Methods and apparatus for linking configuration information and firewall policies
By constructing a knowledge graph to associate application configuration information and firewall policies, the problem of untimely updates of application system configuration information and firewall policies under different environments is solved, achieving efficient configuration deployment and firewall management, and ensuring environmental stability and information security.
Patent Information
- Application Number
- CN202311568709.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-23
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2043-11-23
AI Technical Summary
When an application system acts as a service provider or access point, it is difficult to update configuration information and firewall policies in a timely manner, leading to problems such as call errors, omissions, long processing times, information security risks, and impact on business transactions.
By constructing a knowledge graph, the application's configuration information and firewall policies are linked together. The knowledge graph is used to obtain configuration information and firewall policies in different environments, enabling configuration deployment and firewall activation, and timely policy changes based on the change information.
It reduces communication costs for multi-environment operation and maintenance, reduces the risk of errors and omissions, ensures the stability of the environment and information security, and avoids the risk of environment unavailability caused by missing configuration information or missing firewall access.
Smart Images

Figure CN119316170B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the fields of information security technology, artificial intelligence technology, financial technology or other related fields, and in particular to a method, apparatus, device, medium and program product for linking configuration information and firewall policies. Background Technology
[0002] Organizations typically contain multiple application systems, meaning that implementing a single function often requires access and calls between different applications. Application systems frequently act as both service providers for other applications to access and call, and as accessors to call services from other applications to achieve complete functionality.
[0003] However, when the application system acts as the service provider, it is difficult to obtain information on all connected applications, which can easily lead to errors and omissions in the calls. Furthermore, since the information provided to the outside world may change, there is a risk that the access party may not update its firewall policies or configuration information in a timely manner, resulting in application service unavailability and impacting business transactions. When the application system acts as the access party, it needs to deploy applications in multiple environments, which makes the process of obtaining configuration information and firewall policies for multiple environments time-consuming and prone to information omissions and errors. Summary of the Invention
[0004] In view of the above problems, this disclosure provides a method, apparatus, device, media and program product for linking configuration information and firewall policies.
[0005] According to the first aspect of this disclosure, a method for linking configuration information and firewall policies is provided, including:
[0006] Obtain source data corresponding to various applications under different environments;
[0007] Based on the above source data, a knowledge graph is constructed that associates the configuration information and firewall policies of the above applications.
[0008] When the target application acts as an access point to other applications, the configuration information and firewall policies corresponding to these other applications under different environments are obtained from the aforementioned knowledge graph to enable the configuration deployment and firewall access of the target application; and
[0009] When the aforementioned target application provides services to the outside world as a service provider, the aforementioned knowledge graph is used to modify the configuration information and firewall policies corresponding to the aforementioned target application based on the change information corresponding to the aforementioned target application.
[0010] According to embodiments of this disclosure, when the target application accesses other applications as an access party, obtaining configuration information and firewall policies corresponding to the other applications under different environments from the knowledge graph to achieve configuration deployment and firewall access for the target application includes:
[0011] Based on the configuration information corresponding to the other applications mentioned above, configure and deploy the application on the target application; and
[0012] Based on the service addresses corresponding to the other applications identified in the aforementioned firewall policy, open the firewall between the service addresses corresponding to the other applications and the service address corresponding to the target application.
[0013] According to embodiments of this disclosure, when the target application provides services externally as a service provider, the knowledge graph is used to modify the configuration information and firewall policies corresponding to the target application based on the change information corresponding to the target application, including:
[0014] In the case where the service address of the target application has changed as indicated by the above change information, the first server with an access relationship to the old service address is determined from the knowledge graph based on the old service address in the above change information.
[0015] Based on the configuration information corresponding to the aforementioned old service address, a second server using the aforementioned configuration information is determined from the aforementioned knowledge graph; and
[0016] Based on the new service address, the first server, and the second server in the above change information, the firewall policy corresponding to the target application is changed to obtain the changed firewall policy.
[0017] According to embodiments of this disclosure, the method for linking the above configuration information and firewall policies further includes:
[0018] According to the revised firewall policy, the firewall between the new service address and the service address corresponding to the target server is opened, wherein the target server includes the first server and the second server.
[0019] According to embodiments of this disclosure, the method for linking the above configuration information and firewall policies further includes:
[0020] When the aforementioned change information indicates a change in the configuration information of the target application, the target server using the old configuration information is determined from the aforementioned knowledge graph based on the old configuration information in the aforementioned change information; and
[0021] Based on the new configuration information in the above change information, the configuration information used by the target server is changed.
[0022] According to embodiments of this disclosure, the method for linking the above configuration information and firewall policies further includes:
[0023] Add the new service address or new configuration information from the above change information as a new node to the above knowledge graph to obtain the first knowledge graph;
[0024] Based on the target application and the target server described above, the edges in the first knowledge graph are adjusted to obtain the second knowledge graph.
[0025] According to embodiments of this disclosure, the method for linking the above configuration information and firewall policies further includes:
[0026] If the old service address or the old configuration information is not accessed within a preset time range, the old service address or the old configuration information will be taken offline, and the nodes and edges related to the old service address or the old configuration information in the second knowledge graph will be deleted.
[0027] According to embodiments of this disclosure, the above-mentioned knowledge graph, constructed based on the source data, associates the configuration information and firewall policies of the aforementioned applications, including:
[0028] Based on the constructed architecture corresponding to the aforementioned knowledge graph, the source data is extracted to obtain extracted information; and
[0029] Based on the extracted information, the aforementioned knowledge graph was constructed.
