Firewall security policy adaptive migration method, device, equipment and medium
By automatically identifying and replacing old addresses in firewall information with new addresses on the server side, the problem of low efficiency in firewall policy migration is solved, achieving efficient and accurate firewall information migration and adapting to the change requirements of complex systems.
Patent Information
- Application Number
- CN202311132433.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-09-04
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2043-09-04
AI Technical Summary
Existing technologies suffer from low efficiency and the risk of oversights during firewall policy migration, especially in complex systems where efficient and accurate policy change migration is difficult to achieve.
By obtaining firewall information changes from clients through the server, the system automatically identifies and replaces old address information with new address information and deletes old definitions, thus achieving adaptive migration of firewall information. The system also utilizes timed reporting mechanisms and database management on both the server and client sides to ensure the accuracy and efficiency of the migration process.
It improves the efficiency and accuracy of firewall policy migration, reduces the risks associated with manual operations, ensures the normal operation of new address information, and adapts to the migration needs of complex systems.
Smart Images

Figure CN119561704B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to a method, apparatus, device, and medium for adaptive migration of firewall security policies. Background Technology
[0002] Firewall technology is the most commonly used and effective defense measure in network security. It helps computer networks build a relatively isolated protective barrier between the internal network and the external network to protect user data and information security.
[0003] With the rapid development of business in recent years, access control requirements within data centers, especially in testing environments, have become increasingly complex, and the number of access control policies has grown rapidly, posing a significant challenge to the accurate implementation of firewall policies. In complex systems, when changes or migrations to security policies within the firewall are required, manual migration by application maintenance personnel is necessary. Manual processing is prone to oversights that can lead to risks and inefficiencies.
[0004] Therefore, this application proposes a more convenient and efficient adaptive migration method. Summary of the Invention
[0005] This application provides a firewall security policy adaptive migration method, apparatus, device, and medium to solve the problems of low efficiency and easy error in manual processing in the prior art.
[0006] Firstly, this application provides a method for adaptive migration of firewall security policies, including:
[0007] The server obtains whether the firewall information of the first client has changed. If so, it obtains the old address information that needs to be changed from the firewall information.
[0008] If the old address information exists in the firewall information of the second client, replace the new address information in the firewall information with the old address information in the second client.
[0009] If the firewall information of the first client and / or the second client contains an old definition of the new address information, then delete the old definition of the new address information in the first client and / or the second client.
[0010] In one possible implementation, replacing the modified address information in the firewall information with the second client includes:
[0011] If the firewall information of the second client contains the old address information that needs to be changed, then the new address information after the change is added to the firewall information of the second client, and the old address information is deleted.
[0012] The firewall information includes address information, which includes a source address and a destination address. The source address is used to indicate the incoming address, and the destination address is used to indicate the destination address. The old address information includes at least one of the old source address and the old destination address.
[0013] In one possible implementation, determining whether there is an old definition for the new address information in the firewall information obtained from the first client and / or the second client includes:
[0014] If at least one of the new source address and new destination address in the modified address information in the firewall information exists in the firewall information of the first client and / or the second client, then it is confirmed that the firewall information of the first client and / or the second client contains an old definition of the new address information.
[0015] In one possible implementation, the process of the server obtaining whether the firewall information of the first client has changed includes:
[0016] If the new address information after the change in the firewall information is inconsistent with the old address information that needs to be changed in the firewall information, then it is confirmed that the firewall information of the first client has been changed, and the new address information is saved to the database of the server.
[0017] If the new address information after the change in the firewall information is consistent with the old address information that needs to be changed in the firewall information, then confirm and end the current process.
[0018] In one possible implementation, before confirming the end of the current process, the method further includes:
[0019] If the action message corresponding to the new address information in the firewall information is updated, the updated action message will replace the action message corresponding to the old address information that needs to be changed in the firewall information; wherein, the firewall information includes action messages, and the action messages are used to instruct the address information to perform actions.
[0020] In one possible implementation, before the server obtains whether the firewall information of the first client has changed, the method further includes:
[0021] The firewall information of the first client is obtained through the reporting instruction of the first client. The first client feeds back the reporting instruction to the first client according to a preset period. The reporting instruction includes the firewall information of the first client.
