A Security Audit and Compliance Check Method in IPv6 Network

By conducting security audits and compliance inspections on the active events of the IPv6 network, a level distribution is generated, and the problem of low monitoring efficiency in the existing technology is solved, accurate security audits and compliance inspections are achieved, and the monitoring efficiency of the IPv6 network is improved.

CN119788435BActive Publication Date: 2025-07-08BEIJING HUADIAN TIANREN ELECTRIC POWER CONTROL TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510280241.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-11
Publication Date
2025-07-08
Estimated Expiration
2045-03-11

AI Technical Summary

Technical Problem

The existing technology cannot conduct accurate security audits and compliance inspections on IPv6 networks, resulting in low monitoring efficiency.

Method used

By obtaining active events in the IPv6 network, generating event logs and conducting security audits, statistical level distribution, generating processing instructions based on evaluation results, redetermining component operating parameters, and achieving accurate security audits and compliance inspections.

Benefits of technology

It improves the monitoring efficiency of IPv6 network, ensures the system operation efficiency, and conducts targeted adjustments based on activity events, achieving accurate security audits and compliance inspections.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788435B_ABST
    Figure CN119788435B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of communication technologies, and in particular, to a method for security auditing and compliance checking in an IPv6 network. The present invention obtains activity events within a detection period in the IPv6 network, generates event logs for each activity event, generates corresponding activity items for each event log, collects and stores each preset activity item, performs security auditing on each event log to generate audit logs of corresponding levels, statistically analyzes the level distribution of each audit log within the detection period, makes an assessment for the IPv6 network based on the level distribution, the assessment includes performing security auditing and compliance checking on the IPv6 network, generates corresponding processing instructions based on the assessment results or completes the periodic assessment of the IPv6 network, and re-determines the operating parameters of the corresponding components based on the received processing instructions. The present invention effectively realizes accurate security auditing, compliance checking and targeted adjustment of the IPv6 network according to activity events, and effectively improves the monitoring efficiency for the IPv6 network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and in particular, to a method for security auditing and compliance checking in an IPv6 network. Background Art

[0002] IPv6 is the 6th version of the Internet protocol. The address length of IPv6 is 128 bits, and the total number of available IP addresses is approximately 340 trillion. Compared with IPv4, IPv6 has a longer address length and can provide a larger total number of IP addresses, effectively solving the problem that IPv4 cannot meet the current and future network requirements. As the next-generation Internet protocol, IPv6 can provide sufficient address space and efficient network performance to meet the needs of future network development. Conducting security auditing on the IPv6 network can record network behaviors, and the compliance checking of IPv6 can ensure that the network environment complies with relevant standards and regulations. The security auditing and compliance checking of the IPv6 network can discover potential security hazards and vulnerabilities, and avoid security problems and data leakage problems caused by improper network configurations.

[0003] Chinese Patent Application Publication No.: CN116545984A, discloses a method and device for IPv6 address allocation. The method performs structured processing on each IP network segment in the obtained allocated network segment information to generate a structured IP network segment, and based on this, an IP network segment information pool is established. The subnet number of each structured IP network segment in the IP network segment information pool is calculated based on the IP network segment demand prefix and the affiliated unit received from the application end. Then, the subnet number and the network address prefix of the structured IP network segment are combined to generate a set of binary tuples, and based on this set and the IP network segment demand prefix, an allocated subnet number set is generated. Any natural number that does not exist in the allocated subnet number set is used as an unallocated subnet number, and padding processing is performed to generate an unallocated IPv6 address and return it to the application end.

[0004] It can be seen that the above solution can quickly and accurately generate an unallocated IPv6 address and return it to the application end by receiving the IP network segment demand prefix and the affiliated unit from the application end, improving the generation efficiency of the unallocated IPv6 address while optimizing the user experience. However, the above solution cannot perform accurate security auditing, compliance checking, and targeted adjustment on the IPv6 network according to activity events, thus unable to ensure the monitoring efficiency for the IPv6 network. Summary of the Invention

[0005] Therefore, the present invention provides a method for security auditing and compliance checking in an IPv6 network to overcome the problem in the prior art that accurate security auditing, compliance checking, and targeted adjustment of the IPv6 network cannot be performed according to activity events, resulting in low monitoring efficiency for the IPv6 network.

[0006] To achieve the above object, the present invention provides a security auditing and compliance checking method in an IPv6 network, including:

[0007] Obtaining active events within a detection period in the IPv6 network;

[0008] Sequentially generating event logs for each of the active events, and generating corresponding active items for each event log;

[0009] Collecting and storing each preset active item from the IPv6 network;

[0010] Performing security auditing on each of the event logs to generate audit logs of corresponding levels;

[0011] Statistically analyzing the level distribution of each of the audit logs within the detection period;

[0012] Evaluating the IPv6 network based on the level distribution;

[0013] Generating corresponding processing instructions based on the evaluation result,

[0014] Or, completing the periodic evaluation of the IPv6 network and evaluating the IPv6 network in the next detection period;

[0015] Wherein, the evaluation includes performing security auditing on the IPv6 network and performing compliance checking on the IPv6 network;

[0016] Re-determining the operating parameters of the corresponding components based on the received processing instructions.

