Access control policy recommendation method and device
By obtaining asset access information, determining the access control policy model and classifying and evaluating it, and generating the initial access control policy, we can solve the problem that traditional manual configuration cannot effectively manage complex network access relationships, implement automated network security policy recommendations, and improve network security efficiency and stability.
Patent Information
- Application Number
- CN202411709004.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-26
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2044-11-26
AI Technical Summary
Traditional network-layer access control strategies rely on manual configuration and are unable to effectively understand complex and changing network access relationships, resulting in the inability to effectively reduce network exposure and posing security risks.
By obtaining access information of assets, determining the access control policy model, classifying based on the access information and model, generating the initial access control policy, and evaluating and recommending based on preset indicators, recommending a whitelist-based policy model, and automatically collecting access relationships with business attributes.
It improves the efficiency of access control policy implementation, enhances network security, generates policy coverage, exposure reduction rate and business stability indicators through automated methods, and reduces reliance on manual configuration.
Smart Images

Figure CN119496663B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this specification relate to the field of network security technology, and in particular to an access control policy recommendation method. Background Art
[0002] Traditional network-layer access control policies rely on manual configuration. However, in the cloud computing era, network access relationships within data centers are complex and ever-changing. It's difficult for humans to fully understand all access relationships and accurately implement whitelist control policies. This makes it difficult to effectively reduce network exposure and creates security risks. Therefore, a better solution is urgently needed. Summary of the Invention
[0003] In view of this, embodiments of this specification provide an access control policy recommendation method. One or more embodiments of this specification also involve an access control policy recommendation apparatus, a computing device, a computer-readable storage medium, and a computer program to address technical deficiencies in the prior art.
[0004] According to a first aspect of an embodiment of this specification, a method for recommending an access control policy is provided, including:
[0005] Obtain access information for assets and determine the access control policy model;
[0006] Classify access information and access control policy models to determine business relationships;
[0007] Generate policies based on business relationships and determine initial access control policies;
[0008] An assessment is conducted based on the initial access control policy and preset indicators, the indicator assessment results are determined, and access control policy recommendations are made based on the indicator assessment results; among them, the preset indicators include policy coverage, exposure reduction rate, and business stability.
[0009] In one possible implementation, obtaining access information of an asset and determining an access control policy model include:
[0010] Determine the target time period and obtain access information of assets within the target time period;
[0011] At least two access control policy models are selected from a plurality of set access control policy models, wherein the plurality of set access control policy models include access control policies of a plurality of different levels.
[0012] In one possible implementation, classification is performed based on access information and a policy model to determine business relationships, including:
[0013] Determine classification rules based on the access control policy model;
[0014] Business relationships are determined based on the access information and classification rules, where the business relationships include role business relationships, workload business relationships, group business relationships, and address business relationships.
[0015] In one possible implementation, policy generation is performed based on business relationships to determine an initial access control policy, including:
[0016] Generate accessibility rules based on business relationships;
[0017] An initial access control policy is determined based on the accessibility rules.
[0018] In one possible implementation, an evaluation is performed based on the initial access control policy and preset indicators to determine an indicator evaluation result, including:
[0019] Perform matching based on the access information and the initial access control policy, and determine a matching result;
[0020] Determine the policy coverage based on the matching results;
[0021] Generate indicator evaluation results based on policy coverage.
[0022] In one possible implementation, an evaluation is performed based on the initial access control policy and preset indicators to determine an indicator evaluation result, including:
[0023] Determine the original exposure surface and the current exposure surface based on the initial access control policy;
[0024] determining an exposure reduction rate based on the original exposure and the current exposure;
[0025] Generate indicator evaluation results based on the exposure surface reduction rate.
[0026] In one possible implementation, an evaluation is performed based on the initial access control policy and preset indicators to determine an indicator evaluation result, including:
[0027] Determine the number of new accesses based on the initial access control policy;
[0028] Determine business stability based on the number of new visits and business relationships;
[0029] Generate indicator evaluation results based on business stability.