[0022] In one possible implementation, if a preset number of the second clients have performance metrics exceeding a preset performance level, the method further includes:
[0023] The server confirms that the firewall information of the first client is forwarded to the second client, so that the second client can determine whether to update its firewall information based on the firewall information of the first client.
[0024] Secondly, this application provides a firewall security policy adaptive migration device, comprising:
[0025] The confirmation module is used by the server to obtain whether the firewall information of the first client has changed. If so, it obtains the old address information that needs to be changed from the firewall information.
[0026] The processing module is used to obtain whether the old address information exists in the firewall information of the second client; if so, it replaces the new address information after the change in the firewall information with the second client.
[0027] The clearing module is used to obtain whether there is an old definition of the new address information in the firewall information of the first client and / or the second client. If so, the old definition of the new address information is deleted in the first client and / or the second client.
[0028] Thirdly, this application provides a firewall security policy adaptive migration device, comprising: at least one processor and a memory;
[0029] The memory stores computer-executed instructions;
[0030] The at least one processor executes the computer execution instructions stored in the memory, causing the at least one processor to execute the firewall security policy adaptive migration method as described above.
[0031] Fourthly, this application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the firewall security policy adaptive migration method as described above.
[0032] This application provides a firewall security policy adaptive migration method, apparatus, device, and medium. The server obtains whether the firewall information of a first client has changed. If so, it obtains the old address information that needs to be changed from the firewall information. The server obtains whether the old address information exists in the firewall information of a second client. If so, it replaces the new address information in the firewall information with the new address information in the second client. The server obtains whether the firewall information of the first client and / or the second client has an old definition for the new address information. If so, it deletes the old definition of the new address information in the first client and / or the second client.
[0033] In the above method, the first client is responsible for reporting firewall information, and the server is responsible for receiving firewall information. When the server detects that the firewall information has changed, it can search for the client containing the old address information in the second client according to the old address information that needs to be changed in the firewall information, and replace the old address information with the new address information to realize the automatic migration of firewall information. If the new address information has been defined (occupied) by the first client and / or the second client, the old definition of the new address information will be deleted to ensure that the new operation of the new address information is not affected. Attached Figure Description
[0034] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0035] Figure 1 A schematic diagram illustrating a scenario of adaptive migration of firewall security policies provided in an embodiment of this application;
[0036] Figure 2 A flowchart illustrating a firewall security policy adaptive migration method provided in this application embodiment. Figure One ;
[0037] Figure 3 A flowchart illustrating a firewall security policy adaptive migration method provided in this application embodiment. Figure Two ;
[0038] Figure 4 A flowchart illustrating a firewall security policy adaptive migration method provided in this application embodiment. Figure Three ;
[0039] Figure 5 A diagram of a firewall security policy adaptive migration device provided in an embodiment of the present invention;
[0040] Figure 6 This is a hardware schematic diagram of a firewall security policy adaptive migration device provided in an embodiment of the present invention. Detailed Implementation
[0041] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0042] In the actual production process, as businesses change and different security needs arise, it is necessary to replace firewalls during the upgrade of network equipment at the customer's site. The data of the firewall being replaced will be migrated to the new firewall.
[0043] Large data center LANs typically deploy thousands of servers and storage devices, supporting the daily operation of hundreds of application systems. To ensure the normal operation of various businesses, there are extremely complex access relationships between different nodes of the same application and between different applications.
[0044] The existing migration process typically involves maintenance personnel manually identifying firewall requirements through application access relationships, thereby completing the firewall data migration. However, this approach is inefficient and prone to errors, posing risks to the migration process. The best existing solution is merely to change the boundary firewall policy, which involves a very small number of firewalls and cannot meet the needs of complex and large firewall systems, resulting in limited efficiency improvements.
[0045] Therefore, this application proposes a processing method that can automatically migrate according to changes in needs, thereby improving processing efficiency.
[0046] The implementation process of the firewall security policy adaptive migration method proposed in this application is described below with reference to the accompanying drawings and specific embodiments.
