Firewall policy optimization method and device, computer device and storage medium

CN116827649BActive Publication Date: 2026-10-09SHENZHEN POWER SUPPLY BUREAU
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310831694.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-06
Publication Date
2026-10-09
Estimated Expiration
2043-07-06

AI Technical Summary

Technical Problem

[0003]然而,随着网络规模的不断扩大,策略规则数目增长迅速,长期运维和策略变更,防火墙策略库中积累了大量的冗余规则和重复配置,增加了策略管理的复杂性和风险

Benefits of technology

[0048]上述防火墙策略优化方法、装置、计算机设备和存储介质,先构建规范化结构模型,通过规范化结构模型将防火墙策略库中的各待优化防火墙策略进行规范化,实现一致性。之后确定防火墙策略库中的冗余策略和宽松策略,清理该冗余策略和宽松策略。并确定冲突策略,清理该冲突策略,从而实现对策略库的优化。通过这样的方式,降低了策略管理的复杂性和风险,并提高了网络的安全性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116827649B_ABST
    Figure CN116827649B_ABST
Patent Text Reader

Abstract

The application relates to a firewall policy optimization method and device, computer equipment and a storage medium. The method comprises the following steps: acquiring a firewall policy library and constructing a normalized structure model of the firewall policy library; the firewall policy library comprises a plurality of to-be-optimized firewall policies; inputting the firewall policy library into the normalized structure model, normalizing each to-be-optimized firewall policy according to field information of each to-be-optimized firewall policy; determining redundant policies and loose policies in the plurality of to-be-optimized firewall policies and cleaning up the redundant policies and the loose policies; determining conflict policies in the plurality of to-be-optimized firewall policies and cleaning up the conflict policies based on a genetic algorithm. The method can reduce the complexity and risk of firewall policy management and improve the security of a network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a firewall policy optimization method, apparatus, computer device, and storage medium. Background Technology

[0002] To protect sensitive data and network assets, network users commonly use firewalls as a crucial component of network security. User networks often contain multiple heterogeneous firewall devices. These heterogeneous firewalls can provide multi-layered security protection, preventing various network threats through combinations of different technologies and strategies. Furthermore, they can avoid reliance on firewall devices from a single vendor, thereby reducing the risk of single points of failure.

[0003] However, as the network scale continues to expand, the number of policy rules grows rapidly. Long-term operation and maintenance and policy changes have led to a large number of redundant rules and duplicate configurations accumulating in the firewall policy library, increasing the complexity and risk of policy management.

[0004] Furthermore, the lack of mechanisms for detecting and resolving policy conflicts may lead to conflicting policy rules, resulting in reduced network security. Summary of the Invention

[0005] Therefore, it is necessary to provide a firewall policy optimization method, apparatus, computer device, and storage medium that can clean up redundant policies, lenient policies, and conflicting policies in the firewall policy library and optimize the firewall policy library, in order to address the above-mentioned technical problems.

[0006] Firstly, this application provides a firewall policy optimization method. The method includes:

[0007] Obtain the firewall policy library and construct a standardized structural model of the firewall policy library; the firewall policy library includes multiple firewall policies to be optimized.

[0008] The firewall policy library is input into the normalized structure model, and each firewall policy to be optimized is normalized according to the field information of each firewall policy to be optimized.

[0009] Identify redundant and lenient policies among multiple firewall policies to be optimized, and clean up redundant and lenient policies.

[0010] Identify conflicting policies among multiple firewall policies to be optimized, and clean up the conflicting policies based on a genetic algorithm.

[0011] In one embodiment, before identifying redundant and lenient policies among multiple firewall policies to be optimized, and before cleaning up redundant and lenient policies, the method further includes:

[0012] By using a pre-defined rule set, compliance checks are performed on multiple firewall policies to be optimized, non-compliant policies are identified, and non-compliant policies are cleaned up or modified.

[0013] In one embodiment, redundant and lenient policies among multiple firewall policies to be optimized are identified, and the redundant and lenient policies are cleaned up, including:

[0014] For multiple firewall policies to be optimized, the lenient rules are compared with each firewall policy to be optimized, the lenient policies are selected, and the lenient policies are cleaned up to obtain the remaining multiple retainable policies.

[0015] Behavioral analysis and redundancy assessment are performed on multiple retention strategies to identify and eliminate redundant strategies.