[0030] The second aspect of this disclosure provides an apparatus for linking configuration information and firewall policies, comprising: a first acquisition module, a construction module, a second acquisition module, and a modification module. The first acquisition module is used to acquire source data corresponding to each application under different environments. The construction module is used to construct a knowledge graph that associates the configuration information and firewall policies of the aforementioned applications based on the source data. The second acquisition module is used to acquire configuration information and firewall policies corresponding to the aforementioned other applications under different environments from the knowledge graph when the target application acts as an access party to access other applications, thereby enabling the configuration deployment and firewall access of the target application. The modification module is used to modify the configuration information and firewall policies corresponding to the target application when the target application acts as a service provider to provide services externally, using the knowledge graph and based on the modification information corresponding to the target application.
[0031] A third aspect of this disclosure provides an electronic device comprising: one or more processors; and a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors perform the methods described above.
[0032] A fourth aspect of this disclosure also provides a computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the methods described above.
[0033] The fifth aspect of this disclosure also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.
[0034] Based on the methods, apparatus, devices, media, and program products for linking configuration information and firewall policies provided in this disclosure, a knowledge graph can be constructed that associates the configuration information and firewall policies of each application with the source data corresponding to each application under different environments. Therefore, when the target application acts as an access party to other applications, the configuration information and firewall policies corresponding to other applications under different environments can be directly obtained from the knowledge graph, enabling configuration deployment and firewall activation. This reduces communication costs during multi-environment operation and maintenance, and also reduces the risk of errors and omissions. When the target application acts as a service provider to provide services externally, the knowledge graph can be used to modify the configuration information and firewall policies corresponding to the target application based on the change information corresponding to the target application. This enables timely changes to the configuration information or firewall policies of all access parties corresponding to the target application, reducing the risk of environment unavailability and information security risks caused by missed configuration information changes or unenabled firewalls, and ensuring the stability of each environment. Attached Figure Description
[0035] The foregoing contents, as well as other objects, features, and advantages of this disclosure, will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:
[0036] Figure 1 This diagram illustrates an application scenario of a method for linking configuration information and firewall policies according to embodiments of the present disclosure.
[0037] Figure 2 A flowchart illustrating a method for linking configuration information and firewall policies according to an embodiment of this disclosure is shown schematically.
[0038] Figure 3 A schematic diagram of a knowledge graph according to an embodiment of the present disclosure is shown.
[0039] Figure 4This illustration schematically shows a graph link diagram in which a target application, as an access party, accesses other applications according to an embodiment of this disclosure;
[0040] Figure 5 This illustration shows a flowchart of changes to configuration information and firewall policies according to embodiments of the present disclosure;
[0041] Figure 6 This illustration schematically shows a knowledge graph after changes to the service address and configuration information of a target application according to an embodiment of this disclosure;
[0042] Figure 7 This schematic diagram illustrates a system diagram for implementing a method for linking configuration information and firewall policies according to an embodiment of the present disclosure;
[0043] Figure 8 This schematically illustrates a structural block diagram of an apparatus for linking configuration information and firewall policies according to embodiments of the present disclosure; and
[0044] Figure 9 A block diagram schematically illustrates an electronic device suitable for implementing a method of linking configuration information and firewall policies according to an embodiment of the present disclosure. Detailed Implementation
[0045] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.
[0046] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0047] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.
[0048] When using expressions such as "at least one of A, B, and C", they should generally be interpreted in accordance with the meaning that is commonly understood by a person skilled in the art (e.g., "a system having at least one of A, B, and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B, and C, etc.).
[0049] In the technical solution of this invention, the user information (including but not limited to user personal information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with the relevant laws, regulations, and standards of the relevant countries and regions, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entry points for users to choose to authorize or refuse.
[0050] In implementing this disclosure, it was discovered that inter-application calls require configuration information on the access side and the firewall to the target application to be enabled before service calls can be made. In the software development lifecycle management, development, testing, and production operations personnel need to deploy applications in multiple environments, and the configuration information and firewall enabling policies differ in each environment.
[0051] When an application system connects to a new application, the development, testing, and production personnel need to check the configuration information and firewall access policies of multiple environments in multiple rounds. This cumbersome process is not only time-consuming and labor-intensive, but also prone to errors and omissions.
[0052] When an application system acts as a service provider, and changes occur in its service configuration or firewall access addresses due to various modifications, all connected application systems must be notified to update their configurations or modify their firewall access policies. This is especially problematic for foundational support applications, which often lack access to all connected applications. Failure to notify all connected applications to update their configurations or modify their firewall policies in a timely manner can easily lead to information security risks and disrupt business transactions.
[0053] To this end, embodiments of this disclosure provide a method for linking configuration information and firewall policies, including: obtaining source data corresponding to each application under different environments; constructing a knowledge graph that associates the configuration information and firewall policies of each application based on the source data; when the target application accesses other applications as an access party, obtaining the configuration information and firewall policies corresponding to other applications under different environments from the knowledge graph to realize the configuration deployment and firewall access of the target application; when the target application provides services to the outside world as a service provider, using the knowledge graph to change the configuration information and firewall policies corresponding to the target application based on the change information corresponding to the target application.
[0054] Figure 1 The diagram illustrates an application scenario of a method for linking configuration information and firewall policies according to an embodiment of this disclosure.
[0055] like Figure 1 As shown, application scenario 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 serves as a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.
[0056] Users can interact with server 105 via network 104 using at least one of the first terminal device 101, second terminal device 102, and third terminal device 103 to receive or send messages, etc. Various communication client applications can be installed on the first terminal device 101, second terminal device 102, and third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).
[0057] The first terminal device 101, the second terminal device 102, and the third terminal device 103 can be various electronic devices with displays and support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.
[0058] Server 105 can be a server that provides various services, such as a backend management server that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103 (this is just an example). The backend management server can analyze and process data such as received user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.
