Firewall-based Network Security Analysis Method, System and Storage Medium
By conducting fine-grained security analysis of user behavior data and device communication data, calculating behavior index and communication index, and dynamically adjusting access and communication modes, the problem of reducing the effectiveness of traditional firewalls in the face of fuzzy network boundaries and internal threats is solved, real-time monitoring and isolation of potential threats is achieved, and overall defense capabilities are improved.
Patent Information
- Application Number
- CN202411406537.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-10
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2044-10-10
AI Technical Summary
Traditional firewalls have reduced their effectiveness in the face of vague network boundaries and internal threats, making it difficult to monitor internal user behavior and device communication, and lack effective identification and prevention of potential internal security risks.
By collecting user behavior data and device communication data, fine-grained security analysis is carried out, behavior index and communication index are calculated, and user access mode and device communication mode are dynamically adjusted based on these indexes to achieve real-time monitoring and isolation of potential threats.
A comprehensive security assessment is achieved, the speed and accuracy of response to potential threats is improved, real-time monitoring of abnormal behaviors and equipment risks is ensured, and overall defense capabilities are enhanced.
Smart Images

Figure CN119030785B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and specifically to a network security analysis method, system and storage medium based on a firewall. Background Art
[0002] As the core device or software for network security, a firewall effectively protects a computer or network from unauthorized access and malicious attacks by controlling the incoming and outgoing traffic of the network. It screens and filters network activities such as data packets and connection requests, building a security barrier to prevent malicious behavior from entering the network; therefore, network security analysis for firewalls is particularly important;
[0003] Traditional firewalls mainly control the traffic entering and leaving the network by setting an external boundary. However, with the development of network technology and the wide application of emerging technologies such as cloud computing, the Internet of Things, and mobile office, the network boundaries of enterprises have become increasingly blurred, and the boundaries between external and internal threats are no longer so clear; therefore, when an attacker has entered the network or an internal user has negligently leaked data, the effectiveness of the firewall is greatly reduced; in addition, the firewall lacks in-depth monitoring of internal user behavior and communication between devices, making it difficult to identify and prevent internal security risks. Summary of the Invention
[0004] The present invention provides a network security analysis method, system and storage medium based on a firewall to solve the above technical problems.
[0005] The first aspect of the present invention provides a network security analysis method based on a firewall, including the following steps:
[0006] Step1: Collect the behavior data of each user, the communication data of each device, and the historical login information of each user in the station, and save them; where the behavior data includes the login time, login IP address, number of operations, and the operation type, operation data, and operation duration corresponding to each operation; the communication data includes traffic, data transmission volume, memory usage, and CPU load;
[0007] Step2: Perform fine-grained security analysis on each user and each device based on the behavior data and communication data to obtain a behavior index and a communication index, and send them to Step3;
[0008] Step3: Dynamically adjust the access mode of the user and the communication mode of the device based on the behavior index of the user and the communication index of the device, specifically:
[0009] The behavior index of each user is retrieved and compared with the set behavior interval. When the behavior index is greater than the maximum value in the set behavior interval, the user is locked and can only query data. When the behavior index is within the set behavior interval, the user's account is restricted and can only query data and download data. When the behavior index is less than the minimum value in the set behavior interval, no restrictions are required and normal access rights are maintained.
[0010] The communication index of each device is retrieved and compared with the set communication interval. When the communication index is less than the minimum value in the set communication interval, the device is recorded as a safe device; when the communication index is in the set communication interval, the device is recorded as a medium-risk device and isolated. The specific isolation method is: redirect the communication traffic of the medium-risk device to the safe device through SDN to form an independent logical subnet; when the communication index is greater than the maximum value in the set communication interval, the device is recorded as a high-risk device and controlled to enter the island mode.