[0017] The process of performing security auditing on each of the event logs to generate the audit logs of corresponding levels includes:

[0018] For a single active event, the active items in the event log of the active event include time node, terminal address, type of request information, digital signature, and request result;

[0019] Performing security auditing on each of the event logs based on the active items in each of the event logs, and generating audit logs of corresponding levels for each of the event logs according to the audit results.

[0020] The process of performing security auditing on each of the event logs based on the active items in each of the event logs, and generating audit logs of corresponding levels for each of the event logs according to the audit results includes:

[0021] Matching and comparing the active items in a single event log with each of the preset active items;

[0022] When a single said active item is consistent with a single said preset active item, the active item passes the matching comparison;

[0023] Count the number of the active items that pass the matching comparison in a single said event log, and record the obtained number of active items as the number of active items;

[0024] Calculate the ratio of the number of the active items to the total number of the active items, and record the obtained ratio as the proportion of matching items;

[0025] When the proportion of matching items is greater than a second preset proportion of matching items, it is determined that a single said event log passes the security audit, and the corresponding said audit log is recorded as a first-level audit log;

[0026] When the proportion of matching items is less than or equal to the second preset proportion of matching items and greater than a first preset proportion of matching items, perform a level evaluation on the said audit log corresponding to the event log based on the said request result;

[0027] When the proportion of matching items is less than or equal to the first preset proportion of matching items, it is determined that a single said event log fails the security audit, and the corresponding said audit log is recorded as a third-level audit log;

[0028] Complete the level evaluation of each said audit log corresponding to each said event log in sequence.

[0029] Further, the process of performing the level evaluation on the said audit log corresponding to the event log based on the said request result includes:

[0030] Obtain the request result of the active event corresponding to a single said event log;

[0031] When the request result is rejection, it is determined that a single said event log passes the security audit, and the corresponding said audit log is recorded as a second-level audit log;

[0032] When the request result is approval, it is determined that a single said event log fails the security audit, and the corresponding said audit log is recorded as a third-level audit log.

[0033] Further, the process of performing an evaluation on the IPv6 network based on the level distribution includes:

[0034] When the level distribution is that the number of first-level audit logs is greater than the number of second-level audit logs and greater than the number of third-level audit logs, it is determined that the IPv6 network passes the security audit within the detection period, and perform an evaluation on the security audit of the IPv6 network in the next detection period;

[0035] When the quantity of the secondary audit logs is greater than that of the primary audit logs and greater than that of the tertiary audit logs in the hierarchical distribution, it is determined that the IPv6 network fails the security audit during the detection period, and the reason why the quantity of the secondary audit logs is greater than that of the primary audit logs and greater than that of the tertiary audit logs is determined based on the log quantity ratio, where the log quantity ratio is the ratio of the quantity of the secondary audit logs to the quantity of the tertiary audit logs;

[0036] When the quantity of the tertiary audit logs is greater than that of the primary audit logs and greater than that of the secondary audit logs in the hierarchical distribution, it is determined that the IPv6 network fails the security audit during the detection period, and a compliance check is performed on the IPv6 network.

[0037] Further, the process of determining the reason why the quantity of the secondary audit logs is greater than that of the primary audit logs and greater than that of the tertiary audit logs based on the log quantity ratio includes:

[0038] When the log quantity ratio is greater than the preset log quantity ratio, it is determined that there are security risks in the IPv6 network, and a notice to optimize the data interaction security algorithm in the IPv6 network is issued;

[0039] When the log quantity ratio is less than or equal to the preset log quantity ratio, it is determined that the compliance check needs to be performed on the IPv6 network.

[0040] Further, the process of performing the compliance check on the IPv6 network includes:

[0041] Each activity item that fails the matching comparison in each of the tertiary audit logs is determined in sequence, and the obtained activity items are recorded as tertiary activity items;

[0042] The quantity of each of the tertiary activity items is counted, and the variance of the quantity of each of the tertiary activity items is calculated, and the obtained variance is recorded as the item quantity variance;

[0043] When the item quantity variance is less than or equal to the preset item quantity variance, it is determined that the IPv6 network fails the compliance check, and the reason for the failure of compliance is that there are problems with the network, and a network maintenance notice is issued;

[0044] When the item quantity variance is greater than the preset item quantity variance, it is determined that the IPv6 network fails the compliance check, and the reason for the failure of compliance of the IPv6 network is determined based on the quantity of each of the tertiary activity items.

[0045] Further, the process of evaluating the reason why the compliance of the IPv6 network does not meet the standard based on the quantity of each of the third-level activity items includes:

[0046] When the third-level activity item with the largest quantity is the time node, record each event log that fails to pass the matching comparison at the time node as a node event log;

[0047] Determine the quantity of the node event logs that match the third-level audit logs, and record the obtained quantity as the node matching quantity;

[0048] Calculate the ratio of the node matching quantity to the total number of the node event logs, and record the obtained ratio as the node ratio;

[0049] When the node ratio is greater than the preset node ratio, evaluate that the quantity of the event logs audited during the security audit of the IPv6 network is greater than the audit standard, and optimize the audit cycle based on the node ratio;

[0050] When the node ratio is less than or equal to the preset node ratio, evaluate that there is an increase or deletion in the event logs, and issue a notice that the event log data does not meet the standard.

