Firewall policy management system

By classifying and optimizing firewall data, the problem of lagging data processing in traditional firewalls has been solved, achieving efficient abnormal data management, reducing operational and maintenance pressure, and improving security.

CN116723039BActive Publication Date: 2026-05-15SHENZHEN POWER SUPPLY BUREAU
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHENZHEN POWER SUPPLY BUREAU
Filing Date
2023-07-06
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Traditional firewalls suffer from redundancy in data processing, leading to data processing delays, consuming a large amount of resources, reducing security protection functions, and lacking data analysis and distribution, which increases the workload of operation and maintenance personnel and terminal devices.

Method used

The system acquires terminal data through the data input module, identifies anomalies through the detection module, determines the anomaly type through the data analysis module, determines the risk level through the allocation module, processes the data through the grading module, and performs secondary processing through the rule set module to achieve data grading and optimization.

Benefits of technology

It effectively solved the data anomaly problem, reduced the workload of operation and maintenance personnel and terminal devices, and improved the efficiency and security of firewall policy management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116723039B_ABST
    Figure CN116723039B_ABST
Patent Text Reader

Abstract

The present application relates to a kind of firewall policy management systems, for executing firewall policy management to the firewall of terminal.The system includes: data input module, for obtaining the data to be processed of terminal;Detection module, for judging whether the data to be processed exists exception;Data analysis module, for judging the exception type of data to be processed;Allocation module, for determining the risk level of data to be processed according to the risk condition of data to be processed;Hierarchical module, for determining the data processing mode of data to be processed according to risk level, and processing, obtain processing result;And rule set module, for determining exception data processing model according to processing result, and processing data to be processed, obtain processed data, and transmit processed data to terminal.The present application is classified after allocation to data, solves the exception problem of data and reduces the work pressure of operation and maintenance personnel and terminal equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a firewall policy management system. Background Technology

[0002] Firewall technology is a technique that combines various software and hardware devices used for security management and screening to help computer networks build a relatively isolated protective barrier between their internal and external networks, thereby protecting user data and information security. Due to the massive volume and complexity of computer network data, firewalls require daily management to ensure their effectiveness in protecting information.

[0003] Traditional technologies address the increased workload for operations and maintenance personnel by dynamically managing firewall policies. However, the complex data processing procedures of firewalls lead to data processing delays, consume significant firewall resources, and reduce the firewall's security protection capabilities. Summary of the Invention

[0004] Therefore, it is necessary to provide a firewall policy management system to address the problem of data processing difficulties in firewall policy management.

[0005] A firewall policy management system is used to manage firewall policies on terminal firewalls. The system includes:

[0006] The data input module communicates with the terminal and is used to acquire the data to be processed from the terminal; the data to be processed is the data that needs to be input to the firewall for processing.

[0007] The detection module, connected to the data input module, is used to determine whether there are any abnormalities in the data to be processed;

[0008] The data analysis module, connected to the detection module, is used to determine the type of anomaly in the data to be processed when there are anomalies. The anomaly types include shadow anomalies and redundancy anomalies.

[0009] The allocation module, connected to the data analysis module, is used to determine the risk level of the data to be processed based on its risk profile when the anomaly type of the data to be processed is a shadow anomaly.

[0010] The grading module, connected to the allocation module, is used to determine the data processing method for the data to be processed based on its risk level, and then process the data according to the processing method to obtain the processing result; and

[0011] The rule set module, connected to the hierarchical module, is used to determine the abnormal data processing model that matches the data to be processed based on the processing results. The abnormal data processing model is used to process the data to be processed to obtain the processed data, and the processed data is then transmitted to the terminal.

[0012] In one embodiment, the firewall policy management system further includes a management and maintenance module, which is connected to the detection module and is used to update the firewall logs based on the data to be processed if there are no anomalies in the data to be processed.