[0047] Figure 1 This is a schematic diagram illustrating a scenario of adaptive migration of firewall security policies provided in an embodiment of this application. Figure 1 As shown, the system includes: a server 101, a first client 102, and a second client 103; wherein,
[0048] Both the first client 102 and the second client 103 can be established on server devices different from the server 101, and are used to proxy client services (at this time, the first client 102 and the second client 103 complete the registration with the server 101), etc.; the first client 102 is a certain client device, and the second client 103 is at least one client device, which is equivalent to a client group, and the first client 102 can be included in the second client 103;
[0049] Server 101 is installed on the server device and can be used to manage the first client 102 and the second client 103, including receiving client information. When the first client 102 changes its firewall information, it can report to server 101 at regular intervals. Server 101 receives the firewall information from the first client 102. If it confirms that the firewall information of the first client 102 has changed, it searches for old address information that needs to be changed in the firewall information of the second client 103. If it does, it replaces the old address information with the new address information and completes the migration of firewall information.
[0050] If the firewall information of the second client 103 already uses the address corresponding to the changed new address information, then delete the address corresponding to the new address information to avoid conflict with the changed new address information.
[0051] Figure 2 A flowchart illustrating a firewall security policy adaptive migration method provided in this application embodiment. Figure One .like Figure 2 As shown, the method includes:
[0052] S201. The server obtains whether the firewall information of the first client has changed.
[0053] When there are multiple clients in the environment (multiple servers configured as agents, including the first client and the second client), and the performance of each agent is sufficient, one of the clients (the first client) obtains firewall information in real time and sends it to the server (the server configured as the manager). The server confirms whether the firewall information has changed based on the firewall information reported by the first client.
[0054] The firewall information of the first client can be actively reported by the first client after it connects to the server:
[0055] For example, the firewall information of the first client is obtained through the reporting instruction of the first client, wherein the first client feeds back the reporting instruction to the first client according to a preset period, and the reporting instruction includes the firewall information of the first client.
[0056] The server receives firewall information reported by the first client according to the reporting instruction. The first client reports firewall information to the server at regular intervals, and the time interval is a preset period. Therefore, the firewall information reported by the server at the current moment may be different from the firewall information reported at the previous moment.
[0057] S202. If the firewall information of the first client changes, obtain the old address information that needs to be changed from the firewall information.
[0058] When the firewall information of the first client changes, the old address information that has changed is first identified so that the second client can be found to have the old address information.
[0059] S203. Check whether the old address information exists in the firewall information of the second client.
[0060] Obtain the firewall information of the second client and compare it with the old address information of the first client that needs to be changed to confirm whether the old address information exists in the firewall information of the second client. For example, if the old address information 1.1.1.4 of the firewall information of the first client is changed to the new address information 1.2.3.4, and the firewall information of the second client has the address 1.1.1.4, then the old address information exists in the firewall information of the second client.
[0061] S204. If the old address information exists in the firewall information of the second client, then the new address information after the change in the firewall information is replaced in the second client.
[0062] If a second client has an old address, that old address should be replaced with the new address; for example, find the address 1.1.1.4 of the second client and replace it with the address 1.2.3.4.
[0063] S205. Determine whether there is an old definition for the new address information in the firewall information of the first client and / or the second client.
[0064] When the first client and / or the second client change the address information, in order to ensure the normal operation of the new address information, it is necessary to confirm whether the firewall information of the first client and / or the second client contains the old definition of the new address information.
[0065] S206. If the firewall information of the first client and / or the second client contains an old definition of the new address information, then delete the old definition of the new address information in the first client and / or the second client.
[0066] If the firewall information of the first client and / or the second client contains an old definition of the new address, simply delete the old definition of the new address (which will also delete the new address information). For example, if the firewall information of the first client and / or the second client contains the address 1.2.3.4, then there is an old definition for its usage. In order to avoid conflict with the usage of the new definition, the old definition needs to be deleted, and the address 1.2.3.4 will also be deleted.
[0067] In this embodiment, the first client is responsible for reporting firewall information, and the server is responsible for receiving firewall information. When the server detects a change in firewall information, it can search for the client containing the old address information in the second client based on the old address information that needs to be changed in the firewall information, and replace the old address information with the new address information to realize the automatic migration of firewall information. If the new address information has been defined (occupied) by the first client and / or the second client, the old definition of the new address information will be deleted to ensure that the new operation of the new address information is not affected.
[0068] Figure 3 A flowchart illustrating a firewall security policy adaptive migration method provided in this application embodiment. Figure Two .like Figure 3 As shown, the method includes:
[0069] S301. If the new address information after the change in the firewall information is inconsistent with the old address information that needs to be changed in the firewall information, then it is confirmed that the firewall information of the first client has been changed, and the new address information is saved to the database of the server.
