Method, device and computer readable storage medium for adjusting network configuration policy
By identifying and adjusting network configuration policies that are used infrequently in power monitoring systems, the problem of ineffective verification and adjustment in existing technologies is solved, thereby improving the security and performance of network devices.
Patent Information
- Application Number
- CN202411425343.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-12
- Publication Date
- 2025-12-26
- Estimated Expiration
- 2044-10-12
AI Technical Summary
Existing technologies cannot effectively verify and adjust network devices in power monitoring systems, especially neglecting vertical encryption devices, which leads to security vulnerabilities in network configuration strategies.
By acquiring the configuration policy set of network devices in the power monitoring system, target policies with usage frequency below a threshold are identified, and abnormal policies are identified and adjusted using policy verification rules to optimize network performance.
It enables rapid verification and adjustment of network configuration policies in power monitoring systems, improving network security and performance while reducing potential security risks.
Smart Images

Figure CN119316205B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, in particular to a network configuration policy adjustment method and device and a computer readable storage medium. BACKGROUND
[0002] At present, when the network equipment in the power monitoring system is audited, the general firewall equipment and switch equipment are mainly targeted, and the log data in the firewall equipment and switch equipment are monitored and analyzed to determine the effective policy and the invalid policy. Due to the huge amount of log data, a large amount of computing resources are required, the data processing efficiency is low, and this method mainly targets the firewall device and switch equipment in the network, ignores the vertical encryption device in the power monitoring system, and has the technical problem that the network configuration policy of the network equipment in the power monitoring system cannot be effectively checked and adjusted comprehensively.
[0003] In view of the above technical problem that the network configuration policy of the network equipment in the power monitoring system cannot be effectively checked and adjusted comprehensively, no effective solution has been proposed at present. SUMMARY
[0004] The embodiments of the present application provide a network configuration policy adjustment method, device and computer readable storage medium to at least solve the technical problem that the network configuration policy of the network equipment in the power monitoring system cannot be effectively checked and adjusted comprehensively.
[0005] According to an aspect of the embodiments of the present application, a network configuration policy adjustment method is provided, which is applied to a power monitoring system. The method can include: obtaining a network configuration policy set of network equipment in the power monitoring system, wherein the network configuration policy in the network configuration policy set is used to represent the rule for safely transmitting data in the network equipment in the power monitoring system; extracting a target network configuration policy from the network configuration policy set, wherein the target network configuration policy is used to indicate the network configuration policy in the network configuration policy set whose frequency is lower than a frequency threshold; identifying an abnormal network configuration policy in the target network configuration policy based on a policy checking rule, wherein the policy checking rule is used to indicate the rule for checking the network configuration policy, and the abnormal network configuration policy is used to at least indicate the network configuration policy with security vulnerabilities; and adjusting the abnormal configuration information of the abnormal network configuration policy based on the policy checking rule.
[0006] Optionally, the target network configuration policy is extracted from the set of network configuration policies, including: obtaining network traffic data in the power monitoring system; extracting policy configuration information associated with the network configuration policy from the network traffic data; determining all network configuration policies associated with the network traffic data based on the policy configuration information; determining the number of uses of each network configuration policy within a preset time period based on the network traffic data; and extracting the target network configuration policy from all network configuration policies based on the number of uses.
[0007] Optionally, the target network configuration policy is extracted from all network configuration policies based on the number of uses, including: extracting network configuration policies with a number of uses less than a threshold number of uses from all network configuration policies; and determining the extracted network configuration policies as the target network configuration policy.
[0008] Optionally, the abnormal network configuration policy in the target network configuration policy is identified based on the policy verification rule, including: determining a matching degree between a configuration rule of each network configuration policy in the target network configuration policy and the policy verification rule based on the policy verification rule; and determining a network configuration policy with a matching degree less than a threshold matching degree as an abnormal network configuration policy.
[0009] Optionally, the adjustment method of the network configuration policy further includes: comparing the abnormal network configuration policy and a normal network configuration policy in the same business environment to obtain a policy comparison result, wherein the normal network configuration policy is used to indicate a network configuration policy with a frequency of use higher than a frequency threshold, and the policy comparison result is used to indicate a configuration difference between the abnormal network configuration policy and the normal network configuration policy; and adjusting the abnormal configuration information of the abnormal network configuration policy based on the policy comparison result.
[0010] Optionally, the policy verification rule includes at least one of the following: address information, port information, protocol information, access mode information, and traffic information, the address information includes at least a source address and a destination address with a frequency of use greater than a first frequency threshold, the port information includes at least a network port with a frequency of use greater than a second frequency threshold, the access mode information includes at least access time distribution information of the network configuration policy, and the traffic information includes at least a traffic range of the network configuration policy, wherein the first frequency threshold and the second frequency threshold are the same or different.