[0016] In one embodiment, conflicting policies among multiple firewall policies to be optimized are identified, including:

[0017] Obtain the flow path and processing of test data in each firewall policy to be optimized, and construct a data flow model based on the flow path and processing.

[0018] The data flow model is analyzed based on the data flow analysis algorithm to detect the conflict of each firewall policy to be optimized, and the conflicting policies among the multiple firewall policies to be optimized are determined based on the conflict situation.

[0019] In one embodiment, the conflict resolution strategy based on a genetic algorithm includes:

[0020] An initial strategy population is constructed based on conflict strategies; the initial strategy population consists of multiple individuals, each corresponding to a conflict strategy.

[0021] A genetic algorithm is used to iteratively process the initial strategy population until the preset number of iterations is reached;

[0022] Replace the conflicting strategy with the strategy set obtained from the last iteration.

[0023] In one embodiment, a genetic algorithm is used to iteratively process the initial strategy population until the number of iterations reaches a preset number, including:

[0024] Construct a fitness function and determine the fitness of each individual based on the fitness function;

[0025] Based on fitness, a subset of individuals are selected as parents from the initial strategy population;

[0026] A genetic algorithm is used to iteratively process the selected parent generation to obtain the next population; the iterative process includes crossover and mutation.

[0027] The following group is used as the previous group in the next iteration, and the iteration process is repeated until the preset number of iterations is reached.

[0028] Secondly, this application also provides a firewall policy optimization device. The device includes:

[0029] The model building module is used to obtain the firewall policy library and build a standardized structural model of the firewall policy library; the firewall policy library includes multiple firewall policies to be optimized.

[0030] The normalization processing module is used to input the firewall policy library into the normalization structure model and normalize each firewall policy to be optimized according to the field information of each firewall policy to be optimized.

[0031] The first cleaning module is used to identify redundant and lenient policies among multiple firewall policies to be optimized, and to clean up the redundant and lenient policies.

[0032] The second cleaning module is used to identify conflicting policies among multiple firewall policies to be optimized, and to clean up the conflicting policies based on a genetic algorithm.

[0033] Thirdly, this application also provides a computer device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to perform the following steps:

[0034] Obtain the firewall policy library and construct a standardized structural model of the firewall policy library; the firewall policy library includes multiple firewall policies to be optimized.

[0035] The firewall policy library is input into the normalized structure model, and each firewall policy to be optimized is normalized according to the field information of each firewall policy to be optimized.

[0036] Identify redundant and lenient policies among multiple firewall policies to be optimized, and clean up redundant and lenient policies.

[0037] Identify conflicting policies among multiple firewall policies to be optimized, and clean up the conflicting policies based on a genetic algorithm.

[0038] Fourthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, performs the following steps:

[0039] Obtain the firewall policy library and construct a standardized structural model of the firewall policy library; the firewall policy library includes multiple firewall policies to be optimized.

[0040] The firewall policy library is input into the normalized structure model, and each firewall policy to be optimized is normalized according to the field information of each firewall policy to be optimized.

[0041] Identify redundant and lenient policies among multiple firewall policies to be optimized, and clean up redundant and lenient policies.

[0042] Identify conflicting policies among multiple firewall policies to be optimized, and clean up the conflicting policies based on a genetic algorithm.

[0043] Fifthly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, performs the following steps:

[0044] Obtain the firewall policy library and construct a standardized structural model of the firewall policy library; the firewall policy library includes multiple firewall policies to be optimized.

[0045] The firewall policy library is input into the normalized structure model, and each firewall policy to be optimized is normalized according to the field information of each firewall policy to be optimized.

[0046] Identify redundant and lenient policies among multiple firewall policies to be optimized, and clean up redundant and lenient policies.

[0047] Identify conflicting policies among multiple firewall policies to be optimized, and clean up the conflicting policies based on a genetic algorithm.

[0048] The aforementioned firewall policy optimization method, apparatus, computer equipment, and storage medium first construct a standardized structural model. This model is used to standardize the firewall policies to be optimized in the firewall policy library, achieving consistency. Next, redundant and lenient policies in the firewall policy library are identified and eliminated. Conflicting policies are also identified and eliminated, thereby optimizing the policy library. This approach reduces the complexity and risk of policy management and improves network security. Attached Figure Description

[0049] Figure 1 This is an application environment diagram of a firewall policy optimization method in one embodiment;

[0050] Figure 2 This is a flowchart illustrating a firewall policy optimization method in one embodiment;

[0051] Figure 3 This is a flowchart illustrating the process of determining and cleaning up lenient and redundant policies in one embodiment.

