Firewall Automatic Management System and Method Based on Work Order System
Through the machine learning and risk prediction module, dynamic risk assessment algorithms and multi-layer neural network architecture are used to solve the problem of failure to predict future risks in traditional firewall automation management, and intelligent adjustment and risk optimization of firewall configuration changes are realized, improving network security.
Patent Information
- Application Number
- CN202411841632.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-13
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-12-13
AI Technical Summary
Traditional firewall automation management based on work ticket systems lacks the ability to actively predict and flexible response to potential future risks, resulting in security vulnerabilities that may occur in the firewall due to failure to adjust the configuration in time.
The machine learning and risk prediction module is adopted to predict risks that may be caused by changes in firewall configuration through data acquisition, preprocessing and model construction, and use dynamic risk assessment algorithms and multi-layer neural network architectures to predict risks that firewall configuration changes may be caused, and intelligent adjustment and configuration optimization are carried out in combination with the risk response rule base.
Effectively predict the potential risks of firewall configuration changes, prevent the emergence of security vulnerabilities, narrow risk exposure through dynamic adjustments, and improve network security.
Smart Images

Figure CN119728209B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and particularly relates to a firewall automation management system and method based on a work order system. Background Art
[0002] In today's digital age, the scale of enterprise networks is constantly expanding and becoming increasingly complex, and network security has become a crucial concern. As a key infrastructure for network security protection, the firewall undertakes the core tasks of controlling network access and resisting external threats.
[0003] In traditional firewall automation management based on a work order system, firewall configuration changes are often executed according to established work order processes and rules, lacking the ability to actively predict future potential risks and respond flexibly. This may lead to security vulnerabilities in the firewall due to failure to adjust the configuration in a timely manner. To address the above problems, the following solutions are proposed. Summary of the Invention
[0004] The purpose of the present invention is to provide a firewall automation management system and method based on a work order system. Through a machine learning and risk prediction module, it can predict various risks that may be caused by the firewall configuration changes involved in this work order within a certain period in the future, solving the problem that existing firewalls may have security vulnerabilities due to failure to adjust the configuration in a timely manner.
[0005] To solve the above technical problems, the present invention is realized through the following technical solutions:
[0006] The present invention is a firewall automation management method based on a work order system, and the management method includes:
[0007] Step S1: Data collection, preprocessing, and model construction;
[0008] The process of step S1, data collection, preprocessing, and model construction is as follows:
[0009] Step S11: The data collection module continuously collects various types of data, extracts key feature information, and converts the data into an input format acceptable to the algorithm according to the data feature extraction and encoding rules of the dynamic risk assessment algorithm, providing high-quality data input for the machine learning and risk prediction module;
[0010] Step S12: The machine learning and risk prediction module constructs a dynamic risk assessment model of the dynamic risk assessment algorithm, determines the model architecture, trains the model using historical data, inputs the encoded feature data into the model, and adjusts the weights and biases of the model according to the mean square error loss function through the backpropagation algorithm combined with the stochastic gradient descent optimization algorithm, enabling the model to learn the feature associations and risk patterns in the data until the model converges to achieve better prediction performance;
[0011] Step S2, Work order submission and risk prediction;
[0012] Step S3, Work order adjustment decision: The work order adjustment module receives the risk assessment report and judges whether the risk exceeds the preset threshold. When the risk does not exceed the threshold, the original work order is directly submitted to the regular approval process of the work order system. When the risk exceeds the threshold, the work order is intelligently adjusted according to the rule-based optimization algorithm and the pre-established risk response rule library to generate an adjusted work order, which is resubmitted to the approval process of the work order system together with the adjustment description document. At the same time, a risk warning notice and a message of the details of the adjusted work order are pushed to relevant personnel;
[0013] Step S4, Work order approval and execution: The adjusted work order is circulated in the work order system according to the preset approval process. The approver reviews the work order based on the risk warning information, adjustment description, enterprise security policies and business requirements. If the approval is passed, the automated execution module interacts with the firewall device to send the adjusted configuration instructions to the firewall device to perform the configuration change operation. When the approval is not passed, the work order will be returned to the submitter or the adjustment module for further modification, along with the rejection reason and modification suggestions;
[0014] Step S5, Execution result feedback and monitoring audit.