[0030] According to a second aspect of an embodiment of this specification, there is provided an access control policy recommendation device, comprising:
[0031] a data acquisition module configured to obtain access information of assets and determine an access control policy model;
[0032] A business classification module is configured to classify and determine business relationships based on access information and an access control policy model;
[0033] A policy determination module is configured to generate a policy based on the business relationship and determine an initial access control policy;
[0034] The policy recommendation module is configured to evaluate the initial access control policy and preset indicators, determine the indicator evaluation results, and recommend access control policies based on the indicator evaluation results; wherein the preset indicators include policy coverage, exposure reduction rate and business stability.
[0035] According to a third aspect of an embodiment of this specification, a computing device is provided, including:
[0036] memory and processor;
[0037] The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the access control policy recommendation method are implemented.
[0038] According to a fourth aspect of the embodiments of this specification, a computer-readable storage medium is provided, which stores computer-executable instructions. When the instructions are executed by a processor, the steps of the above-mentioned access control policy recommendation method are implemented.
[0039] According to a fifth aspect of the embodiments of this specification, a computer program is provided, wherein when the computer program is executed in a computer, the computer is caused to execute the steps of the above-mentioned access control policy recommendation method.
[0040] The embodiments of this specification provide an access control policy recommendation method and apparatus, wherein the access control policy recommendation method includes: obtaining access information of assets and determining an access control policy model; classifying based on the access information and the access control policy model to determine business relationships; generating policies based on business relationships to determine an initial access control policy; evaluating based on the initial access control policy and preset indicators to determine indicator evaluation results, and recommending access control policies based on the indicator evaluation results; wherein the preset indicators include policy coverage, exposure reduction rate, and business stability. By automatically collecting access relationships with business attributes, without relying on manual configuration, a whitelist-based policy model is recommended, greatly improving the efficiency of policy implementation and enhancing network security. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Figure 1 This is a flowchart of an access control policy recommendation method provided by an embodiment of this specification;
[0042] Figure 2This is a schematic diagram of an access control policy recommendation method provided by an embodiment of this specification;
[0043] Figure 3 This is a schematic diagram of the structure of an access control policy recommendation device provided by an embodiment of this specification;
[0044] Figure 4 This is a structural block diagram of a computing device provided by one embodiment of this specification. DETAILED DESCRIPTION
[0045] The following description sets forth many specific details to facilitate a thorough understanding of this specification. However, this specification can be implemented in many other ways than those described herein, and those skilled in the art can make similar generalizations without violating the scope of this specification. Therefore, this specification is not limited to the specific implementations disclosed below.
[0046] The terms used in one or more embodiments of this specification are for the purpose of describing specific embodiments only and are not intended to limit one or more embodiments of this specification. The singular forms "a," "an," and "the" used in one or more embodiments of this specification and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items.
[0047] It should be understood that although the terms first, second, etc. may be used to describe various information in one or more embodiments of this specification, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of one or more embodiments of this specification, the first may also be referred to as the second, and similarly, the second may also be referred to as the first. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".
[0048] In this specification, an access control policy recommendation method is provided. This specification also relates to an access control policy recommendation apparatus, a computing device, and a computer-readable storage medium, which are described in detail one by one in the following embodiments.
[0049] See also Figure 1 , Figure 1 A flowchart of an access control policy recommendation method provided according to an embodiment of this specification is shown, which specifically includes the following steps.
[0050] Step 101: Obtain access information of the asset and determine the access control policy model.
[0051] In one possible implementation, obtaining access information of an asset and determining an access control policy model include: determining a target time period and obtaining access information of the asset within the target time period; and selecting at least two access control policy models from a plurality of set access control policy models, wherein the plurality of set access control policy models include access control policies of a plurality of different levels.
[0052] In practical applications, the managed assets and identities are first divided, see Table 1.
[0053] Table 1
[0054]
[0055] Furthermore, it is necessary to obtain access information within a period of time, for example, see Figure 2 ,The connection relationship can be generated by connecting the log table and the asset information ,table, i.e., the access information. The access relationship in the ,last week is shown in Table II.
[0056] Table 2
[0057]
[0058] See Tables 3 and 4 for the policy model. Table 3 shows the basic policy model, while Table 4 shows the strict policy model. The policy model includes business models, such as group-to-group, role-to-role, and workload-to-workload.