[0013] In one embodiment, the management and maintenance module includes a log management module and a visualization module. The visualization module is connected to the terminal and is used to provide a visual operation interface to the user. The log management module is connected to the visualization module and is used to update the firewall logs based on the response of the visualization module.

[0014] In one embodiment, the firewall policy management system further includes a follow-up module, which is connected to both the rule set module and the terminal. The follow-up module is used to obtain feedback information from the terminal on the processed data, optimize the processed data based on the feedback information, and transmit the optimized processed data back to the terminal.

[0015] In one embodiment, the follow-up module includes a feedback module and an optimization module, which are connected. The feedback module is used to receive feedback information from the terminal, and the optimization module is used to optimize the processed data based on the feedback information and then transmit the optimized processed data back to the terminal.

[0016] In one embodiment, the allocation module includes a classification module and an evaluation module, which are connected. The classification module is used to determine the risk status of the data to be processed, and the evaluation module is used to determine the risk level of the data to be processed based on the risk status.

[0017] In one embodiment, the risk levels include high risk, medium risk, and low risk; the classification module includes a first processing module, a second processing module, and a third processing module, wherein the first processing module is used to process low-risk data to be processed, the second processing module is used to process medium-risk data to be processed, and the third processing module is used to process high-risk data to be processed.

[0018] In one embodiment, the firewall policy management system further includes a calling module connected to the rule set module, which is used to obtain the abnormal data processing model and input the abnormal data processing model into the rule set module.

[0019] In one embodiment, the calling module includes a local resource module and a cloud resource module. The local resource module is connected to the terminal and is used to obtain the abnormal data processing model stored in the terminal. The cloud resource module is connected to the server and is used to obtain the abnormal data processing model stored in the server.

[0020] In one embodiment, the firewall policy management system further includes a model building module, which is connected to the rule set module and is used to build an anomaly data processing model and transmit the anomaly data processing model to the rule set module.

[0021] The aforementioned firewall policy management system acquires the terminal's pending data through a data input module, determines whether the pending data is abnormal through a detection module, identifies the type of abnormality through a data analysis module, determines the risk level of the abnormal data through an allocation module, processes the abnormal data through a tiered module to obtain the processing result, and determines the abnormal data processing model through a rule set module and performs secondary processing to obtain the processed data, which is then returned to the terminal. This method achieves anomaly handling for the terminal's pending data. Traditional technologies lack data analysis and allocation in firewall policies, resulting in a heavy workload for the terminal when comparing data against the data processing model one by one. Furthermore, the lack of follow-up feedback after detecting and processing data anomalies hinders data optimization and firewall policy management. The technical solution provided in this application, however, analyzes the data, allocates it, and tiers it, resolving data anomaly issues and reducing the workload of maintenance personnel and terminal devices. Attached Figure Description

[0022] Figure 1 This is a schematic diagram of the firewall policy management system in one embodiment;

[0023] Figure 2 This is a schematic diagram of the firewall policy management system in another embodiment. Detailed Implementation

[0024] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Many specific details are set forth in the following description to provide a thorough understanding of the present invention. However, the present invention can be practiced in many other ways different from those described herein, and those skilled in the art can make similar modifications without departing from the spirit of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0025] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0026] See Figure 1 , Figure 1 This diagram illustrates the structure of a firewall policy management system according to an embodiment of the present invention. The firewall policy management system provided in this embodiment is used to perform firewall policy management on the firewalls of terminals. The terminals in this embodiment can be personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, etc. Portable wearable devices can be smartwatches, smart bracelets, head-mounted devices, etc.

[0027] In one embodiment, the firewall policy management system includes a data input module 100, a detection module 200, a data analysis module 300, an allocation module 400, a classification module 500, and a rule set module 600. The data input module 100 acquires data to be processed from the terminal; the detection module 200 determines whether the data to be processed is abnormal; the data analysis module 300 determines the type of abnormality in the data to be processed; the allocation module 400 determines the risk level of the abnormal data; the classification module 500 determines the data processing method based on the risk level and processes the abnormal data to obtain a processing result; and the rule set module 600 determines the abnormal data processing model based on the processing result, performs secondary processing to obtain processed data, and returns the processed data to the terminal.