[0015] Preferably, the dynamic network risk perception algorithm in the step S11 specifically includes:
[0016] Data feature extraction and encoding:
[0017] Calculate the geographical location risk weight Q of the source IP address: Where n is the number of historical security events related to this geographical area, and W i is the severity score of the i-th historical security event, and E i is the occurrence frequency of the i-th historical security event;
[0018] Calculate the historical access behavior encoding R of the source IP: Where T is the access frequency within the past time window, Y is the total duration of the time window, U r is the number of different port ranges accessed, U t is the total number of ports, I is the number of abnormal connection interruptions, and σ, τ are adjustable weight coefficients;
[0019] Calculate the firewall work order configuration change vector encoding O: Where P nu is the number of IPs covered by the source IP range, P tois the total IP quantity of the entire network, k1 and k2 are constants set according to the network scale and security policy, A represents a threshold, and the threshold is used to distinguish different risk levels of the number of IPs covered by the source IP range;
[0020] Construction of the dynamic risk assessment model:
[0021] Adopt a multi-layer neural network architecture, and the activation function of the hidden layer neurons: f(x) = max(0, x);
[0022] The model training adopts the mean square error (MSE) loss function: where m is the number of training samples, y j is the true risk value of the jth sample, is the risk value of the jth sample predicted by the module, and the weight update adopts the formula: where ω i is the ith weight in the neural network, and η = 0.01.
[0023] Preferably, the step S2, work order submission and risk prediction specifically include:
[0024] Step S21: The user submits a firewall configuration change work order through the work order system and fills in the configuration change requirements;
[0025] Step S22: The work order system module transfers the work order information to the machine learning and risk prediction module, uses the trained dynamic risk assessment model to combine the current network environment data and security threat intelligence to predict the risk of the work order, processes the new work order data and the current relevant data according to the coding rules, inputs them into the dynamic risk assessment model, and the module calculates through forward propagation, outputs the predicted risk type and the quantitative index of the risk level, and generates a risk assessment report.
[0026] Preferably, the step S5, execution result feedback and monitoring and auditing specifically include:
[0027] Step S51: After sending the configuration instruction, the automated execution module waits for the feedback information of the firewall device; when the configuration is successful, the automated execution module will record the operation log and notify the work order system module that the work order processing is completed. When the configuration fails, the automated execution module will record the detailed error information and feedback it to the work order system module, and at the same time trigger the monitoring and auditing module to record the fault and conduct further analysis;
[0028] Step S52: The monitoring and auditing module monitors the running state of the firewall in real time throughout the process, audits and records the whole process of work order processing, and then triggers the adaptive update of the risk prediction module in a timely manner according to the data change situation.
[0029] Preferably, a firewall automation management system based on a work order system, the management system including a work order system module and a data collection module;
[0030] The output end of the work order system module is unidirectionally connected to the input end of the data collection module. The input end of the data collection module is respectively unidirectionally connected to a firewall and an external intelligence library. The data collection module is bidirectionally connected to a machine learning and risk prediction module. The output end of the data collection module is unidirectionally connected to a monitoring and auditing module. The machine learning and risk prediction module is bidirectionally connected to the monitoring and auditing module. The machine learning and risk prediction module is bidirectionally connected to the work order system module. The work order system module is respectively bidirectionally connected to a user terminal, a work order adjustment module, and an automated execution module. The automated execution module is bidirectionally connected to the firewall.
[0031] Preferably, the data collection module is responsible for collecting data from multiple data sources, including historical network connection information recorded in firewall logs, all work order details in past work order systems, external security threat intelligence sources, and real-time firewall operation status data. The work order system module is used to receive the original firewall configuration change work orders submitted by users and transfer the work order information to the machine learning and risk prediction module for risk prediction. The monitoring and auditing module is used to monitor the operation status of the firewall in real time and perform data interaction with the risk prediction module to provide real-time data support for risk prediction. The user terminal is used for users to submit firewall configuration change work orders to the work order system.
[0032] Preferably, the automated execution module is used to interact with the firewall device when the adjusted work order is approved, and send the adjusted firewall configuration instructions to the target firewall device for configuration change operations. The work order adjustment module views the risk assessment report generated by the risk prediction module. When the risk exceeds the preset threshold, the work order adjustment module will start a dynamic work order adjustment mechanism to adjust the firewall configuration change content in the work order.