[0059] Table 3
[0060]
[0061] Table 4
[0062]
[0063] It should be noted that other security level policy models can also be divided. For example, according to different business granularity combinations, five policy models can be divided, including basic, moderate, enhanced, strict, and severe. This specification embodiment does not limit the division and number of policy models.
[0064] Step 102: Classify based on the access information and the access control policy model to determine the business relationship.
[0065] In one possible implementation, classification is performed based on access information and policy models to determine business relationships, including: determining classification rules based on the access control policy model; determining business relationships based on the access information and classification rules, wherein the business relationships include role business relationships, workload business relationships, group business relationships, and address business relationships.
[0066] In practical applications, examples are given according to the above basic level policy model and strict level policy model respectively.
[0067] As shown in Table 5, the five access information are divided into two types: within the group and the source end is an internal IP.
[0068] Table 5
[0069]
[0070] Among them, since g2 has no group tag, it is not counted in the business relationship. Therefore, the business relationship is determined according to the basic level policy model group to group. See Table 6, and the business relationship is determined into two groups, that is, the group and the source end are internal IP.
[0071] Table 6
[0072]
[0073] Step 103: Generate a policy based on the business relationship and determine an initial access control policy.
[0074] In a possible implementation, generating a policy based on the business relationship and determining an initial access control policy includes: generating an accessibility rule based on the business relationship; and determining the initial access control policy based on the accessibility rule.
[0075] In actual applications, as shown in Table 7, policies will be generated according to the determined business relationships.
[0076] Table 7
[0077]
[0078] Accordingly, when determining the business relationship in the strict level policy model, and determining the initial access control policy, as described in Tables 8 and 9.
[0079] Table 8
[0080]
[0081] Table 9
[0082]
[0083] Step 104: Evaluate the initial access control policy and preset indicators, determine the indicator evaluation results, and recommend access control policies based on the indicator evaluation results; wherein the preset indicators include policy coverage, exposure reduction rate, and business stability.
[0084] In one possible implementation, an evaluation is performed based on the initial access control policy and preset indicators to determine the indicator evaluation results, including: matching the access information and the initial access control policy to determine the matching results; determining the policy coverage based on the matching results; and generating the indicator evaluation results based on the policy coverage.
[0085] In actual applications, the above results show that at the basic and strict levels, there are a total of 5 access relationships, of which 4 match the policy rules. The access relationship coverage is: the number of access relationships matching the policy rules / the total number of access relationships, that is, 4 / 5 = 0.8, which is 80%.
[0086] In one possible implementation, an evaluation is performed based on the initial access control policy and preset indicators to determine the indicator evaluation results, including: determining the original exposure surface, determining the current exposure surface based on the initial access control policy; determining the exposure surface reduction rate based on the original exposure surface and the current exposure surface; and generating the indicator evaluation results based on the exposure surface reduction rate.
[0087] In practice, the exposure of a network asset is the sum of the number of assets allowed by the source end for each policy rule that matches each port of each asset. The exposure of each port of an asset can be deduced at the basic level, as shown in Table 10.
[0088] Table 10
[0089]
[0090] Based on the above, the original exposure of the asset is: 25x10=250, and the current estimated exposure is: 23x6=138. The exposure reduction rate is: (original exposure - estimated exposure) / original exposure = (250-138) / 250=0.448=44.8%.
[0091] At the severe level, the exposure of each port of the asset is deduced as shown in Table 11.
[0092] Table 11
[0093]
[0094] Based on the above, we can know that the original exposure of this asset is: 25x10=250, and the estimated exposure is: 2+1+20=23. The exposure reduction rate is: (original exposure - estimated exposure) / original exposure = (250-23) / 250=0.908=90.8%.
[0095] In one possible implementation, an evaluation is performed based on the initial access control policy and preset indicators to determine the indicator evaluation results, including: determining the number of new accesses based on the initial access control policy; determining business stability based on the number of new accesses and the number of business relationships; and generating indicator evaluation results based on business stability.
[0096] In actual applications, if the "first access time" of all access relationships covered by a business relationship is later than the set start query time, it will be determined as a "new business relationship." At the basic level, see Table 12, with 2024 / 10 / 23 as the start query time.