[0011] Optionally, the abnormal configuration information of the abnormal network configuration policy is adjusted based on the policy verification rule, including: generating policy adjustment information of the abnormal network configuration policy based on the policy verification rule, wherein the policy adjustment information is used to adjust the abnormal configuration information in the abnormal network configuration policy; and adjusting the abnormal configuration information of the abnormal network configuration policy based on the policy adjustment information.
[0012] Optionally, the network device comprises at least one of the following: a longitudinal encryption device, a firewall device and a switch device.
[0013] According to another aspect of the embodiments of the present application, there is also provided an adjusting device of network configuration policy, applied in a power monitoring system. The device can comprise: an obtaining unit, configured to obtain a set of network configuration policies of a network device in the power monitoring system, wherein a network configuration policy in the set of network configuration policies is used to represent a rule for securely transmitting data in the power monitoring system in the network device; an extracting unit, configured to extract a target network configuration policy from the set of network configuration policies, wherein the target network configuration policy is used to indicate a network configuration policy in the set of network configuration policies whose frequency of use is lower than a frequency threshold; an identifying unit, configured to identify an abnormal network configuration policy in the target network configuration policy based on a policy checking rule, wherein the policy checking rule is used to indicate a rule for checking the network configuration policy, and the abnormal network configuration policy is used to indicate at least a network configuration policy having a security vulnerability; and an adjusting unit, configured to adjust abnormal configuration information of the abnormal network configuration policy based on the policy checking rule.
[0014] According to another aspect of the embodiments of the present application, there is also provided a computer readable storage medium, comprising a stored program, wherein the program, when executed by a processor, controls a device where the storage medium is located to perform the adjusting method of network configuration policy in the embodiments of the present application.
[0015] According to another aspect of the embodiments of the present application, there is also provided a processor. The processor is used to execute a program, wherein the program, when executed, performs the adjusting method of network configuration policy in the embodiments of the present application.
[0016] According to another aspect of the embodiments of the present application, there is also provided a computer program product. The program product comprises computer instructions, which, when executed by a processor, implement the adjusting method of network configuration policy in the embodiments of the present application.
[0017] In the embodiment of the present application, a network configuration policy set of a network device in a power monitoring system is acquired, wherein the network configuration policy in the network configuration policy set is used to represent a rule for securely transmitting data in the power monitoring system in the network device; a target network configuration policy is extracted from the network configuration policy set, wherein the target network configuration policy is used to indicate a network configuration policy in the network configuration policy set with a frequency lower than a frequency threshold; an abnormal network configuration policy in the target network configuration policy is identified based on a policy checking rule, wherein the policy checking rule is used to indicate a rule for checking the network configuration policy, and the abnormal network configuration policy is used to at least indicate a network configuration policy with a security vulnerability; and the abnormal configuration information of the abnormal network configuration policy is adjusted based on the policy checking rule. That is, in the embodiment of the present application, since the network configuration policy with a lower frequency in the power monitoring system has a higher possibility of being abnormal, based on this, the network configuration policy with a lower frequency in the network configuration policy of all network devices in the power monitoring system is checked based on the policy checking rule, the abnormal network configuration policy can be quickly determined, and the abnormal configuration information in the abnormal network configuration policy is adjusted, so as to achieve the purpose of optimizing the network performance in the power monitoring system, and further achieve the technical effect of effectively checking and adjusting the network configuration policy in the power monitoring system, thereby solving the technical problem that the network configuration policy in the power monitoring system cannot be effectively checked and adjusted. BRIEF DESCRIPTION OF DRAWINGS
[0018] The accompanying drawings, which are included to provide a further understanding of the present application and are incorporated in and constitute a part of this application, illustrate embodiments of the present application and serve to explain the principles of the present application, and are not intended to limit the present application. In the drawings:
[0019] Figure 1 FIG. 1 is a flowchart of a network configuration policy adjustment method according to an embodiment of the present application;
[0020] Figure 2 FIG. 2 is a schematic diagram of a network configuration policy adjustment device according to an embodiment of the present application. DETAILED DESCRIPTION
[0021] In order for those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings of the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should be within the scope of protection of the present application.
[0022] It is to be understood that the terms "first", "second", and the like used in the description and the claims of the present application and the above-described accompanying drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, functional component or device including a series of steps or units does not have to be limited to only those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, functional components or devices.
[0023] Embodiment 1
[0024] According to an embodiment of the present application, an embodiment of a network configuration policy adjustment method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that shown herein.
[0025] Figure 1 is a flowchart of a network configuration policy adjustment method according to an embodiment of the present application, as Figure 1 shown, the method can include the following steps:
[0026] Step S101, obtaining a set of network configuration policies of network devices in a power monitoring system.
