Flow cleaning method, device and electronic equipment

By generating a local cache in the security device and using referenced cleaning traffic and threat status for traffic cleaning, the problem of cloud queries consuming computing resources is solved, thereby reducing the cost of firewall use.

CN119814357BActive Publication Date: 2025-11-25SANGFOR TECH INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411752694.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-02
Publication Date
2025-11-25
Estimated Expiration
2044-12-02

AI Technical Summary

Technical Problem

Querying cloud-based threat intelligence databases for traffic scrubbing consumes significant computing resources during large-scale traffic events, increasing the cost of firewall usage.

Method used

By generating a local cache in the security device, the number of times the cloud database is queried is reduced, and the reference cleanup traffic and threat status in the local cache are used for traffic cleanup.

Benefits of technology

This reduces the number of times security devices need to query the cloud, thus reducing computing resource consumption and lowering usage costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119814357B_ABST
    Figure CN119814357B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of Internet, in particular to a traffic cleaning method and device and electronic equipment, the method is applied to a security device, the method comprises the following steps: obtaining i-round traffic to be cleaned, i is an integer greater than 0; matching the i-round traffic to be cleaned based on a preset cleaning rule; if the i-round traffic to be cleaned is not matched to the preset cleaning rule, querying reference cleaning traffic in a cache of the security device, the reference cleaning traffic in the cache comprises reference threat states of reference cleaning traffic and traffic to be cleaned which is not matched to the preset cleaning rule before the i round; if there is target reference cleaning traffic matched to the i-round traffic to be cleaned in the cache; cleaning the i-round traffic to be cleaned based on the reference threat state of the target reference cleaning traffic; the method provided in the application reduces the number of times of traffic cleaning through cloud query of the security device by introducing the cache, and reduces the use cost of the security device.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet, in particular to a traffic cleaning method and device and electronic equipment. BACKGROUND

[0002] In the Internet technology, the firewall is an important tool to guarantee the network security of users, and the firewall cleans the traffic through preset cleaning rules, so as to realize the interception of threat traffic. With the development of Internet technology, in order to cope with more diverse threat traffic, the concept of next-generation firewall is proposed, that is, the firewall can not only clean the traffic through the preset cleaning rules, but also clean the traffic by querying the threat situation library in the cloud. Because the cloud database in the cloud contains a large amount of threat intelligence, the next-generation firewall can intercept more threat traffic, greatly improving the protection capability of the next-generation firewall. However, querying the threat situation library in the cloud to clean the traffic needs to occupy the computing resources of the device where the firewall is located, and in the face of large-scale traffic, a large amount of computing resources needs to be occupied, greatly increasing the use cost of the firewall. SUMMARY

[0003] Therefore, the embodiments of the present application propose a traffic cleaning method, device and electronic equipment, which can generate a local cache according to the query records of the cloud database of the traffic to be cleaned, so as to reduce the number of queries to the cloud database by querying the local cache, thereby reducing the computing resources occupied by querying the cloud database and reducing the use cost of the firewall.

[0004] The embodiments of the present application are implemented by using the following technical solutions:

[0005] In a first aspect, an embodiment of the present application provides a traffic cleaning method applied to a security device, the method comprising: obtaining i-th round traffic to be cleaned, i being an integer greater than 0; matching the i-th round traffic to be cleaned based on a preset cleaning rule to obtain a matching result of the i-th round traffic to be cleaned; if the matching result of the i-th round traffic to be cleaned indicates that the traffic to be cleaned does not match the preset cleaning rule, querying reference cleaning traffic in a cache of the security device based on the i-th round traffic to be cleaned to obtain a query result, the query result being used to indicate whether there is target reference cleaning traffic matching the i-th round traffic to be cleaned in the cache of the security device, the reference cleaning traffic in the cache of the security device including traffic to be cleaned that does not match the preset cleaning rule in the security device before the i-th round, and the cache of the security device further storing a reference threat state of the reference cleaning traffic; and cleaning the i-th round traffic to be cleaned based on the reference threat state of the target reference cleaning traffic.

[0006] In a second aspect, an embodiment of the present application provides a traffic cleaning device applied to a security device, the device comprising: a first obtaining module configured to obtain i-th round traffic to be cleaned, i being an integer greater than 0; a matching module configured to match the i-th round traffic to be cleaned based on a preset cleaning rule to obtain a matching result of the i-th round traffic to be cleaned; a querying module configured to, if the matching result of the i-th round traffic to be cleaned indicates that the traffic to be cleaned does not match the preset cleaning rule, query reference cleaning traffic in a cache of the security device based on the i-th round traffic to be cleaned to obtain a query result, the query result being used to indicate whether there is target reference cleaning traffic matching the i-th round traffic to be cleaned in the cache of the security device, the reference cleaning traffic in the cache of the security device including traffic to be cleaned that does not match the preset cleaning rule in the security device before the i-th round, and the cache of the security device further storing a reference threat state of the reference cleaning traffic; a second obtaining module configured to, if the query result indicates that there is the target reference cleaning traffic matching the i-th round traffic to be cleaned in the cache, obtain the reference threat state of the target reference cleaning traffic from the cache of the security device; and a cleaning module configured to clean the i-th round traffic to be cleaned based on the reference threat state of the target reference cleaning traffic.

[0007] In some embodiments, the query module is further configured to, if the target reference cleaning traffic associated with the i-th round of traffic to be cleaned does not exist in the cache, send a query request to a cloud database based on the i-th round of traffic to be cleaned, the cloud database containing a plurality of threat traffics and threat states corresponding to each threat traffic, the cloud database querying a target threat traffic matching the i-th round of traffic to be cleaned from the plurality of threat traffics and returning a target threat state corresponding to the target threat traffic in response to the query request; the second acquisition module is further configured to receive the target threat state corresponding to the target threat traffic returned by the cloud database in response to the query request; and the cleaning module is further configured to clean the i-th round of traffic to be cleaned based on the target threat state corresponding to the target threat traffic.

[0008] In some embodiments, the traffic cleaning device further comprises an updating module configured to store the target threat traffic as a reference cleaning traffic and store a target threat state corresponding to the target threat traffic as a reference threat state of the reference cleaning traffic in the cache of the security device.

[0009] In some embodiments, the cache of the security device contains a first version number of the cloud database, the second acquisition module is further configured to acquire a current version number of the cloud database; if the current version number and the first version number do not successfully match, the target threat traffics of the first i rounds of the cloud database and the threat states corresponding to the target threat traffics are acquired, the target threat traffics of the first i rounds being target threat traffics queried by the cloud database in response to query requests corresponding to the first i rounds of traffic to be cleaned; and the updating module is further configured to update the cache of the security device based on the target threat traffics of the first i rounds and the threat states corresponding to the target threat traffics.