[0028] Specifically, the data input module 100 is communicatively connected to the terminal and is used to acquire the data to be processed from the terminal. The terminal's firewall typically processes data through a set of rules, filtering, blocking, or allowing transmission based on those rules. The data to be processed is the data that needs to be input into the firewall for processing.

[0029] The detection module 200 is connected to the data input module 100 and can receive the data to be processed acquired by the data input module 100. The detection module 200 is used to determine whether there are any abnormalities in the data to be processed. At this time, the judgment result of the detection module 200 includes whether there is an abnormality or not. Schematic, the detection module 200 can be used to detect whether there are abnormal fields and abnormal data values ​​in the data.

[0030] The data analysis module 300 is connected to the detection module 200, and can receive the data to be processed and obtain the judgment results of the detection module 200. The data analysis module 300 is used to determine the type of anomaly in the data to be processed when the detection module 200 determines that there is anomaly. Anomaly types include shadow anomalies and redundancy anomalies.

[0031] Shadowing anomalies describe the unusual behavior of a data point or dataset. Specifically, when the behavior of a data point or dataset deviates significantly from expected or normal behavior, it can be called a shadowing anomaly. Illustratively, shadowing anomalies include deviations from normal distributions, violations of statistical laws, mismatches with context, and potential risks.

[0032] Redundancy anomalies are the presence of redundant or duplicate data in a dataset, which can lead to misunderstandings and biases. The presence of redundancy anomalies can adversely affect data analysis, model building, and decision-making, thus requiring their removal. This improves data quality, reduces model complexity, and minimizes the interference of redundancy anomalies on analytical results. Illustratively, redundancy anomalies include duplicate records, redundant features, and data leaks.

[0033] The allocation module 400 is connected to the data analysis module 300 and can receive the data to be processed and the anomaly type of the abnormal data determined by the data analysis module 300. When the anomaly type of the data to be processed is a shadowed anomaly, the allocation module 400 determines the risk level of the data to be processed based on the risk situation of the data. Specifically, the data risk situation used to determine the risk level can be data confidentiality, integrity, and availability, etc.

[0034] The grading module 500, connected to the allocation module 400, receives the data to be processed and the risk level determined by the allocation module 400. The grading module 500 determines the data processing method for the data to be processed based on its risk level, and processes the data according to the processing method to obtain the processing result.

[0035] In the grading module 500, the first step is to process abnormal data, reducing its risk. Different risk levels correspond to different processing methods. On the one hand, more precise processing methods are used for high-risk data to ensure data security; on the other hand, faster processing methods are used for low-risk data to ensure processing efficiency.

[0036] The rule set module 600, connected to the hierarchical module 500, can receive data to be processed and also receive the processing results from the hierarchical module 500. Specifically, the rule set module 600 is used to determine the abnormal data processing model that matches the data to be processed based on the processing results, process the data to be processed using the abnormal data processing model, obtain the processed data, and transmit the processed data to the terminal.

[0037] An anomaly processing model is a model used to detect and process outliers or abnormal behaviors in data. In this embodiment, the selection of a suitable anomaly processing model depends on the characteristics of the data, the problem requirements, and available resources. Illustratively, anomaly processing models can be statistical models and outlier detection models, etc. Statistical models can be mean-variance models, box plot models, or normal distribution models, etc.; outlier detection models include the K-nearest neighbors algorithm, local anomaly factor, and isolated forest, etc.

[0038] Once the anomaly processing model is determined, it can be used to process the anomaly data, thus achieving a second processing of the anomaly data, resolving the anomaly issue, and obtaining processed data. The processed data can then be transmitted to the terminal, ultimately realizing the anomaly detection and handling of the data to be processed.