[0059] For example, source data corresponding to each application under different environments can be obtained through server 105. Based on the source data, a knowledge graph that associates the configuration information and firewall policies of each application can be constructed. Thus, when the target application accesses other applications as an access party, the configuration information and firewall policies corresponding to other applications under different environments can be obtained from the knowledge graph to realize the configuration deployment and firewall access of the target application. Furthermore, when the target application provides services to the outside world as a service provider, the knowledge graph can be used to change the configuration information and firewall policies corresponding to the target application based on the change information corresponding to the target application.
[0060] It should be noted that the method for linking configuration information and firewall policies provided in this embodiment can generally be executed by server 105. Correspondingly, the apparatus for linking configuration information and firewall policies provided in this embodiment can generally be located in server 105. The method for linking configuration information and firewall policies provided in this embodiment can also be executed by a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105. Correspondingly, the apparatus for linking configuration information and firewall policies provided in this embodiment can also be located in a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105.
[0061] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.
[0062] The following will be based on Figure 1 The described scene, through Figures 2-7 The method for linking configuration information and firewall policies in the disclosed embodiments is described in detail.
[0063] Figure 2 A flowchart illustrating a method for linking configuration information and firewall policies according to an embodiment of this disclosure is shown.
[0064] like Figure 2 As shown, the method 200 includes operations S210 to S240.
[0065] Operation S210 acquires source data corresponding to various applications under different environments.
[0066] According to embodiments of this disclosure, different environments may include development environments, testing environments, and production environments. Source data may include configuration information for each application in different environments, firewall policies, the correspondence between applications and servers, groups, and nodes, and network traffic information between different applications.
[0067] According to embodiments of this disclosure, configuration information may include configuration information for an application providing services externally as a service provider, as well as configuration information required for the application system's own services. The configuration information may include multiple configuration items and corresponding configuration values. Firewall policies may include the source address, destination address, destination port, service type, protocol, allow / deny, and effective time range for opening the firewall. The source address may represent the service address of the application acting as the access party, and the destination address may represent the service address of the application acting as the service provider. Network traffic information can be used to determine whether access relationships exist between different applications.
[0068] According to embodiments of this disclosure, each application may contain multiple groups, each group may contain multiple nodes, and each node may contain multiple servers, i.e., there is a hierarchical relationship between applications, groups, nodes, and servers.
[0069] When operating S220, a knowledge graph is constructed based on the source data, linking the configuration information of each application with the firewall policies.
[0070] According to embodiments of this disclosure, a knowledge graph capable of associating configuration information and firewall policies of various applications can be constructed based on the acquired source data and utilizing an architecture corresponding to the knowledge graph. A graph database can be used to store and manage the knowledge graph that associates configuration information and firewall policies across multiple environments.
[0071] When operating S230, if the target application is accessing other applications, the system retrieves configuration information and firewall policies corresponding to other applications under different environments from the knowledge graph, so as to configure and deploy the target application and enable the firewall.
[0072] According to embodiments of this disclosure, when a target application accesses other applications as an access party, the configuration information and firewall policies of the accessed other applications in the corresponding environment can be obtained from the knowledge graph, and the configuration information and firewall policies in other environments can also be obtained synchronously. The other applications accessed by the target application are selected and determined by the application's architect.
[0073] For example, if the application manager in the development environment selects application A as another application that needs to be connected to the target application, they can obtain the service address, configuration items and configuration values of application A in the development environment through a knowledge graph. The application managers in the test environment and production environment can also obtain the service address, configuration items and configuration values of application A in multiple environments such as the test environment and production environment.
[0074] When operating S240, if the target application is providing services to the outside world as a service provider, the knowledge graph is used to modify the configuration information and firewall policies corresponding to the target application based on the change information corresponding to the target application.
[0075] According to embodiments of this disclosure, the change information may include service address changes and configuration information changes, wherein configuration changes may include configuration item changes and configuration value changes. When the target application provides services externally as a service provider, a knowledge graph is used to query all access parties connected to the target application based on the change information, enabling changes to the configuration information and firewall policies corresponding to the access parties and the target application.
[0076] According to embodiments of this disclosure, a knowledge graph linking configuration information and firewall policies of each application can be constructed based on the source data obtained under different environments corresponding to each application. Based on this, when the target application acts as an access party to other applications, configuration information and firewall policies corresponding to other applications under different environments can be directly obtained from the knowledge graph, enabling configuration deployment and firewall activation. This reduces communication costs during multi-environment operation and maintenance, and also reduces the risk of errors and omissions. When the target application acts as a service provider to provide services externally, the knowledge graph can be used to modify the configuration information and firewall policies corresponding to the target application based on change information. This achieves timely changes to the configuration information or firewall policies of all access parties corresponding to the target application, reducing the risk of environment unavailability and information security risks caused by missed configuration information changes or unenabled firewalls, and ensuring the stability of each environment.
[0077] According to embodiments of this disclosure, a knowledge graph that associates configuration information of each application with firewall policies is constructed based on source data, including: extracting source data according to the constructed architecture corresponding to the knowledge graph to obtain extracted information; and constructing the knowledge graph based on the extracted information.
[0078] According to embodiments of this disclosure, the constructed architecture corresponding to the knowledge graph may include the following tables 1 to 4. Table 1 can characterize the entity architecture corresponding to the knowledge graph, and can reflect the entity type and the entity attribute type corresponding to the entity type.
[0079] Table 1
[0080] Entity type Entity attribute type application Application Name, Application Abbreviation Application Manager Name, Environment, Email server Environment, IP address, operating system Group Group Name node Node name Service Address Environment, IP address, port, protocol Configuration items Configuration item name, environment, configuration value
[0081] According to embodiments of this disclosure, Table 2 can characterize the relational architecture corresponding to the knowledge graph, and can reflect the entity type and the relational type corresponding to the entity type.