[0052] Figure 4 This is a flowchart illustrating a data flow analysis algorithm in one embodiment;

[0053] Figure 5 This is a flowchart illustrating a conflict resolution strategy using a genetic algorithm in one embodiment.

[0054] Figure 6 This is a flowchart illustrating a firewall policy optimization method in another embodiment;

[0055] Figure 7 This is a structural block diagram of a firewall policy optimization device in one embodiment;

[0056] Figure 8 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0057] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0058] The firewall policy optimization method provided in this application embodiment can be applied to, for example, Figure 1 In the application environment shown, terminal 102 communicates with server 104 via a network. A data storage system can store the data that server 104 needs to process. The data storage system can be integrated onto server 104 or located in the cloud or on other network servers. After receiving a request to clean up a heterogeneous firewall policy library, server 104 or terminal 102 cleans up redundant, lenient, and conflicting policies in the policy library.

[0059] Terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can include smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, etc. Portable wearable devices can include smartwatches, smart bracelets, head-mounted devices, etc. Server 104 can be implemented using a standalone server or a server cluster consisting of multiple servers.

[0060] In one embodiment, such as Figure 2 As shown, a firewall policy optimization method is provided, which can be applied to... Figure 1 Taking server 104 as an example, the explanation includes the following steps S202 to S208:

[0061] S202, Obtain the firewall policy library and construct a standardized structural model of the firewall policy library; the firewall policy library includes multiple firewall policies to be optimized.

[0062] A firewall policy library is a set of predefined policy rules and configuration options stored within a firewall. These policy rules guide the firewall on how to handle network traffic and connection requests. A firewall policy library can contain multiple firewall policies to be optimized, each defining specific behaviors and rules.

[0063] However, as the network scale continues to expand, the number of firewall policies to be optimized in the firewall policy library gradually increases, resulting in lenient policies, redundant policies, and conflicting policies. The purpose of this embodiment is to optimize these policies.

[0064] A normalized structure model is a standardized structural model used to represent the elements, relationships, and attributes of heterogeneous firewall policies. It helps ensure the consistency, readability, and maintainability of firewall policies, while providing a standardized method for organizing and representing firewall policy rules.

[0065] Indicatively, a standardized structural model can standardize firewall policies from multiple dimensions, including the device corresponding to the policy, policy number, rule name, source address, destination address, port number, application, service, and operation.

[0066] S204. Input the firewall policy library into the normalized structure model, and normalize each firewall policy to be optimized according to the field information of each firewall policy to be optimized.

[0067] Heterogeneous firewalls are primarily deployed to meet the network security needs of power systems. These firewalls, from different vendors and implementing various functions, include packet filtering, stateful inspection, access control, network address translation, and application detection. However, significant differences exist in the syntax and format of these different firewall devices, leading to inconsistencies in the strategies for each firewall to be optimized.

[0068] By inputting the firewall policy library into the normalized structure model, this embodiment can map heterogeneous firewall policies into policy instances with unified structure and semantics, including data type conversion, disambiguation of syntax and semantics, and field mapping, to achieve consistency.

[0069] Ensuring consistency of heterogeneous firewall policies across different devices can improve management efficiency, reduce error risks, and ensure compliance. It also supports policy optimization and conflict resolution, making policy management more reliable, flexible, and automated, which helps improve network security, reduce management costs, and decrease device performance load.

[0070] S206 identifies redundant and lenient policies among multiple firewall policies to be optimized, and cleans up redundant and lenient policies.

[0071] Redundant policies refer to situations where duplicate or redundant rules exist in the firewall policy library. These redundant rules can lead to unnecessary complexity and performance degradation in firewall policies, while also increasing the difficulty of management and maintenance.

[0072] By eliminating redundant policies, firewall policy management and maintenance can be simplified, security and performance can be improved, and the risk of configuration errors and failures can be reduced.