[0039] In this embodiment, the terminal's data to be processed is acquired through a data input module, the presence of anomalies in the data is determined through a detection module, the anomaly type is determined through a data analysis module, the risk level of the anomaly is determined through an allocation module, the processing result is obtained through a grading module, and the anomaly processing model is determined and further processed through a rule set module to obtain the processed data. The final processed data is then returned to the terminal. This method achieves anomaly handling for the terminal's data to be processed. In traditional technologies, firewall policies lack data analysis and allocation, resulting in a heavy workload for the terminal when comparing data against the data processing model one by one. Furthermore, the lack of follow-up feedback after anomaly detection and processing hinders data optimization and firewall policy management. The technical solution provided in this application, however, can resolve data anomaly issues and reduce the workload of maintenance personnel and terminal devices by analyzing and allocating data in a grading manner.

[0040] like Figure 2 As shown, Figure 2 The present invention illustrates a firewall policy management system according to one embodiment. In some embodiments, the firewall policy management system further includes a management and maintenance module 700 for processing pending data that does not contain any anomalies.

[0041] Specifically, the management and maintenance module 700 is connected to the detection module 200. When the detection module 200 determines that the data to be processed is not abnormal, it transmits the data to the management and maintenance module 700. After receiving the data to be processed, which is not abnormal, the management and maintenance module 700 updates the firewall logs based on the data, thereby updating the latest network activity information and enabling timely detection and response to potential threats.

[0042] In this embodiment, data to be processed that does not exhibit any anomalies is input into the management and maintenance module 700, which then updates the firewall. In this way, data can be processed appropriately regardless of whether the detection module 200 categorizes the data to be processed as having or not having anomalies.

[0043] Please continue reading Figure 2 In one embodiment, the management and maintenance module 700 includes a log management module 710 and a visualization module 720. The visualization module 720 is used to provide a visual operation interface to the user, and the log management module 710 is used to update the firewall logs based on the user's operation on the visual operation interface.

[0044] Specifically, the visualization module 720 is used to connect to the terminal device's software for logging and system management interface login, providing users with a visual operation interface that can provide functions such as data recovery, parameter retention, and effect evaluation. Users operate through the visual operation interface. When operating the visual interface, the visualization module 720 responds based on the user's operation, and the log management module 710 updates the firewall logs based on the response.

[0045] In this embodiment, when there are no abnormalities in the data to be processed, the user makes an operation instruction to update the log through the visualization module 720, and the log management module 710 updates the firewall log based on the response of the visualization module 720.

[0046] Please continue reading Figure 2 In one embodiment, the firewall policy management system further includes a follow-up module 800, which is connected to both the rule set module 600 and the terminal. The follow-up module 800 is used to obtain feedback information from the terminal on the processed data, optimize the processed data based on the feedback information, and transmit the optimized processed data back to the terminal.

[0047] The rule set module 600 transmits the processed data to the terminal. The terminal provides feedback on the processed data, which may include whether the processed data meets preset requirements. If the processed data does not meet the preset requirements, the follow-up module 800 receives the feedback from the terminal, further optimizes the processed data, and transmits it to the terminal again to ensure that the data meets the terminal's preset requirements.

[0048] Specifically, the follow-up module 800 may include a feedback module 810 and an optimization module 820. The feedback module 810 and the optimization module 820 are connected. The feedback module 810 is used to receive feedback information from the terminal and transmit the feedback information to the optimization module 820. The optimization module 820 is used to optimize the processed data based on the feedback information and transmit the optimized processed data back to the terminal.

[0049] In this embodiment, the firewall policy management system has a follow-up module 800. The follow-up module 800 performs business testing and follow-up feedback on the data, receives information from terminal devices in a timely manner and optimizes it, thereby improving the management effect of firewall policies and reducing abnormal situations in subsequent firewall use.