[0010] In some embodiments, the second acquisition module is further configured to receive the current version number of the cloud database returned by the cloud database in response to the query request, and the updating module is further configured to update the first version number in the cache to the current version number of the cloud database.

[0011] In some embodiments, the updating module is further configured to determine an effective duration of each reference cleaning traffic based on the reference threat states of each reference cleaning traffic in the cache of the security device; and if a storage duration of a reference cleaning traffic in the cache is not less than an effective duration corresponding to the reference cleaning traffic, the reference cleaning traffic and the reference threat state of the reference cleaning traffic are deleted from the cache.

[0012] In some embodiments, the traffic cleaning device further comprises a reporting module, the reporting module is configured to generate a cleaning log corresponding to the to-be-cleaned traffic, the cleaning log comprises the to-be-cleaned traffic and a cleaning result corresponding to the to-be-cleaned traffic, and the reporting module is configured to send the cleaning log to a client.

[0013] In some embodiments, the cleaning module is further configured to, if the matching result of the to-be-cleaned traffic in the i th round indicates that the to-be-cleaned traffic matches the preset cleaning rule, clean the to-be-cleaned traffic in the i th round based on the preset cleaning rule.

[0014] In a third aspect, an embodiment of the present application provides an electronic device, the electronic device comprising one or more processors; a memory; and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to perform the above method.

[0015] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, the computer-readable storage medium storing program code, and the program code being invocable by a processor to perform the above method.

[0016] The flow cleaning method, device and electronic equipment provided by the embodiment of the application, the method is applied to a security device, and the method comprises the following steps: obtaining i-round to-be-cleaned flow, i is an integer greater than 0; matching the i-round to-be-cleaned flow based on a preset cleaning rule to obtain a matching result of the i-round to-be-cleaned flow; if the matching result of the i-round to-be-cleaned flow indicates that the to-be-cleaned flow does not match the preset cleaning rule, querying a reference cleaning flow in a cache of the security device based on the i-round to-be-cleaned flow to obtain a query result, the query result is used to indicate whether there is a reference cleaning flow matching the i-round to-be-cleaned flow in the cache of the security device, the reference cleaning flow in the cache of the security device comprises to-be-cleaned flow that does not match the preset cleaning rule in the security device before the i round, and the cache of the security device also stores a reference threat state of the reference cleaning flow; if the query result indicates that there is a target reference cleaning flow matching the i-round to-be-cleaned flow in the cache, obtaining the reference threat state of the target reference cleaning flow from the cache of the security device; and cleaning the i-round to-be-cleaned flow based on the reference threat state of the target reference cleaning flow. According to the method provided by the application, the reference cleaning flow in the cache of the security device comprises to-be-cleaned flow that does not match the preset cleaning rule before the i round, which cannot be matched and cleaned by the preset cleaning rule in the security device, that is, the reference threat state corresponding to the reference cleaning flow in the cache of the security device is the threat state obtained by querying the cloud. In the case that the i-round to-be-cleaned flow does not match the preset cleaning rule, if the query result indicates that there is a target reference cleaning flow matching the i-round to-be-cleaned flow in the cache, it can be understood that the to-be-cleaned flow has been queried from the cloud database for a period of time, therefore, the reference threat state corresponding to the matched target reference cleaning flow can be used as the threat state of the i-round to-be-cleaned flow, so that the i-round to-be-cleaned flow is cleaned based on the reference threat state of the target reference cleaning flow, thereby avoiding the process of querying the cloud for the i-round to-be-cleaned flow, reducing the number of cloud queries of the security device, and reducing the use cost of the security device.

[0017] These aspects or other aspects of the application will be more apparent in the following description of the embodiments. BRIEF DESCRIPTION OF DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can also be obtained by those skilled in the art without any creative effort.

[0019] Figure 1A scene diagram related to an embodiment of the present application is shown.

[0020] Figure 2 A first flow diagram of a traffic cleaning method provided by an embodiment of the present application is shown.

[0021] Figure 3 A second flow diagram of a traffic cleaning method provided by an embodiment of the present application is shown.

[0022] Figure 4 A third flow diagram of a traffic cleaning method provided by an embodiment of the present application is shown.

[0023] Figure 5 A fourth flow diagram of a traffic cleaning method provided by an embodiment of the present application is shown.

[0024] Figure 6 A fifth flow diagram of a traffic cleaning method provided by an embodiment of the present application is shown.

[0025] Figure 7 Another application scene diagram related to an embodiment of the present application is shown.

[0026] Figure 8 A flow diagram of a traffic cleaning method provided by an embodiment of the present application is shown. Figure 7 A flow diagram of a traffic cleaning method provided by an embodiment of the present application is shown.

[0027] Figure 9 A diagram of a traffic cleaning device provided by an embodiment of the present application is shown.

[0028] Figure 10 A diagram of an electronic device provided by an embodiment of the present application is shown. DETAILED DESCRIPTION

[0029] The embodiments of the present application will be described in detail below with reference to the drawings, in which the same or similar components have the same reference numerals throughout. The embodiments described below are examples for explaining the present application and are not intended to limit the present application.

[0030] In order to make the personnel in the technical field better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.

[0031] In the following description, the terms "first\second" and the like are merely intended to distinguish similar objects and do not represent a specific order or sequence for the objects. It is understood that the "first\second" can be interchangeable with each other in specific order or sequence, as long as it is allowed, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.

[0032] "Multiple" mentioned herein refers to two or more. "And / or" describes the association between the associated objects, which means that there can be three relationships, for example, A and / or B can represent three cases: A exists alone, A and B exist together, and B exists alone. The character " / " generally represents that the associated objects before and after are in an "or" relationship.

[0033] With the development of Internet technology, while enjoying more and more rich network content, it is also necessary to face the increasing variety of network threats. In network devices, the firewall is an important tool to ensure user network security and prevent network threats. The firewall cleans the traffic through preset cleaning rules, thereby realizing the interception of threat traffic. With the development of Internet technology, in order to cope with more diverse threat traffic, the concept of next-generation firewall is proposed, that is, the firewall can not only clean the traffic through preset cleaning rules, but also query the threat situation library in the cloud to clean the traffic. Because the cloud database in the cloud contains a large amount of threat intelligence, the next-generation firewall can intercept more threat traffic, greatly improving the protection capability of the next-generation firewall. However, querying the threat situation library in the cloud to clean the traffic needs to occupy the computing resources of the device where the firewall is located. In the face of large-scale traffic, a large amount of computing resources needs to be occupied, greatly increasing the use cost of the firewall.