[0051] Further, the process of optimizing the audit cycle based on the node ratio includes:

[0052] Calculate the difference between the node ratio and the preset node ratio, and record the obtained difference as the node ratio difference;

[0053] Reduce the audit cycle based on the node ratio difference, and the reduction amplitude of the audit cycle is proportional to the log ratio difference.

[0054] Further, the process of comparing the quantities of each of the third-level activity items to determine the third-level activity item with the largest quantity includes:

[0055] When the activity item with the largest quantity is the terminal address or the digital signature, optimize the firewall of the IPv6 network;

[0056] Record each event log that fails to pass the matching comparison for the terminal address and the digital signature as a marked event log;

[0057] Count the quantity of the marked event logs with the request result being passed in the marked event logs, and record the obtained quantity as the log passed quantity;

[0058] Calculate the ratio of the log passed quantity to the total number of the marked event logs, and record the obtained ratio as the marked ratio;

[0059] Increase the memory of the firewall in the IPv6 network based on the marking ratio, and the increase amplitude of the firewall's memory is proportional to the marking ratio.

[0060] Compared with the prior art, the beneficial effects of the present invention are as follows: by periodically obtaining active events in the IPv6 network, the present invention effectively realizes the real-time collection of active events in the IPv6 network, conducts security audits on each event log to generate audit logs of corresponding levels, and evaluates the IPv6 network based on the level distribution of each audit log. The evaluation includes conducting a security audit on the IPv6 network and a compliance check on the IPv6 network, effectively realizing accurate security audit and compliance check of the IPv6 network according to active events, generating corresponding processing instructions based on the evaluation results, re-determining the operating parameters of the corresponding components based on the received processing instructions, effectively ensuring the operation efficiency of the system while effectively realizing the targeted adjustment of the IPv6 network according to active events, and effectively improving the monitoring efficiency for the IPV6 network.

[0061] The present invention classifies the active items of the event log, which can more clearly analyze each active event in detail, is conducive to accurately generating audit logs of corresponding levels for each active event, and further improves the monitoring efficiency for the IPV6 network.

[0062] The present invention matches and compares the active items in the event log with the preset active items, evaluates whether a single event log passes the security audit based on the proportion of the matching items, and conducts a level evaluation on the corresponding audit log, which can more accurately conduct a level evaluation on the audit log corresponding to the event log. While further realizing the accurate security audit of the IPv6 network according to active events, it further improves the monitoring efficiency for the IPV6 network.

[0063] Furthermore, when the proportion of the matching items is less than or equal to the second preset matching item proportion and greater than the first preset matching item proportion, the present invention conducts a level evaluation on the audit log corresponding to the event log based on the request result, effectively avoiding the situation where the event log does not correspond to the generated audit log when the proportion of the matching items is within the above range. While further realizing the accurate security audit of the IPv6 network according to active events, it further improves the monitoring efficiency for the IPV6 network.

[0064] Furthermore, the present invention evaluates the IPv6 network based on the hierarchical distribution of the quantity of first-level audit logs, the quantity of second-level audit logs, and the quantity of third-level audit logs, and can quickly and accurately evaluate whether the activity events obtained during the detection period pass the security audit. While further realizing the accurate security audit of the IPv6 network according to the activity events, the monitoring efficiency for the IPv6 network is further improved.

[0065] Furthermore, when the hierarchical distribution is such that the quantity of second-level audit logs is greater than the quantity of first-level audit logs and greater than the quantity of third-level audit logs, the present invention can timely and accurately determine the reason why the quantity of second-level audit logs is greater than the quantity of first-level audit logs and greater than the quantity of third-level audit logs based on the log quantity ratio. When it is determined that the reason for non-passing is that there are security hazards in the IPv6 network, a notice to optimize the data interaction security algorithm in the IPv6 network is issued to effectively handle the existing security hazards. When it is determined that a compliance check is required, the compliance check is carried out. While further realizing the targeted adjustment of the IPv6 network according to the activity events, the monitoring efficiency for the IPv6 network is further improved.

[0066] Furthermore, when the present invention conducts a compliance check on IPv6, it evaluates whether the compliance check is passed based on the variance of the project quantity, further realizing the accurate compliance check of the IPv6 network according to the activity events. The variance of the project quantity can effectively and accurately evaluate the compliance of the IPv6 network, ensuring the consistency between the activity events and the evaluation results. When it is determined that the reason for non-passing the compliance check is that there are problems with the network, a network maintenance notice is issued, further realizing the targeted adjustment of the IPv6 network according to the activity events, avoiding the occurrence of situations where the network does not meet the standards, and further improving the monitoring efficiency for the IPv6 network.

[0067] Furthermore, the present invention evaluates the reason why the compliance of the IPv6 network does not meet the standards based on the quantity of each third-level activity item. When the third-level activity item with the largest quantity is the time node, the node ratio is calculated, and the node ratio is used to evaluate and optimize the audit cycle or issue a notice that the event log data does not meet the standards, further ensuring the operation efficiency of the system and accurately evaluating the reason why the compliance does not meet the standards. While further realizing the accurate compliance check of the IPv6 network according to the activity events, the monitoring efficiency for the IPv6 network is further improved.

[0068] Furthermore, the present invention reduces the audit period based on the node ratio difference, further ensuring the operation efficiency of the system, effectively avoiding the occurrence of the situation where the time node is the tertiary activity item with the largest number due to the non-compliance of the audit period. While further realizing the accurate security audit and compliance check of the IPv6 network according to the activity events, the monitoring efficiency for the IPv6 network is further improved.