[0073] A lenient policy refers to relatively open rule settings that allow more traffic to pass through the firewall. The advantages of a lenient policy are convenience and flexibility; however, it also introduces potential security risks such as security vulnerabilities, data breaches, and resource abuse.

[0074] By implementing lenient policies, network security can be improved for users.

[0075] S208 identifies conflicting policies among multiple firewall policies to be optimized and cleans up the conflicting policies based on a genetic algorithm.

[0076] A conflict policy refers to the method for handling rule conflicts or the setting of rule priorities. When multiple rules match the same traffic, the conflict policy determines which rule will be executed.

[0077] Optimizing conflict policies can improve the overall security of a firewall. Conflicts can cause rules to become ineffective or be incompletely executed, thus creating vulnerabilities for malicious attackers. Conflict detection and optimization can help identify and resolve these potential security risks in a timely manner, enhancing the overall protective capabilities of the firewall.

[0078] Genetic algorithms simulate the process of biological evolution, iteratively applying operations such as selection, crossover, and mutation to find the optimal or near-optimal solution to a problem. In this embodiment, a genetic algorithm is used to clear conflict strategies.

[0079] The firewall policy optimization method described above first constructs a standardized structural model. This model standardizes the firewall policies to be optimized in the firewall policy library, ensuring consistency. Next, redundant and lenient policies in the firewall policy library are identified and removed. Conflicting policies are then identified and removed, thereby optimizing the policy library. This approach reduces the complexity and risk of policy management and improves network security.

[0080] In one embodiment, before determining redundant and lenient policies among multiple firewall policies to be optimized and cleaning up redundant and lenient policies in step S206, the firewall policy optimization method may further include the following steps:

[0081] By using a pre-defined rule set, compliance checks are performed on multiple firewall policies to be optimized, non-compliant policies are identified, and non-compliant policies are cleaned up or modified.

[0082] Firewall policy compliance ensures that an enterprise's firewall deployment and configuration comply with relevant regulations, standards, and best practices to provide effective network security protection and reduce potential risks.

[0083] In this embodiment, a pre-defined rule set is established based on actual security policies and compliance requirements. This pre-defined rule set may include access control rules, security policy specifications, network traffic restrictions, etc. Based on the defined compliance rules, the firewall policy is inspected, including checks on the rule syntax, compliance, and security. Illustratively, this embodiment uses Python and regular expressions to automatically match rules, identify non-compliant policies, and clean or modify them.

[0084] In this embodiment, by normalizing and performing compliance checks on the firewall policies to be optimized, the consistency of heterogeneous firewall policies on different devices can be ensured, which can improve management efficiency, reduce error risks, and ensure compliance. At the same time, it supports policy optimization and conflict resolution, making policy management more reliable, flexible and automated, which helps to improve network security, reduce management costs and device performance load.

[0085] In one embodiment, step S206, which identifies redundant and lenient policies among multiple firewall policies to be optimized and cleans up the redundant and lenient policies, includes: comparing the lenient rules with each firewall policy to be optimized, filtering out the lenient policies, and cleaning up the lenient policies to obtain the remaining multiple retained policies; performing behavioral analysis and redundancy judgment on the multiple retained policies, filtering out the redundant policies, and cleaning up the redundant policies.

[0086] like Figure 3 As shown, in a feasible implementation, the determination of the leniency strategy and the redundancy strategy includes the following steps S302-S308:

[0087] S302, Select strategy data tactics0.

[0088] Select one of the multiple firewall policies to be optimized from the firewall policy library, obtain information such as the rule set, rule attributes, matching conditions, and actions from the data tactics0 of that firewall policy to be optimized, and obtain network traffic data as input for behavioral analysis.

[0089] S304 matches the selected strategy with a lenient rule.

[0090] The selected firewall policy to be optimized is matched with a lenient rule. If it is identified as a lenient rule, step S308 is executed to modify it and record the reason for the modification and the version before the change; otherwise, step S306 is executed.

[0091] S306, Select unanalyzed strategy data (tactics) i This involves conducting behavioral analysis and redundancy assessment.

[0092] Select unanalyzed firewall policy data (tactics) from the firewall policy library that needs optimization. i Selected tactics i Behavioral analysis is performed with tactics0, including analysis of operational behavior, resource access behavior, and data packet transmission behavior. Then, behavioral features and effects are extracted, and redundancy strategies with the same or similar behaviors are identified based on these features.

