, or the corresponding DNS server configuration command (i.e., the second configuration command) can be generated on the application firewall according to the network information to assist the client in configuration.

[0071] In this embodiment, business traffic is diverted to the application firewall for security protection, thereby improving the security of the application firewall configuration.

[0072] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0073] Based on the same inventive concept, this application also provides an application firewall configuration apparatus for implementing the application firewall configuration method described above. The solution provided by this apparatus is similar to the implementation described in the above method; therefore, the specific limitations in one or more application firewall configuration apparatus embodiments provided below can be found in the limitations of the application firewall configuration method described above, and will not be repeated here.

[0074] In one embodiment, such as Figure 8 As shown, an application firewall configuration device is provided, including: a receiving and analysis module 81, a protection rule generation module 82, a resource configuration rule generation module 83, and a configuration module 84, wherein...

[0075] The receiving and analysis module 81 is used to receive service traffic, analyze the service traffic, and obtain the network information and load information of the site. The service traffic is obtained through switch mirroring.

[0076] The protection rule generation module 82 is used to obtain the site information of the protected site based on the network information, and generate corresponding site protection rules based on the site information of the protected site.

[0077] The resource configuration rule generation module 83 is used to generate corresponding site resource configuration rules based on load information.

[0078] Configuration module 84 is used to configure the application firewall according to site protection rules and site resource configuration rules.

[0079] The various modules of the application firewall configuration device described above can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.

[0080] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 9 As shown, the computer device includes a processor, memory, input / output interfaces, a communication interface, a display unit, and an input device. The processor, memory, and input / output interfaces are connected via a system bus, and the communication interface and input device are also connected to the system bus via the input / output interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The input / output interfaces are used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When executed by the processor, the computer program implements an application firewall configuration method.

[0081] Those skilled in the art will understand that Figure 9 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0082] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:

[0083] The system receives and analyzes service traffic to obtain network and load information for each site. This service traffic is obtained by mirroring the traffic received by the switch. Based on the network information, it acquires site information for protected sites and generates corresponding site protection rules. Based on the load information, it generates corresponding site resource configuration rules. Finally, it configures the application firewall based on the site protection and resource configuration rules.

[0084] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0085] Based on network information, obtain the first destination address and the first domain name. Use the first destination address as the IP address and port of the protected site, and use the first domain name as the domain name of the protected site.

[0086] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0087] Based on network information, obtain the second destination address and second domain name. Obtaining the second destination address includes: converting the external network address to the second destination address, or resolving the second domain name field and, based on the resolution result, resolving the external network address to the second destination address. Use the second destination address as the IP address and port of the protected site, and use the second domain name or the second destination address as the domain name of the protected site.

[0088] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0089] The load information is analyzed, including the number of new connections, throughput, and concurrent connections within a preset time period. Based on the analysis results, the reserved address range in the network is minimized, and recommended access addresses, recommended port number ranges, and recommended outgoing interfaces are generated.

[0090] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0091] Configure policy routing to redirect business traffic to the application firewall. When the application firewall is in an intranet environment, configuring policy routing includes: specifying the management address of the network firewall through site resource configuration rules and issuing a first configuration command to configure policy routing; or, generating a corresponding second configuration command to configure policy routing based on network information.

[0092] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0093] By configuring a network address translation mapping table, specifying the management address of the network firewall, and issuing the first configuration command to configure policy routing; or, based on network information, generating the corresponding second configuration command to configure policy routing.

[0094] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0095] By configuring the resolution field, the management address of the domain name server is specified, and the first configuration command is issued to configure policy routing; or, based on network information, the corresponding second configuration command is generated to configure policy routing.

[0096] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor:

[0097] The system receives and analyzes service traffic to obtain network and load information for each site. This service traffic is obtained by mirroring the traffic received by the switch. Based on the network information, it acquires site information for protected sites and generates corresponding site protection rules. Based on the load information, it generates corresponding site resource configuration rules. Finally, it configures the application firewall based on the site protection and resource configuration rules.

[0098] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0099] Based on network information, obtain the first destination address and the first domain name. Use the first destination address as the IP address and port of the protected site, and use the first domain name as the domain name of the protected site.

[0100] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0101] Based on network information, obtain the second destination address and second domain name. Obtaining the second destination address includes: converting the external network address to the second destination address, or resolving the second domain name field and, based on the resolution result, resolving the external network address to the second destination address. Use the second destination address as the IP address and port of the protected site, and use the second domain name or the second destination address as the domain name of the protected site.