[0011] Optionally, the specific process of fine-grained security analysis based on behavioral data is as follows:
[0012] 201: Retrieve the behavior data of each user, wherein the behavior data includes login time, login IP address, number of operations, operation type, operation data and operation duration corresponding to each operation, and record the operation duration as Tj, wherein i=1,2,3...J, J is a positive integer, J represents the total operation type, and j represents any one of the operation types;
[0013] 202: Set a number of time periods for the user, each time period corresponds to a habit coefficient, and compare the login time of the user with each set time period to match the corresponding habit coefficient; set a number of login IP addresses for account login, each IP address corresponds to a confidence coefficient, and compare the login IP address of the user's login with all set login IP addresses to match the corresponding confidence coefficient;
[0014] 203: Perform correlation analysis on the operation data of each operation of the user and the user to obtain the operation risk value;
[0015] 204: The custom coefficient G1, confidence coefficient G2 and operational risk value HT are calculated by the formula The behavior index GH is calculated, where f3, f4, and f5 are respectively the set proportional coefficients; when a login behavior is completed, the historical login information is accumulated, where the historical login information includes the historical login time and the historical login IP, and the accumulated information is updated to the server;
[0016] 205: Retrieve the user's historical login information, where the historical login information includes the historical login times, historical login moments, and historical login IPs; divide the 24 hours of a day into several time periods, match the historical login moments with each time period, and if the historical login moment belongs to a certain time period, then that time period accumulates one login; thus, the historical login times can be accumulated into each time period respectively; count the cumulative times in each time period separately, and divide it by the historical login times to obtain the proportion of times in each time period; multiply the proportion of times in each time period by the set habit conversion coefficient to obtain the habit coefficient;
[0017] Traverse the historical login times to extract several IP addresses, match the login IP address of each login with all IP addresses to obtain the cumulative login times of each IP address, and divide it by the historical login times to obtain the proportion of times of each IP address; multiply the proportion of times of each IP address by the set confidence conversion coefficient to obtain the confidence coefficient;
[0018] Update the habit coefficients of each time period and the confidence coefficients of each IP address to 202.
[0019] Optionally, the specific process of association analysis is as follows:
[0020] Retrieve the operation data corresponding to each operation, use natural language processing technology to extract several keywords from the operation data, and use the TF-IDF technology to obtain the importance scores of each keyword in the operation data; compare the user's keywords with the keywords of the operation data to obtain the number of intersection keywords and the number of union keywords, and record them as I and N respectively; thus, the importance score corresponding to each intersection keyword can be recorded as Fi, where i = 1, 2, 3... I, I takes positive integer values, I represents the total number of intersection keywords, and i represents any one of the intersection keywords;
[0021] Compare and analyze the importance scores of each intersection keyword with the set score range to classify the intersection keywords corresponding to the importance scores into heavy keywords, medium keywords, and light keywords, count the numbers of heavy keywords, medium keywords, and light keywords respectively, and record them as H1, H2, and H3;
[0022] Substitute H1, H2, H3, I, N, and Fi into the set formula Perform calculations to obtain the association degree Ha between each operation data and the user, where are the set proportionality coefficients respectively, and a1 > a2 > a3 > 0; thus, the association degrees corresponding to each type of operation can be recorded as Haj, and substitute it and the corresponding operation duration Tj into the set formula Perform calculations to obtain the operation risk value HT, where are the proportionality constants corresponding to each type of operation, and f1, f2 are the set proportionality coefficients respectively.
[0023] Optionally, the specific process of performing fine-grained security analysis based on line communication data is as follows:
[0024] 401: Retrieve the communication data of each device at each collection moment, where the communication data includes traffic, data transmission volume, memory usage, and CPU load, and denote them as Lk, Ck, Yk, and Zk respectively, where k = 1, 2, 3... K, K is a positive integer, K represents the total number of collection moments, and k represents the serial number of any one of the collection moments;
[0025] 402: Set a regular communication baseline for each device respectively, where the regular communication baseline includes expected traffic, expected data transmission volume, expected memory usage, and expected CPU load, and denote them as QL, QC, QY, and QZ respectively;
[0026] 403: Substitute Lk, Ck, Yk, Zk, QL, QC, QY, and QZ into the set formula for calculation to obtain the communication risk value Zg at each collection moment, where g1, g2, g3, g4 are respectively set proportionality coefficients;
[0027] 403: Construct a two-dimensional rectangular coordinate system with time as the abscissa and the communication risk value as the ordinate, plot points in the coordinate axis according to the communication risk value corresponding to its collection moment to obtain several communication points, and connect the communication points in sequence to obtain a line graph of the communication risk changing with time, and perform graphical analysis on the line graph of the communication risk changing with time to obtain a communication index.