[0027] In the technical solution provided in the above step S101 of the present application, the network devices can at least include longitudinal encryption devices, firewall devices and switch devices in the power monitoring system; the set of network configuration policies can at least include: network configuration policies in the longitudinal encryption devices, network configuration policies in the firewall devices, network configuration policies in the switch devices, wherein the network configuration policies are used to represent rules for secure transmission of data in the network devices in the power monitoring system, and the network configuration policies can be: routing information, tunnel information, policy information, etc., which are only exemplary and do not limit the specific content of the network configuration policies.
[0028] In this embodiment, the management interface of the network devices in the power monitoring system can be accessed using a command line interface, and then the network configuration policy information of the network devices can be obtained through a command line tool. For example, the network configuration policies in the longitudinal encryption devices, firewall devices and switch devices in the power monitoring system are collected through the command line tool, and then the collected network configuration policies are summarized to obtain the set of network configuration policies of the network devices in the power monitoring system.
[0029] Step S102, extracting a target network configuration policy from the network configuration policy set.
[0030] In the technical solution provided by step S102 of the present application, the target network configuration policy is used to indicate a network configuration policy in the network configuration policy set whose frequency of use is lower than a frequency threshold.
[0031] In this embodiment, the target network configuration policy can be extracted according to the frequency of use of the network configuration policies included in the network configuration policy set.
[0032] For example, the network configuration policies in the network configuration policy set are first divided into different types, and then the frequency of use of each type of network configuration policy is determined according to the traffic data in the power monitoring system, and the frequency of use of each type of network configuration policy is compared with the frequency threshold to obtain a comparison result.
[0033] Optionally, according to the comparison result, the network configuration policy whose frequency of use is greater than the frequency threshold and the network configuration policy whose frequency of use is lower than the frequency threshold are determined. The network configuration policy whose frequency of use is greater than the frequency threshold can be referred to as a majority policy, and the network configuration policy whose frequency of use is lower than the frequency threshold can be referred to as a minority policy. The majority policy is less likely to be abnormal because it often appears in the network, while the minority policy is less likely to be used and has a low frequency of use, which may be abnormal. The frequency threshold can be set in advance, for example, it can be set to 50, which is only an example and does not limit the specific value of the frequency threshold.
[0034] Optionally, after the majority policy and the minority policy in the network configuration policy set are determined, the minority policy can be determined as the target network configuration policy and extracted from the network configuration policy set.
[0035] Optionally, by analyzing the majority policy, a set of network configuration policy configuration rules, which can also be referred to as policy verification rules, can be automatically formed. The majority policy usually includes the following contents: common address information, common ports and protocols, typical access mode, and legal traffic. The minority policy usually includes the following contents: uncommon address information, uncommon port information, abnormal access mode, and traffic beyond the normal range, which may contain potential security risks or configuration errors.
[0036] In this step, since the network configuration policy with less use in the network is more likely to be abnormal, based on this, the target network configuration policy is quickly extracted from the network configuration policy set by using the frequency of use, which helps to improve the verification efficiency of the network configuration policy.
[0037] In step S103, an abnormal network configuration policy in the target network configuration policy is identified based on a policy verification rule.
[0038] In the above technical solution provided by step S103 of the present application, the policy verification rule is used to indicate a rule for verifying the network configuration policy, and the policy verification rule can be generated in advance according to the network configuration policy frequently used in the power monitoring system network, for example, by summarizing the configuration rules of the network configuration policy frequently used in the network. The abnormal network configuration policy is used to at least indicate a network configuration policy with a security vulnerability.
[0039] In this embodiment, the policy verification rule can at least include the following contents: common source Internet Protocol (Internet Protocol, referred to as IP) address and target IP address, common port and protocol, typical access mode, and legal traffic. The common source IP address and target IP address are used to indicate the addresses of the hosts or devices that are legal and frequently communicated in the network. The common port and protocol can include Hypertext Transfer Protocol (Hypertext Transfer Protocol, referred to as HTTP) and the corresponding port, Hypertext Transfer Protocol Secure port (Hypertext Transfer Protocol Secure port, referred to as HTTPS) and the corresponding port, and Secure Hypertext Transfer Protocol (Secure Hypertext Transfer Protocol, referred to as SSH) and the corresponding port. Here, only exemplary examples are given. The typical access mode is used to indicate that the access amount of the network configuration policy is high during the working time period and is low during the non-working time period. The legal traffic is used to indicate the communication range in the normal case determined by traffic analysis. The policy verification rule can be based on the analysis of the network configuration policy frequently used in the network, and then a standard is formed to help identify whether the network configuration policy meets the policy verification rule. If it meets, it is confirmed as a normal network configuration policy. If it does not meet, it is confirmed as an abnormal network configuration policy.
[0040] For example, each network configuration policy in the target network configuration policy is verified by the policy verification rule, and the network configuration policy in the target network configuration policy that does not meet the policy verification rule is extracted to determine the abnormal network configuration policy, wherein the abnormal network configuration policy includes abnormal configuration information.
[0041] In this step, the abnormal network configuration policy can be identified from the target network configuration policy by the policy verification rule to locate the potential security risks existing in the network.