[0082] Table 2
[0083]
[0084] According to embodiments of this disclosure, Table 3 can characterize another relational architecture corresponding to the knowledge graph, and can reflect the relation type and the relation attributes corresponding to the relation type.
[0085] Table 3
[0086] Relationship type Relationship attributes Network traffic exists Protocol, timestamp, or time range Firewall policies exist Allow / Deny, Agreement, Time Range Access relationship timestamp or time range Configuration changes Change type, change version, timestamp Service Changes Change type, change version, timestamp
[0087] According to embodiments of this disclosure, Table 4 can characterize another relational architecture corresponding to the knowledge graph, which can reflect the relationship types between different entity types.
[0088] Table 4
[0089] Entity type Relationship type Entity type server Network traffic exists Service Address server Firewall policies exist Service Address application Corresponding person in charge Application Manager Configuration items correspond Service Address IP address Access relationship Service Address
[0090] According to the embodiments of this disclosure, the obtained source data can be preprocessed to unify the format of the source data, and then the knowledge graph-related architecture in Tables 1 to 4 above can be used to extract entity, relationship, and attribute information related to configuration information and firewall policies from the source data to obtain the extracted information.
[0091] According to embodiments of this disclosure, extracted information can be integrated through knowledge fusion and knowledge reasoning to obtain a knowledge graph, ensuring the consistency of entities and relationships.
[0092] Knowledge reasoning can include logic-based reasoning and knowledge graph-based reasoning, in order to enrich the knowledge graph.
[0093] For example, Reasoning 1: Based on the fact that node Aa in application A contains a server with IP address ip_a, and node Aa contains configuration item cfg_Aa, it can be concluded that the server with IP address ip_a is configured with configuration item cfg_Aa and its corresponding configuration value; Reasoning 2: Based on the existence of network traffic or firewall policies between IP address and service address within a time range, it can be concluded that IP address and corresponding service address have an access relationship.
[0094] According to embodiments of this disclosure, source data is extracted based on the constructed architecture corresponding to the knowledge graph, enabling the extraction of information that is more relevant to configuration information and firewall policies. This reduces the use of data in the source data that is unrelated to configuration information and firewall policies, making the constructed knowledge graph more accurate and effective.
[0095] Figure 3 A schematic diagram of a knowledge graph according to an embodiment of the present disclosure is shown.
[0096] like Figure 3 As shown, knowledge graph 300 can represent a portion of the knowledge graph involving application A and application B.
[0097] According to embodiments of this disclosure, application A310 can represent an access party, and application B can represent a service provider. Application A310 may include group A311 among multiple groups, group A311 may include node A312 among multiple nodes, and node A312 may include server A313 among multiple servers.
[0098] According to embodiments of this disclosure, since applications, groups, nodes, and servers have a hierarchical relationship, when server A313 has a calling relationship with application B320, the parent node A312 of server A313, group A311, and application A310 will also have calling relationships with application B320. The service address for application B320 to provide services externally can be service address B321, and the configuration item corresponding to service address B321 is configuration item B322. Node A312 and server A313 can configure configuration item B322 for application B320.
[0099] According to embodiments of this disclosure, the edges in the knowledge graph 300 can represent the relationships between various entities.
[0100] According to embodiments of this disclosure, when a target application accesses other applications as an access party, configuration information and firewall policies corresponding to other applications under different environments are obtained from a knowledge graph to enable configuration deployment and firewall access for the target application. This includes: configuring and deploying the target application based on the configuration information corresponding to other applications; and opening the firewall between the service address corresponding to other applications and the service address corresponding to the target application based on the service address corresponding to other applications determined from the firewall policy.
[0101] According to embodiments of this disclosure, when the configuration information and service address of the accessed application are obtained, the corresponding configuration information can be correctly configured on the server corresponding to the target application, and the firewall between the target application and the accessed application can be automatically enabled based on the service address of the accessed application.
[0102] According to embodiments of this disclosure, when a target application accesses other applications as an access party, all configuration information and firewall policies corresponding to other applications in different environments can be directly obtained from the knowledge graph, enabling configuration deployment and firewall activation. This reduces communication costs during multi-environment operation and maintenance, and also reduces the risk of errors and omissions.
[0103] Figure 4 This illustration schematically depicts a graph link diagram in which a target application, as an access party, accesses other applications according to an embodiment of this disclosure.
[0104] like Figure 4 As shown, the knowledge graph 400 can represent the graph links through which a target application, as an access party, obtains multi-environment configuration information and service addresses when accessing other applications.
[0105] According to embodiments of this disclosure, application A410 can represent the target application, and application B420 can represent other accessed applications. Application A410 may include group A411 among multiple groups, group A411 may include node A412 among multiple nodes, and node A412 may include server A413 among multiple servers.
[0106] According to embodiments of this disclosure, application A410, group A411, node A412, and server A413 can all invoke application B420. The service address provided by application B420 can include service address B421_1 in the development environment, service address B422_1 in the test environment, and service address B423_1 in the production environment. The configuration item corresponding to service address B421_1 is configuration item B421_2, the configuration item corresponding to service address B422_1 is configuration item B422_2, and the configuration item corresponding to service address B423_1 is configuration item B423_2.
[0107] According to an embodiment of this disclosure, when server A413 is in a production environment, it can access the service address B423_1 in the production environment and configure the configuration item B423_2 in the production environment.
[0108] Among them, Knowledge Graph 400 can link the configuration information and firewall policies of applications and their external services in multiple environments such as development, testing, and production.
[0109] Figure 5 The flowchart illustrating the changes to configuration information and firewall policies according to embodiments of the present disclosure is shown in the illustration.