[0028] Optionally, the specific process of performing graphical analysis on the line graph of the communication risk changing with time is as follows:
[0029] Calculate the slope of the line segment formed by two adjacent communication points and denote it as Sum up the slopes greater than zero to obtain the risk increase value denoted as A1, and sum up the slopes less than zero to obtain the risk decrease value denoted as 2;
[0030] Denote the slope equal to zero as the balance slope, and calculate the average value of the communication risk values corresponding to the two adjacent collection moments corresponding to it to obtain the balance value; thus, the balance values corresponding to each balance slope can be obtained; compare and analyze each balance value with the set balance interval to classify each balance value into high-risk balance, medium-risk balance, and low-risk balance, respectively count the quantities of high-risk balance, medium-risk balance, and low-risk balance, and denote them as P1, P2, and P3 respectively; calculate the average value of each balance value to obtain the balance average value denoted as P4; substitute P1, P2, P3, and P4 into the set formula Perform calculations to obtain the balance degree value Pb, where b1, b2, and b3 are respectively set proportionality coefficients, and b1 > b2 > b3 > 1;
[0031] The slope The risk increase value A1, the risk reduction value A2, and the balance degree value Pb are calculated through a set formula to obtain the communication index AP, where h1, h2, and h3 are respectively set proportionality coefficients, is the mean value of each slope.
[0032] The second aspect of the present invention provides a network security analysis system based on a firewall, and the system includes: a server, a security analysis module, and a security control module;
[0033] The server collects the behavior data of each user in the station, the communication data of each device, and the historical login information of each user, and saves them; where the behavior data includes the login time, login IP address, number of operations, and the operation type, operation data, and operation duration corresponding to each operation; the communication data includes traffic, data transmission volume, memory usage, and CPU load;
[0034] The security analysis module performs fine-grained security analysis on each user and each device based on the behavior data and communication data to obtain the behavior index and communication index, and sends them to the security control module;
[0035] The security control module dynamically adjusts the access mode of the user and the communication mode of the device based on the behavior index of the user and the communication index of the device. Specifically:
[0036] Retrieve the behavior index of each user, and compare and analyze it with the set behavior interval. When the behavior index is greater than the maximum value in the set behavior interval, then lock this user, and only query data operations can be performed; when the behavior index is within the set behavior interval, then restrict the account of this user, and only query data and download data operations can be performed; when the behavior index is less than the minimum value in the set behavior interval, then no restrictions are required, and normal access rights are maintained;
[0037] Retrieve the communication index of each device, and compare and analyze it with the set communication interval. When the communication index is less than the minimum value in the set communication interval, then mark this device as a secure device; when the communication index is within the set communication interval, then mark this device as a medium-risk device, and isolate it. The specific isolation method is: redirect the communication traffic of the medium-risk device to a secure device through SDN to form an independent logical subnet; when the communication index is greater than the maximum value in the set communication interval, then mark this device as a high-risk device, and control this device to enter the island mode.
[0038] The third aspect of the present invention provides a computer-readable storage medium, in which instructions are stored. When the instructions run on a computer, the computer is caused to execute the above-mentioned network security analysis method based on a firewall.
[0039] In the technical solution provided by the present invention, compared with the prior art, the beneficial effects are as follows:
[0040] 1. By performing fine-grained security analysis on the behavior data of users and the communication data of devices to obtain a behavior index and a communication index, a comprehensive security assessment is formed. Combining data from multiple dimensions, an all-round analysis method is provided; fine-grained monitoring is achieved, providing data support for the security control decision-making of the firewall, effectively improving the response speed and accuracy to potential threats, and ensuring real-time monitoring of abnormal behaviors and device risks.