[0042] Step S104, adjusting the abnormal configuration information of the abnormal network configuration policy based on the policy verification rule.
[0043] In the technical solution provided in step S104 of the present application, the abnormal configuration information is used to indicate the configuration information in the abnormal network configuration policy that does not meet the policy verification rule.
[0044] In this embodiment, after determining the abnormal configuration information in the abnormal network configuration policy, the abnormal configuration information can be adjusted according to the policy verification rule to adjust it to normal configuration information that meets the policy verification rule.
[0045] In the above steps S101 to S104, since the network configuration policy with low frequency of use in the power monitoring system is more likely to be abnormal, based on this, by using the policy verification rule, the network configuration policy with low frequency of use in the network configuration policy of all network devices in the power monitoring system is verified, which can quickly determine the abnormal network configuration policy and adjust the abnormal configuration information in the abnormal network configuration policy, so as to optimize the network performance in the power monitoring system, and further realize the technical effect of effectively verifying and adjusting the network configuration policy in the power monitoring system, thereby solving the technical problem that the network configuration policy in the power monitoring system cannot be effectively verified and adjusted.
[0046] The above method of this embodiment will be further introduced below.
[0047] As an optional embodiment, step S102, extracting the target network configuration policy from the network configuration policy set, includes: obtaining network traffic data in the power monitoring system; extracting policy configuration information associated with the network configuration policy from the network traffic data; determining all network configuration policies associated with the network traffic data based on the policy configuration information; determining the number of uses of each network configuration policy in a preset time length based on the network traffic data; and extracting the target network configuration policy from all network configuration policies based on the number of uses.
[0048] In this embodiment, the network traffic data is used to monitor the real-time situation of the network, and the network traffic data can be used to indicate the packet information monitored in the network for a period of time. By analyzing the network traffic data, the network configuration policy information used in the transmission process of the network traffic data can be identified.
[0049] Optionally, after obtaining the network configuration policy information corresponding to the network traffic data, the network configuration policy associated with each piece of network traffic data can be determined, and then the use times of each network configuration policy within a preset time period are counted, and the target network configuration policy is selected from all network configuration policies according to the use times, where the preset time period can be set in advance, for example, the preset time period can be one day, one week or one month, which is only an example and does not limit the specific value of the preset time period.
[0050] For example, after obtaining the use times of each network configuration policy within the preset time period, the use times of each network configuration policy are compared with the number threshold to obtain a comparison result. According to the comparison result, the network configuration policy with a use time less than the number threshold is selected, and the selected network configuration policy is determined as the target network configuration policy.
[0051] In this step, by obtaining the network traffic data in the power monitoring system, and then according to the network configuration policy associated with the network traffic data and the use times of each network configuration policy within a preset time period, the network configuration policy with a low use frequency can be quickly determined, and the screening efficiency of the network configuration policy with a potential security risk in the power monitoring system network is improved.
[0052] As an optional embodiment, the target network configuration policy is extracted from all network configuration policies based on the use times, including: extracting the network configuration policy with a use time less than the number threshold from all network configuration policies; and determining the extracted network configuration policy as the target network configuration policy.
[0053] In this embodiment, since the use times are used to indicate the use frequency of the network configuration policy, based on this, after extracting the use times of all network traffic data from the network traffic data, the network configuration policy with a use time less than the number threshold can be extracted from all network configuration policies according to the use times of each network configuration policy, and the extracted network configuration policy is determined as the target network configuration policy, where the target network configuration policy can be used to indicate the network configuration policy with a low use frequency in the network.
[0054] For example, when the number threshold is 50, the network configuration policy with a use time less than 50 can be determined as the target network configuration policy, where this is only an example and does not limit the specific data of the number threshold.
[0055] As an optional implementation, based on the policy verification rule, the abnormal network configuration policy in the target network configuration policy is identified, including: based on the policy verification rule, determining the matching degree between the configuration rule of each network configuration policy in the target network configuration policy and the policy verification rule; determining the network configuration policy with a matching degree less than a matching threshold as an abnormal network configuration policy.
[0056] In this embodiment, since the policy verification rule is a set of predefined rules or standards for evaluating whether the network configuration policy meets the expected security and performance requirements. These rules may include checking port opening, service running status, protocol usage, network access permission, etc. Based on this, the configuration rule of each network configuration policy in the target network configuration policy can be detected by the policy verification rule to determine the matching degree between each network configuration policy and the policy verification rule. The matching degree is used to indicate the degree to which the corresponding network configuration policy meets the policy verification rule.
[0057] Optionally, after determining the matching degree between the configuration rule of each network configuration policy in the target network configuration policy and the policy verification rule, the network configuration policy with a matching degree less than a matching threshold can be determined as an abnormal network configuration policy.
[0058] In this step, by detecting the configuration rule of each network configuration policy in the target network configuration policy through the policy verification rule, the abnormal network configuration policy can be quickly determined to improve the efficiency of locating the abnormal network configuration policy in the target network configuration policy.