[0033] The present invention has the following beneficial effects:
[0034] 1. The present invention uses the machine learning and risk prediction module to comprehensively analyze and learn a large amount of historical work order data, network traffic data, security threat intelligence, and firewall operation status data. When a new work order is submitted, this module can predict various risks that may be caused by the firewall configuration changes involved in this work order in a future period of time, preventing security vulnerabilities from occurring due to the firewall not being configured in a timely manner.
[0035] 2. The present invention utilizes a work order adjustment module to view the risk assessment report generated by the risk prediction module. If the risk exceeds the preset threshold, this module activates a dynamic work order adjustment mechanism to adjust the firewall configuration change content in the work order, automatically optimize the work order according to the risk assessment result, and narrow the risk exposure.
[0036] Of course, it is not necessary for any product implementing the present invention to simultaneously achieve all the above-mentioned advantages. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0038] Figure 1 It is the internal system framework diagram of the present invention;
[0039] Figure 2 It is the step flow chart of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0040] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0041] Please refer to Figure 1-2 As shown, the present invention is a firewall automation management method based on a work order system, and the management method includes:
[0042] Step S1: Data collection, preprocessing, and model construction;
[0043] The process of step S1: Data collection, preprocessing, and model construction is as follows:
[0044] Step S11: The data collection module continuously collects various types of data, extracts key feature information, and converts the data into an input format acceptable to the algorithm according to the data feature extraction and encoding rules of the dynamic risk assessment algorithm, providing high-quality data input for the machine learning and risk prediction module;
[0045] Step S12: The machine learning and risk prediction module constructs a dynamic risk assessment model for the dynamic risk assessment algorithm, determines the model architecture, trains the model using historical data, inputs the encoded feature data into the model, and adjusts the weights and biases of the model according to the mean square error loss function through the backpropagation algorithm combined with the stochastic gradient descent optimization algorithm, enabling the model to learn the feature associations and risk patterns in the data until the model converges to achieve better prediction performance;
[0046] Step S2, Work order submission and risk prediction;
[0047] Step S3, Work order adjustment decision: The work order adjustment module receives the risk assessment report and determines whether the risk exceeds the preset threshold. When the risk does not exceed the threshold, the original work order is directly submitted to the regular approval process of the work order system. When the risk exceeds the threshold, the work order is intelligently adjusted according to the rule-based optimization algorithm and the pre-established risk response rule library to generate an adjusted work order, which is resubmitted to the approval process of the work order system together with the adjustment description document. At the same time, a risk warning notice and a message about the details of the adjusted work order are triggered and pushed to relevant personnel;
[0048] Step S4, Work order approval and execution: The adjusted work order is circulated in the work order system according to the preset approval process. The approver reviews the work order based on the risk warning information, adjustment description, the enterprise's security policies, and business requirements. If the approval is passed, the automated execution module interacts with the firewall device to send the adjusted configuration instructions to the firewall device to perform the configuration change operation. When the approval is not passed, the work order is returned to the submitter or the adjustment module for further modification, along with the rejection reason and modification suggestions;
[0049] Step S5, Feedback on execution results and monitoring and auditing.
[0050] The dynamic network risk perception algorithm in Step S11 specifically includes:
[0051] Data feature extraction and encoding:
[0052] Calculate the geographical location risk weight Q of the source IP address: where n is the number of historical security events related to this geographical area, W i is the severity score of the i-th historical security event, E i is the occurrence frequency of the i-th historical security event;
[0053] Calculate the encoded historical access behavior R of the source IP: where T is the access frequency within the past time window, Y is the total duration of the time window, U r is the number of different port ranges accessed, U tLet \(N\) be the total number of ports, \(I\) be the number of abnormal connection interruptions, and \(\sigma\), \(\tau\) be adjustable weight coefficients;
[0054] Calculate the firewall work order configuration change vector encoding \(O\): where \(P\) nu is the number of IPs covered by the source IP range, \(P\) to is the total number of IPs in the entire network, \(k_1\) and \(k_2\) are constants set according to the network scale and security policy, and \(A\) represents a threshold used to distinguish different risk levels of the number of IPs covered by the source IP range;
[0055] Dynamic risk assessment model construction:
[0056] Adopt a multi-layer neural network architecture, and the activation function of the hidden layer neurons is: \(f(x)=\max(0,x)\);
[0057] The model training uses the mean square error (MSE) loss function: where \(m\) is the number of training samples, \(y\) j is the true risk value of the \(j\)-th sample, is the risk value of the \(j\)-th sample predicted by the module, and the weight update uses the formula: where \(\omega\) i is the \(i\)-th weight in the neural network, and \(\eta = 0.01\).