[0070] The server compares the old address information in the firewall information of the first client with the new address information in the firewall information of the first client. If the two are not completely consistent, it means that the firewall information of the first client has changed. The new address information can be saved to the server's database. The server can also iterate through the firewall information of each second client to see if there is any that matches the old and new address information. If so, it will perform the corresponding processing.
[0071] S302. If the firewall information of the second client contains the old address information that needs to be changed, then the changed new address information in the firewall information is added to the firewall information of the second client, and the old address information is deleted.
[0072] The firewall information includes address information, which includes a source address and a destination address. The source address is used to indicate the incoming address, and the destination address is used to indicate the destination address. The old address information includes at least one of the old source address and the old destination address.
[0073] Firewall information can be represented as <IP S IP D ,Action>; where IP S The source address indicates that the current client can be accessed via the source address; IP address D The target address indicates that the current client can access the target address, and the Action is the action message, indicating the action that can be taken, such as accept, forward, or send.
[0074] If the second client's firewall information contains old address information that needs to be changed, first add the new address information to the second client's firewall information, and then delete the old address information; for example, if the old address information belongs to the second client's IP address. S (or IP) D The new address information is represented as new_ip, and the old address information is represented as old_ip. Therefore, the new address information can replace the old address information as follows: Replace the IP address with the new address information. S Change to IP S ∪{new_ip}-{old_ip} (or simply use the IP address) D Change to IP D ∪{new_ip}-{old_ip}); Substitute actual data to explain:
[0075] IP S ={1.1.1.1-1.1.1.10}, IP D ={0.0.0.0 / 0}, when 1.1.1.4 is changed to 1.2.3.4, the changed IP address is... S ={1.1.1.1-1.1.1.3}∪{1.1.1.5-1.1.1.10}∪{1.2.3.4}, IP D ={0.0.0.0 / 0}, which indicates that in IP... S Version 1.1.1.4 was deleted, and version 1.2.3.4 was added.
[0076] S303. If at least one of the new source address and the new destination address in the modified address information in the firewall information exists in the firewall information of the first client and / or the second client, then it is confirmed that the firewall information of the first client and / or the second client contains an old definition of the new address information.
[0077] If the firewall information of the first client and / or the second client contains the new address information after the change, then the new address information in the firewall information of the first client and / or the second client must be deleted; the new address information includes the new source address and the new destination address, and if either the first client or the second client has either one, the corresponding address must be deleted;
[0078] For example, the new address information belongs to the IP address of the first client and / or the second client. S (or IP) D The new address information is represented as new_ip, and the old address information is represented as old_ip. Therefore, the method for deleting new address information can be: [remove IP address from the original address]. S Change to IP S -{new_ip} (or simply use the IP address) D Change to IP D -{new_ip}).
[0079] S304. If the new address information after the change in the firewall information is consistent with the old address information that needs to be changed in the firewall information, then confirm the end of the current process.
[0080] If the old address information in the firewall information of the first client is completely consistent with the new address information in the firewall information of the first client, it means that the firewall information of the first client has not changed, and there is no need to migrate the firewall information or perform any further processing.
[0081] In addition to updating address information, firewalls may also experience changes in action messages:
[0082] For example, if the action message corresponding to the new address information in the firewall information is updated, the updated action message will be replaced with the action message corresponding to the old address information that needs to be changed in the firewall information; wherein, the firewall information includes action messages, and the action messages are used to instruct the address information to perform actions.
[0083] If a change in address information is accompanied by a change in the action message, then the action message is modified at the corresponding location; for example, IP address. S The corresponding Action was initially set to Allow forwarding, but was later changed to Allow receiving. This will then apply to the IP address. S The corresponding Action was modified.
[0084] In this embodiment, the firewall information of the first client is confirmed to have changed by using the specific address information in the firewall information, including the source address and the destination address. If so, the client with the corresponding address information (including the old and new address information) is found, and the firewall information is migrated to achieve autonomous migration of firewall information, thereby increasing migration efficiency.