[0041] 2. By real-time monitoring and analysis of the user behavior index and the device communication index, it is possible to dynamically adjust the access mode of users and the communication mode of devices. This dynamic adjustment method based on behavior and communication risks greatly improves the flexibility of the system and the ability to respond to potential threats, ensuring that the permissions of users or devices can be quickly restricted when abnormal behaviors occur; the entire process is based on automated monitoring analysis and dynamic adjustment, can timely adapt to the constantly changing security situation, and combines behavior monitoring and SDN technology to achieve rapid response and isolation of potential attacks, enhancing the overall defense ability. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. The following drawings are not deliberately drawn to scale in actual size, and the focus is on showing the gist of the present application.
[0043] Figure 1 It is a block diagram of the principle of the present invention;
[0044] Figure 2 It is a block diagram of the connection of system modules of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0045] Embodiments of the present invention provide a network security analysis method, system and storage medium based on a firewall. Terms such as "first", "second", "third", "fourth", etc. (if any) in the specification, claims and above-mentioned drawings of the present invention are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data used can be interchanged under appropriate circumstances so that the embodiments described here can be implemented in an order different from that shown or described here. In addition, the term "including" or "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0046] For ease of understanding, the specific process of the embodiments of the present invention will be described below. Please refer to Figure 1-2 , in the embodiments of the present invention, the network security analysis method based on a firewall is implemented by applying to a network security analysis system based on a firewall, where the network security analysis system based on a firewall includes a server, a security analysis module and a security control module;
[0047] Specifically, the method includes the following steps:
[0048] Step1: The server collects the behavior data of each user in the station and the communication data of each device, and saves them; where the behavior data includes; the communication data includes; in addition, the server also stores the historical login information of each user;
[0049] Step2: The security analysis module performs fine-grained security analysis on each user and each device in the station based on the behavior data and communication data to obtain the behavior index of each user and the communication index of each device; specifically:
[0050] Performing fine-grained security analysis based on behavior data:
[0051] Step 1: Retrieve the behavior data of each user, where the behavior data includes the login time, login IP address, number of operations, and the operation type, operation data, and operation duration corresponding to each operation. The operation duration is denoted as Tj, where i = 1, 2, 3... J, J is a positive integer, J represents the total type of operations, and j represents any one of the operation types; specifically, the operation types include querying data, downloading data, modifying data, and deleting data. Then the data queried, downloaded, modified, and deleted are denoted as operation data;
[0052] Step 2: Set that there are several time periods for the user, and each time period corresponds to a habit coefficient. Compare the login time of the user's current login with the set time periods to match the corresponding habit coefficient, and record it as G1;
[0053] Set that there are several login IP addresses for the account, and each IP address corresponds to a confidence coefficient. Compare the login IP address of the user's current login with all the set login IP addresses to match the corresponding confidence coefficient, and record it as G2;
[0054] Step 3: Retrieve the operation data corresponding to each operation, use natural language processing (NLP) technology to extract several keywords from the operation data, and use the TF-IDF technology to obtain the importance scores of each keyword in the operation data; set that each user corresponds to several keywords. It should be noted that the keywords of each user are set by the personnel in the field according to the identities or positions corresponding to each user; compare the keywords of the user with the keywords of the operation data to obtain the number of intersection keywords and the number of union keywords, and record them as I and N respectively; thus, the importance score corresponding to each intersection keyword is recorded as Fi, where i = 1, 2, 3... I, I takes positive integers, I represents the total number of intersection keywords, and i represents any one of the intersection keywords;
[0055] Compare and analyze the importance scores of each intersection keyword with the set score interval. When the importance score is greater than the maximum value in the set score interval, the intersection keyword corresponding to the importance score is recorded as a heavy keyword; when the importance score is within the set score interval, the intersection keyword corresponding to the importance score is recorded as a medium keyword; when the importance score is less than the minimum value in the set score interval, the intersection keyword corresponding to the importance score is recorded as a light keyword; respectively count the numbers of heavy keywords, medium keywords and light keywords, and record them as H1, H2, H3, and use the set formula to calculate the correlation degree Ha between each operation data and the user, where are the set proportionality coefficients, and a1 > a2 > a3 > 0; thus, the correlation degree corresponding to each type of operation is recorded as Haj, and it is combined with the corresponding operation duration Tj through the set formula Perform calculations to obtain the operational risk value HT, where αj is the proportionality constant corresponding to each type of operation. For example, the proportionality constant corresponding to the operation of deleting data is greater than that corresponding to the operation of downloading data; f1 and f2 are the set proportionality coefficients respectively. It can be seen from the formula that the more sensitive the operation (the sensitivity of the operation of deleting data is higher than that of the operations of downloading data and querying data, that is, the larger the proportionality constant αj corresponding to the operation, the more sensitive the operation), the greater the operational risk value; when the correlation between the data being operated on and the user is smaller, the operational risk value is greater; when the operation duration is longer, the operational risk value is greater.