[0058] Step S2, work order submission and risk prediction specifically include:
[0059] Step S21: The user submits a firewall configuration change work order through the work order system and fills in the configuration change requirements;
[0060] Step S22: The work order system module transfers the work order information to the machine learning and risk prediction module, uses the trained dynamic risk assessment model to combine the current network environment data and security threat intelligence to predict the risk of the work order, processes the new work order data and the current relevant data according to the encoding rules, inputs them into the dynamic risk assessment model, and the module calculates through forward propagation to output the predicted risk type and the quantitative index of the risk level, and generates a risk assessment report.
[0061] Step S5, execution result feedback and monitoring and auditing specifically include:
[0062] Step S51: After sending the configuration instruction, the automated execution module waits for the feedback information from the firewall device; when the configuration is successful, the automated execution module will record the operation log and notify the work order system module that the work order processing is completed, and when the configuration fails, the automated execution module will record the detailed error information and feedback it to the work order system module, and at the same time trigger the monitoring and auditing module to record the failure and conduct further analysis;
[0063] Step S52: The monitoring and auditing module monitors the running status of the firewall in real time throughout the process, audits and records the whole process of work order processing, and then triggers the adaptive update of the risk prediction module in a timely manner according to the data change situation.
[0064] A firewall automation management system based on a work order system, the management system includes a work order system module and a data collection module;
[0065] The output end of the work order system module is unidirectionally connected to the input end of the data collection module. The input end of the data collection module is unidirectionally connected to a firewall and an external intelligence library respectively. The data collection module is bidirectionally connected to a machine learning and risk prediction module. The output end of the data collection module is unidirectionally connected to a monitoring and auditing module. The machine learning and risk prediction module is bidirectionally connected to the monitoring and auditing module. The machine learning and risk prediction module is bidirectionally connected to the work order system module. The work order system module is bidirectionally connected to a user terminal, a work order adjustment module and an automated execution module respectively. The automated execution module is bidirectionally connected to the firewall.
[0066] The data collection module is responsible for collecting data from multiple data sources, including historical network connection information recorded in firewall logs, all work order details in the past work order system, external security threat intelligence sources, and real-time running status data of the firewall. The work order system module is used to receive the original firewall configuration change work order submitted by the user and transfer the work order information to the machine learning and risk prediction module for risk prediction. The monitoring and auditing module is used to monitor the running status of the firewall in real time and conduct data interaction with the risk prediction module to provide real-time data support for risk prediction. The user terminal is used for the user to submit a firewall configuration change work order to the work order system.
[0067] The automated execution module is used to interact with the firewall device when the adjusted work order is approved, and send the adjusted firewall configuration instruction to the target firewall device for configuration change operation. The work order adjustment module views the risk assessment report generated by the risk prediction module. When the risk exceeds the preset threshold, the work order adjustment module will start a dynamic work order adjustment mechanism to adjust the firewall configuration change content in the work order.