[0069] Furthermore, when the activity item with the largest number is the terminal address or digital signature, the present invention increases the memory of the firewall in the IPv6 network based on the marked ratio, effectively avoiding the occurrence of the situation where the terminal address or digital signature is the tertiary activity item with the largest number due to the non-compliance of the firewall memory. While further realizing the targeted adjustment of the IPv6 network according to the activity events, the monitoring efficiency for the IPv6 network is further improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0070] Figure 1 It is a structural block diagram of the security audit and compliance check system in the IPv6 network according to an embodiment of the present invention;

[0071] Figure 2 It is a flowchart of the security audit and compliance check method in the IPv6 network according to an embodiment of the present invention;

[0072] Figure 3 It is a flowchart of performing security audit on each event log to generate audit logs of corresponding levels according to an embodiment of the present invention;

[0073] Figure 4 It is a flowchart of evaluating the IPv6 network according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0074] In order to make the objectives and advantages of the present invention clearer, the present invention will be further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0075] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are only used to explain the technical principle of the present invention and do not limit the protection scope of the present invention.

[0076] In addition, it should be noted that in the description of the present invention, unless otherwise clearly specified and defined, the terms "installation", "connection", and "coupling" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium, and it can be the communication inside two components. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0077] Please refer to Figure 1 as shown, which is a structural block diagram of the security audit and compliance check system in the IPv6 network according to an embodiment of the present invention. The structure of the embodiment of the present invention includes a data extraction unit, a data audit unit, a database, an audit analysis unit, and a control unit; wherein,

[0078] the data extraction unit is used to obtain the active events within the detection period in the IPv6 network;

[0079] the data audit unit is connected to the data extraction unit and is used to generate event logs for each of the active events in sequence and generate corresponding active items for each event log;

[0080] the database is connected to the data audit unit and is used to collect and store each preset active item from the IPv6 network;

[0081] the data audit unit is also used to perform security audits on each of the event logs to generate audit logs of corresponding levels;

[0082] the audit analysis unit is connected to the data audit unit and is used to count the level distribution of each of the audit logs within the detection period;

[0083] the audit analysis unit is also used to evaluate the IPv6 network based on the level distribution;

[0084] the audit analysis unit is also used to generate corresponding processing instructions based on the evaluation results, or complete the periodic evaluation of the IPv6 network and evaluate the IPv6 network in the next detection period; wherein, the evaluation includes performing a security audit on the IPv6 network and performing a compliance check on the IPv6 network;

[0085] the control unit is respectively connected to the data audit unit and the audit analysis unit and is used to re-determine the operating parameters of the corresponding components based on the received processing instructions.

[0086] Please refer to Figure 2As shown, it is a flowchart of the security audit and compliance check method in the IPv6 network of the embodiment of the present invention. The method of the embodiment of the present invention includes:

[0087] Obtain the active events within the detection period D in the IPv6 network, where the detection period D = 48h in the embodiment of the present invention;

[0088] Generate respective event logs for each of the active events in sequence, and generate respective activity items corresponding to the event logs;

[0089] Collect and store each of the preset activity items from the IPv6 network;

[0090] Conduct a security audit on each of the event logs to generate the audit logs of corresponding levels;

[0091] Statistically analyze the level distribution of each of the audit logs within the detection period;

[0092] Evaluate the IPv6 network based on the level distribution;

[0093] Generate corresponding processing instructions based on the evaluation results,

[0094] Or, complete the periodic evaluation of the IPv6 network and conduct an evaluation on the IPv6 network of the next detection period;

[0095] Among them, the evaluation includes conducting a security audit on the IPv6 network and conducting a compliance check on the IPv6 network;

[0096] Re-determine the operating parameters of the corresponding components based on the received processing instructions.

[0097] Please refer to Figure 3 As shown, it is a flowchart of conducting a security audit on each of the event logs to generate the audit logs of corresponding levels in the embodiment of the present invention. The process of conducting a security audit on each of the event logs to generate the audit logs of corresponding levels in the embodiment of the present invention includes:

[0098] For a single active event, the activity items in the event log of this active event include time node, terminal address, type of request information, digital signature, and request result;

[0099] Conduct a security audit on each of the event logs based on each of the activity items in the event logs, and generate respective audit logs of corresponding levels for each of the event logs according to the audit results.

[0100] Please continue to refer to Figure 3As shown, the process of the embodiment of the present invention for performing security audits on each event log based on each activity item in each of the event logs and generating each audit log corresponding to each event log according to the audit results includes:

[0101] Match and compare each activity item in a single event log with each of the preset activity items;

[0102] When a single activity item is consistent with a single preset activity item, the activity item passes the match and comparison;

[0103] Count the number of activity items that pass the match and comparison in a single event log, and record the obtained number of activity items as the number of activity items;

[0104] Calculate the ratio of the number of activity items to the total number of activity items, and record the obtained ratio as the proportion of matching items;

[0105] Based on the proportion of matching items, perform a grade evaluation on the audit log corresponding to a single event log;

[0106] When the proportion of matching items is greater than the second preset proportion of matching items R2, it is determined that a single event log passes the security audit, and the corresponding audit log is recorded as a first-level audit log. In this embodiment, the second preset proportion of matching items R2 = 79%;

[0107] When the proportion of matching items is less than or equal to the second preset proportion of matching items R2 and greater than the first preset proportion of matching items R1, perform a grade evaluation on the audit log corresponding to the event log based on the request result. In this embodiment, the first preset proportion of matching items R1 = 20%;

[0108] When the proportion of matching items is less than or equal to the first preset proportion of matching items R1, it is determined that a single event log fails the security audit, and the corresponding audit log is recorded as a third-level audit log;

[0109] Complete the grade evaluation of each audit log corresponding to each event log in sequence.