[0097] Table 12
[0098]
[0099] Convert the newly added access information into business relationships. If no new business relationships are generated, the business relationship stability is: (total number of business relationships - number of newly added business relationships) / total number of business relationships = (2-0) / 2 = 1, which is 100%.
[0100] In the strict level, see Table 12. Since sequence number 3 is newly added access information, it is converted into a business relationship, generating a new business relationship. Therefore, the business relationship stability is: (total number of business relationships - number of newly added business relationships) / total number of business relationships = (4-1) / 4 = 0.75, which is 75%.
[0101] In summary, based on asset and access relationship data, at the basic level, access relationship policy coverage is 80%, exposure reduction is 44.8%, and business relationship stability is 100%. Based on asset and access relationship data, the policy model at the strict level calculates the following indicators: access relationship policy coverage is 80%, exposure reduction is 90.8%, and business relationship stability is 75%.
[0102] Furthermore, access control policy recommendations can be generated based on the above data.
[0103] For example, the two levels of policy coverage have the same effect. The stringent level will achieve greater exposure reduction, but the business relationship stability is insufficient, which may lead to the risk of future business interruption. The basic level provides sufficient business relationship stability and also reduces exposure. We recommend that users first implement the basic level policy, which will reduce exposure without interrupting business. Observe for a period of time and then implement the corresponding level policy when the stability of the higher level policy is sufficient.
[0104] It should be noted that the format of generating access control policy recommendations can be customized, for example, it can be displayed in the form of a chart, which will not be described in detail here.
[0105] The embodiments of this specification provide an access control policy recommendation method and apparatus, wherein the access control policy recommendation method includes: obtaining access information of assets and determining an access control policy model; classifying based on the access information and the access control policy model to determine business relationships; generating policies based on business relationships to determine an initial access control policy; evaluating based on the initial access control policy and preset indicators to determine indicator evaluation results, and recommending access control policies based on the indicator evaluation results; wherein the preset indicators include policy coverage, exposure reduction rate, and business stability. By automatically collecting access relationships with business attributes, without relying on manual configuration, a whitelist-based policy model is recommended, greatly improving the efficiency of policy implementation and enhancing network security.
[0106] Corresponding to the above method embodiment, this specification also provides an access control policy recommendation device embodiment, Figure 3 FIG. 1 shows a schematic diagram of the structure of an access control policy recommendation device provided by an embodiment of this specification. Figure 3 As shown, the device includes:
[0107] The data acquisition module 301 is configured to obtain access information of assets and determine an access control policy model;
[0108] The service classification module 302 is configured to classify the access information and the access control policy model and determine the service relationship;
[0109] A policy determination module 303 is configured to generate a policy based on the business relationship and determine an initial access control policy;
[0110] The policy recommendation module 304 is configured to evaluate the initial access control policy and preset indicators, determine the indicator evaluation results, and recommend access control policies based on the indicator evaluation results; wherein the preset indicators include policy coverage, exposure reduction rate, and business stability.
[0111] In one possible implementation, obtaining access information of an asset and determining an access control policy model include:
[0112] Determine the target time period and obtain access information of assets within the target time period;
[0113] At least two access control policy models are selected from a plurality of set access control policy models, wherein the plurality of set access control policy models include access control policies of a plurality of different levels.
[0114] In one possible implementation, classification is performed based on access information and a policy model to determine business relationships, including:
[0115] Determine classification rules based on the access control policy model;
[0116] Business relationships are determined based on the access information and classification rules, where the business relationships include role business relationships, workload business relationships, group business relationships, and address business relationships.
[0117] In one possible implementation, policy generation is performed based on business relationships to determine an initial access control policy, including:
[0118] Generate accessibility rules based on business relationships;
[0119] An initial access control policy is determined based on the accessibility rules.
[0120] In one possible implementation, an evaluation is performed based on the initial access control policy and preset indicators to determine an indicator evaluation result, including:
[0121] Perform matching based on the access information and the initial access control policy, and determine a matching result;
[0122] Determine the policy coverage based on the matching results;
[0123] Generate indicator evaluation results based on policy coverage.