[0034] To solve the above problems, the application provides a traffic cleaning method and device and electronic equipment. The method is applied to a security device, and the method comprises the following steps: obtaining i-round traffic to be cleaned, i being an integer greater than 0; matching the i-round traffic to be cleaned based on a preset cleaning rule to obtain a matching result of the i-round traffic to be cleaned; if the matching result of the i-round traffic to be cleaned indicates that the traffic to be cleaned does not match the preset cleaning rule, querying a reference cleaning traffic in a cache of the security device based on the i-round traffic to be cleaned to obtain a query result, the query result being used to indicate whether there is a reference cleaning traffic matching the i-round traffic to be cleaned in the cache of the security device, the reference cleaning traffic in the cache of the security device comprising traffic to be cleaned that does not match the preset cleaning rule in the security device before the i round, and the cache of the security device also storing a reference threat state of the reference cleaning traffic; if the query result indicates that there is a target reference cleaning traffic matching the i-round traffic to be cleaned in the cache, obtaining the reference threat state of the target reference cleaning traffic from the cache of the security device; and cleaning the i-round traffic to be cleaned based on the reference threat state of the target reference cleaning traffic.

[0035] According to the method provided by the application, the reference cleaning traffic in the cache of the security device comprises traffic to be cleaned that does not match the preset cleaning rule before the i round, and the reference cleaning traffic cannot be cleaned by the preset cleaning rule in the security device, that is, the reference cleaning traffic in the cache of the security device is traffic that needs to be matched by querying the cloud, and the corresponding reference threat state is the threat state obtained by querying the cloud. In the case that the i-round traffic to be cleaned does not match the preset cleaning rule, the cache of the security device is queried, and if the query result indicates that there is a target reference cleaning traffic matching the i-round traffic to be cleaned in the cache, it can be understood that the traffic to be cleaned has been queried in the cloud database for a period of time, and therefore, the reference threat state corresponding to the matched target reference cleaning traffic can be used as the threat state of the i-round traffic to be cleaned, so that the i-round traffic to be cleaned is cleaned based on the reference threat state of the target reference cleaning traffic, thereby avoiding the process of querying the cloud for the i-round traffic to be cleaned, reducing the number of cloud queries of the security device, and reducing the use cost of the security device.

[0036] Please refer to Figure 1 , Figure 1 A scene diagram related to the application is given, comprising a device 10 and a server 20, wherein the device 10 and the server 20 are connected in wired or wireless network communication.

[0037] The device 10 stores at least one preset cleaning rule, and the device 10 is provided with a cache, and the cache stores a reference cleaning flow and a reference threat state of the reference cleaning flow; the server 20 can be deployed with a database, and the database can store a large amount of flow and a threat state corresponding to the flow.

[0038] When the device 10 receives the flow, the device 10 matches the received flow according to the stored preset cleaning rule, and if the matching is successful, the device 10 cleans the flow based on the matched preset cleaning rule; if the matching is not successful, the device 10 queries whether there is a target reference cleaning flow that matches in the cache of the device 10; if there is a target reference cleaning flow that matches, the device 10 cleans the flow according to the reference threat state of the target reference cleaning flow; if there is no target reference cleaning flow that matches, the device 10 sends a query request to the server 20 to query the threat state of the flow, the server 20 responds to the query request, queries the threat state corresponding to the flow in the database and returns to the device 10, and the device 10 cleans the flow according to the threat state returned by the server 20.

[0039] In the above application scenario, the device 10 can complete the cleaning of the flow without sending a query request to the server 20 in the case of matching the preset cleaning rule or matching the target reference cleaning flow in the cache; only in the case of not matching the preset cleaning rule and not matching the target reference cleaning flow, the device 10 sends a query request to the server 20 to complete the cleaning of the flow, which avoids the device 10 querying the server 20 for flow cleaning for each flow that does not match the preset cleaning rule, reduces the frequency of the device 10 sending a query request to the server 20, and thus reduces the occupation of the computing resources of the device 10 by flow cleaning.

[0040] In some embodiments, the device 10 can be a smart phone, a tablet computer, a notebook computer, a desktop computer, a smart television, a vehicle-mounted terminal, or the like, which can access network flow. The server 200 can be a standalone physical server, a server cluster or a distributed system composed of multiple physical servers, a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content distribution networks, and big data and artificial intelligence platforms, and the like, basic cloud computing services, and the like, and the present application is not limited thereto.

[0041] It should be understood that the application scenarios of the above-described method steps are only illustrative and are not limiting to the present application.

[0042] The embodiments provided by the present application will be described below with reference to the accompanying drawings.

[0043] Please refer to Figure 2 ,Figure 2 A first flowchart of a traffic cleaning method provided by an embodiment of the present application is given, the method being applied to a security device, and the method comprising steps S110-S150:

[0044] S110, obtaining i-th round of to-be-cleaned traffic, i being an integer greater than 0.

[0045] The to-be-cleaned traffic, i.e., the traffic, refers to a data packet accessing the security device, and usually includes domain name, IP (Internet protocol), URL (Uniform Resource Locator), file MD5 (MD5 Message-Digest Algorithm, which is a widely used password hash function), and the like.

[0046] The rounds of to-be-cleaned traffic can have various division manners; for example, a fixed number of traffics can be regarded as one round of traffic, such as setting 100 traffics as one round of traffic, the first round of traffic being the 1st traffic to the 100th traffic received by the security device, the second round of traffic being the 101st traffic to the 200th traffic received by the security device, and the like; a fixed time length of traffic can be regarded as one round of traffic; one traffic can be directly regarded as one round of traffic, and the like, which are not specifically limited herein.

[0047] S120, matching the i-th round of to-be-cleaned traffic based on a preset cleaning rule to obtain a matching result of the i-th round of to-be-cleaned traffic.

[0048] It should be noted that the preset cleaning rule is pre-configured and stored in the security device; the preset cleaning rule can include a domain name filtering rule, an IP filtering rule, a URL filtering rule, and the like.

[0049] For example, as shown in Table 1, Table 1 gives an exemplary example of a domain name filtering rule:

[0050]

[0051] Table 1

[0052] The various domain name filtering rules in Table 1 are briefly described as follows.

[0053] In Table 1, the domain name filtering rule domain_valid_character is used to filter out invalid domain names by the value range of characters, which is "A-Z, a-z, 0-9, *, -,."; that is, if the domain name of the to-be-cleaned traffic contains characters outside the value range, such as α, it is determined that the domain name of the to-be-cleaned traffic is an invalid domain name, and the to-be-cleaned traffic is subjected to corresponding cleaning operations, such as interception or warning.