[0056] Step Four: Calculate the behavior index GH through the set formula using the habit coefficient G1, confidence coefficient G2, and operational risk value HT Perform calculations to obtain the behavior index GH, where f3, f4, and f5 are the set proportionality coefficients respectively. When a login behavior is completed, the historical login information is accumulated once, where the historical login information includes the historical login time and the historical login IP, and it is accumulated and updated to the server.
[0057] Step Five: Retrieve the user's historical login information, where the historical login information includes the historical login times, historical login time, and historical login IP. Divide the 24 hours of a day into several time periods (specifically, the time segmentation is based on the login time corresponding to each login). Match the historical login time with each time period. If the historical login time belongs to a certain time period, then the login is accumulated once for that time period. Thus, the historical login times can be accumulated into each time period respectively. Count the cumulative number of times in each time period separately, and divide it by the historical login times to obtain the proportion of the number of times in each time period. Multiply the proportion of the number of times in each time period by the set habit conversion coefficient (the habit conversion coefficient is a set constant) to obtain the habit coefficient.
[0058] Traverse the historical login times to extract several IP addresses. Match the login IP address of each login with all IP addresses to obtain the cumulative login times of each IP address, and divide it by the historical login times to obtain the proportion of the number of times of each IP address. Multiply the proportion of the number of times of each IP address by the set confidence conversion coefficient (the confidence conversion coefficient is a set constant) to obtain the confidence coefficient.
[0059] Update the habit coefficients of each time period and the confidence coefficients of each IP address to Step Two.
[0060] Conduct fine-grained security analysis based on communication data:
[0061] Retrieve the communication data of each device at each collection moment, where the communication data includes traffic, data transmission volume, memory usage, and CPU load, and record them as Lk, Ck, Yk, and Zk respectively, where k = 1, 2, 3... K, K takes positive integer values, and K represents the total number of collection moments, and k represents the serial number of any one of the collection moments; it should be noted that an abnormal increase or decrease in traffic indicates that the device has an abnormal risk; a sudden increase or decrease in the transmission volume may mean abnormal activities of the device, indicating that the device has an abnormal risk; an abnormal increase in memory usage and CPU load indicates that the device is at risk of being attacked;
[0062] Set that each device corresponds to a regular communication baseline respectively, where the regular communication baseline includes expected traffic, expected data transmission volume, expected memory usage, and expected CPU load, and record them as QL, QC, QY, and QZ respectively; it should be noted that the regular communication baseline here is set by those skilled in the art according to actual needs, and the specific setting method is set according to the daily work of the device, and is used as a reference standard for monitoring the health and safety status of the device;
[0063] Use the set formula Calculate to obtain the communication risk value Zg at each collection moment, where g1, g2, g3, g4 are respectively set proportionality coefficients; it can be seen from the formula that the greater the deviation of the communication data from the regular communication baseline, the greater the communication risk value;
[0064] Construct a two-dimensional rectangular coordinate system with time as the abscissa and the communication risk value as the ordinate, plot points in the coordinate axis according to the communication risk value corresponding to its collection moment to obtain several communication points, and connect the communication points in sequence to obtain a line graph of the change of communication risk over time, and calculate the slope of the line segment formed by two adjacent communication points and record it as Sum up the slopes greater than zero to obtain the risk increase value recorded as A1, and sum up the slopes less than zero to obtain the risk decrease value recorded as A2;
[0065] The slope equal to zero is denoted as the equilibrium slope. It should be noted that the equilibrium slope refers to the state where the communication risk value remains unchanged. The average value of the communication risk values corresponding to two adjacent acquisition times of the equilibrium slope is calculated to obtain the equilibrium value. Thus, the equilibrium values corresponding to each equilibrium slope can be obtained. If the equilibrium value is larger, it indicates that the device is balanced in a state with a relatively large communication risk value. The equilibrium values are compared and analyzed with the set equilibrium interval. When each equilibrium value is greater than the maximum value in the equilibrium interval, a high-risk equilibrium is accumulated. When each equilibrium value is within the equilibrium interval, a medium-risk equilibrium is accumulated. When each equilibrium value is less than the minimum value in the equilibrium interval, a low-risk equilibrium is accumulated. The quantities of high-risk equilibrium, medium-risk equilibrium, and low-risk equilibrium are respectively counted and denoted as P1, P2, and P3. The average value of each equilibrium value is calculated to obtain the equilibrium average value denoted as P4, and the equilibrium degree value Pb is calculated using the set formula where b1, b2, and b3 are respectively set proportionality coefficients, and b1 > b2 > b3 > 1;