[0050] Please continue reading Figure 2 In one embodiment, the allocation module 400 includes a classification module 410 and an evaluation module 420, which are connected. The classification module 410 is used to determine the risk situation, and the evaluation module 420 is used to determine the risk level based on the risk situation.

[0051] Specifically, the classification module 410 receives the data to be processed transmitted by the data analysis module 300 and determines the risk level of the data to be processed based on the anomaly type determined by the data analysis module 300. After determining the risk level, the classification module 410 transmits the risk level to the evaluation module 420, which determines the risk level of the data to be processed based on the risk level. Illustratively, the data to be processed is divided into three risk levels: low risk, medium risk, and high risk.

[0052] In this embodiment, the classification module 410 is used to determine the risk situation, and the assessment module 420 is used to determine the risk level based on the risk situation, so that the data to be processed is processed sequentially, which facilitates the determination of different processing methods based on the risk level in the future.

[0053] Please continue reading Figure 2 In one embodiment, the risk levels include high risk, medium risk, and low risk. The classification module 500 includes a first processing module 510, a second processing module 520, and a third processing module 530. The first processing module 510 is used to process low-risk data to be processed, the second processing module 520 is used to process medium-risk data to be processed, and the third processing module 530 is used to process high-risk data to be processed.

[0054] The allocation module 400 divides the risk level into low risk, medium risk and high risk, and further divides the data to be processed into low-risk data, medium-risk data and high-risk data according to the risk status of the data to be processed.

[0055] The grading module 500 includes a first processing module 510, a second processing module 520, and a third processing module 530, which process low-risk, medium-risk, and high-risk data respectively. The grading module 500 selects different processing modules based on the risk level of the data. Optionally, the processing quality of the third processing module 530 can be higher than that of the first processing module 510 and the second processing module 520, while the processing speed of the first processing module 510 can be higher than that of the second processing module 520 and the third processing module 530. Optionally, the first processing module 510 can also be used to process low-level data with a small amount of data and relatively simple data; the second processing module 520 can also be used to process medium-level data with a small amount of data and relatively auxiliary data; and the third processing module 530 can also be used to process high-level data with a large amount of data and relatively complex data.

[0056] In this embodiment, different processing modules are selected based on the different risk levels. On the one hand, higher quality processing methods are used for data with high risk levels to ensure data security; on the other hand, faster processing methods are used for data with lower risk levels to ensure processing efficiency.

[0057] Please continue reading Figure 2 In one embodiment, the firewall policy management system further includes a calling module 900, which is connected to the rule set module 600 and is used to obtain an anomaly data processing model and input the anomaly data processing model into the rule set module 600.

[0058] The rule set module 600 is used to determine the abnormal data processing model based on the processing result, and to process the data to be processed according to the abnormal data processing model. Therefore, multiple abnormal data processing models need to be provided to the rule set module 600. In this embodiment, the abnormal data processing model is obtained by calling module 900, and the multiple obtained abnormal data processing models are input into the rule set module 600.

[0059] Specifically, the calling module 900 may include a local resource module 910 and a cloud resource module 920. The local resource module 910 is connected to the terminal and is used to obtain the exception data processing model stored in the terminal. The cloud resource module 920 is connected to the server and is used to obtain the exception data processing model stored in the server.

[0060] A server is a computer system or software used to provide services, store data, and process requests. Servers can be implemented using a standalone server or a server cluster consisting of multiple servers.

[0061] In this embodiment, the abnormal data processing model stored on the terminal is obtained through the local resource module 910, and the abnormal data processing model stored on the server is obtained through the cloud resource module, and then provided to the rule set module 600, so that the rule set module can select based on multiple abnormal data processing models.

[0062] Please continue reading Figure 2 In one embodiment, the firewall policy management system further includes a model building module 1000, which is connected to the rule set module 600 and is used to build an anomaly data processing model and transmit the anomaly data processing model to the rule set module 600.