[0054] Similarly, the domain name filtering rule domain_necessary_character is used to filter out invalid domain names by specifying characters, where the specified characters are characters that must appear in the domain name, such as "."; that is, if the domain name of the to-be-cleaned traffic does not contain ".", it is determined that the domain name of the to-be-cleaned traffic is an invalid domain name.

[0055] The domain name filtering rules domain_safe_suffix, domain_country_suffix, and domain_local_suffix all refer to filtering domain names by different levels of specified domain names (such as domain suffix, top-level domain, and local domain). Specifically, domain_safe_suffix is filtered by whether the domain suffix is in the whitelist (such as gov and edu in Table 1), and domain names in the whitelist are considered safe by default. domain_country_suffix is filtered by whether the top-level domain (TLD) is in the whitelist, and domain names in the whitelist are considered safe by default. domain_local_suffix is filtered by whether there is a local resource domain name, and local resource domain names are considered safe by default.

[0056] As shown in Table 2, Table 2 exemplarily shows an IP filtering rule.

[0057]

[0058]

[0059] Table 2

[0060] In Table 2, the IP filtering rule IP_reserved_address refers to only keeping the traffic corresponding to IP addresses within the value range, and filtering out the traffic corresponding to IP addresses outside the value range, where the value range is configured in advance and can include private networks, network loops, and other addresses that need to be reserved. The specific configuration can be based on actual needs.

[0061] As shown in Table 3, Table 3 exemplarily gives a URL filtering rule.

[0062]

[0063] Table 3

[0064] In Table 3, the URL filtering rule URL_invalid_file_extend refers to judging whether the flow is meaningless flow through the URL of the flow, such as containing gif in the URL, which represents that the corresponding flow resource is gif image resource, and there is no need to clean, which can be defaulted as safe flow.

[0065] In the matching of the various preset cleaning rules in Table 1-Table 3 to the to-be-cleaned flow, the matching can be sequentially matched in a certain order, such as matching the domain name filtering rule first, and then matching the IP filtering rule, and when any filtering rule is successfully matched, the matching is stopped; or the matching of multiple preset cleaning rules can be performed simultaneously, which is not limited here.

[0066] Further, the matching result of the to-be-cleaned flow contains the preset cleaning rule matched by the cleaning flow; if the sequential matching is performed in a certain order, the matching result of the to-be-cleaned flow will only contain one matched preset cleaning rule; if the matching of multiple preset cleaning rules is performed simultaneously, the matching result of the to-be-cleaned flow can contain one matched preset cleaning rule, or multiple preset cleaning rules.

[0067] In some embodiments, if the matching result of the to-be-cleaned flow in the i-th round indicates that the to-be-cleaned flow matches the preset cleaning rule, the to-be-cleaned flow in the i-th round is cleaned based on the preset cleaning rule.

[0068] In some embodiments, when there is only one preset cleaning rule in the matching result, the to-be-cleaned flow is cleaned according to the corresponding cleaning operation (such as interception, allowing to pass, waiting for query, generating alarm information, etc.) of the preset cleaning rule, such as the matched preset cleaning rule being domain_safe_suffix, that is, the domain suffix of the to-be-cleaned flow is in the white list, and the to-be-cleaned flow is allowed to pass.

[0069] In the case that there are multiple preset cleaning rules in the matching result, different priority levels can be set for different preset cleaning rules, and the to-be-cleaned flow is cleaned based on the cleaning operation corresponding to the preset cleaning rule with high priority level; or different priority levels can also be set for different cleaning operations, and the to-be-cleaned flow is cleaned by the cleaning operation with high priority level, and the specific mode is not limited here.

[0070] S130, if the matching result of the to-be-cleaned traffic of the i-th round indicates that the to-be-cleaned traffic does not match the preset cleaning rule, querying a reference cleaning traffic in the cache of the security device based on the to-be-cleaned traffic of the i-th round to obtain a query result, the query result being used to indicate whether there is a reference cleaning traffic matching the to-be-cleaned traffic of the i-th round in the cache of the security device, the reference cleaning traffic in the cache of the security device including to-be-cleaned traffic that does not match the preset cleaning rule in the security device before the i-th round, and the cache of the security device also storing a reference threat state of the reference cleaning traffic.

[0071] The threat state of a traffic can also be understood as a security state of the traffic. For example, the threat state of a traffic can include black (threat), white (no threat), and gray (unknown threat), and the corresponding traffic can be divided into black traffic, white traffic, and gray traffic.

[0072] It can be understood that, as the round of the to-be-cleaned traffic gradually increases, the reference cleaning traffic in the cache of the security device will be gradually updated.

[0073] It can be understood that, since the reference cleaning traffic is to-be-cleaned traffic that does not match the preset cleaning rule in the security device before the i-th round, it cannot determine its state based on the preset cleaning rule of the security device, and it cannot be cleaned based on the preset cleaning rule of the security device, therefore, the reference cleaning traffic needs to determine its state by means of external query (such as cloud database query, manual review, etc.), and then determine how to clean.

[0074] In some embodiments, the reference threat state of the reference cleaning traffic stored in the cache of the security device is queried from a cloud database, and the cloud database stores a plurality of threat traffics and the threat states corresponding to the threat traffics.

[0075] S140, if the query result indicates that there is a target reference cleaning traffic matching the to-be-cleaned traffic of the i-th round in the cache, obtaining the reference threat state of the target reference cleaning traffic from the cache of the security device.

[0076] The target reference cleaning traffic matching the to-be-cleaned traffic of the i-th round can be traffic having one or more characteristics completely same as the to-be-cleaned traffic of the i-th round, such as a domain name, an IP, a URL, etc. that are completely matched, or can be traffic having one or more characteristics partially same as the to-be-cleaned traffic of the i-th round, such as a domain name suffix being same, an IP address subnet mask being same, etc. The specific matching rule can be set according to actual needs.

[0077] In a case where the query result indicates that there is a target reference cleaning traffic matching the i-th round of to-be-cleaned traffic in the cache, it can be understood that the i-th round of to-be-cleaned traffic has been queried as a target reference cleaning traffic before the i-th round. Considering that the threat state of a traffic will remain stable within a period of time, therefore, the reference threat state of the target reference cleaning traffic can represent the threat state of the i-th round of to-be-cleaned traffic to a certain extent.

[0078] S150, cleaning the i-th round of to-be-cleaned traffic based on the reference threat state of the target reference cleaning traffic.