[0110] Please continue to refer to Figure 3 As shown, the process of the embodiment of the present invention for performing the grade evaluation on the audit log corresponding to the event log based on the request result includes:

[0111] Obtain the request result of the activity event corresponding to a single event log;

[0112] When the request result is rejection, evaluate that a single event log passes the security audit, and record the corresponding audit log as a secondary audit log;

[0113] When the request result is approval, evaluate that a single event log fails the security audit, and record the corresponding audit log as a tertiary audit log.

[0114] Please refer to Figure 4 As shown, it is a flowchart for the embodiment of the present invention to evaluate the IPv6 network. The process for the embodiment of the present invention to evaluate the IPv6 network based on the grade distribution includes:

[0115] Count the quantities of the primary audit log, the secondary audit log, and the tertiary audit log respectively, and determine the grade distribution of each audit log;

[0116] When the grade distribution is that the quantity of the primary audit log is greater than the quantity of the secondary audit log and greater than the quantity of the tertiary audit log, evaluate that the IPv6 network passes the security audit during the detection period, and evaluate the security audit of the IPv6 network in the next detection period;

[0117] When the grade distribution is that the quantity of the secondary audit log is greater than the quantity of the primary audit log and greater than the quantity of the tertiary audit log, evaluate that the IPv6 network fails the security audit during the detection period, and determine the reason why the quantity of the secondary audit log is greater than the quantity of the primary audit log and greater than the quantity of the tertiary audit log based on the log quantity ratio, where the log quantity ratio is the ratio of the quantity of the secondary audit log to the quantity of the tertiary audit log;

[0118] When the grade distribution is that the quantity of the tertiary audit log is greater than the quantity of the primary audit log and greater than the quantity of the secondary audit log, evaluate that the IPv6 network fails the security audit during the detection period, and conduct a compliance check on the IPv6 network.

[0119] Please continue to refer to Figure 4 As shown, the process for the embodiment of the present invention to determine the reason why the quantity of the secondary audit log is greater than the quantity of the primary audit log and greater than the quantity of the tertiary audit log based on the log quantity ratio includes:

[0120] When the log quantity ratio is greater than the preset log quantity ratio A, evaluate that the IPv6 network has a security hidden danger, and send a notice to optimize the data interaction security algorithm in the IPv6 network. In the embodiment of the present invention, the preset log quantity ratio A = 1.5;

[0121] Specifically, when optimizing the data interaction security algorithm in the IPv6 network, vulnerability scanning and risk analysis are performed on the network system, etc., the risks that may be brought by various security hazards are evaluated, potential attack paths and the possibility of data leakage are considered, etc., specific security goals are determined according to the relevant risk assessment results, the risk of data leakage is reduced to the target ratio, the data interaction security algorithm is improved in combination with the network characteristics and security requirements, and the security algorithm is integrated into the network system and application programs to ensure the compatibility and stability of the security algorithm with the system. Comprehensive functional testing, simulated attack testing, etc. are performed on the system integrated with the new security algorithm to verify whether the optimized system can resist various network attacks;

[0122] When the ratio of the number of logs is less than or equal to the preset ratio A of the number of logs, it is determined that the IPv6 network needs to be subjected to the compliance check.

[0123] Please continue to refer to Figure 4 As shown, the process of the embodiment of the present invention performing the compliance check on the IPv6 network includes:

[0124] Determine each activity item that fails to pass the matching comparison in each of the third-level audit logs in sequence, and record the obtained activity items as third-level activity items;

[0125] Count the number of each of the third-level activity items, and calculate the variance of the number of each of the third-level activity items, and record the obtained variance as the variance of the number of items;

[0126] When the variance of the number of items is less than or equal to the preset variance C of the number of items, it is determined that the IPv6 network fails the compliance check, and the reason for the failure of compliance is that there is a problem with the network, and a network maintenance notice is issued. Among them, the preset variance C of the number of items in the embodiment of the present invention is 0.32;

[0127] When the variance of the number of items is greater than the preset variance C of the number of items, it is determined that the IPv6 network fails the compliance check, and the reason for the failure of compliance of the IPv6 network is evaluated based on the number of each of the third-level activity items.

[0128] Please continue to refer to Figure 4 As shown, the process of the embodiment of the present invention evaluating the reason why the compliance of the IPv6 network does not meet the standard based on the number of each of the third-level activity items includes:

[0129] Compare the number of each of the third-level activity items to determine the third-level activity item with the largest number;

[0130] When the third-level activity item with the largest number is the time node, record each event log that fails to pass the matching comparison at the time node as a node event log;

[0131] Determine the number of node event logs that match the tertiary audit logs, and record the obtained number as the node matching number;

[0132] Calculate the ratio of the node matching number to the total number of node event logs, and record the obtained ratio as the node ratio;

[0133] When the node ratio is greater than the preset node ratio N, it is determined that the number of event logs audited during the security audit of the IPv6 network is greater than the audit standard, and the audit cycle is optimized based on the node ratio, where the preset node ratio N = 72.8% in the embodiments of the present invention;

[0134] When the node ratio is less than or equal to the preset node ratio N, it is determined that there is a situation of addition or deletion of the event logs, and a notice that the event log data does not meet the standard is issued.