[0093] S308, the policy cleans up and records the reasons for modifications and the unmodified versions.

[0094] Based on the analysis results, redundancy is assessed, redundant policies in the firewall policy library are identified, and these redundant policies are modified, merged, or cleaned up.

[0095] In this embodiment, lenient policies are identified from multiple firewall policies to be optimized using lenient rules, and these lenient policies are then cleaned up. Next, among the remaining firewall policies not considered lenient policies, redundant policies are identified through behavioral analysis and redundancy assessment, and these redundant policies are then cleaned up. This two-stage assessment accurately filters out lenient and redundant policies.

[0096] In one embodiment, step S208, determining conflicting policies among multiple firewall policies to be optimized, includes: acquiring the flow path and processing procedure of test data in each firewall policy to be optimized, constructing a data flow model based on the flow path and processing procedure; analyzing the data flow model based on a data flow analysis algorithm, detecting the conflict situation of each firewall policy to be optimized, and determining the conflicting policies among multiple firewall policies to be optimized based on the conflict situation.

[0097] Based on the collected firewall policy database data, a data flow model is established. This model describes the flow path and processing of data within each firewall policy to be optimized. Data flow analysis algorithms track the data flow path within the rule set and detect any conflicts. This allows for the analysis of the data flow model using data flow analysis algorithms to identify conflicting policies.

[0098] Data flow graphs represent the flow and dependencies of data. Nodes in a data flow graph represent service ports or host addresses, and edges represent the impact of policies on data flow. Conflicting firewall policies are identified by determining whether a policy will affect the direction of future data flow.

[0099] like Figure 4 As shown, the data flow analysis algorithm's judgment process includes: First, a policy set is obtained by aggregating the firewall policies to be optimized. The first policy in this policy set is selected and removed from the set. If the policy set is empty, a conflicting policy set is output; if not, the policy set is iterated through, checking if the data flow appears in the data flow graph. If the data flow does not appear in the graph, new edges and nodes are added, and the policy is checked to see if it is the last policy. If the data flow does appear, the flow is further checked to see if it has changed the current data flow direction. If it has changed the current data flow direction, the policy is determined to be a conflicting policy, and the policy is checked to see if it is the last policy. If it has not changed the data flow direction, the policy is directly checked to see if it is the last policy. If the policy is determined to be the last policy, the algorithm returns to selecting the first policy in the policy set; if the policy is not the last policy, the algorithm returns to iterating through the policy set.

[0100] In this embodiment, a data flow analysis algorithm is used to determine the conflict strategy. By making multiple judgments on the firewall strategy to be optimized, the accuracy is improved.

[0101] like Figure 5 As shown, in one embodiment, step S208, which uses a genetic algorithm to clear conflicts, includes the following steps:

[0102] S502, Generate an initial population P0 based on the conflicting strategy set. Specifically, construct an initial strategy population based on the conflicting strategies; the initial strategy population includes multiple individuals, each corresponding to a conflicting strategy.

[0103] An initial policy population is randomly generated, with each individual representing a set of firewall policies to be optimized. An initial population P0 is generated based on the set of conflicting policies, containing M randomly generated individuals, with a maximum evolutionary generation of T and a crossover probability of P. c The probability of mutation is P. v .

[0104] S504 uses a genetic algorithm to iteratively process the initial strategy population until the preset number of iterations is reached.

[0105] Genetic algorithms simulate the process of biological evolution, iteratively applying operations such as selection, crossover, and mutation to find the optimal or near-optimal solution to a problem. Once the preset number of iterations has been reached, the result can be output.

[0106] In one embodiment, a genetic algorithm is used to iteratively process the initial strategy population until the number of iterations reaches a preset number, including:

[0107] First, a fitness function is constructed to determine the fitness of each individual. Then, a fitness function is designed to evaluate the effectiveness of each policy. This fitness function considers the number and severity of conflicts, policy priority, and policy performance. The fitness function is shown in the following equation:

[0108]

[0109] Where C mult It is a specified multiple, ranging from [1,2], Fit max It is the maximum fitness value, Fit avg This represents the average fitness level.

[0110] Secondly, based on fitness, a subset of individuals is selected as parents from the initial strategy population. Then, a genetic algorithm is used to iteratively process the selected parents to obtain the next population; the iterative process includes crossover and mutation.