[0079] wherein the cleaning operation corresponding to each threat state is pre-stored in the security device; for example, when the i-th round of to-be-cleaned traffic is black traffic (i.e., the reference threat state is black), the cleaning operation for is interception; when the i-th round of to-be-cleaned traffic is gray traffic (i.e., the reference threat state is gray), the cleaning operation for is alarm; and when the i-th round of to-be-cleaned traffic is white traffic (i.e., the reference threat state is white), the cleaning operation for is allowed to pass.

[0080] By the method provided in the embodiments of the present application, since the reference cleaning traffic in the cache of the security device includes to-be-cleaned traffic before the i-th round that cannot be matched with the preset cleaning rule, the reference cleaning traffic cannot be matched and cleaned by the preset cleaning rule in the security device, that is, the reference cleaning traffic in the cache of the security device is traffic that needs to be matched by querying the cloud, and the corresponding reference threat state is the threat state obtained by querying the cloud. In a case where the i-th round of to-be-cleaned traffic cannot be matched with the preset cleaning rule, by querying the cache of the security device, if the query result indicates that there is a target reference cleaning traffic matching the i-th round of to-be-cleaned traffic in the cache, it can be understood that the to-be-cleaned traffic has been queried in the cloud database within a period of time, therefore, the reference threat state corresponding to the matched target reference cleaning traffic can be used as the threat state of the i-th round of to-be-cleaned traffic, so that the i-th round of to-be-cleaned traffic is cleaned based on the reference threat state of the target reference cleaning traffic, thereby avoiding the process of querying the cloud for the i-th round of to-be-cleaned traffic, reducing the number of cloud queries of the security device, and reducing the use cost of the security device.

[0081] In other embodiments, please refer to Figure 3 , Figure 3 A second flowchart of the traffic cleaning method provided in the embodiments of the present application is given, after step S120, the traffic cleaning method further includes steps S210-S230:

[0082] S210, if the target reference cleaning traffic associated with the i-th round of to-be-cleaned traffic does not exist in the cache, a query request is sent to the cloud database based on the i-th round of to-be-cleaned traffic, the cloud database contains a plurality of threat traffics and threat states corresponding to each threat traffic, and the cloud database responds to the query request, queries the target threat traffic matching the i-th round of to-be-cleaned traffic from the plurality of threat traffics, and returns the target threat state corresponding to the target threat traffic.

[0083] It can be understood that the query request contains information of the i-th round of to-be-cleaned traffic; after receiving the query request, the cloud database can query according to the information of the i-th round of to-be-cleaned traffic contained in the query request.

[0084] S220, receiving the target threat state corresponding to the target threat traffic returned by the cloud database in response to the query request.

[0085] In some embodiments, after receiving the target threat state corresponding to the target threat traffic returned by the cloud database in response to the query request, the target threat traffic can also be used as a reference cleaning traffic, and the target threat state corresponding to the target threat traffic can be stored as a reference threat state of the reference cleaning traffic in the cache of the security device, thereby updating the cache, so as to query the updated cache for the next round of to-be-cleaned traffic.

[0086] S230, cleaning the i-th round of to-be-cleaned traffic based on the target threat state corresponding to the target threat traffic.

[0087] Wherein, the process of step S230 is similar to that of step S150 in the foregoing embodiments, and the specific description of step S230 can refer to the specific description of step S150 in the foregoing embodiments, which will not be repeated here.

[0088] The method provided by the embodiments of the present application, when the i-th round of to-be-cleaned traffic fails to successfully match the preset cleaning rule and fails to query the matching target reference cleaning traffic in the cache, queries the corresponding target threat traffic and the target threat state of the target threat traffic by sending a query request to the cloud database, and cleans the i-th round of to-be-cleaned traffic based on the target threat state corresponding to the target threat traffic. Through the method provided by the embodiments of the present application, the range of traffic cleaning of the security device is enriched, the traffic cleaning capability of the security device is improved, and the protection capability of the security device is improved.

[0089] In other embodiments, the cloud database also needs to be maintained and updated, please refer to Figure 4 , Figure 4A third flowchart of the traffic cleaning method provided by the embodiment is shown. The cache of the security device contains a first version number of the cloud database. After step S210, the traffic cleaning method further includes steps S310-S330.

[0090] S310, acquire the current version number of the cloud database.

[0091] It should be noted that the version number of the cloud database is one-to-one corresponding to the content in the cloud database, that is, when the version number of the cloud database is updated, it means that the content in the cloud database is also updated, and the update of the content in the cloud database can include multiple operations such as adding, deleting, and modifying the content.

[0092] Obviously, the current version number of the cloud database is the latest version number of the cloud database, and the content of the cloud database corresponding to the current version number is also the latest and most accurate.

[0093] In some embodiments, the security device can separately send a request for acquiring the version number before sending a query request each time, send a query request for the i-th round of target threat traffic in the case that the current version number and the first version number are successfully matched, and send a query request for the i-th round of target threat traffic in the case that the current version number and the first version number are not successfully matched.

[0094] The security device can also query the version number of the cloud database through the query request, and send a request for acquiring the target threat traffic and the threat state corresponding to the target threat traffic of the i-th round of the cloud database in the case that the current version number and the first version number are not successfully matched.

[0095] In the case that the security device queries the version number of the cloud database through the query request, step S310 specifically includes: receiving the current version number of the cloud database returned by the cloud database in response to the query request.

[0096] S320, if the current version number and the first version number are not successfully matched, acquire the target threat traffic and the threat state corresponding to the target threat traffic of the i-th round of the cloud database, and the target threat traffic of the i-th round is the target threat traffic queried by the cloud database in response to the query request corresponding to the i-th round of the traffic to be cleaned.

[0097] If the current version number does not match the first version number, it indicates a potential data inconsistency between the cache and the cloud database. For example, in the cloud database corresponding to the first version number, the threat status of traffic A is "unknown threat." Since the cache corresponding to the first version number is based on the cloud database corresponding to the first version number, the cache also stores the threat status of traffic A as "unknown threat." If the threat status of traffic A is updated to "threatened" in the cloud database corresponding to the current version number, this will cause a data inconsistency between the cache and the cloud database, thereby reducing the effectiveness of traffic scrubbing.

[0098] Therefore, if the current version number does not match the first version number, the target threat traffic and the threat status corresponding to the target threat traffic in the previous i rounds are obtained from the cloud database. The target threat traffic in the previous i rounds is the target threat traffic queried by the cloud database in response to the query requests corresponding to the traffic to be cleaned from the first round to the i rounds. Obviously, the target threat traffic in the previous i rounds includes all reference cleaned traffic in the cache.