[0135] Please continue to refer to Figure 4 As shown, the process of optimizing the audit cycle based on the node ratio in the embodiments of the present invention includes:

[0136] Calculate the difference between the node ratio and the preset node ratio, and record the obtained difference as the node ratio difference;

[0137] Reduce the audit cycle based on the node ratio difference;

[0138] When the node ratio difference is greater than the second preset node ratio difference F2, reduce the audit cycle to 0.88 times the initial audit cycle, where the second preset node ratio difference F2 = 21.3% in the embodiments of the present invention;

[0139] When the node ratio difference is less than or equal to the second preset node ratio difference F2 and greater than the first preset node ratio difference F1, reduce the audit cycle to 0.91 times the initial audit cycle, where the first preset node ratio difference F1 = 12.9% in the embodiments of the present invention;

[0140] When the node ratio difference is less than or equal to the first preset node ratio difference F1, reduce the audit cycle to 0.95 times the initial audit cycle.

[0141] Please continue to refer to Figure 4 As shown, the process of comparing the quantities of each of the tertiary activity items to determine the tertiary activity item with the largest quantity in the embodiments of the present invention includes:

[0142] When the activity item with the largest quantity is the terminal address or the digital signature, optimize the firewall of the IPv6 network;

[0143] Record the event logs for which the terminal address and the digital signature do not pass the matching comparison as marked event logs;

[0144] Count the number of marked event logs with a passed request result in the marked event logs, and record the obtained number as the log passing number;

[0145] Calculate the ratio of the log passing number to the total number of the marked event logs, and record the obtained ratio as the marked ratio;

[0146] Increase the memory of the firewall in the IPv6 network based on the marked ratio;

[0147] When the marked ratio is greater than the second preset marked ratio M2, increase the memory of the firewall to 1.23 times the memory of the initial firewall, where the second preset marked ratio M2 = 52% in the embodiments of the present invention;

[0148] When the marked ratio is less than or equal to the second preset marked ratio M2 and greater than the first preset marked ratio M1, increase the memory of the firewall to 1.16 times the memory of the initial firewall, where the first preset marked ratio M1 = 33% in the embodiments of the present invention;

[0149] When the marked ratio is less than or equal to the first preset marked ratio M1, increase the memory of the firewall to 1.08 times the memory of the initial firewall. Embodiment 1

[0150] Obtain 21 active events within a detection period of 48h in the IPv6 network, and generate event logs for each active event in sequence. For a single active event, its event log includes a time node, a terminal address, the type of request information, a digital signature, and a request result. Match and compare the time node, terminal address, type of request information, digital signature, and request result of each event log with each preset event log, and perform a security audit on each event log to generate an audit log of the corresponding level.

[0151] For a single activity event, each activity item in the single event log is matched and compared with each preset activity item. When a single activity item is consistent with a single preset activity item, the activity item passes the matching comparison. The number of activity items that pass the matching is 5. Calculate the ratio of the number of activity items 5 to the total number of activity items 5. The proportion of matching items is 100%. When it is greater than the second preset proportion of matching items 79%, it is determined that the event log passes the security audit, and the audit log corresponding to the activity event is recorded as a first-level audit log; for a single activity event, the number of activity items that pass the matching is 3. Calculate the ratio of the number of activity items 3 to the total number of activity items 5. The proportion of matching items is 60%. When it is less than or equal to the second preset proportion of matching items 79% and greater than the first preset proportion of matching items 20%, based on the request result, the level evaluation of the audit log corresponding to the event log is performed. When the request result is rejection, it is determined that the single event log passes the security audit, and the corresponding audit log is recorded as a second-level audit log. When the request result is approval, it is determined that the single event log fails the security audit, and the corresponding audit log is recorded as a third-level audit log; for a single activity event, the number of activity items that pass the matching is 1. Calculate the ratio of the number of activity items 1 to the total number of activity items 5. The proportion of matching items is 20%. When it is less than or equal to the first preset proportion of matching items 20%, it is determined that the single event log fails the security audit, and the corresponding audit log is recorded as a third-level audit log; the level evaluation of each audit log corresponding to each event log is completed in sequence.