[0102] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0103] The load information is analyzed, including the number of new connections, throughput, and concurrent connections within a preset time period. Based on the analysis results, the reserved address range in the network is minimized, and recommended access addresses, recommended port number ranges, and recommended outgoing interfaces are generated.

[0104] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0105] Configure policy routing to redirect business traffic to the application firewall. When the application firewall is in an intranet environment, configuring policy routing includes: specifying the management address of the network firewall through site resource configuration rules and issuing a first configuration command to configure policy routing; or, generating a corresponding second configuration command to configure policy routing based on network information.

[0106] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0107] By configuring a network address translation mapping table, specifying the management address of the network firewall, and issuing the first configuration command to configure policy routing; or, based on network information, generating the corresponding second configuration command to configure policy routing.

[0108] In one embodiment, the processor, when executing a computer program, also performs the following steps:

[0109] By configuring the resolution field, the management address of the domain name server is specified, and the first configuration command is issued to configure policy routing; or, based on network information, the corresponding second configuration command is generated to configure policy routing.

[0110] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data shall comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0111] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0112] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0113] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A method for configuring an application firewall, characterized in that, include: Receive service traffic, analyze the service traffic to obtain the network information and load information of the site, wherein the service traffic is obtained by mirroring the traffic received by the switch; Based on the network information, obtain the site information of the protected site, and generate corresponding site protection rules based on the site information of the protected site; Based on the load information, generate corresponding site resource configuration rules; Configure the application firewall according to the site protection rules and the site resource configuration rules; Configure policy routing to redirect the service traffic to the application firewall; wherein, when the application firewall is in an intranet environment, configuring the policy routing includes: specifying the management address of the network firewall through the site resource configuration rules and issuing a first configuration command to configure the policy routing; or, generating a corresponding second configuration command to configure the policy routing based on the network information.

2. The application firewall configuration method according to claim 1, characterized in that, When the application firewall is in an intranet environment, obtaining the site information of the protected site based on the network information includes: Based on the network information, obtain the first destination address and the first domain name, use the first destination address as the IP address and port of the protected site, and use the first domain name as the domain name of the protected site.

3. The application firewall configuration method according to claim 1, characterized in that, When the application firewall is in an external network environment, obtaining the site information of the protected site based on the network information includes: Based on the network information, a second destination address and a second domain name are obtained, wherein obtaining the second destination address includes: converting the external network address into the second destination address, or resolving the second domain name field and resolving the external network address into the second destination address based on the resolution result; Use the second destination address as the IP address and port of the protected site, and use the second domain name or the second destination address as the domain name of the protected site.

4. The application firewall configuration method according to claim 1, characterized in that, Based on the load information, the corresponding site resource configuration rules are generated, including: The load information is analyzed, wherein the load information includes the number of new connections, throughput, and concurrent connections within a preset time period; Based on the analysis results, the reserved address range in the network is minimized, and recommended access addresses, recommended port number ranges, and recommended outgoing interfaces are generated.

5. The application firewall configuration method according to claim 1, characterized in that, When the application firewall is in an external network environment, configuring policy routing also includes: By configuring a network address translation mapping table, specifying the management address of the network firewall, and issuing the first configuration command to configure the policy routing; or, Based on the network information, generate the corresponding second configuration command to configure the policy routing.

6. The application firewall configuration method according to claim 1, characterized in that, When the application firewall is in an external network environment, configuring policy routing also includes: By configuring the resolution field, the management address of the domain name server is specified, and the first configuration command is issued to configure the policy routing; or, Based on the network information, generate the corresponding second configuration command to configure the policy routing.

7. An application firewall configuration device, characterized in that, include: The receiving and analysis module is used to receive service traffic, analyze the service traffic, and obtain the network information and load information of the site, wherein the service traffic is obtained through switch mirroring; The protection rule generation module is used to obtain the site information of the protected site based on the network information, and generate corresponding site protection rules based on the site information of the protected site. The resource configuration rule generation module is used to generate corresponding site resource configuration rules based on the load information. The configuration module is used to configure the application firewall according to the site protection rules and the site resource configuration rules; configure policy routing to redirect the service traffic to the application firewall; wherein, when the application firewall is in an intranet environment, configuring the policy routing includes: specifying the management address of the network firewall through the site resource configuration rules and issuing a first configuration command to configure the policy routing; or, generating a corresponding second configuration command to configure the policy routing based on the network information.

8. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the application firewall configuration method as described in any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the steps of the application firewall configuration method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Web application firewall protection website collection method and device and electronic device

    CN112235248A