[0066] The slope The risk increase value A1, the risk decrease value A2, and the equilibrium degree value Pb are calculated using the set formula to obtain the communication index AP, where h1, h2, and h3 are respectively set proportionality coefficients, is the average value of each slope. It can be seen from the formula that when the slope is more volatile, it indicates that the communication state of the device is more unstable, and the communication index is larger. When the risk increase value is larger, the risk decrease value is smaller, and the equilibrium degree value is larger, the communication index is larger;
[0067] The behavior index and the communication index are sent to Step3;
[0068] By performing fine-grained security analysis on the user's behavior data and the device's communication data to obtain the behavior index and the communication index, a comprehensive security assessment is formed. Combining data from multiple dimensions, a comprehensive analysis method is provided; fine-grained monitoring is achieved, providing data support for the security control decision-making of the firewall, effectively improving the response speed and accuracy to potential threats, and ensuring the real-time monitoring of abnormal behaviors and device risks.
[0069] Step3: The security control module dynamically adjusts the user's access mode and the device's communication mode based on the user's behavior index and the device's communication index to achieve the internal security protection of the firewall; specifically:
[0070] Retrieve the behavior indices of each user, and compare and analyze them with the set behavior interval. When the behavior index is greater than the maximum value in the set behavior interval, it indicates that the user has a relatively high risk, and then the user will be locked and can only perform data query operations; when the behavior index is within the set behavior interval, the user's account will be restricted and can only perform data query and download operations; when the behavior index is less than the minimum value in the set behavior interval, no restrictions are required and normal access rights are maintained.
[0071] Retrieve the communication indices of each device, and compare and analyze them with the set communication interval. When the communication index is less than the minimum value in the set communication interval, it indicates that the device is in a normal state, and then the device is marked as a safe device; when the communication index is within the set communication interval, the device is marked as a medium-risk device and is isolated. The specific isolation method is: through SDN (Software Defined Network), redirect the communication traffic of the medium-risk device to the safe device to form an independent logical subnet (that is, only allow high-risk devices and safe devices to connect), prevent communication with other devices, and avoid the spread of attacks.
[0072] When the communication index is greater than the maximum value in the set communication interval, it indicates that the device has a relatively high security risk, and then the device is marked as a high-risk device and is controlled to enter the island mode (that is, through SDN (Software Defined Network), block the communication traffic of the high-risk device to form a communication island), which can effectively contain the spread of security risks and protect the security of the entire network.
[0073] Through the real-time monitoring and analysis of the user behavior index and the device communication index, it is possible to dynamically adjust the access mode of the user and the communication mode of the device. This dynamic adjustment method based on behavior and communication risks greatly improves the flexibility of the system and the ability to respond to potential threats, ensuring that the permissions of users or devices can be quickly restricted when abnormal behaviors occur; the entire process is based on automated monitoring analysis and dynamic adjustment, can timely adapt to the changing security situation, and combines behavior monitoring and SDN technology to achieve rapid response and isolation of potential attacks, enhancing the overall defense ability.
[0074] The present invention also provides a computer-readable storage medium. The computer-readable storage medium can be a non-volatile computer-readable storage medium or a volatile computer-readable storage medium. Instructions are stored in the computer-readable storage medium. When the instructions run on a computer, the computer is made to execute the steps of the network security analysis method based on the firewall.