[0124] In one possible implementation, an evaluation is performed based on the initial access control policy and preset indicators to determine an indicator evaluation result, including:
[0125] Determine the original exposure surface and the current exposure surface based on the initial access control policy;
[0126] determining an exposure reduction rate based on the original exposure and the current exposure;
[0127] Generate indicator evaluation results based on the exposure surface reduction rate.
[0128] In one possible implementation, an evaluation is performed based on the initial access control policy and preset indicators to determine an indicator evaluation result, including:
[0129] Determine the number of new accesses based on the initial access control policy;
[0130] Determine business stability based on the number of new visits and business relationships;
[0131] Generate indicator evaluation results based on business stability.
[0132] The embodiments of this specification provide an access control policy recommendation method and apparatus, wherein the access control policy recommendation apparatus comprises: obtaining access information of assets and determining an access control policy model; classifying based on the access information and the access control policy model and determining business relationships; generating policies based on business relationships and determining an initial access control policy; evaluating based on the initial access control policy and preset indicators and determining indicator evaluation results, and recommending access control policies based on the indicator evaluation results; wherein the preset indicators include policy coverage, exposure reduction rate, and business stability. By automatically collecting access relationships with business attributes and without relying on manual configuration, a whitelist-based policy model is recommended, thereby greatly improving the efficiency of policy implementation and enhancing network security.
[0133] The above is a schematic diagram of an access control policy recommendation device according to this embodiment. It should be noted that the technical solution of the access control policy recommendation device and the technical solution of the access control policy recommendation method described above are based on the same concept. For details not described in detail in the technical solution of the access control policy recommendation device, please refer to the description of the technical solution of the access control policy recommendation method described above.
[0134] Figure 4 The block diagram of a computing device 400 according to one embodiment of the present disclosure is shown. Components of the computing device 400 include, but are not limited to, a memory 410 and a processor 420. The processor 420 is connected to the memory 410 via a bus 430, and a database 450 is used to store data.
[0135] Computing device 400 also includes an access device 440 that enables computing device 400 to communicate via one or more networks 460. Examples of such networks include a public switched telephone network (PSTN), a local area network (LAN), a wide area network (WAN), a personal area network (PAN), or a combination of communication networks such as the Internet. Access device 440 may include one or more of any type of network interface (e.g., a network interface controller (NIC)) whether wired or wireless, such as an IEEE 802.11 wireless local area network (WLAN) wireless interface, a Worldwide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a universal serial bus (USB) interface, a cellular network interface, a Bluetooth interface, or a near field communication (NFC) interface.
[0136] In one embodiment of the present specification, the above components of the computing device 400 and Figure 4 Other components not shown in the figure may also be connected to each other, for example, via a bus. Figure 4 The computing device structure block diagram shown is for illustrative purposes only and is not intended to limit the scope of this specification. Those skilled in the art may add or replace other components as needed.
[0137] Computing device 400 can be any type of stationary or mobile computing device, including a mobile computer or mobile computing device (e.g., a tablet computer, personal digital assistant, laptop computer, notebook computer, netbook computer, etc.), a mobile phone (e.g., a smartphone), a wearable computing device (e.g., a smartwatch, smart glasses, etc.), or other types of mobile devices, or a stationary computing device such as a desktop computer or personal computer (PC). Computing device 400 can also be a mobile or stationary server.
[0138] Processor 420 is configured to execute the following computer-executable instructions, which, when executed by the processor, implement the steps of the aforementioned access control policy recommendation method. The above is a schematic diagram of a computing device according to this embodiment. It should be noted that the technical solution of this computing device and the technical solution of the aforementioned access control policy recommendation method are based on the same concept. For details not described in detail in the technical solution of the computing device, please refer to the description of the technical solution of the aforementioned access control policy recommendation method.
[0139] An embodiment of the present specification further provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the above-mentioned access control policy recommendation method.
[0140] The above is a schematic diagram of a computer-readable storage medium according to this embodiment. It should be noted that the technical solution of this storage medium is based on the same concept as the technical solution of the access control policy recommendation method described above. For details not described in detail in the technical solution of the storage medium, please refer to the description of the technical solution of the access control policy recommendation method described above.