[0152] The number of first-level audit logs is counted as 18, the number of second-level audit logs is 2, and the number of third-level audit logs is 1. It is determined that the IPv6 network passes the security audit during the detection period, and the security audit of the IPv6 network in the next detection period is evaluated. Embodiment 2

[0153] Twenty-three activity events within a 48-hour detection period in the IPv6 network are obtained. The level evaluation of each activity event is completed in sequence. The process of level evaluation is the same as that in Embodiment 1. The number of second-level audit logs is counted as 13, the number of first-level audit logs is 2, and the number of third-level audit logs is 8. It is determined that the IPv6 network fails the security audit during the detection period, and the reason for the failure of the security audit for the IPv6 network is determined based on the ratio of the log quantities. The ratio of the number of second-level logs 13 to the number of third-level logs 8 is 1.625, which is greater than the preset log quantity ratio 1.5. It is determined that there are security risks in the IPv6 network, and a notice is issued to optimize the data interaction security algorithm in the IPv6 network. Embodiment 3

[0154] Obtain 22 active events within a detection period of 48 hours in the IPv6 network, and complete the level evaluation of each active event in sequence. The process of level evaluation is the same as that in Embodiment 1. Count the number of level-three audit logs as 12, the number of level-one audit logs as 9, and the number of level-two audit logs as 1. It is determined that the IPv6 network fails the security audit within the detection period. Conduct a compliance check on the IPv6 network, determine each active item that fails to pass the matching comparison in each level-three audit log in sequence, and record the obtained active items as level-three active items. Count the number of each level-three active item. The number of time nodes is 5, the number of terminal addresses is 2, the number of types of request information is 1, the number of digital signatures is 2, and the number of request results is 2. Calculate the variance of the number of items of each level-three active item as 2.3, which is greater than the preset variance of the number of items 0.32. It is determined that the IPv6 network fails the compliance check. Based on the number of each level-three active item, determine the reason for the failure of the IPv6 network's compliance. Determine that the level-three active item with the largest number is the time node, and record each event log that fails to pass the matching comparison of the time node as a node event log. Determine that the node matching number 4 of the node event log 5 matching the level-three audit log 12, and calculate the node ratio of the node matching number 4 to the total number 5 of the node event logs as 80%, which is greater than the preset node ratio 72.8%. It is determined that the number of event logs audited during the security audit is greater than the audit standard, and optimize the audit period based on the node ratio. Calculate the difference between the node ratio 80% and the preset node ratio 72.8% as 7.2%, which is less than or equal to the first preset node ratio difference 12.9%. Reduce the audit period to 0.95 times the initial audit period. Embodiment 4

[0155] Obtain 20 active events within a detection period of 48 hours in the IPv6 network, and successively complete the level evaluation of each active event. The process of the level evaluation is the same as that in Embodiment 1. Count the number of level-three audit logs as 11, the number of level-one audit logs as 8, and the number of level-two audit logs as 1. It is determined that the IPv6 network fails the security audit within the detection period. Conduct a compliance check on the IPv6 network, successively determine each active item that fails the matching comparison in each level-three audit log, and record the obtained active items as level-three active items. Count the number of each level-three active item. The number of time nodes is 1, the number of terminal addresses is 6, the number of types of request information is 2, the number of digital signatures is 1, and the number of request results is 1. Calculate the variance of the number of items of each level-three active item as 4.7, which is greater than the preset variance of the number of items of 0.32. It is determined that the IPv6 network fails the compliance check. Based on the number of each level-three active item, determine the reason for the failure of the IPv6 network's compliance. It is determined that the level-three active item with the largest number is the terminal address. Optimize the firewall of the IPv6 network. Record the event logs of each terminal address that fails the matching comparison as marked event logs. Count the number of marked event logs with a passed request result as 5 among the marked event logs. Calculate the marked ratio of 83.33% of the number of passed logs of 5 to the total number of marked event logs of 6, which is greater than the second preset marked ratio of 52%. Increase the memory of the firewall to 1.23 times the memory of the initial firewall.

[0156] So far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.

[0157] The above are only the preferred embodiments of the present invention and are not used to limit the present invention; for those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent substitution, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A security auditing and compliance checking method in an IPv6 network, characterized in that, Including: Obtain the active events within the detection period in the IPv6 network; Generate respective event logs for each of the active events in sequence, and generate respective activity items corresponding to the event logs; Collect and store each of the preset activity items from the IPv6 network; Conduct a security audit on each of the event logs to generate audit logs of corresponding levels; Statistically analyze the level distribution of each of the audit logs within the detection period; Conduct an assessment on the IPv6 network based on the level distribution; Generate corresponding processing instructions based on the assessment result, Or, complete the periodic assessment of the IPv6 network and conduct an assessment on the IPv6 network of the next detection period; Wherein, the assessment includes conducting a security audit on the IPv6 network and conducting a compliance check on the IPv6 network; Re-determine the operating parameters of the corresponding components based on the received processing instructions; The process of conducting a security audit on each of the event logs to generate the audit logs of corresponding levels includes: For a single active event, the activity items in the event log of this active event include time node, terminal address, type of request information, digital signature, and request result; Conduct a security audit on each of the event logs based on each of the activity items in the event logs, and generate respective audit logs of corresponding levels for each of the event logs according to the audit results; The process of conducting a security audit on each of the event logs based on each of the activity items in the event logs and generating respective audit logs of corresponding levels for each of the event logs according to the audit results includes: Match and compare each of the activity items in a single event log with each of the preset activity items; When a single activity item is consistent with a single preset activity item, this activity item passes the match and comparison; Statistically analyze the number of the activity items that pass the match and comparison in a single event log, and record the obtained number of activity items as the number of activity items; Calculate the ratio of the number of activity items to the total number of activity items, and record the obtained ratio as the proportion of matching items; When the proportion of matching items is greater than the second preset proportion of matching items, assess that a single event log passes the security audit, and record the corresponding audit log as a first-level audit log; When the proportion of matching items is less than or equal to the second preset proportion of matching items and greater than the first preset proportion of matching items, conduct a level evaluation on the audit log corresponding to the event log based on the request result; When the proportion of matching items is less than or equal to the first preset proportion of matching items, assess that a single event log fails the security audit, and record the corresponding audit log as a third-level audit log; Complete the level evaluation of each of the audit logs corresponding to each of the event logs in sequence.