[0111] Genetic algorithms use three genetic operators: selection, crossover, and mutation. First, superior individuals are selected from the old population with a certain probability to form a new population, which then reproduces to obtain the next generation of individuals.

[0112] From the current population, select a subset of individuals based on their fitness values ​​to serve as parents, and randomly select two individuals for crossover. Among these, individuals Tac... i The probability of being selected is:

[0113]

[0114] Where N is the population size, fit i For individual Tac i The fitness of a firewall policy depends on its selection probability. If the selection probability of the corresponding firewall policy is high, it will have the opportunity to be selected multiple times, and its genetic potential will expand in the population. If the selection probability of the policy is low, it will be more likely to be eliminated.

[0115] Next, crossover is performed. Crossover refers to randomly selecting two individuals from the population and exchanging their chromosomes to pass on the superior traits of the parent string to the child string, thereby producing new superior individuals.

[0116] Finally, to prevent embedding of local optima during the optimization process, single-point mutation is used on individuals, meaning only one position in the gene sequence needs to be mutated. The generated new individuals are then subjected to mutation, and their fitness is evaluated. Based on the fitness values ​​and the optimization objective, a subset of the better individuals are selected for the next generation population, while the optimal individuals are retained.

[0117] During iterative processing, the next group is used as the previous group in the next iteration, and the iterative processing is repeated until the preset number of iterations is reached.

[0118] Specifically, if the iteration termination condition is met, the algorithm ends; otherwise, the next iteration begins. Illustratively, a preset number of iterations T is set. If the number of iterations t ≤ T, then t = t + 1 and the next iteration begins; if t > T, the iteration terminates.

[0119] In this embodiment, a genetic algorithm is used to iteratively process the set of conflict strategies to clean up the conflicting strategies. The genetic algorithm simulates natural selection, crossover, and mutation to solve the complex firewall conflict strategy optimization problem.

[0120] S506 outputs the optimal result, replacing the original conflict strategy, and records the reason for the conflict and the version before modification. Specifically, it replaces the conflict strategy with the strategy set obtained in the last iteration.

[0121] The optimal solution to the conflict resolution strategy problem is obtained by using a genetic algorithm. The result of the last iteration is taken as the final result. At this point, the conflict resolution strategy of the firewall strategy to be optimized has been completed.

[0122] In this embodiment, a conflict resolution strategy based on a genetic algorithm is used to effectively identify and optimize conflicts, thereby improving firewall security. The existence of conflicting strategies can lead to rule failure or incomplete execution of the strategies, thus providing security vulnerabilities for malicious attackers. Through conflict detection and optimization, these potential security risks can be identified and resolved in a timely manner, enhancing the firewall's protective capabilities.

[0123] like Figure 6 As shown, in one embodiment, a firewall policy optimization method includes the following steps:

[0124] S602, Obtain the firewall policy library and construct a standardized structural model of the firewall policy library; the firewall policy library includes multiple firewall policies to be optimized.

[0125] S604 inputs the firewall policy library into the normalized structure model and normalizes each firewall policy to be optimized based on the field information of each firewall policy to be optimized.

[0126] S606 performs compliance checks on multiple firewall policies to be optimized using a pre-defined rule set, identifies non-compliant policies, and cleans up or modifies them.

[0127] S608 compares the lenient rules with each of the multiple firewall policies to be optimized, filters out the lenient policies, cleans up the lenient policies, and obtains the remaining multiple retainable policies.

[0128] S610 performs behavioral analysis and redundancy assessment on multiple retention strategies, filters out redundant strategies, and cleans up redundant strategies.

[0129] S612: Obtain the flow path and processing of test data in each firewall policy to be optimized, and construct a data flow model based on the flow path and processing.

[0130] S614 analyzes the data flow model based on the data flow analysis algorithm, detects the conflict situation of each firewall policy to be optimized, and determines the conflicting policies among multiple firewall policies to be optimized based on the conflict situation.

[0131] S616, Construct an initial strategy population based on conflict strategies; the initial strategy population includes multiple individuals, and each individual corresponds to a conflict strategy.

[0132] S618, construct a fitness function, determine the fitness of each individual based on the fitness function, and select some individuals from the initial strategy population as parents based on the fitness.

[0133] S620 uses a genetic algorithm to iteratively process the selected parent generation to obtain the next population; the iterative process includes crossover and mutation processing.