[0075] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0076] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0077] As described above, the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A network security analysis method based on a firewall, characterized in that: The following steps are involved: Step 1: Collect and save the behavior data of each user in the station, the communication data of each device and the historical login information of each user; the behavior data includes login time, login IP address, number of operations, and the operation type, operation data and operation duration corresponding to each operation; Communication data includes traffic, data transfer, memory usage, and CPU load; Step 2: Perform fine-grained security analysis on each user and each device based on the behavior data and communication data to obtain the behavior index and communication index, and send them to Step 3; Step 3: Dynamically adjust the user's access mode and the device's communication mode based on the user's behavior index and the device's communication index, specifically: The behavior index of each user is retrieved and compared with the set behavior interval. When the behavior index is greater than the maximum value in the set behavior interval, the user is locked and can only query data. When the behavior index is within the set behavior interval, the user's account is restricted and can only query data and download data. When the behavior index is less than the minimum value in the set behavior interval, no restrictions are required and normal access rights are maintained. The communication index of each device is retrieved and compared with the set communication interval. When the communication index is less than the minimum value in the set communication interval, the device is recorded as a safe device; when the communication index is within the set communication interval, the device is recorded as a medium-risk device and isolated. The specific isolation method is: redirect the communication traffic of the medium-risk device to the safe device through SDN to form an independent logical subnet; when the communication index is greater than the maximum value in the set communication interval, the device is recorded as a high-risk device and is controlled to enter the island mode; The specific process of fine-grained security analysis based on behavioral data is as follows: 201: Retrieving the behavior data of each user, wherein the behavior data includes login time, login IP address, number of operations, and operation type, operation data and operation duration corresponding to each operation; 202: Set a number of time periods for the user, each time period corresponds to a habit coefficient, and compare the login time of the user with each set time period to match the corresponding habit coefficient; set a number of login IP addresses for account login, each IP address corresponds to a confidence coefficient, and compare the login IP address of the user's login with all set login IP addresses to match the corresponding confidence coefficient; 203: Perform correlation analysis on the operation data of each operation of the user and the user to obtain the operation risk value; 204: normalize the habit coefficient, confidence coefficient and operational risk value and take their values, and analyze the values to obtain the behavior index; When a login behavior is completed, historical login information is accumulated, where the historical login information includes historical login time and historical login IP, and the accumulated information is updated to the server; 205: Retrieve the historical login information of the user, wherein the historical login information includes the historical login times, historical login times, and historical login IP addresses; divide the twenty-four hours of a day into a number of time periods, match the historical login times with each time period, and if the historical login time belongs to a certain time period, then the time period accumulates one login; thus, the historical login times can be accumulated into each time period respectively; count the cumulative times in each time period respectively, and divide it by the historical login times to obtain the times ratio of each time period; multiply the times ratio of each time period by the set habit conversion coefficient to obtain the habit coefficient; Traverse the historical login times to extract several IP addresses, match the login IP address of each login with all IP addresses to obtain the cumulative login times of each IP address, and divide it by the historical login times to obtain the number of times proportion of each IP address; multiply the number of times proportion of each IP address by the set confidence conversion coefficient to obtain the confidence coefficient; Update the habit coefficient of each time period and the confidence coefficient of each IP address to 202; The specific process of fine-grained security analysis based on communication data is as follows: 401: Retrieve the communication data of each device at each collection time, where the communication data includes flow, data transmission volume, memory usage and CPU load; 402: Set a regular communication baseline for each device, where the regular communication baseline includes expected traffic, expected data transmission volume, expected memory usage, and expected CPU load; 403: normalize the traffic, data transmission volume, memory usage, CPU load, expected traffic, expected data transmission volume, expected memory usage, and expected CPU load, and obtain their values, and analyze the values to obtain the communication risk value of the device at each collection time; 403: A two-dimensional rectangular coordinate system is constructed with time as the horizontal coordinate and the communication risk value as the vertical coordinate. Points are drawn on the coordinate axis according to the communication risk values and their corresponding collection times to obtain a number of communication points. The communication points are connected in sequence to obtain a line graph of communication risk changes over time. The line graph of communication risk changes over time is graphically analyzed to obtain a communication index.