[0085] Figure 4 A flowchart illustrating a firewall security policy adaptive migration method provided in this application embodiment. Figure Three .like Figure 4 As shown, the method includes:
[0086] If a preset number of the second clients' performance metrics exceed a preset performance, then the server will forward the firewall information of the first client to the second client, so that the second client can determine whether to update its firewall information based on the firewall information of the first client.
[0087] If the performance metrics of the second client exceed the preset performance, the server can broadcast the firewall information. Before the second client receives the firewall information from the first client, the server confirms that the firewall information has changed, stores the changed information in the database, and then sends the firewall information of the first client to the second client for subsequent processing by the second client and / or the first client.
[0088] Example:
[0089] S401. The server confirms that the firewall information of the first client has changed and sends the firewall information of the first client to the second client.
[0090] The above embodiments mainly describe how the server iterates through the client firewall information, identifies the clients that need to have their firewall information changed, and then sends the change method to the corresponding clients. This is a unicast case, which can be arranged when the client performance is insufficient. If the client performance is sufficient, the server can also be used as a control medium to obtain the firewall information uploaded by a certain client (the first client). When it is confirmed that the firewall information has changed, the firewall information is directly forwarded to each client. This is a broadcast case.
[0091] The difference between broadcast and unicast is that unicast only needs to find the client corresponding to the changed address and send the change, while broadcast requires the server to confirm that the client's address information has changed, send the changed firewall information to all clients, and let the clients check if they have the corresponding address. If not, no action is taken; if they do, each client and the server will perform similar deletion and replacement processing. See the following steps for details.
[0092] S402. Obtain the old address information that needs to be changed from the firewall information of the first client, and confirm whether the old address information exists in the firewall information of the second client.
[0093] Each second client independently checks its own firewall information to see if it contains the corresponding old address information.
[0094] S403. If the old address information exists in the firewall information of the second client, then the new address information after the change in the firewall information is replaced in the second client.
[0095] If the second client finds a corresponding old address in its firewall information, then the new address information to be replaced in the first client's firewall information is replaced in the corresponding position in the second client's firewall information; the specific example is the same as the server-side replacement method, and will not be repeated here.
[0096] The first client will definitely have the old address information; simply replace it with the new address information.
[0097] S404. Obtain whether there is an old definition for the new address information in the firewall information of the second client. If so, delete the old definition of the new address information from the first client and / or the second client.
[0098] If the first client and / or the second client find that their firewall information contains an old definition of the corresponding new address information, then delete the old definition of the new address information to avoid conflict with the operation of replacing the old address information.
[0099] In this embodiment of the application, considering the good performance of the server, each server can determine whether it needs to change the firewall information, which reduces the workload of the server and also achieves adaptive migration.
[0100] Besides broadcast and unicast methods, the firewall information replacement process can also be implemented through the OpenStack management platform. When one server acts as the server (with the manager installed) and other servers do not have the agent installed, the OpenStack management platform manages the other servers. The server periodically queries each other server for firewall information changes and sends the changed firewall information to each other server through the Ansible tool, allowing the other servers to check whether they have corresponding old and new address information to process (similar to the client processing process in broadcast, specific examples will not be elaborated). The core steps in the adaptive migration method of this application can be applied in different environments, facilitating firewall information migration.
[0101] Figure 5 A diagram of a firewall security policy adaptive migration device provided in an embodiment of the present invention is shown below. Figure 5 As shown, the device includes: a confirmation module 501, a processing module 502, and a clearing module 503;
[0102] The confirmation module 501 is used by the server to obtain whether the firewall information of the first client has changed. If so, it obtains the old address information that needs to be changed from the firewall information.
[0103] The processing module 502 is used to obtain whether the old address information exists in the firewall information of the second client. If so, the new address information after the change in the firewall information is replaced in the second client.
[0104] The clearing module 503 is used to obtain whether there is an old definition of the new address information in the firewall information of the first client and / or the second client, and if so, delete the old definition of the new address information in the first client and / or the second client.
[0105] This application also provides a firewall security policy adaptive migration device, comprising: at least one processor and memory;
[0106] The memory stores computer-executed instructions;
[0107] The at least one processor executes computer execution instructions stored in the memory, causing the at least one processor to execute a firewall security policy adaptive migration method.