[0134] S622, the next group is used as the previous group in the next iteration, and the iteration process is repeated until the preset number of iterations is reached.

[0135] S624 replaces the conflicting strategy with the strategy set obtained in the last iteration.

[0136] In this embodiment, a standardized structural model of the firewall policy library is constructed. This model is then used to standardize the firewall policies to be optimized within the library. Following this, a pre-defined rule set is used to perform compliance checks on the firewall policies to be optimized, and compliant policies are cleaned up or modified. Lenient policies are identified and cleaned up using lenient rules, and redundant policies are identified and cleaned up using behavioral analysis and redundancy judgment. Conflicting policies are then identified using a data flow analysis algorithm, and conflicting policies are cleaned up using a genetic algorithm. Finally, lenient, redundant, and conflicting policies in the firewall policy library are cleaned up. This reduces the complexity and risk of policy management and improves network security.

[0137] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0138] Based on the same inventive concept, this application also provides a firewall policy optimization apparatus for implementing the firewall policy optimization method described above. The solution provided by this apparatus is similar to the implementation described in the above method; therefore, the specific limitations in one or more firewall policy optimization apparatus embodiments provided below can be found in the limitations of the firewall policy optimization method described above, and will not be repeated here.

[0139] In one embodiment, such as Figure 7 As shown, a firewall policy optimization device 700 is provided, including: a model building module 702, a normalization processing module 704, a first cleaning module 706, and a second cleaning module 708, wherein:

[0140] The model building module 702 is used to obtain the firewall policy library and build a standardized structural model of the firewall policy library; the firewall policy library includes multiple firewall policies to be optimized.

[0141] The normalization processing module 704 is used to input the firewall policy library into the normalization structure model and normalize each firewall policy to be optimized according to the field information of each firewall policy to be optimized.

[0142] The first cleanup module 706 is used to identify redundant and lenient policies among multiple firewall policies to be optimized, and to clean up the redundant and lenient policies.

[0143] The second cleaning module 708 is used to identify conflicting policies among multiple firewall policies to be optimized, and to clean up conflicting policies based on a genetic algorithm.

[0144] In one embodiment, the firewall policy optimization device 700 further includes a non-compliant policy cleanup module, which is used to perform compliance detection on multiple firewall policies to be optimized through a preset rule set, identify non-compliant policies, and clean up or modify non-compliant policies.

[0145] In one embodiment, the first cleaning module 706 is specifically used to: compare the lenient rules with each firewall policy to be optimized for multiple firewall policies to be optimized, filter out the lenient policies, and clean up the lenient policies to obtain the remaining multiple retained policies; perform behavioral analysis and redundancy judgment on the multiple retained policies, filter out the redundant policies, and clean up the redundant policies.

[0146] In one embodiment, the second cleaning module 708 is specifically used to: obtain the flow path and processing of test data in each firewall policy to be optimized, construct a data flow model based on the flow path and processing; analyze the data flow model based on the data flow analysis algorithm, detect the conflict situation of each firewall policy to be optimized, and determine the conflicting policies among the multiple firewall policies to be optimized based on the conflict situation.

[0147] In one embodiment, the second cleanup module 708 is specifically used to: construct an initial strategy population based on the conflict strategy; the initial strategy population includes multiple individuals, each corresponding to a conflict strategy; use a genetic algorithm to iteratively process the initial strategy population until the number of iterations reaches a preset number; and replace the conflict strategy with the strategy set obtained from the last iteration.

[0148] In one embodiment, the second cleanup module 708 is specifically used for: constructing a fitness function and determining the fitness of each individual based on the fitness function; selecting some individuals from the initial strategy population as parents based on the fitness; using a genetic algorithm to iteratively process the selected parents to obtain the next population; the iterative process includes crossover and mutation processing; using the next population as the previous population in the next iteration, and repeating the iterative process until the number of iterations reaches a preset number.

[0149] Each module in the aforementioned firewall policy optimization device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can invoke and execute the corresponding operations of each module.

[0150] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 8As shown, this computer device includes a processor, memory, input / output interfaces (I / O), and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operating system and computer programs stored in the non-volatile storage media. The database stores firewall policies. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communication with external terminals via a network connection. When the computer program is executed by the processor, it implements a firewall policy optimization method.