[0141] An embodiment of the present specification further provides a computer program, wherein when the computer program is executed in a computer, the computer is caused to execute the steps of the above-mentioned access control policy recommendation method.
[0142] The above is a schematic diagram of a computer program according to this embodiment. It should be noted that the technical solution of this computer program and the technical solution of the access control policy recommendation method described above are based on the same concept. For details not described in detail in the technical solution of the computer program, please refer to the description of the technical solution of the access control policy recommendation method described above.
[0143] The foregoing description of this specification describes specific embodiments. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0144] The computer instructions include computer program code, which may be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium may include any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal, and software distribution medium. It should be noted that the content of the computer-readable medium may be appropriately increased or decreased based on the requirements of legislation and patent practice within a jurisdiction. For example, in some jurisdictions, based on legislation and patent practice, computer-readable media does not include electric carrier signals and telecommunication signals.
[0145] It should be noted that for the aforementioned method embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the embodiments of this specification are not limited by the order of the actions described, because according to the embodiments of this specification, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the embodiments of this specification.
[0146] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0147] The preferred embodiments disclosed above are intended only to help illustrate this specification. The optional embodiments do not exhaustively describe all details, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made based on the content of the embodiments of this specification. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the embodiments of this specification, so that those skilled in the art can better understand and utilize this specification. This specification is limited only by the claims and their full scope and equivalents.
Claims
1. A method for recommending an access control policy, characterized in that: include: Obtain access information for assets and determine the access control policy model; Classify the access information and the access control policy model to determine the business relationship; Generating a policy based on the business relationship to determine an initial access control policy; Evaluate the initial access control policy and preset indicators, determine the indicator evaluation results, and recommend an access control policy based on the indicator evaluation results; wherein the preset indicators include policy coverage, exposure reduction rate, and business stability; The performing of the evaluation based on the initial access control policy and the preset indicators to determine the indicator evaluation result includes: Performing a match based on the access information and the initial access control policy to determine a match result; determining a policy coverage rate based on the matching result; Determine an original exposure surface, and determine a current exposure surface based on the initial access control policy; determining an exposure surface reduction rate based on the original exposure surface and the current exposure surface; Determining the number of new accesses based on the initial access control policy; determining business stability based on the number of new visits and the number of business relationships; An indicator evaluation result is generated based on the policy coverage, the exposure reduction rate, and the business stability.
2. The method according to claim 1, characterized in that The obtaining of asset access information and determining the access control policy model includes: Determine a target time period, and obtain access information of the asset within the target time period; At least two access control policy models are selected from a plurality of set access control policy models, wherein the plurality of set access control policy models include access control policies of a plurality of different levels.
3. The method according to claim 1, characterized in that The classifying based on the access information and the policy model to determine the business relationship includes: determining a classification rule based on the access control policy model; A business relationship is determined based on the access information and the classification rule, wherein the business relationship includes a role business relationship, a workload business relationship, a group business relationship, and an address business relationship.
4. The method according to claim 1, wherein Generating a policy based on the business relationship to determine an initial access control policy includes: generating accessibility rules based on the business relationship; An initial access control policy is determined based on the accessibility rules.
5. An access control policy recommendation device, characterized in that: The steps for implementing the access control policy recommendation method according to any one of claims 1 to 4 include: a data acquisition module configured to obtain access information of assets and determine an access control policy model; a service classification module configured to classify the access information and the access control policy model to determine a service relationship; A policy determination module is configured to generate a policy based on the business relationship and determine an initial access control policy; The policy recommendation module is configured to evaluate the initial access control policy and preset indicators, determine the indicator evaluation results, and recommend the access control policy based on the indicator evaluation results; wherein the preset indicators include policy coverage, exposure reduction rate and business stability.
6. A computing device, characterized in that include: memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the access control policy recommendation method according to any one of claims 1 to 4 are implemented.
7. A computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the access control policy recommendation method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Network micro-isolation strategy self-generation method and system
CN113923028A
Big data security protection method and device based on zero trust
CN117436102A