[0068] A specific application of this embodiment is:
[0069] The data collection module first collects data from multiple sources, and through cleaning, sorting, and standardization processes, it removes noise data and invalid data and extracts key feature information, such as calculating the geographical location risk weight of the source IP address, encoding the historical access behavior of the source IP, and encoding the firewall work order configuration change vector according to specific formulas. Then, when a user submits a firewall configuration change work order through the work order system, the machine learning and risk prediction module combines the processed data to perform risk prediction, outputs the risk quantification value and the probability distribution of the risk type, and generates a risk assessment report. If the risk exceeds the preset threshold, the work order adjustment module intelligently optimizes and adjusts the work order according to the rule library, resubmits it for approval, and pushes notifications. If the approval is passed, the automated execution module communicates with the firewall device according to the instructions to execute the configuration change and feedback the result. At the same time, the monitoring and auditing module monitors the running status of the firewall in real time, triggers the adaptive update of the machine learning and risk prediction module according to data changes, and the whole process of audit records is used for subsequent work. The specific steps are as follows:
[0070] Step S1, Data collection, preprocessing, and model construction:
[0071] Step S11: The data collection module continuously collects various data from firewalls, work order systems, external security intelligence sources, etc., and performs cleaning, sorting, and standardization processing on the data, removes noise data and invalid data, extracts key feature information, and then converts the data into an input format acceptable to the algorithm according to the data feature extraction and encoding rules of the dynamic risk assessment algorithm, providing high-quality data input for the machine learning and risk prediction module;
[0072] Step S12: The machine learning and risk prediction module constructs a dynamic risk assessment model of the dynamic risk assessment algorithm, determines the model architecture (settings of the multi-layer neural network, including the input layer, hidden layer, and output layer), trains the model using historical data, inputs the encoded feature data into the model, and adjusts the weights and biases of the model through the backpropagation algorithm combined with the stochastic gradient descent optimization algorithm according to the mean square error loss function, so that the model can learn the feature associations and risk patterns in the data until the model converges to achieve better prediction performance;
[0073] Among them, the data collection module: is responsible for collecting data from multiple data sources, including historical network connection information recorded in firewall logs, all work order details in the past work order system (such as configuration change content, submission time, approval result, etc.), external security threat intelligence sources (such as vulnerability information released by well-known security agencies, malicious IP address libraries, etc.), and real-time firewall operation status data (such as current connection count, traffic load, status of each port, etc.);
[0074] Machine Learning and Risk Prediction Module: The dynamic network risk perception algorithm is used to process data and predict risks. The dynamic network risk perception algorithm is an algorithm specifically designed for accurate risk assessment in the firewall automation management system. It mainly consists of the following key parts:
[0075] Data Feature Extraction and Encoding:
[0076] Calculate the geographical location risk weight of the source IP address: Among them, n is the number of historical security events related to this geographical area, W i is the severity score of the i-th historical security event, E i is the occurrence frequency of the i-th historical security event. In this way, the geographical location information of the source IP address is combined with the historical security situation to provide geographical factor considerations for subsequent risk assessment;
[0077] Calculate the encoded historical access behavior of the source IP: Among them, T is the access frequency within the past time window, Y is the total duration of the time window, U r is the number of different port ranges accessed, U t is the total number of ports, I is the number of abnormal connection interruptions (1 if there is, 0 if not), σ, τ are adjustable weight coefficients. This encoding comprehensively considers various factors such as the historical access activity, access diversity, and abnormal situations of the source IP to quantify the risk level of its behavior pattern;
[0078] Calculate the encoded change vector of the firewall work order configuration: Among them, P nu is the number of IPs covered by the source IP range, P to is the total number of IPs in the entire network, k1 and k2 are constants set according to the network scale and security policy, A represents a threshold, and this threshold is used to distinguish different risk levels of the number of IPs covered by the source IP range. This encoding focuses on the source IP range configuration in the firewall work order and preliminarily quantifies the risk according to the range size;
[0079] Construction of the dynamic risk assessment model:
[0080] Adopt a multi-layer neural network architecture, determine that the number of neurons in the input layer corresponds to the dimension of the encoded feature data. For example, use the geographical location risk weight of the source IP, the encoded historical access behavior of the source IP, the encoded change vector of the firewall work order configuration, etc. as the input of the neurons in the input layer, design the hidden layer structure, set the appropriate number of hidden layers and the number of neurons in each layer, and use the ReLU function as the activation function of the hidden layer neurons: f(x) = max(0, x);
[0081] Determine the output layer, and output the risk quantification value and the probability distribution of risk types (such as intrusion risk, network performance degradation risk, data leakage risk, etc.);
[0082] The model training adopts the mean squared error (MSE) loss function: where m is the number of training samples, and y j is the true risk value of the j-th sample, is the risk value of the j-th sample predicted by the module, and the weight update adopts the stochastic gradient descent (SGD) formula: where ω i is the i-th weight in the neural network, η = 0.01 (example learning rate). The model is trained with a large number of historical data samples, and the gradient is calculated according to the loss function using the backpropagation algorithm. The weights and biases of the neural network are continuously adjusted to minimize the loss function value, so that the model gradually converges to a better risk prediction performance state;