[0059] As an optional embodiment, the network policy configuration adjustment method further includes: comparing the abnormal network configuration policy and the normal network configuration policy in the same business environment to obtain a policy comparison result, wherein the normal network configuration policy is used to indicate a network configuration policy with a frequency higher than a frequency threshold, and the policy comparison result is used to indicate the configuration difference between the abnormal network configuration policy and the normal network configuration policy; based on the policy comparison result, adjusting the abnormal configuration information of the abnormal network configuration policy.
[0060] In this embodiment, the abnormal network configuration policy is used to indicate the network configuration that is not common or non-standard in the network environment. These configurations may be caused by errors, malicious behavior or outdated configurations, and may cause security risks or performance problems. The normal network configuration policy is used to indicate the network configuration that is considered standard and secure in the network environment. These configurations are usually verified and widely accepted as best practices.
[0061] Optionally, the abnormal configuration policy can generally exhibit the following characteristics: there is abnormal configuration information, there is a security vulnerability, there is a redundant policy, and there is a non-compliant policy. Among them, the abnormal configuration information is generally used to indicate that there is a configuration rule in the network configuration policy that is different from the normal configuration policy (common configuration policy) due to misconfiguration; the security vulnerability is generally used to indicate that there can be a situation of allowing unauthorized access or data leakage in the network configuration policy; the redundant policy is used to indicate that the network configuration policy can cause policy conflicts or affect network performance; and the non-compliant policy is generally used to indicate a policy that violates enterprise security policies or best practices.
[0062] Optionally, since the network configuration policies in the same business environment satisfy the same configuration rules, based on this, by comparing the abnormal network configuration policy and the normal network configuration policy in the same business environment, the policy comparison result obtained can be used to represent the configuration difference between the abnormal network configuration policy and the normal network configuration policy, wherein the comparison can involve checking whether the configuration of IP address, port, protocol, service, etc. of the abnormal network configuration policy conforms to the standard in the normal business environment, and the configuration difference can include ports that should not be opened, services that should not exist, incorrect routing rules, etc., which are not limited here.
[0063] Optionally, after determining the configuration difference, the abnormal configuration information in the abnormal network configuration policy can be adjusted to be closer to the normal network configuration policy. For example, unnecessary services in the abnormal network configuration policy are closed, incorrect configurations in the abnormal network configuration policy are changed, routing rules are updated, etc., which are not limited here.
[0064] In this step, the differential feature comparison technology is applied to compare the majority policy and the minority policy in the same business environment, and the adaptive adjustment of the abnormal network configuration policy is realized to optimize the network performance and security configuration.
[0065] As an optional embodiment, in step S104, the abnormal configuration information of the abnormal network configuration policy is adjusted based on the policy verification rule, including: generating policy adjustment information of the abnormal network configuration policy based on the policy verification rule, wherein the policy adjustment information is used to adjust the abnormal configuration information in the abnormal network configuration policy; and adjusting the abnormal configuration information of the abnormal network configuration policy based on the policy adjustment information.
[0066] In this embodiment, as known from the foregoing, the policy verification rule is a set of predefined rules or standards used to evaluate whether the network configuration policy meets the expected security and performance requirements. These rules can include checking port opening, service running status, protocol usage, network access permission, etc.
[0067] Optionally, after obtaining the abnormal network configuration policy, the abnormal network configuration policy can be analyzed in detail according to the policy checking rule to locate the specific reason for the abnormal network configuration policy, identify the security problem or configuration error in the abnormal configuration policy, and provide detailed rectification suggestions. For example, the ports that need to be closed, the configuration files that need to be updated, the services that need to be changed, etc. in the abnormal network configuration policy, which are not limited here.
[0068] In this step, by automatically detecting and adjusting the abnormal configuration information in the abnormal network configuration policy, human errors can be reduced, response speed can be improved, and the stability and security of the network environment can be ensured.
[0069] The technical solutions of the embodiments of the application will be illustrated below in conjunction with preferred embodiments.
[0070] At present, when auditing the network equipment in the power monitoring system, the general firewall equipment and switch equipment are mainly targeted, and the log data in the firewall equipment and switch equipment are monitored and analyzed to determine the effective policy and the invalid policy. Due to the huge amount of log data, a large amount of computing resources are required, the data processing efficiency is low, and this method mainly targets the firewall device and switch equipment in the network, ignoring the vertical encryption device in the power monitoring system, which has the technical problem that the network configuration policy of the network equipment in the power monitoring system cannot be effectively checked and adjusted comprehensively.