[0110] like Figure 5 As shown, the method 500 includes operations S510 to S530.
[0111] When operating S510, if the service address of the target application representing the change information changes, the first server with an access relationship to the old service address is determined from the knowledge graph based on the old service address in the change information.
[0112] According to embodiments of this disclosure, a first server that has an access relationship with the old service address within a specified time range can be determined from a knowledge graph based on the old service address in the change information. The application, node, and group to which the first server belongs can also be determined. The first server may include multiple servers, and the specified time range can be determined by the application administrator.
[0113] For example, with Figure 4 For example, the target application can be represented as application B420. If the service address B423_1 of application B420 changes in the production environment, the knowledge graph 400 can be used to determine the first server that has an access relationship with the old service address B423_1 within a specified time range, namely server A413.
[0114] When operating S520, a second server using the configuration information is determined from the knowledge graph based on the configuration information corresponding to the old service address.
[0115] According to embodiments of this disclosure, different servers have access relationships. However, because the access time interval between some servers is relatively long, exceeding a specified time range, that server may be missed. To avoid missing servers that have access relationships with the old service address, a second server using the configuration information can be determined from a knowledge graph. Furthermore, the application, node, and group to which the second server belongs can also be determined. The second server may include multiple servers.
[0116] When operating S530, based on the new service address, first server, and second server in the change information, the firewall policy corresponding to the target application is modified to obtain the modified firewall policy.
[0117] According to embodiments of this disclosure, based on the determined first server and second server, all servers that have access relationships with the old service address can be determined, thereby changing the firewall policy corresponding to the target application to obtain the changed firewall policy.
[0118] According to embodiments of this disclosure, when the service address of the target application as a service provider changes, a knowledge graph can be used to identify all servers that have access relationships with the old service address. This enables timely changes to the firewall policies of all access parties corresponding to the target application, reducing the risk of environmental unavailability and information security risks caused by firewall loopholes, and ensuring the stability of each environment.
[0119] According to embodiments of this disclosure, the method for linking the above configuration information and firewall policy further includes: opening a firewall between the new service address and the service address corresponding to the target server according to the changed firewall policy, wherein the target server may include a first server and a second server.
[0120] According to embodiments of this disclosure, the destination address in the firewall policy before the change can represent the old service address, and the destination address in the firewall policy after the change can represent the new service address. Based on this, a firewall can be opened between the new service address and the target server according to the destination address and source address in the changed firewall policy.
[0121] According to embodiments of this disclosure, when the target application acts as a service provider and the service address for providing services to the outside world changes, all access parties involved need to enable firewalls to the new service address, without requiring access parties to modify their configuration information.
[0122] According to embodiments of this disclosure, the firewall between the target server and the new service address can be opened in a timely manner based on the modified firewall policy, reducing the risk of environmental unavailability and information security risks caused by firewall lapses, and ensuring the stability of each environment.
[0123] According to embodiments of this disclosure, the method for linking configuration information and firewall policies further includes: when the configuration information of the target application represented by the change information changes, determining the target server using the old configuration information from the knowledge graph based on the old configuration information in the change information; and changing the configuration information used by the target server based on the new configuration information in the change information.
[0124] According to embodiments of this disclosure, the target server using the old configuration information can be determined from a knowledge graph based on the old configuration information in the change information. It can also determine the application, node, and group to which the target server belongs. The target server may include multiple servers; the old configuration information may include old configuration items and old configuration values.
[0125] For example, with Figure 4 For example, the target application can be represented as application B420. If the configuration item B423_1 of application B420 changes in the production environment, the target server that has an access relationship with the old configuration item B423_1 can be identified through the knowledge graph 400, namely server A413.
[0126] According to embodiments of this disclosure, the target server can represent the access party involved. Configuration items or values used by the target server can be modified based on new configuration information. The new configuration information may include new configuration items and new configuration values.
[0127] According to the embodiments of this disclosure, when the configuration information of the target application as a service provider providing services to the outside world changes, a knowledge graph can be used to identify all servers using the old configuration information, thereby enabling timely changes to the configuration information of all access parties corresponding to the target application and reducing the risk of environmental unavailability caused by missed configuration changes.
[0128] According to embodiments of this disclosure, the method for linking configuration information and firewall policies further includes: adding the new service address or new configuration information in the change information as a new node to the knowledge graph to obtain a first knowledge graph; and adjusting the edges in the first knowledge graph according to the target application and the target server to obtain a second knowledge graph.
[0129] According to embodiments of this disclosure, when the configuration information or service address of the target application changes, the change information needs to be recorded in the knowledge graph.
[0130] According to embodiments of this disclosure, the new service address or new configuration information in the change information can be added as a new node to the knowledge graph, and the edges between the target application, the target server, and the new and old nodes can be adjusted to obtain a second knowledge graph. The old node can represent the old service address or old configuration information.
[0131] According to embodiments of this disclosure, the knowledge graph can be updated in real time based on change information to maintain the accuracy and timeliness of data and information in the knowledge graph, so that the corresponding configuration information and service address can be obtained based on the latest knowledge graph.
[0132] Figure 6 This illustration schematically shows a knowledge graph after changes to the service address and configuration information of a target application according to an embodiment of this disclosure.
[0133] like Figure 6 As shown, knowledge graph 600 can represent a portion of the knowledge graph after changes to the service address and configuration information of the target application. The target application can be represented by application B610.
[0134] According to embodiments of this disclosure, before the service address and configuration information of application B610 are changed, the service address corresponding to application B610 is service address B1611, and the configuration item is configuration item B1612. After the service address and configuration information of application B610 are changed, service address B2613 and configuration item B2612 can be used as new nodes in the knowledge graph, and the edges between the nodes representing application B610, service address B1611, configuration item B1612, service address B2613, and configuration item B2612 in the knowledge graph can be adjusted to obtain knowledge graph 600.