[0099] In some implementations, after determining that the current version number and the first version number do not match successfully, and after obtaining the target threat traffic and the threat status corresponding to the target threat traffic in the previous i rounds in the cloud database, the first version number in the cache can be updated to the current version number in the cloud database, thereby realizing the update of the cached first version number.

[0100] S330 updates the security device's cache based on the target threat traffic and the threat status corresponding to the target threat traffic in the previous i rounds.

[0101] Specifically, there is a one-to-one correspondence between the target threat traffic in the first i rounds and the reference cleanup traffic in the cache of the security device. The threat status corresponding to the target threat traffic in the first i rounds is used to replace the reference threat status of the corresponding reference cleanup traffic, thereby updating the cache.

[0102] The method adopted in this application embodiment ensures that the reference cleaning traffic and the reference threat status of the reference cleaning traffic in the cache are consistent with the target threat traffic and the threat status corresponding to the target threat traffic in the cloud database, thus avoiding data inconsistency between the cache and the cloud database, which would otherwise result in poor traffic cleaning performance.

[0103] In other implementations, please refer to Figure 5 , Figure 5 A fourth flowchart of the flow cleaning method provided in this application embodiment is shown. The flow cleaning method further includes steps S410-S420:

[0104] S410. Based on the reference threat status of each reference scrubbing traffic in the cache of the security device, determine the effective duration of each reference scrubbing traffic.

[0105] The effective duration of the reference cleaning traffic can also be understood as the duration in which the threat state of the reference cleaning traffic remains stable, that is, the threat state of the reference cleaning traffic is likely to remain stable within the effective duration of the reference cleaning traffic.

[0106] S420, if the storage duration of a reference cleaning traffic in the cache is not less than the effective duration corresponding to the reference cleaning traffic, the reference cleaning traffic and the reference threat state corresponding to the reference cleaning traffic are deleted from the cache.

[0107] For example, still taking the threat state of traffic including black, white and gray as an example; for black traffic and white traffic, the effective duration corresponding thereto can be set to 7 days, and for gray traffic, the effective duration corresponding thereto can be set to 1 hour; if the reference cleaning traffic A is black traffic, the storage duration of the reference cleaning traffic A in the cache reaches 7 days, and the reference cleaning traffic A and the corresponding reference threat state are deleted from the cache.

[0108] In some embodiments, when the corresponding reference cleaning traffic and the reference threat state corresponding to the reference cleaning traffic in the cache are updated, the effective duration of the reference cleaning traffic can be updated correspondingly, as in step S330 of the foregoing embodiment; of course, in other embodiments, when the corresponding reference cleaning traffic and the reference threat state corresponding to the reference cleaning traffic in the cache are updated, the effective duration of the reference cleaning traffic can not be updated.

[0109] The method provided in the present application sets different effective durations for reference threat traffic with different reference threat states, ensures the effectiveness of the reference threat state, and at the same time, by setting the effective duration, the expired data in the cache can be cleared in time, the amount of data in the cache is prevented from being too large, and the efficiency of cache query is further improved.

[0110] In other embodiments, please refer to Figure 6 , Figure 6 A fifth flowchart of the traffic cleaning method provided in the embodiment of the present application is given, and the traffic cleaning method further includes steps S510-S520:

[0111] S510, a cleaning log corresponding to the to-be-cleaned traffic is generated, and the cleaning log includes the to-be-cleaned traffic and the cleaning result corresponding to the to-be-cleaned traffic.

[0112] S520, the cleaning log is sent to the client.

[0113] Wherein, the client can deeply mine the cleaning log after receiving the cleaning log, so as to find the traffic which is cleaned by mistake due to being wrongly judged in the cleaning log, and then send the traffic cleaned by mistake and the correct judgment of the traffic to the cloud database, the cloud database maintains the cloud database based on the traffic cleaned by mistake and the correct judgment of the traffic, and realizes the update of the cloud database; further, after the cloud database is updated, the version number thereof needs to be updated correspondingly.

[0114] For the convenience of understanding, the following will be illustrated in combination with specific scene diagrams, please refer to Figure 7 , Figure 7 Another application scene diagram of the traffic cleaning method provided by the embodiments of the present application is given, including a next-generation firewall 30 (that is, the security device of the present application), a cloud log center 40 (that is, the client of the present application), and a threat intelligence center 50 (that is, the cloud database of the present application).

[0115] The next-generation firewall 30 cleans the traffic by using the traffic cleaning method provided by the present application after receiving the traffic, and reports the generated cleaning log to the cloud log center 40, the cloud log center 40 mines the cleaning log after receiving the cleaning log reported by the next-generation firewall 30 (which can be realized by manual mining by personnel, or realized by program code and the like), obtains new threat intelligence, and sends the mined new threat intelligence to the threat intelligence center 50, the threat intelligence center 50 is updated according to the new threat intelligence sent by the cloud log center 40.

[0116] In the process of cleaning the traffic by the next-generation firewall 30 by using the traffic cleaning method provided by the present application, the next-generation firewall 30 will query the threat intelligence center 50 at regular intervals (that is, the process of sending a query request and obtaining the current version number by the security device to the cloud database in the present application), the threat intelligence center 50 returns the threat intelligence to the next-generation firewall 30 in response to the query of the next-generation firewall 30, and the next-generation firewall 30 realizes the update of the cache according to the received threat intelligence.

[0117] Please refer to Figure 8 , Figure 8 A flowchart of the process of cleaning the traffic by the next-generation firewall 30 in Figure 7 is given, and the process of cleaning the traffic by the next-generation firewall 30 is as follows:

[0118] The next-generation firewall 30 matches the preset cleaning rules after receiving the traffic, wherein the preset cleaning rules include basic IP rules, basic domain name rules and basic URL rules, and if the traffic successfully matches the preset cleaning rules, the traffic is cleaned by using the preset cleaning rules.

[0119] If the traffic does not match the preset cleaning rules, the traffic is queried in the cache. The cache contains various types of traffic and their corresponding threat statuses. If a target traffic corresponding to the traffic is successfully matched in the cache, the threat status of the target traffic in the cache is obtained, and the traffic is cleaned based on the threat status of the target traffic.

[0120] If no target traffic corresponding to the traffic is successfully matched in the cache, a request is made to the cloud to query the threat status of the traffic. Based on the threat status of the traffic queried and returned by the cloud, the traffic is cleaned.