[0083] When a new work order is submitted, the data related to the work order and the current network environment data are processed according to the encoding rules and then input into the dynamic risk assessment model. The module calculates through forward propagation, outputs the risk quantification value and the probability distribution of risk types (such as intrusion risk, network performance degradation risk, data leakage risk, etc.), and generates a risk assessment report;
[0084] Step S2: Work order submission and risk prediction:
[0085] Step S21: The user submits a firewall configuration change work order to the work order system through the user terminal, and fills in the configuration change requirements in detail (such as newly added or modified firewall rules, source IP address range, destination port number, protocol type, etc.);
[0086] Step S22: The work order system module transfers the work order information to the machine learning and risk prediction module. This module uses the trained dynamic risk assessment model to combine the current network environment data and security threat intelligence to predict the risk of the work order. First, the new work order data and the current relevant data are processed according to the encoding rules, and then input into the dynamic risk assessment model. The model calculates through forward propagation, uses a multi-layer neural network architecture (the activation function of the hidden layer neurons is f(x) = max(0, x)), outputs the predicted risk types (such as being attacked by DDoS, port scanning attack, network congestion, etc.) and the risk degree quantification index (such as risk probability value), and generates a risk assessment report;
[0087] Among them, the work order system module is used to receive the original firewall configuration change work order submitted by the user, and transfer the work order information to the machine learning and risk prediction module for risk prediction;
[0088] After resubmitting the adjusted work order in the work order adjustment module, it is routed according to the regular approval process, including steps such as department head approval and security team review. At the same time, it is able to push notifications containing risk warning information and details of the adjusted work order to relevant personnel, facilitating decision-making by approval personnel considering risk factors during the approval process;
[0089] Step S3, Work Order Adjustment Decision: The work order adjustment module receives the risk assessment report and determines whether the risk exceeds the preset threshold. If it does not exceed the threshold, the original work order is directly submitted to the regular approval process of the work order system; if it exceeds the threshold, the work order is intelligently adjusted to generate an adjusted work order, which is resubmitted to the approval process of the work order system together with the adjustment description document, and at the same time, a message to push risk warning notifications and details of the adjusted work order to relevant personnel (such as work order submitters, approvers, security administrators, etc.) is triggered;
[0090] Among them, the work order adjustment module can view the risk assessment report generated by the risk prediction module. If the risk exceeds the preset threshold, this module starts a dynamic work order adjustment mechanism to adjust the firewall configuration change content in the work order. For example, a risk response rule library is established in advance. When it is predicted that opening a certain port may lead to a high intrusion risk, according to the response rules for port opening risks in the rule library, such as "if the probability of intrusion risk caused by port opening is greater than 60%, then reduce the port opening range to 50% of the original range and add access restrictions based on source IP reputation, only allowing access from high-reputation source IPs", the work order is modified according to this rule;
[0091] Resubmit the adjusted work order to the approval process of the work order system and generate a detailed adjustment description document, recording information such as the reason for adjustment and the comparison of work order configurations before and after adjustment, so that approval personnel and relevant technical personnel can understand the situation;
[0092] Step S4, Work Order Approval and Execution: The adjusted work order is routed in the work order system according to the preset approval process. The approval personnel review the work order based on the risk warning information, adjustment description, and the enterprise's security policies and business requirements. If the approval is passed, the automated execution module interacts with the firewall device to send the adjusted configuration instructions to the firewall device to perform the configuration change operation. If the approval is not passed, the work order is returned to the submitter or the adjustment module for further modification, along with the reason for rejection and modification suggestions;
[0093] Among them, after the adjusted work order is approved, the automated execution module interacts with the firewall device to send the adjusted firewall configuration instructions to the target firewall device for configuration change operations;
[0094] Receive the configuration execution result information returned by the firewall device. If the configuration is successful, record the operation log and notify the work order system module that the work order processing is completed; if the configuration fails, record the detailed error information and feedback it to the work order system module, and at the same time trigger the monitoring and auditing module to record the failure and conduct further analysis;
[0095] Step S5: Feedback of Execution Results and Monitoring & Auditing:
[0096] Step S51: After the automation execution module sends the configuration instruction, wait for the feedback information from the firewall device. If the configuration is successful, record the operation log and notify the work order system module that the work order processing is completed; if the configuration fails, record the detailed error information and feedback it to the work order system module, and at the same time trigger the monitoring and auditing module to record the failure and conduct further analysis;
[0097] Step S52: The monitoring and auditing module monitors the running status of the firewall in real time throughout the process, and conducts an audit record of the entire work order processing process to generate an audit report for subsequent security reviews, compliance checks, and fault troubleshooting. By regularly analyzing the audit report, the parameters of the risk prediction module and the risk response rule library can be continuously optimized to improve the accuracy and effectiveness of the system. At the same time, according to the data change situation (such as the change rate of the mean value of the source IP access frequency feature When it exceeds 0.3), trigger the adaptive update of the risk prediction module in a timely manner to ensure that the module always adapts to the dynamic changes of the network environment;