[0135] According to embodiments of this disclosure, the method for linking configuration information and firewall policies further includes: taking the old service address or old configuration information offline and deleting the nodes and edges related to the old service address or old configuration information in the second knowledge graph when the old service address or old configuration information has not been accessed within a preset time range.
[0136] According to embodiments of this disclosure, if the old service address or old configuration information is not accessed within a preset time range, the old service address or old configuration information can be taken offline, and the nodes and edges related to the old service address or old configuration information in the second knowledge graph can be deleted. The preset time range can be determined by the application administrator.
[0137] For example, with Figure 6 Taking the knowledge graph 600 in the middle as an example, if the old service address 611 is not accessed within a preset time range, the nodes of the old service address 611 and the edges between the old service address 611 and application B610 and configuration item 612 can be deleted.
[0138] According to embodiments of this disclosure, if the old service address or old configuration information is not accessed within a preset time range, the old service address or old configuration information will be taken offline in a timely manner to avoid affecting services due to the access party using the old configuration information and opening a firewall between the access party and the old service address.
[0139] Figure 7 The illustration shows a system diagram of a method for implementing the linkage between configuration information and firewall policies according to an embodiment of the present disclosure.
[0140] like Figure 7 As shown, the system 700 used to implement the method of linking configuration information and firewall policies may include a configuration management module 710, a network management module 720, a network map management module 730, and an information push module 740.
[0141] According to embodiments of this disclosure, the system 700 may further include a permission management module. The permission management module can be used to manage user roles, i.e., permissions, that is, to determine user management rights based on the user's role and user type.
[0142] User roles and user types can represent operations and maintenance personnel or application managers in different environments.
[0143] According to embodiments of this disclosure, operations and maintenance personnel in different environments only have the authority to maintain and manage configuration information and firewall policies in the corresponding environment.
[0144] For example, operations and maintenance personnel in the development environment have the authority to maintain and modify the configuration information and firewall policies in the development environment, but they do not have the authority to maintain and manage the configuration information and firewall policies in testing, production, and other environments.
[0145] According to embodiments of this disclosure, the application manager in the development, testing, and production environments of each application system can maintain and modify the configuration information and firewall policies for the external services provided by the application under their responsibility. The application manager in the development, testing, and production environments of each application system can also obtain the configuration information and firewall policies of other applications accessed by their application in the corresponding environment, in order to configure the configuration information and firewall policies of the accessed application and enable the firewall between the service provider and the access party, allowing network access between the service provider and the access party.
[0146] According to embodiments of this disclosure, the configuration management module 710 enables application administrators to perform configuration management on an operable display interface, such as adding, modifying, and querying configurations.
[0147] According to embodiments of this disclosure, application administrators can configure and maintain configuration information and firewall policies for the services provided by the application through the configuration management module 710. The configuration management module 710 can also configure and maintain configuration information required for the application's own services, allowing for unified configuration by node group and setting special configuration items for service addresses corresponding to specific nodes within a node group. Furthermore, the configuration management module 710 can configure the mapping relationship between service addresses and their corresponding applications, groups, and nodes in various environments.
[0148] Among them, node groups can represent groups; the configuration information required by the application's own services can be used directly when installing the application in each environment version.
[0149] According to embodiments of this disclosure, the network management module 720 can be used to configure the mapping relationship between service addresses and configuration information, and can also be used to collect network traffic information or firewall policies between terminals and network devices. The configuration items in the configuration information may include domain names. The network management module 720 can also be used to automatically add and implement firewall policies based on firewall change information received from the information push module 740. The firewall change information can represent the changed firewall policy, and may include the service address of the target server and the new service address of the target application.
[0150] According to embodiments of this disclosure, the graph management module 730 can perform the aforementioned operations S210 and S220. The graph management module 730 can obtain the following data from the configuration management module 710: configuration information for applications providing external services and firewall access addresses; configuration information required for the application system's own services; and the correspondence between configuration server IP addresses and their corresponding applications, groups, and nodes. The graph management module 730 can also obtain the following data from the network management module 720: network traffic information between terminals; the mapping relationship between network domain names and IP addresses; and firewall policy information.
[0151] According to embodiments of this disclosure, the knowledge graph management module 730 can also add and modify entities and relationships in the knowledge graph based on change information from the configuration management module 710 and the network management module 720. This means updating changes in configuration information and service addresses to the knowledge graph in real time, and updating network traffic and firewall access relationships based on preset knowledge fusion and reasoning. It also periodically maintains and updates expired network policies to ensure the accuracy of data and information in the knowledge graph. These network policies may include service addresses and configuration information.
[0152] In the configuration management module 710, the application administrator can modify the service address, configuration items, and configuration values for providing services to the outside world.
[0153] According to embodiments of this disclosure, when an application acts as a service provider and the service address or configuration information for providing services to the outside world changes, the information push module 740 can be used to push the information output from the knowledge graph stored in the knowledge graph management module 730 to the application manager of the corresponding environment. This allows the application manager to promptly understand the changes in configuration information or firewall policies and to verify the new service address and new configuration information, i.e., verification in network and business scenarios.
[0154] According to embodiments of this disclosure, when an application acts as an access party, it can utilize the configuration information and firewall policies corresponding to other applications in the corresponding environment, output from the knowledge graph stored in the knowledge graph management module 730. The information push module 740 can push the output information to the application manager of the corresponding environment, enabling the application manager to quickly understand the scope of the changed configuration items, including groups, nodes, and server ranges, thereby accurately and quickly modifying the configuration information. If the configuration information changes simultaneously and the accessing application also needs to be modified, the access party can also quickly locate the scope of the modified nodes. According to embodiments of this disclosure, the information push module 740 can also send the service address information output from the knowledge graph management module 730 to the network management module 720 so that the network management module 720 can automatically enable the firewall. The service address information may include the source address and the destination address.