[0151] Those skilled in the art will understand that Figure 8 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0152] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above-described method embodiments.

[0153] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps in the above method embodiments.

[0154] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.

[0155] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0156] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0157] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A firewall policy optimization method, characterized in that, The method includes: Obtain the firewall policy library and construct a standardized structural model of the firewall policy library; the firewall policy library includes multiple firewall policies to be optimized. The firewall policy library is input into the normalized structure model, and each firewall policy to be optimized is normalized according to the field information of each firewall policy to be optimized. Identify redundant and lenient policies among the multiple firewall policies to be optimized, and clean up the redundant and lenient policies; The process involves acquiring the flow path and processing procedure of test data within each of the firewall policies to be optimized, constructing a data flow model based on the flow path and processing procedure, analyzing the data flow model using a data flow analysis algorithm to detect conflicts in each of the firewall policies to be optimized, and determining conflicting policies among the multiple firewall policies to be optimized based on the conflicting policies, constructing an initial policy population based on the conflicting policies, the initial policy population comprising multiple individuals corresponding to the conflicting policies, iteratively processing the initial policy population using a genetic algorithm until the number of iterations reaches a preset number, and replacing the conflicting policies with the policy set obtained from the last iteration.

2. The method according to claim 1, characterized in that, Before determining the redundant and lenient policies among the plurality of firewall policies to be optimized, and cleaning up the redundant and lenient policies, the method further includes: The multiple firewall policies to be optimized are subjected to compliance checks using a pre-defined rule set. Non-compliant policies are identified and then cleaned up or modified.

3. The method according to claim 1, characterized in that, The step of identifying redundant and lenient policies among the plurality of firewall policies to be optimized, and cleaning up the redundant and lenient policies, includes: For the multiple firewall policies to be optimized, the lenient rules are compared with each of the firewall policies to be optimized, the lenient policies are selected, and the lenient policies are cleaned up to obtain the remaining multiple retainable policies. Behavioral analysis and redundancy judgment are performed on the multiple retention strategies to filter out redundant strategies and clean up the redundant strategies.

4. The method according to claim 1, characterized in that, The step of inputting the firewall policy library into the normalized structure model and normalizing each firewall policy to be optimized according to the field information of each firewall policy to be optimized includes: The firewall policy library is input into the normalized structure model, and the firewall policy is mapped to a policy instance with unified structure and semantics based on the field information of each firewall policy to be optimized.

5. The method according to claim 2, characterized in that, The method further includes: The pre-defined rule set is developed based on actual security strategies and compliance requirements.

6. The method according to claim 1, characterized in that, The step of iteratively processing the initial strategy population using a genetic algorithm until the number of iterations reaches a preset number includes: Construct a fitness function, and determine the fitness of each individual based on the fitness function; Based on the fitness, a subset of the individuals are selected as parents from the initial strategy population; A genetic algorithm is used to iteratively process the selected parent generation to obtain the next population; the iterative process includes crossover and mutation processing; The next group is used as the previous group in the next iteration, and the iteration process is repeated until the number of iterations reaches the preset number.

7. A firewall policy optimization device, characterized in that, The device includes: The model building module is used to obtain the firewall policy library and build a standardized structural model of the firewall policy library; the firewall policy library includes multiple firewall policies to be optimized. The normalization processing module is used to input the firewall policy library into the normalization structure model and normalize each firewall policy to be optimized according to the field information of each firewall policy to be optimized. The first cleanup module is used to identify redundant and lenient policies among the multiple firewall policies to be optimized, and to clean up the redundant and lenient policies. The second cleaning module is used to acquire the flow path and processing procedure of test data in each of the firewall policies to be optimized, construct a data flow model based on the flow path and processing procedure, analyze the data flow model based on the data flow analysis algorithm, detect the conflict situation of each firewall policy to be optimized, determine the conflicting policies among the multiple firewall policies to be optimized based on the conflict situation, construct an initial policy population based on the conflicting policies, the initial policy population includes multiple individuals, each individual corresponds to a conflicting policy, iterate the initial policy population using a genetic algorithm until the number of iterations reaches a preset number, and replace the conflicting policies with the policy set obtained from the last iteration.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Packet matching method based on genetic algorithm

    CN106817376A

  • Equipment security policy configuration method

    CN113572780A