2. The security audit and compliance check method in the IPv6 network according to claim 1, characterized in that, The process of conducting the level evaluation on the audit log corresponding to the event log based on the request result includes: Obtain the request result of the active event corresponding to a single event log; When the request result is rejection, assess that a single event log passes the security audit, and record the corresponding audit log as a second-level audit log; When the request result is passed, it is determined that a single event log fails the security audit, and the corresponding audit log is recorded as a third-level audit log.

3. The security audit and compliance check method in the IPv6 network according to claim 2, characterized in that, The process of evaluating the IPv6 network based on the grade distribution includes: When the number of first-level audit logs in the grade distribution is greater than the number of second-level audit logs and greater than the number of third-level audit logs, it is determined that the IPv6 network passes the security audit during the detection period, and the security audit of the IPv6 network in the next detection period is evaluated; When the number of second-level audit logs in the grade distribution is greater than the number of first-level audit logs and greater than the number of third-level audit logs, it is determined that the IPv6 network fails the security audit during the detection period, and the reason why the number of second-level audit logs is greater than the number of first-level audit logs and greater than the number of third-level audit logs is determined based on the log quantity ratio, where the log quantity ratio is the ratio of the number of second-level audit logs to the number of third-level audit logs; When the number of third-level audit logs in the grade distribution is greater than the number of first-level audit logs and greater than the number of second-level audit logs, it is determined that the IPv6 network fails the security audit during the detection period, and a compliance check is performed on the IPv6 network.

4. The security audit and compliance check method in the IPv6 network according to claim 3, characterized in that, The process of determining the reason why the number of second-level audit logs is greater than the number of first-level audit logs and greater than the number of third-level audit logs based on the log quantity ratio includes: When the log quantity ratio is greater than the preset log quantity ratio, it is determined that there are security risks in the IPv6 network, and a notice to optimize the data interaction security algorithm in the IPv6 network is issued; When the log quantity ratio is less than or equal to the preset log quantity ratio, it is determined that a compliance check needs to be performed on the IPv6 network.

5. The security auditing and compliance checking method in the IPv6 network according to claim 4, wherein The process of performing the compliance check on the IPv6 network includes: Each activity item that fails the matching comparison in each of the third-level audit logs is determined in sequence, and the obtained activity items are recorded as third-level activity items; The number of each of the third-level activity items is counted, and the variance of the number of each of the third-level activity items is calculated, and the obtained variance is recorded as the item quantity variance; When the item quantity variance is less than or equal to the preset item quantity variance, it is determined that the IPv6 network fails the compliance check, and the reason for the failure of compliance is that there is a problem with the network, and a network maintenance notice is issued; When the item quantity variance is greater than the preset item quantity variance, it is determined that the IPv6 network fails the compliance check, and the reason for the failure of compliance of the IPv6 network is evaluated based on the number of each of the third-level activity items.

6. The security audit and compliance check method in the IPv6 network according to claim 5, characterized in that, The process of evaluating the reason why the compliance of the IPv6 network does not meet the standard based on the number of each of the third-level activity items includes: When the most numerous third-level activity item is the time node, each event log that fails the matching comparison at the time node is recorded as a node event log; Determine the number of matches between the node event log and the tertiary audit log, and record the obtained number as the node matching number; Calculate the ratio of the node matching number to the total number of the node event log, and record the obtained ratio as the node ratio; When the node ratio is greater than the preset node ratio, it is evaluated that the number of the event logs audited during the security audit of the IPv6 network is greater than the audit standard, and the audit cycle is optimized based on the node ratio; When the node ratio is less than or equal to the preset node ratio, it is evaluated that there is an addition or deletion of the event logs, and a notice that the event log data does not meet the standard is issued.

7. The security auditing and compliance checking method in the IPv6 network according to claim 6, wherein The process of optimizing the audit cycle based on the node ratio includes: Calculate the difference between the node ratio and the preset node ratio, and record the obtained difference as the node ratio difference; Reduce the audit cycle based on the node ratio difference, and the reduction range of the audit cycle is proportional to the log ratio difference.

8. The security auditing and compliance checking method in the IPv6 network according to claim 6, characterized in that, The process of comparing the quantities of each of the tertiary activity items to determine the tertiary activity item with the largest quantity includes: When the activity item with the largest quantity is the terminal address or the digital signature, optimize the firewall of the IPv6 network; Record each of the event logs for which the terminal address and the digital signature do not pass the matching comparison as a marked event log; Count the number of marked event logs with a passing request result in the marked event logs, and record the obtained number as the log passing number; Calculate the ratio of the log passing number to the total number of the marked event logs, and record the obtained ratio as the marked ratio; Increase the memory of the firewall in the IPv6 network based on the marked ratio, and the increase range of the firewall memory is proportional to the marked ratio.

Citation Information

Patent Citations

  • Method and device for allocating IPV6 (Internet Protocol Version 6) address

    CN116545984A

  • Log-based early warning method and device, server and storage medium

    CN112636957A