[0155] Based on the above-described method for linking configuration information and firewall policies, this disclosure also provides an apparatus for linking configuration information and firewall policies. The following will be combined with... Figure 8 The device is described in detail.
[0156] Figure 8 The diagram illustrates a structural block diagram of an apparatus for linking configuration information and firewall policies according to an embodiment of the present disclosure.
[0157] like Figure 8 As shown, the device 800 for linking configuration information and firewall policies in this embodiment includes a first acquisition module 810, a construction module 820, a second acquisition module 830, and a modification module 840.
[0158] The first acquisition module 810 is used to acquire source data corresponding to each application under different environments. In one embodiment, the first acquisition module 810 can be used to perform the operation S210 described above, which will not be repeated here.
[0159] The construction module 820 is used to construct a knowledge graph that associates the configuration information of each application with firewall policies based on the source data. In one embodiment, the construction module 820 can be used to perform the operation S220 described above, which will not be repeated here.
[0160] The second acquisition module 830 is used to obtain configuration information and firewall policies corresponding to other applications under different environments from the knowledge graph when the target application accesses other applications as an access party, so as to realize the configuration deployment of the target application and the opening of the firewall. In one embodiment, the second acquisition module 830 can be used to perform the operation S230 described above, which will not be repeated here.
[0161] The change module 840 is used to modify the configuration information and firewall policies corresponding to the target application when the target application is providing services externally as a service provider, by utilizing a knowledge graph and based on the change information corresponding to the target application. In one embodiment, the change module 840 can be used to perform the operation S240 described above, which will not be repeated here.
[0162] According to embodiments of this disclosure, the second acquisition module 830 includes a deployment unit and a first activation unit.
[0163] The deployment unit is used to configure and deploy on the target application based on the configuration information corresponding to other applications.
[0164] The first enabling unit is used to enable the firewall between the service address corresponding to the other application and the service address corresponding to the target application, based on the service address corresponding to the other application determined from the firewall policy.
[0165] According to embodiments of this disclosure, the change module 840 includes a first determining unit, a second determining unit, and a first change unit.
[0166] The first determining unit is used to determine, in the case that the service address of the target application represented by the change information has changed, the first server with an access relationship with the old service address from the knowledge graph based on the old service address in the change information.
[0167] The second determining unit is used to determine the second server that uses the configuration information from the knowledge graph based on the configuration information corresponding to the old service address.
[0168] The first modification unit is used to modify the firewall policy corresponding to the target application based on the new service address, the first server, and the second server in the modification information, so as to obtain the modified firewall policy.
[0169] According to embodiments of this disclosure, the modification module 840 further includes a second activation unit.
[0170] The second activation unit is used to activate the firewall between the new service address and the service address corresponding to the target server according to the changed firewall policy. The target server includes the first server and the second server.
[0171] According to embodiments of this disclosure, the modification module 840 further includes a third determining unit and a second modification unit.
[0172] The third determining unit is used to determine the target server that uses the old configuration information from the knowledge graph when the configuration information of the target application representing the change information has changed.
[0173] The second modification unit is used to modify the configuration information used by the target server based on the new configuration information in the modification information.
[0174] According to embodiments of this disclosure, the modification module 840 further includes an adding unit and an adjusting unit.
[0175] The addition unit is used to add the new service address or new configuration information from the change information as a new node to the knowledge graph, thus obtaining the first knowledge graph.
[0176] The adjustment unit is used to adjust the edges in the first knowledge graph according to the target application and the target server to obtain the second knowledge graph.
[0177] According to embodiments of this disclosure, the change module 840 further includes a decommissioning unit.
[0178] The offline unit is used to take the old service address or old configuration information offline when there is no access to the old service address or old configuration information within a preset time range, and to delete the nodes and edges related to the old service address or old configuration information in the second knowledge graph.
[0179] According to embodiments of this disclosure, the construction module 820 includes an extraction unit and a construction unit.
[0180] The extraction unit is used to extract source data based on the constructed architecture corresponding to the knowledge graph, and obtain the extracted information.
[0181] The building unit is used to construct the knowledge graph based on the extracted information.
[0182] According to embodiments of this disclosure, any plurality of modules among the first acquisition module 810, construction module 820, second acquisition module 830, and modification module 840 may be combined into one module, or any one of these modules may be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules may be combined with at least part of the functionality of other modules and implemented in one module. According to embodiments of this disclosure, at least one of the first acquisition module 810, construction module 820, second acquisition module 830, and modification module 840 may be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or implemented in hardware or firmware by any other reasonable means of integrating or packaging the circuitry, or implemented in any one of software, hardware, and firmware methods, or in a suitable combination of any of these methods. Alternatively, at least one of the first acquisition module 810, the construction module 820, the second acquisition module 830, and the change module 840 may be implemented at least partially as a computer program module, which can perform corresponding functions when the computer program module is run.
[0183] Figure 9 A block diagram schematically illustrates an electronic device suitable for implementing a method of linking configuration information and firewall policies according to an embodiment of the present disclosure.
[0184] like Figure 9 As shown, an electronic device 900 according to an embodiment of the present disclosure includes a processor 901, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 902 or a program loaded from a storage portion 908 into a random access memory (RAM) 903. The processor 901 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 901 may also include onboard memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0185] RAM 903 stores various programs and data required for the operation of electronic device 900. Processor 901, ROM 902, and RAM 903 are interconnected via bus 904. Processor 901 performs various operations of the method flow according to embodiments of the present disclosure by executing programs in ROM 902 and / or RAM 903. It should be noted that the programs may also be stored in one or more memories other than ROM 902 and RAM 903. Processor 901 may also perform various operations of the method flow according to embodiments of the present disclosure by executing programs stored in said one or more memories.