[0121] As can be seen, in the above traffic cleaning process, when a preset cleaning rule is matched or a target traffic in the cache is matched, there is no need to initiate a query to the cloud. That is, by introducing caching, the number of queries to the cloud is reduced, thereby reducing the cost of traffic cleaning.

[0122] In some implementations, please refer to Figure 9 , Figure 9 A schematic diagram of a flow cleaning device provided in an embodiment of this application is given. The flow cleaning device 600 includes:

[0123] The first acquisition module 610 is used to acquire the flow rate to be cleaned in the i-th round, where i is an integer greater than 0.

[0124] The matching module 620 is used to match the traffic to be cleaned in the i-th round based on the preset cleaning rules, and obtain the matching result of the traffic to be cleaned in the i-th round.

[0125] The query module 630 is used to query the reference cleaning traffic in the cache of the security device based on the traffic to be cleaned in the i-th round if the matching result of the traffic to be cleaned in the i-th round indicates that the traffic to be cleaned does not match the preset cleaning rule, and obtain the query result. The query result is used to indicate whether there is a reference cleaning traffic in the cache of the security device that matches the traffic to be cleaned in the i-th round. The reference cleaning traffic in the cache of the security device includes the traffic to be cleaned that did not match the preset cleaning rule in the security device before the i-th round. The cache of the security device also stores the reference threat status of the reference cleaning traffic.

[0126] The second acquisition module 640 is used to acquire the reference threat status of the target reference cleaning traffic from the cache of the security device if the query result indicates that there is a target reference cleaning traffic in the cache that matches the traffic to be cleaned in the i-th round.

[0127] The cleaning module 650 is used to clean the traffic to be cleaned in the i-th round based on the reference threat state of the target reference cleaning traffic.

[0128] In some embodiments, the query module 630 is further configured to, if the target reference cleaning traffic associated with the to-be-cleaned traffic of the i-th round does not exist in the cache, send a query request to a cloud database based on the to-be-cleaned traffic of the i-th round, the cloud database containing a plurality of threat traffics and threat states corresponding to the threat traffics, the cloud database querying a target threat traffic matching the to-be-cleaned traffic of the i-th round from the plurality of threat traffics and returning a target threat state corresponding to the target threat traffic in response to the query request; the second acquisition module 640 is further configured to receive the target threat state corresponding to the target threat traffic returned by the cloud database in response to the query request; and the cleaning module 650 is further configured to clean the to-be-cleaned traffic of the i-th round based on the target threat state corresponding to the target threat traffic.

[0129] In some embodiments, the traffic cleaning device 600 further comprises an updating module, the updating module being configured to store a target threat traffic as a reference cleaning traffic and a target threat state corresponding to the target threat traffic as a reference threat state of the reference cleaning traffic in the cache of the security device.

[0130] In some embodiments, the cache of the security device contains a first version number of the cloud database, the second acquisition module 640 is further configured to acquire a current version number of the cloud database; if the current version number and the first version number do not successfully match, the target threat traffics of the first i rounds and the threat states corresponding to the target threat traffics are acquired, the target threat traffics of the first i rounds being target threat traffics queried by the cloud database in response to query requests corresponding to the to-be-cleaned traffics of the first i rounds; and the updating module is further configured to update the cache of the security device based on the target threat traffics of the first i rounds and the threat states corresponding to the target threat traffics.

[0131] In some embodiments, the second acquisition module 640 is further configured to receive the current version number of the cloud database returned by the cloud database in response to the query request, and the updating module is further configured to update the first version number in the cache to the current version number of the cloud database.

[0132] In some embodiments, the updating module is further configured to determine the valid time length of each reference cleaning traffic based on the reference threat states of the reference cleaning traffics in the cache of the security device; and if the storage time length of a reference cleaning traffic in the cache is not less than the valid time length corresponding to the reference cleaning traffic, the reference cleaning traffic and the reference threat state of the reference cleaning traffic are deleted from the cache.

[0133] In some embodiments, the traffic cleaning device 600 further comprises a reporting module, the reporting module being configured to generate a cleaning log corresponding to the to-be-cleaned traffic, the cleaning log containing the to-be-cleaned traffic and a cleaning result corresponding to the to-be-cleaned traffic; and send the cleaning log to a client.

[0134] In some embodiments, the cleaning module 650 is further configured to, if the matching result of the i th round of the to-be-cleaned traffic indicates that the to-be-cleaned traffic matches the preset cleaning rule, clean the i th round of the to-be-cleaned traffic based on the preset cleaning rule.

[0135] In some embodiments, based on the traffic cleaning determination method provided in the above embodiments, the present embodiment further provides an electronic device, which includes a processor, a memory, and one or more programs stored in the memory and configured to be executed by the processor. Figure 10 , Figure 10 A structural block diagram of an electronic device provided by an embodiment of the present application is given, and the electronic device 700 includes one or more processors 710, a memory 720, and one or more programs, wherein the one or more programs are stored in the memory 720 and configured to be executed by the one or more processors 710, and the one or more programs are configured to execute the above method.

[0136] The electronic device 700 can be a terminal device, which can be a computer, a tablet computer, a vehicle-mounted terminal, etc.

[0137] The processor 710 can include one or more processing cores. The processor 710 connects various parts in the wearable device through various interfaces and lines, and performs various functions of the wearable device and processes data by running or executing instructions, programs, code sets or instruction sets stored in the memory 720, and calling data stored in the memory 720. Optionally, the processor 710 can be implemented in at least one of a digital signal processing (DSP), a field-programmable gate array (FPGA), and a programmable logic array (PLA). The processor 710 can integrate a combination of one or more of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. Among them, the CPU mainly processes the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing the content to be displayed; and the modem is used for processing wireless communication. It can be understood that the above-mentioned modem can also not be integrated into the processor, but can be realized by a separate communication chip.

[0138] The memory 720 can include a random access memory (RAM) and can also include a read-only memory (ROM). The memory 720 can be used to store instructions, programs, codes, code sets, or instruction sets. The memory 720 can include a program storage area and a data storage area, where the program storage area can store instructions for implementing an operating system, instructions for implementing at least one function (such as a touch function, a sound playing function, an image playing function, etc.), instructions for implementing each of the methods described below, and the like. The data storage area can also store data created by the electronic device in use.

[0139] In some embodiments, the present application also provides a computer-readable storage medium storing program codes, which can be invoked by a processor to execute the above method.

[0140] The computer-readable storage medium can be an electronic memory such as a flash memory, an EEPROM (electrically erasable programmable read-only memory), an EPROM, a hard disk, or a ROM. Alternatively, the computer-readable storage medium includes a non-transitory computer-readable medium. The computer-readable storage medium has storage space for program codes for executing any of the method steps described above. These program codes can be read from or written to one or more computer program products. The program codes can be compressed in a suitable form.