[0071] However, the present application provides a network configuration policy adjustment method, which obtains the network configuration policy of the network equipment in the power monitoring system, wherein the network equipment at least includes a vertical encryption device, a firewall device and a switch device, and utilizes a pre-established policy checking rule to classify and cluster the obtained network configuration policy to obtain a majority policy with a higher frequency of use and a minority policy with a lower frequency of use, and then utilizes data statistics and differential analysis to automatically extract the hidden hazard policy in the minority policy and locate the specific reason for the hidden hazard policy in detail to form a rectification suggestion to guide the operation and maintenance personnel to correct the hidden hazard policy according to the rectification suggestion to optimize the network environment and protect the network security of the power monitoring system, thereby realizing the technical effect of effectively checking and adjusting the network configuration policy in the power monitoring system, and solving the technical problem that the network configuration policy in the power monitoring system cannot be effectively checked and adjusted.
[0072] Optionally, by collecting various key information of the longitudinal encryption device, firewall device and switch device, such as routing information, tunnel information, policy information and the like, based on the collected data, analysis of various policy problems can be carried out. For example, it is originally planned to open 1024 ports, but after analyzing the collected data, it is found that 1000-1024 ports are actually opened, too many ports are opened, and there is a security risk, guiding the user to modify the policy.
[0073] Next, the constitution of classifying and clustering the network configuration policy adopted by the network device in the power monitoring system is further introduced.
[0074] In this embodiment, after obtaining the network configuration policy in the network device in the power monitoring system, the use frequency of each network configuration policy in a preset time length can be counted, and then according to the use frequency and the frequency threshold, the majority policy and the minority policy are determined, wherein the majority policy is used to indicate the policy with higher use frequency, and the minority policy is used to indicate the policy with lower use frequency.
[0075] For example, assuming that the frequency threshold is 50, the majority policy can be used to indicate the network configuration policy with a use frequency greater than 50 in the network configuration policy, and the minority policy can be used to indicate the network configuration policy with a use frequency less than 50 in the network configuration policy.
[0076] Optionally, the majority policy refers to the policy that often appears in the network and is frequently used. The minority policy refers to the policy that rarely appears in the network, has a lower use frequency or may have an abnormality. Among them, the hidden danger policy in the minority policy is used to indicate the policy with lower use frequency but may pose a threat to network security and performance found through data statistics and differential analysis in the network policy audit process. These hidden danger policies usually exhibit the following characteristics: configuration anomaly, security vulnerability, or redundant policy, or policy that does not comply with regulations. Among them, the configuration anomaly may be an unreasonable policy caused by misconfiguration, the security vulnerability may manifest as allowing unauthorized access or data leakage, the redundant policy may cause policy conflicts or performance problems, and the policy that does not comply with regulations may be a policy that violates enterprise security.
[0077] Optionally, after the hidden danger policy is determined, the hidden danger policy can be analyzed in detail, for example, by deeply analyzing the network policy and traffic data, identifying potential security problems or configuration errors, and providing detailed rectification suggestions to ensure network security and performance and reduce potential security risks.
[0078] Optionally, the network configuration policy adjustment method provided by the present application is applicable to analyzing the network configuration policy in the network security boundary device in the power monitoring system. Traditional policy audit is directed to general firewall devices and switch devices, and lacks policy audit products for longitudinal encryption devices in the power monitoring system. The present application, in view of the business characteristics and compliance control requirements of the power monitoring system, empowers data mining technology, automatically analyzes a large number of policy risks of longitudinal encryption devices, reduces the exposure of part of assets in the substation, and protects the network security of the power monitoring system.
[0079] Optionally, the traditional policy audit product determines the valid and invalid policy by log monitoring and analysis to determine the policy hit. This method is indirect, time-consuming and low in accuracy. The present application directly obtains all policy configurations in the longitudinal encryption device, firewall device and switch device, and deeply analyzes. When used by the user, the longitudinal encryption device can also be connected to the longitudinal encryption device management center, and the one-key operation check is automatically logged into the boundary device to collect, read the policy configuration and the number of hits, directly and quickly analyze the policy, quickly generate a report, and accurately evaluate the policy risk.
[0080] Optionally, the present application uses a feature engineering method to analyze the key attributes (such as source address, destination address, port, etc.) of the network policy in detail, and realizes accurate classification of the policy through a clustering algorithm, and constructs an efficient policy management mechanism.
[0081] Optionally, based on the standard of the majority of automatically formed policies and the abnormal assumption of the minority of policies, the present application uses the adaptive learning principle to realize automatic identification and classification of the policy through threshold analysis, and provides a new risk assessment method for network security.
[0082] Optionally, the present application applies a differentiated feature comparison technology to compare the majority of policies and the minority of policies in the same business environment, realizes adaptive adjustment of the policy configuration, and optimizes the network performance and security configuration.
[0083] According to the embodiment of the present application, a network configuration policy adjustment device is also provided. It should be noted that the network configuration policy adjustment device can be used to execute the network configuration policy adjustment method in embodiment 1.