[0098] Among them, the monitoring and auditing module is used to monitor the running status of the firewall in real time, including the number of connections, traffic rate, rule matching situation, etc., and conduct data interaction with the risk prediction module to provide real-time data support for risk prediction;
[0099] Regularly analyze the differences between newly incoming data and historical data, and calculate the change rate of the feature mean value (taking the source IP access frequency feature as an example, ) When the change rate exceeds the set threshold (assumed to be 0.3), trigger the update training of the dynamic risk assessment model. Adopt the incremental learning method to retain the weights and knowledge that have been learned in the original model, and only adjust the model parameters related to the new data features;
[0100] Conduct an audit record of the entire work order processing process, including the original work order information, risk prediction results, work order adjustment details, approval process, automation execution results, etc., to generate a detailed audit report for subsequent security reviews, compliance checks, and fault troubleshooting.
[0101] In the description of this specification, the descriptions referring to terms such as "one embodiment", "example", "specific example", etc. mean that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in a suitable manner in any one or more embodiments or examples.
[0102] The preferred embodiments of the present invention disclosed above are only used to help explain the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification in order to better explain the principles and practical applications of the present invention, so that those skilled in the art can well understand and utilize the present invention. The present invention is only limited by the claims and their full scope and equivalents.
Claims
1. A firewall automation management method based on a work order system, characterized in that: The management method includes: Step S1, data collection, preprocessing, and model construction; The process of step S1, data collection, preprocessing, and model construction is as follows: Step S11: The data collection module continuously collects various types of data, extracts key feature information, and converts the data into an input format acceptable to the algorithm according to the data feature extraction and encoding rules of the dynamic risk assessment algorithm, providing high-quality data input for the machine learning and risk prediction module; Step S12: The machine learning and risk prediction module constructs a dynamic risk assessment model of the dynamic risk assessment algorithm, determines the model architecture, trains the model using historical data, inputs the encoded feature data into the model, and adjusts the weights and biases of the model according to the mean square error loss function through the backpropagation algorithm combined with the stochastic gradient descent optimization algorithm, enabling the model to learn the feature associations and risk patterns in the data until the model converges to achieve better prediction performance; Step S2, work order submission and risk prediction; Step S3, work order adjustment decision: The work order adjustment module receives the risk assessment report and determines whether the risk exceeds the preset threshold. When the risk does not exceed the threshold, the original work order is directly submitted to the regular approval process of the work order system. When the risk exceeds the threshold, the work order is intelligently adjusted according to the rule-based optimization algorithm and the pre-established risk response rule library, generating an adjusted work order, which is resubmitted to the approval process of the work order system together with the adjustment description document, and at the same time triggering a message to push the risk warning notice and the details of the adjusted work order to relevant personnel; Step S4, work order approval and execution: The adjusted work order is circulated in the work order system according to the preset approval process. The approver reviews the work order based on the risk warning information, adjustment description, enterprise security policies, and business requirements. If the approval is passed, the automated execution module interacts with the firewall device to send the adjusted configuration instructions to the firewall device to perform the configuration change operation. When the approval is not passed, the work order is returned to the submitter or the adjustment module for further modification, along with the rejection reason and modification suggestions; Step S5, execution result feedback and monitoring audit; The dynamic network risk perception algorithm in step S11 specifically includes: Data feature extraction and encoding: Calculate the geographical location risk weight Q of the source IP address: where n is the number of historical security events related to the geographical area, and W i is the severity score of the i-th historical security event, and E i is the occurrence frequency of the i-th historical security event; Calculate the source IP historical access behavior code R: where T is the access frequency within the past time window, Y is the total duration of the time window, U r is the number of different port ranges visited, U t is the total number of ports, I is the number of abnormal connection interruptions, σ, τ is an adjustable weight coefficient; Calculating the Encoding of the Configuration Change Vector of the Firewall Work Order O: Among them, P nu is the number of IPs covered by the source IP range, and P to is the total number of IPs in the entire network. k1 and k2 are constants set according to the network scale and security policies. A represents a threshold, which is used to distinguish different risk levels of the number of IPs covered by the source IP range; Dynamic risk assessment model construction: Adopt a multi-layer neural network architecture, and the activation function of the hidden layer neurons: f(x) = max(0, x); The model training uses the mean squared error (MSE) loss function: where m is the number of training samples, y j is the true risk value of the j-th sample, is the risk value of the j-th sample predicted by the module, and the weight update uses the formula: where ω i is the i-th weight in the neural network, and η = 0.01; Determine that the number of input layer neurons corresponds to the dimension of the encoded feature data. Use the source IP geographical location risk weight, source IP historical access behavior encoding, and firewall work order configuration change vector encoding as the input of the input layer neurons, and determine the output layer, outputting the risk quantification value and the probability distribution of the risk type.