[0141] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program with a predetermined function, and works together with other related parts to achieve a predetermined target, and can be implemented entirely or partially by using software, hardware (such as a processing circuit or a memory), or a combination thereof, and similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of an overall module or unit of the function of the module or unit.

[0142] The above is only a preferred embodiment of the present application, and does not limit the present application in any form. Although the present application has been disclosed as the above preferred embodiment, it is not intended to limit the present application. Any person skilled in the art can make some changes or modifications to the above disclosed technical content to make equivalent embodiments with equivalent changes, without departing from the scope of the technical solution of the present application. Any modification, change, equivalent change, and modification of the above embodiments made in accordance with the technical essence of the present application, without departing from the technical solution of the present application, are still within the scope of the technical solution of the present application.

Claims

1. A flow cleaning method, characterized in that, Applied to safety equipment, including: Get the traffic to be cleaned in the i-th round, where i is an integer greater than 0; The flow rate to be cleaned in the i-th round is matched based on the preset cleaning rules to obtain the matching result of the flow rate to be cleaned in the i-th round; If the matching result of the traffic to be cleaned in the i-th round indicates that the traffic to be cleaned does not match the preset cleaning rule, the reference cleaning traffic in the cache of the security device is queried based on the traffic to be cleaned in the i-th round to obtain the query result. The query result is used to indicate whether there is a reference cleaning traffic in the cache of the security device that matches the traffic to be cleaned in the i-th round. The reference cleaning traffic in the cache of the security device includes the traffic to be cleaned that did not match the preset cleaning rule in the security device before the i-th round. The cache of the security device also stores the reference threat status of the reference cleaning traffic. If the query result indicates that there is a target reference cleaning traffic in the cache that matches the traffic to be cleaned in the i-th round, the reference threat status of the target reference cleaning traffic is obtained from the cache of the security device; The traffic to be cleaned in the i-th round is cleaned based on the reference threat state of the target reference cleaning traffic.

2. The method according to claim 1, characterized in that, The method further includes: If there is no target reference cleaning traffic associated with the cleaning traffic in the i-th round in the cache, a query request is sent to the cloud database based on the cleaning traffic in the i-th round. The cloud database contains multiple threat traffic and the threat status corresponding to each threat traffic. In response to the query request, the cloud database queries the multiple threat traffic for the target threat traffic that matches the cleaning traffic in the i-th round and returns the target threat status corresponding to the target threat traffic. Receive the target threat status corresponding to the target threat traffic returned by the cloud database in response to the query request; The traffic to be cleaned in the i-th round is cleaned based on the target threat status corresponding to the target threat traffic.

3. The method according to claim 2, characterized in that, After receiving the target threat status corresponding to the target threat traffic returned by the cloud database in response to the query request, the method includes: The target threat traffic is used as reference cleaning traffic, and the target threat status corresponding to the target threat traffic is stored in the cache of the security device as the reference threat status of the reference cleaning traffic.

4. The method according to claim 2, characterized in that, The cache of the security device contains the first version number of the cloud database, and the method further includes: Obtain the current version number of the cloud database; If the current version number does not match the first version number, obtain the target threat traffic of the first i rounds in the cloud database and the threat status corresponding to the target threat traffic. The target threat traffic of the first i rounds is the target threat traffic queried by the cloud database in response to the query request corresponding to the traffic to be cleaned from the first round to the i rounds. The cache of the security device is updated based on the target threat traffic in the previous i rounds and the threat status corresponding to the target threat traffic.

5. The method according to claim 4, characterized in that, Obtaining the current version number of the cloud database includes: Receive the current version number of the cloud database returned by the cloud database in response to the query request; After obtaining the target threat traffic from the previous i rounds in the cloud database and the threat status corresponding to the target threat traffic, the method further includes: Update the first version number in the cache to the current version number of the cloud database.

6. The method according to claim 1, characterized in that, The method further includes: Based on the reference threat status of each reference scrubbing traffic in the cache of the security device, the effective duration of each reference scrubbing traffic is determined; If the storage duration of a reference cleaning traffic in the cache is not less than the effective duration corresponding to the reference cleaning traffic, the reference cleaning traffic and its reference threat status are deleted from the cache.

7. The method according to claim 1, characterized in that, The method further includes: Generate a cleaning log corresponding to the traffic to be cleaned, the cleaning log containing the traffic to be cleaned and the cleaning result corresponding to the traffic to be cleaned; Send the cleaning log to the client.

8. The method according to claim 1, characterized in that, The method further includes: If the matching result of the traffic to be cleaned in the i-th round indicates that the traffic to be cleaned matches the preset cleaning rule, the traffic to be cleaned in the i-th round is cleaned based on the preset cleaning rule.

9. A flow-rate cleaning device, characterized in that, Applied to safety equipment, including: The first acquisition module is used to acquire the traffic to be cleaned in the i-th round, where i is an integer greater than 0; The matching module is used to match the flow rate to be cleaned in the i-th round based on the preset cleaning rules, and obtain the matching result of the flow rate to be cleaned in the i-th round; The query module is used to query the reference cleaning traffic in the cache of the security device based on the reference cleaning traffic in the i-th round if the matching result of the traffic to be cleaned in the i-th round indicates that the traffic to be cleaned does not match the preset cleaning rule, and obtain the query result. The query result is used to indicate whether there is a reference cleaning traffic in the cache of the security device that matches the traffic to be cleaned in the i-th round. The reference cleaning traffic in the cache of the security device includes the traffic to be cleaned that did not match the preset cleaning rule in the security device before the i-th round. The cache of the security device also stores the reference threat status of the reference cleaning traffic. The second acquisition module is used to acquire the reference threat status of the target reference cleaning traffic from the cache of the security device if the query result indicates that there is a target reference cleaning traffic in the cache that matches the traffic to be cleaned in the i-th round. The cleaning module is used to clean the traffic to be cleaned in the i-th round based on the reference threat state of the target reference cleaning traffic.

10. An electronic device, characterized in that, include: One or more processors; Memory; One or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, the one or more programs being configured to perform the method as claimed in any one of claims 1-8.

11. A computer-readable storage medium, characterized in that, include: The computer-readable storage medium stores program code that can be invoked by a processor to perform the method as claimed in any one of claims 1-8.

Citation Information

Patent Citations

  • Integrated data cleaning method and device, server and storage medium

    CN115687318A

  • Method and system for updating customized embedded threat intelligence library

    CN116015912A