[0084] Figure 2 is a schematic diagram of a network configuration policy adjustment device according to an embodiment of the present application. As shown in Figure 2 the network configuration policy adjustment device 200 can include an acquisition unit 201, an extraction unit 202, an identification unit 203 and an adjustment unit 204.
[0085] The acquisition unit 201 is configured to acquire a set of network configuration policies of a network device in a power monitoring system, wherein each network configuration policy in the set of network configuration policies is used to represent a rule for securely transmitting data in the power monitoring system in the network device.
[0086] The extraction unit 202 is configured to extract a target network configuration policy from the set of network configuration policies, wherein the target network configuration policy is used to indicate a network configuration policy in the set of network configuration policies with a frequency of use lower than a frequency threshold.
[0087] The identification unit 203 is configured to identify an abnormal network configuration policy in the target network configuration policy based on a policy checking rule, wherein the policy checking rule is used to indicate a rule for checking the network configuration policy, and the abnormal network configuration policy is used to indicate at least a network configuration policy with a security vulnerability.
[0088] The adjustment unit 204 is configured to adjust abnormal configuration information of the abnormal network configuration policy based on the policy checking rule.
[0089] Optionally, the extraction unit 202 is further configured to acquire network traffic data in the power monitoring system, extract policy configuration information associated with the network configuration policy from the network traffic data, determine all network configuration policies associated with the network traffic data based on the policy configuration information, determine a number of uses of each network configuration policy in a preset time length based on the network traffic data, and extract the target network configuration policy from the all network configuration policies based on the number of uses.
[0090] Optionally, the extraction unit 202 is further configured to extract a network configuration policy with a number of uses less than a number threshold from the all network configuration policies, and determine the extracted network configuration policy as the target network configuration policy.
[0091] Optionally, the identification unit 203 is further configured to determine a matching degree between a configuration rule of each network configuration policy in the target network configuration policy and the policy checking rule based on the policy checking rule, and determine a network configuration policy with a matching degree less than a matching threshold as the abnormal network configuration policy.
[0092] Optionally, the adjustment device 200 of the network configuration policy is further configured to compare the abnormal network configuration policy and a normal network configuration policy in the same service environment to obtain a policy comparison result, wherein the normal network configuration policy is used to indicate a network configuration policy with a frequency of use higher than the frequency threshold, and the policy comparison result is used to indicate a configuration difference between the abnormal network configuration policy and the normal network configuration policy; and adjust the abnormal configuration information of the abnormal network configuration policy based on the policy comparison result.
[0093] Optionally, the adjusting unit 204 is further configured to generate policy adjustment information of the abnormal network configuration policy based on the policy checking rule, wherein the policy adjustment information is used to adjust the abnormal configuration information in the abnormal network configuration policy; and adjust the abnormal configuration information in the abnormal network configuration policy based on the policy adjustment information.
[0094] In this embodiment, since the network configuration policy with low frequency of use is more likely to be abnormal in the power monitoring system, based on this, by using the policy checking rule, the network configuration policy with low frequency of use in the network configuration policy of all network devices in the power monitoring system is checked, the abnormal network configuration policy can be quickly determined, the abnormal configuration information in the abnormal network configuration policy is adjusted, the purpose of optimizing the network performance in the power monitoring system is achieved, and the technical effect of effectively checking and adjusting the network configuration policy in the power monitoring system is achieved, thereby solving the technical problem that the network configuration policy in the power monitoring system cannot be effectively checked and adjusted.
[0095] According to the embodiment of the present application, a computer readable storage medium is further provided, the storage medium comprises a stored program, wherein the program executes the network configuration policy adjustment method in the embodiment 1.
[0096] According to the embodiment of the present application, a processor is further provided, the processor is used to run a program, wherein the program runs to execute the network configuration policy adjustment method in the embodiment 1.
[0097] According to another aspect of the embodiment of the present application, a computer program product is further provided. The program product comprises computer instructions, which, when executed by a processor, implement the network configuration policy adjustment method in the embodiment 1.
[0098] The above-mentioned embodiment numbers of the present application are only for description, and do not represent the advantages and disadvantages of the embodiments.
[0099] In the above-mentioned embodiments of the present application, the description of each embodiment has its own emphasis, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments.
[0100] In the several embodiments provided in the present application, it should be understood that the disclosed technology can be implemented in other ways. Of course, the unit embodiment described above is only schematic. For example, the division of the units can be a logical function division, and there can be another division manner in actual implementation, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interface, and can be electrical or other forms.