[0108] Figure 6 This is a hardware schematic diagram of a firewall security policy adaptive migration device provided in an embodiment of the present invention. Figure 6 As shown, the firewall security policy adaptive migration device 60 provided in this embodiment includes at least one processor 601 and a memory 602. The device 60 also includes a communication component 603. The processor 601, memory 602, and communication component 603 are connected via a bus 604.
[0109] In the specific implementation process, at least one processor 601 executes the computer execution instructions stored in the memory 602, causing at least one processor 601 to execute the above-mentioned firewall security policy adaptive migration method.
[0110] The specific implementation process of processor 601 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.
[0111] In the above Figure 6In the illustrated embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.
[0112] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.
[0113] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.
[0114] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the firewall security policy adaptive migration method described above.
[0115] The aforementioned computer-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.
[0116] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.
[0117] The division of units described herein is merely a logical functional division. In actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.
[0118] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0119] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0120] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.
Claims
1. A firewall security policy adaptive migration method, characterized in that, include: The server obtains whether the firewall information of the first client has changed. If so, it obtains the old address information that needs to be changed from the firewall information. If the old address information exists in the firewall information of the second client, replace the new address information in the firewall information with the old address information in the second client. If the firewall information of the first client and / or the second client contains an old definition of the new address information, then delete the old definition of the new address information in the first client and / or the second client.
2. The method according to claim 1, characterized in that, The step of replacing the modified address information in the firewall information with the second client includes: If the firewall information of the second client contains the old address information that needs to be changed, then the new address information after the change is added to the firewall information of the second client, and the old address information is deleted. The firewall information includes address information, which includes a source address and a destination address. The source address is used to indicate the incoming address, and the destination address is used to indicate the destination address. The old address information includes at least one of the old source address and the old destination address.
3. The method according to claim 2, characterized in that, Whether there is an old definition for the new address information in the firewall information obtained from the first client and / or the second client includes: If at least one of the new source address and new destination address in the modified address information in the firewall information exists in the firewall information of the first client and / or the second client, then it is confirmed that the firewall information of the first client and / or the second client contains an old definition of the new address information.
4. The method according to claim 1, characterized in that, The process of the server obtaining whether the firewall information of the first client has changed includes: If the new address information after the change in the firewall information is inconsistent with the old address information that needs to be changed in the firewall information, then it is confirmed that the firewall information of the first client has been changed, and the new address information is saved to the database of the server. If the new address information after the change in the firewall information is consistent with the old address information that needs to be changed in the firewall information, then confirm and end the current process.
5. The method according to claim 4, characterized in that, Before confirming the end of the current process, the method further includes: If the action message corresponding to the new address information in the firewall information is updated, the updated action message will replace the action message corresponding to the old address information that needs to be changed in the firewall information; wherein, the firewall information includes action messages, and the action messages are used to instruct the address information to perform actions.
6. The method according to claim 1, characterized in that, Before the server obtains whether the firewall information of the first client has changed, the method further includes: The firewall information of the first client is obtained through the reporting instruction of the first client. The first client feeds back the reporting instruction to the first client according to a preset period. The reporting instruction includes the firewall information of the first client.
7. The method according to claim 1, characterized in that, If a preset number of the second clients have performance metrics exceeding a preset performance level, the method further includes: The server confirms that the firewall information of the first client is forwarded to the second client, so that the second client can determine whether to update its firewall information based on the firewall information of the first client.
8. A firewall security policy adaptive migration device, characterized in that, include: The confirmation module is used by the server to obtain whether the firewall information of the first client has changed. If so, it obtains the old address information that needs to be changed from the firewall information. The processing module is used to obtain whether the old address information exists in the firewall information of the second client; if so, it replaces the new address information after the change in the firewall information with the second client. The clearing module is used to obtain whether there is an old definition of the new address information in the firewall information of the first client and / or the second client. If so, the old definition of the new address information is deleted in the first client and / or the second client.
9. A firewall security policy adaptive migration device, characterized in that, include: At least one processor and memory; The memory stores computer-executed instructions; The at least one processor executes computer execution instructions stored in the memory, causing the at least one processor to perform the firewall security policy adaptive migration method as described in any one of claims 1-7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the firewall security policy adaptive migration method as described in any one of claims 1-7.
Citation Information
Patent Citations
Method and system for realizing dynamic network protection, and dynamic firewall
CN106209799A
Configuration method, device for virtual firewall, and computer readable storage medium
CN109495422A