[0063] If neither the terminal nor the server stores a suitable abnormal data processing model, a new abnormal data processing model can be constructed through the model building module 1000 and input into the rule set module 600 for selection.

[0064] In this embodiment, the firewall policy management system also includes a model building module 1000, which can build a new abnormal data processing model and provide it to the rule set module 600. This enables the construction of a new processing model to match the data to be processed when there is no processing model corresponding to the data to be processed, thus ensuring the comprehensiveness of the data processing.

[0065] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0066] The embodiments described above are merely illustrative of several implementations of the present invention, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of the present invention, and these all fall within the protection scope of the present invention. Therefore, the protection scope of this invention patent should be determined by the appended claims.

Claims

1. A firewall policy management system, characterized in that, The system is used to perform firewall policy management on the firewall of the terminal, and includes: A data input module, communicatively connected to the terminal, is used to acquire the data to be processed from the terminal; the data to be processed is data that needs to be input to the firewall for processing. A detection module, connected to the data input module, is used to determine whether the data to be processed is abnormal; A data analysis module, connected to the detection module, is used to determine the anomaly type of the data to be processed when there is an anomaly. The anomaly type includes shadow anomaly and redundancy anomaly. An allocation module, connected to the data analysis module, is used to determine the risk level of the data to be processed based on the risk status of the data to be processed when the anomaly type of the data to be processed is a shadow anomaly. A grading module, connected to the allocation module, is used to determine the data processing method for the data to be processed based on the risk level of the data to be processed, and to process the data to be processed based on the data processing method to obtain a processing result; and The rule set module, connected to the hierarchical module, is used to determine an anomaly data processing model that matches the data to be processed based on the processing result, process the data to be processed through the anomaly data processing model to obtain processed data, and transmit the processed data to the terminal. The model building module, connected to the rule set module, is used to construct a new abnormal data processing model when no suitable abnormal data processing model is stored in the terminal or the server, and to transmit the new abnormal data processing model to the rule set module.

2. The system according to claim 1, characterized in that, The system also includes a management and maintenance module, which is connected to the detection module and is used to update the firewall logs based on the data to be processed if there are no anomalies in the data to be processed.

3. The system according to claim 2, characterized in that, The management and maintenance module includes a log management module and a visualization module. The visualization module is connected to the terminal and is used to provide a visual operation interface to the user. The log management module is connected to the visualization module and is used to update the firewall logs based on the response of the visualization module.

4. The system according to claim 1, characterized in that, The system also includes a follow-up module, which is connected to both the rule set module and the terminal. The follow-up module is used to obtain feedback information from the terminal on the processed data, optimize the processed data based on the feedback information, and transmit the optimized processed data back to the terminal.

5. The system according to claim 4, characterized in that, The follow-up module includes a feedback module and an optimization module, which are connected. The feedback module is used to receive the feedback information from the terminal, and the optimization module is used to optimize the processed data based on the feedback information and then transmit the optimized processed data back to the terminal.

6. The system according to claim 1, characterized in that, The allocation module includes a classification module and an evaluation module, which are connected. The classification module is used to determine the risk status of the data to be processed, and the evaluation module is used to determine the risk level of the data to be processed based on the risk status.

7. The system according to claim 1, characterized in that, The risk levels include high risk, medium risk, and low risk; the classification module includes a first processing module, a second processing module, and a third processing module. The first processing module is used to process low-risk data to be processed, the second processing module is used to process medium-risk data to be processed, and the third processing module is used to process high-risk data to be processed.

8. The system according to claim 1, characterized in that, The system also includes a calling module, which is connected to the rule set module and is used to obtain the abnormal data processing model and input the abnormal data processing model into the rule set module.

9. The system according to claim 8, characterized in that, The calling module includes a local resource module and a cloud resource module. The local resource module is communicatively connected to the terminal and is used to obtain the abnormal data processing model stored in the terminal. The cloud resource module is communicatively connected to the server and is used to obtain the abnormal data processing model stored in the server.