2. The firewall-based network security analysis method according to claim 1, characterized in that: The specific process of association analysis is as follows: Retrieve the operation data corresponding to each operation, extract several keywords from the operation data using natural language processing technology, and use TF-IDF technology to obtain the importance score of each keyword in the operation data; compare the user's keywords with the keywords of the operation data to obtain the number of intersection keywords and the number of union keywords, thereby obtaining the importance score corresponding to each intersection keyword; Compare and analyze the importance score of each intersection keyword with the set score range to divide the intersection keywords corresponding to the importance score into heavy keywords, medium keywords and light keywords, count the number of heavy keywords, medium keywords and light keywords respectively, and normalize them with the importance score of the intersection keywords, the number of intersection keywords and the number of union keywords and take their numerical values, and analyze the numerical values to obtain the correlation between the operation data and the user; thereby, the correlation corresponding to each type of operation can be obtained, and it is normalized with the corresponding operation time and take its numerical value, and the operation risk value is obtained by numerical analysis.
3. The firewall-based network security analysis method according to claim 1, characterized in that: The specific process of graphically analyzing the line graph of communication risk changes over time is as follows: Calculate the slope of the line segment formed by two adjacent communication points, sum the slopes greater than zero to obtain the risk increase value, and sum the slopes less than zero to obtain the risk reduction value; The slope equal to zero is recorded as the equilibrium slope, and the communication risk values corresponding to the two adjacent acquisition moments are averaged to obtain the equilibrium value; thus, the equilibrium value corresponding to each equilibrium slope can be obtained; each equilibrium value is compared and analyzed with the set equilibrium interval to divide each equilibrium value into risk balance, medium risk balance and light risk balance, and the number of high risk balance, medium risk balance and light risk balance is counted respectively, and the average of each equilibrium value is calculated to obtain the equilibrium mean; The balance degree value is obtained by formulating and analyzing the number of balance mean, high risk balance, medium risk balance and light risk balance; The slope, risk increase value, risk reduction value and balance degree value are normalized and their values are taken, and the communication index is obtained by numerical analysis.
4. A network security analysis system based on a firewall, characterized in that: Applied to the firewall-based network security analysis method as claimed in any one of claims 1 to 3, the system comprises: a server, a security analysis module and a security management and control module; The server collects and stores the behavior data of each user in the station, the communication data of each device and the historical login information of each user. The behavior data includes the login time, login IP address, number of operations, and the operation type, operation data and operation duration corresponding to each operation. The communication data includes traffic, data transmission volume, memory usage and CPU load. The security analysis module performs fine-grained security analysis on each user and each device based on the behavior data and communication data to obtain the behavior index and communication index, and sends them to the security control module; The security control module dynamically adjusts the user's access mode and the device's communication mode based on the user's behavior index and the device's communication index. Specifically: The behavior index of each user is retrieved and compared with the set behavior interval. When the behavior index is greater than the maximum value in the set behavior interval, the user is locked and can only query data. When the behavior index is within the set behavior interval, the user's account is restricted and can only query data and download data. When the behavior index is less than the minimum value in the set behavior interval, no restrictions are required and normal access rights are maintained. The communication index of each device is retrieved and compared with the set communication interval. When the communication index is less than the minimum value in the set communication interval, the device is recorded as a safe device; when the communication index is in the set communication interval, the device is recorded as a medium-risk device and isolated. The specific isolation method is: redirect the communication traffic of the medium-risk device to the safe device through SDN to form an independent logical subnet; when the communication index is greater than the maximum value in the set communication interval, the device is recorded as a high-risk device and controlled to enter the island mode.
5. A computer-readable storage medium having instructions stored thereon, characterized in that: When the instructions are executed by the processor, the firewall-based network security analysis method as described in any one of claims 1-3 is implemented.
Citation Information
Patent Citations
Intelligent campus archive data security management system
CN118710461A
Risky code pre-detection method and apparatus, electronic device, computer readable storage medium, and computer program product
WO2023236538A1