[0186] According to embodiments of this disclosure, the electronic device 900 may further include an input / output (I / O) interface 905, which is also connected to a bus 904. The electronic device 900 may also include one or more of the following components connected to the input / output (I / O) interface 905: an input section 906 including a keyboard, mouse, etc.; an output section 907 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 908 including a hard disk, etc.; and a communication section 909 including a network interface card such as a LAN card, modem, etc. The communication section 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the input / output (I / O) interface 905 as needed. A removable medium 911, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 910 as needed so that computer programs read from it can be installed into the storage section 908 as needed.
[0187] This disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs that, when executed, implement the method according to the embodiments of this disclosure.
[0188] According to embodiments of this disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, such as including, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this disclosure, the computer-readable storage medium may include ROM 902 and / or RAM 903 and / or one or more memories other than ROM 902 and RAM 903 described above.
[0189] Embodiments of this disclosure also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code is used to cause the computer system to implement the methods provided in the embodiments of this disclosure.
[0190] When the computer program is executed by the processor 901, it performs the functions defined in the system / apparatus of this disclosure embodiments. According to embodiments of this disclosure, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0191] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and downloaded and installed via the communication section 909, and / or installed from a removable medium 911. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.
[0192] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 909, and / or installed from the removable medium 911. When the computer program is executed by the processor 901, it performs the functions defined in the system of this disclosure embodiment. According to embodiments of this disclosure, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0193] According to embodiments of this disclosure, program code for executing the computer programs provided in embodiments of this disclosure can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C", or similar programming languages. The program code can execute entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0194] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0195] Those skilled in the art will understand that the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways, even if such combinations or combinations are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.
[0196] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. The scope of this disclosure is defined by the appended claims and their equivalents. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.
Claims
1. A method for linking configuration information and firewall policies, comprising: Obtain source data corresponding to various applications under different environments; Based on the source data, a knowledge graph is constructed that associates the configuration information and firewall policies of each application. When the target application accesses other applications as an access party, the configuration information and firewall policies corresponding to the other applications in different environments are obtained from the knowledge graph to realize the configuration deployment and firewall access of the target application. as well as When the target application provides services to the outside world as a service provider, the knowledge graph is used to modify the configuration information and firewall policies corresponding to the target application based on the change information corresponding to the target application.
2. The method according to claim 1, wherein, When the target application accesses other applications as an access party, the method of obtaining configuration information and firewall policies corresponding to the other applications under different environments from the knowledge graph to achieve configuration deployment and firewall access for the target application includes: Based on the configuration information corresponding to the other applications, configure and deploy the application on the target application; and Based on the service address corresponding to the other application determined from the firewall policy, the firewall between the service address corresponding to the other application and the service address corresponding to the target application is opened.
3. The method according to claim 1, wherein, When the target application provides services externally as a service provider, the knowledge graph is used to modify the configuration information and firewall policies corresponding to the target application based on the change information corresponding to the target application, including: When the change information indicates that the service address of the target application has changed, the first server with an access relationship to the old service address is determined from the knowledge graph based on the old service address in the change information. Based on the configuration information corresponding to the old service address, a second server using the configuration information is determined from the knowledge graph; and Based on the new service address, the first server, and the second server in the change information, the firewall policy corresponding to the target application is modified to obtain the modified firewall policy.
4. The method according to claim 3, further comprising: According to the modified firewall policy, the firewall between the new service address and the service address corresponding to the target server is opened, wherein the target server includes the first server and the second server.
5. The method according to claim 4, further comprising: When the change information represents a change in the configuration information of the target application, the target server using the old configuration information is determined from the knowledge graph based on the old configuration information in the change information. as well as Based on the new configuration information in the change information, the configuration information used by the target server is changed.
6. The method according to claim 5, further comprising: The new service address or the new configuration information in the change information is added as a new node to the knowledge graph to obtain the first knowledge graph; Based on the target application and the target server, the edges in the first knowledge graph are adjusted to obtain the second knowledge graph.
7. The method according to claim 6, further comprising: If the old service address or the old configuration information is not accessed within a preset time range, the old service address or the old configuration information will be taken offline, and the nodes and edges related to the old service address or the old configuration information in the second knowledge graph will be deleted.
8. The method according to claim 1, wherein, The step of constructing a knowledge graph that associates the configuration information and firewall policies of each application based on the source data includes: Based on the constructed architecture corresponding to the knowledge graph, the source data is extracted to obtain extracted information; and The knowledge graph is constructed based on the extracted information.
9. An apparatus for linking configuration information and firewall policies, comprising: The first acquisition module is used to acquire source data corresponding to each application under different environments; The construction module is used to construct a knowledge graph that associates the configuration information and firewall policies of each application based on the source data; The second acquisition module is used to acquire configuration information and firewall policies corresponding to other applications under different environments from the knowledge graph when the target application accesses other applications as an access party, so as to realize the configuration deployment and firewall access of the target application. as well as The modification module is used to modify the configuration information and firewall policies corresponding to the target application by utilizing the knowledge graph and based on the modification information corresponding to the target application when the target application provides services to the outside world as a service provider.
10. An electronic device, comprising: One or more processors; Storage device for storing one or more programs. Wherein, when the one or more programs are executed by the one or more processors, the one or more processors perform the method according to any one of claims 1 to 8.
11. A computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Container visit firewall intelligent linkage method and device, equipment and medium
CN113315754A
Firewall policy configuration method and device and electronic equipment
CN113422778A