2. The firewall automation management method based on the work order system according to claim 1, characterized in that The specific content of step S2, work order submission and risk prediction includes: Step S21: The user submits a firewall configuration change work order through the work order system and fills in the configuration change requirements; Step S22: The work order system module transmits the work order information to the machine learning and risk prediction module. Using the trained dynamic risk assessment model, it combines the current network environment data and security threat intelligence to predict the risk of the work order. The new work order data and the current relevant data are processed according to the coding rules and input into the dynamic risk assessment model. The module calculates through forward propagation, outputs the predicted risk type and the quantitative index of the risk level, and generates a risk assessment report.
3. The firewall automation management method based on a work order system according to claim 1, wherein The above-mentioned step S5, execution result feedback and monitoring and auditing specifically include: Step S51: After sending the configuration instruction, the automated execution module waits for the feedback information from the firewall device; when the configuration is successful, the automated execution module will record the operation log and notify the work order system module that the work order processing is completed. When the configuration fails, the automated execution module will record the detailed error information and feedback it to the work order system module, and at the same time trigger the monitoring and auditing module to record the failure and conduct further analysis; Step S52: The monitoring and auditing module monitors the running status of the firewall in real time throughout the process, conducts audit records on the whole process of work order processing, and then triggers the adaptive update of the risk prediction module in a timely manner according to the data change situation.
4. A firewall automated management system based on a work order system, the management system includes a work order system module and a data collection module, characterized in that: The output end of the work order system module is unidirectionally connected to the input end of the data collection module. The input end of the data collection module is respectively unidirectionally connected to a firewall and an external intelligence library. The data collection module is bidirectionally connected to a machine learning and risk prediction module. The output end of the data collection module is unidirectionally connected to a monitoring and auditing module. The machine learning and risk prediction module is bidirectionally connected to the monitoring and auditing module. The machine learning and risk prediction module is bidirectionally connected to the work order system module. The work order system module is respectively bidirectionally connected to a user terminal, a work order adjustment module and an automated execution module. The automated execution module is bidirectionally connected to the firewall.
5. The firewall automation management system based on the work order system according to claim 4, characterized in that, The data collection module is responsible for collecting data from multiple data sources, including the historical network connection information recorded in the firewall log, all the work order details in the past work order system, external security threat intelligence sources, and the real-time running status data of the firewall. The work order system module is used to receive the original firewall configuration change work order submitted by the user and transmit the work order information to the machine learning and risk prediction module for risk prediction. The monitoring and auditing module is used to monitor the running status of the firewall in real time and conduct data interaction with the risk prediction module to provide real-time data support for risk prediction. The user terminal is used for the user to submit a firewall configuration change work order to the work order system.
6. The firewall automation management system based on the work order system according to claim 5, characterized in that The automated execution module is used to interact with the firewall device after the adjusted work order is approved, and send the adjusted firewall configuration instruction to the target firewall device for configuration change operation. The work order adjustment module views the risk assessment report generated by the risk prediction module. When the risk exceeds the preset threshold, the work order adjustment module will start the dynamic work order adjustment mechanism to adjust the firewall configuration change content in the work order.
Citation Information
Patent Citations
Arch bridge construction single-end management system based on big data
CN117787711A
Information security management method and system
CN119089455A