[0101] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0102] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0103] If the integrated unit is implemented as a software functional unit and sold or used as an independent functional component, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software functional component. This computer software functional component is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0104] The above are merely preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for adjusting a network configuration strategy, characterized in that, The method is applied to a power monitoring system, and comprises the following steps: obtaining a set of network configuration policies of network devices in the power monitoring system, wherein each network configuration policy in the set of network configuration policies represents a rule for securely transmitting data in the power monitoring system in the network device; extracting a target network configuration policy from the set of network configuration policies, wherein the target network configuration policy indicates a network configuration policy in the set of network configuration policies whose frequency of use is lower than a frequency threshold; identifying an abnormal network configuration policy in the target network configuration policy based on a policy verification rule, wherein the policy verification rule indicates a rule for verifying the network configuration policy, and the abnormal network configuration policy indicates at least a network configuration policy having a security vulnerability; adjusting abnormal configuration information of the abnormal network configuration policy based on the policy verification rule. The method further comprises the following steps:
2. The method of claim 1, wherein, comparing the abnormal network configuration policy and a normal network configuration policy in the same business environment to obtain a policy comparison result, wherein the normal network configuration policy indicates a network configuration policy whose frequency of use is higher than the frequency threshold, and the policy comparison result indicates a configuration difference between the abnormal network configuration policy and the normal network configuration policy; and adjusting the abnormal configuration information of the abnormal network configuration policy based on the policy comparison result. The method further comprises the following steps: obtaining network traffic data in the power monitoring system; extracting policy configuration information associated with the network configuration policy from the network traffic data; determining all network configuration policies associated with the network traffic data based on the policy configuration information; 3. The method of claim 2, wherein, determining a number of times each network configuration policy is used within a preset time period based on the network traffic data; extracting the target network configuration policy from all network configuration policies based on the number of times. The method further comprises the following steps:
4. The method of claim 1, wherein, extracting a network configuration policy whose number of times is less than a number threshold from all network configuration policies; determining the extracted network configuration policy as the target network configuration policy. The method further comprises the following steps: obtaining network traffic data in the power monitoring system; extracting policy configuration information associated with the network configuration policy from the network traffic data; determining all network configuration policies associated with the network traffic data based on the policy configuration information; determining a number of times each network configuration policy is used within a preset time period based on the network traffic data; extracting the target network configuration policy from all network configuration policies based on the number of times. The method further comprises the following steps: extracting a network configuration policy whose number of times is less than a number threshold from all network configuration policies; determining the extracted network configuration policy as the target network configuration policy.
5. The method of claim 1, wherein, The policy verification rule includes at least one of address information, port information, protocol information, access mode information, and traffic information. The address information includes at least a source address and a destination address with a frequency greater than a first frequency threshold. The port information includes at least a network port with a frequency greater than a second frequency threshold. The access mode information includes at least access time distribution information of the network configuration policy. The traffic information includes at least a traffic range of the network configuration policy. The first frequency threshold and the second frequency threshold are the same or different.
6. The method of claim 1, wherein, The adjusting of the abnormal configuration information of the abnormal network configuration policy based on the policy verification rule includes: generating policy adjustment information of the abnormal network configuration policy based on the policy verification rule, wherein the policy adjustment information is used to adjust the abnormal configuration information in the abnormal network configuration policy; adjusting the abnormal configuration information of the abnormal network configuration policy based on the policy adjustment information.
7. The method according to any one of claims 1 to 6, characterized in that, The network device includes at least one of a longitudinal encryption device, a firewall device, and a switch device.
8. A network configuration policy adjustment device, characterized in that, The device is applied to a power monitoring system, and the device includes: an acquisition unit configured to acquire a set of network configuration policies of a network device in the power monitoring system, wherein a network configuration policy in the set of network configuration policies is used to represent a rule for securely transmitting data in the network device in the power monitoring system; an extraction unit configured to extract a target network configuration policy from the set of network configuration policies, wherein the target network configuration policy is used to indicate a network configuration policy in the set of network configuration policies with a frequency lower than a frequency threshold; an identification unit configured to identify an abnormal network configuration policy in the target network configuration policy based on a policy verification rule, wherein the policy verification rule is used to indicate a rule for verifying the network configuration policy, and the abnormal network configuration policy is used to indicate at least a network configuration policy with a security vulnerability; an adjustment unit configured to adjust abnormal configuration information of the abnormal network configuration policy based on the policy verification rule. The identification unit is configured to identify the abnormal network configuration policy in the target network configuration policy based on the policy verification rule by performing the following steps: determining a matching degree between a configuration rule of each network configuration policy in the target network configuration policy and the policy verification rule based on the policy verification rule, wherein the policy verification rule is used to evaluate whether the network configuration policy meets expected security and performance requirements; and determining the network configuration policy with a matching degree less than a matching threshold as the abnormal network configuration policy.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein the program controls a device where the storage medium is located to perform the method of any one of claims 1 to 7 when the program is run by a processor.
10. A processor, comprising: The processor is configured to run a program, wherein the program performs the method of any one of claims 1 to 7 when the program is run.
11. A computer program product comprising computer instructions, characterized in that, The computer instructions are executed by a processor to implement the method of any one of claims 1 to 7.
Citation Information
Patent Citations
Firewall policy detection method and device
CN106603471A
Message identification rule base processing method and device, and network equipment
CN115695257A