Front-end safety control method and system
By setting up independent security policy modules on the front-end and back-end, the front-end obtains security policies from the back-end, solving the problem of insufficient flexibility in front-end security adaptation in the existing technology, and achieving flexible configuration and effective management of front-end security policies.
Patent Information
- Application Number
- CN202311447179.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-01
- Publication Date
- 2025-05-06
AI Technical Summary
The existing technology lacks flexibility in security adaptation for front-end security in security governance, resulting in the need to develop multiple versions when dealing with different security standards, frequent upgrades, and strong invasiveness to software business modules, and high R&D costs.
By setting up independent security policy modules on the front-end and back-end, the front-end obtains security policies from the back-end through asynchronous monitoring of communication and synchronous communication, achieving flexible configuration of front-end security policies.
It realizes flexible adaptation of front-end security policies, reduces the invasiveness of software, reduces the workload of security governance, and effectively meets the security needs of front-end in different scenarios.
Smart Images

Figure CN119945689A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security, and more specifically, to a front-end security control method and system. Background Art
[0002] With the continuous development of 5G technology, the ToB scenario that promotes the application of 5G's advanced wireless technology in the industrial field has become the next hot application. Due to the cross-industry characteristics and different networking methods, ToB network security faces multiple standards and multiple scenarios. Customers in different industries have introduced different scanning software, but the scanning standards are not exactly the same. Especially in terms of WEB security parameters (security-related parameters in the Hypertext Transfer Protocol), different security scanning software has different standard definitions due to historical reasons. For example, some standards define different scopes of Hypertext Transfer Protocol (HTTP) security methods. Some scanning software can pass with the PUT (modify) / DELETE (delete) method, while others cannot.
[0003] In the related art, security management is performed by modifying the code, but this method lacks the flexibility to adapt to the front-end security. When dealing with different security standards, multiple versions need to be developed and frequently upgraded. In addition, this method is highly invasive to the software business module and requires upgrading all business modules, resulting in high R&D costs. Another method used in the related art is to set the back-end security policy. Although this can meet the requirements of the back-end related security specifications, it lacks flexible customization means for the front-end security.
[0004] In summary, there is no good solution to the above technical problems. Summary of the invention
[0005] The embodiments of the present application provide a front-end security control method and system to at least solve the problem that the security management method in the related technology lacks flexibility in front-end security adaptation.
[0006] According to one embodiment of the present application, a front-end security control method is provided, which includes: the front-end security policy module obtains the security policy entry from the back-end security policy module, wherein asynchronous listening communication and synchronous communication are supported between the front-end security policy module and the back-end security policy module; the front-end security policy module stores the security policy entry in the front-end storage to complete the configuration of the front-end security policy.
[0007] According to another embodiment of the present application, a front-end security control system is provided, which includes: a back-end security policy module for managing the security policy entries; a front-end security policy module for obtaining the security policy entries from the back-end security policy module and storing the security policy entries in the front-end storage to complete the configuration of the front-end security policy, wherein asynchronous listening communication and synchronous communication are supported between the front-end security policy module and the back-end security policy module.
[0008] According to another embodiment of the present application, a computer-readable storage medium is provided, in which a computer program is stored, wherein the computer program executes the steps of any of the above method embodiments when executed by a processor.
[0009] According to another embodiment of the present application, an electronic device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0010] Through the embodiments of the present application, independent security policy modules are set at the front end and the back end. The front end obtains the security policy from the back end through asynchronous listening communication and synchronous communication, which can realize flexible configuration of the front-end security policy, thereby solving the problem that the security management method in related technologies lacks flexibility in front-end security adaptation. It can effectively meet the security needs of the front end in different scenarios while reducing the intrusiveness of the software, and also reduces the workload of security management research and development. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] Figure 1 It is a hardware structure block diagram of the front-end security control method of the embodiment of the present application;
[0012] Figure 2 is a flow chart of a front-end security control method according to an embodiment of the present application;
[0013] Figure 3 is a block diagram of a front-end security control system according to an embodiment of the present application;
[0014] Figure 4 is a schematic diagram of a processing flow of a front-end security control system according to an embodiment of the present application;
[0015] Figure 5 is a schematic diagram of a process for timely effectiveness of a security policy according to an embodiment of the present application;
[0016] Figure 6 is a flow chart of the security policy of the front-end security policy module taking effect in a timely manner according to an embodiment of the present application;
[0017] Figure 7is a schematic diagram of a security policy query validation process according to an embodiment of the present application;
[0018] Figure 8 is a flow chart of a security policy query of a front-end security policy module according to an embodiment of the present application;
[0019] Fig. 9 is a schematic diagram of the monitoring duration in the asynchronous monitoring mechanism according to an embodiment of the present application;
[0020] Fig.10 It is a flowchart of the business processing flow of the front-end security policy module according to an embodiment of the present application. DETAILED DESCRIPTION
[0021] The embodiments of the present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0022] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0023] The embodiments of the present application provide a front-end security control method and system to at least solve the problem that the security management method in the related technology lacks flexibility in front-end security adaptation. The ToB network manager has different requirements for front-end security scanning when dealing with customers in different industries. The embodiments of the present application have made improvements in system security management, flexible configuration and policy execution to achieve flexible adaptation of front-end security policies and reduce the workload and complexity of system security management.
[0024] In the embodiments of the present application, the front end refers to the user-visible interface, such as the visual interface of a website or application, which is responsible for user interface presentation and user business logic processing, and the back end runs in the background or server side of the website or application, and controls the content of the front end, interacts with the front end and processes the corresponding business logic. The front end can be implemented by Hypertext Markup Language (HTML), JavaScript, etc., and the back end can be implemented by server-side programming languages (such as Java, Python, PHP, etc.), databases (such as MySQL, Oracle, etc.), etc., and this application does not limit this.
[0025] In the embodiment of the present application, the user can use a mobile terminal or a computer terminal to access the front end through a website or an application program, and send a service request. The embodiment of the present application sets a front-end security policy module dedicated to front-end security processing at the front end, which can centrally process the service request securely, avoid intrusion into the software, and has stronger versatility.
[0026] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Taking running on a mobile terminal as an example, Figure 1 is a hardware structure block diagram of the front-end security control method of the embodiment of the present application, such as Figure 1 As shown, the hardware board may include one or more ( Figure 1 Only one is shown in the figure) a processor 12 (the processor 12 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device) and a memory 14 for storing data, wherein the mobile terminal may also include a transmission device 16 for communication functions and an input and output device 18. It can be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the mobile terminal. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations shown.
[0027] The memory 14 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the front-end security control method in the embodiment of the present application. The processor 12 executes various functional applications and the front-end security control method by running the computer program stored in the memory 14, that is, to implement the above method. The memory 14 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 14 may further include a memory remotely arranged relative to the processor 12, and these remote memories can be connected to the mobile terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0028] The transmission device 16 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider. In one example, the transmission device 16 includes a network adapter (Network Interface Controller, referred to as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 16 can be a radio frequency (Radio Frequency, referred to as RF) module, which is used to communicate with the Internet wirelessly.
[0029] In one embodiment of the present application, a front-end security control method is provided. Figure 2 is a flow chart of a front-end security control method according to an embodiment of the present application. Figure 2 As shown, the process includes the following steps:
[0030] Step S201, setting at least one security policy item in the back-end security policy module through the network management software interface, wherein the security policy item is a combination of front-end security rules;
[0031] Step S202, when the triggering conditions for the front-end policy update are met, the front-end security policy module obtains the security policy entry from the back-end security policy module so as to perform security control on the front end based on the security policy entry, wherein asynchronous listening communication and synchronous communication are supported between the front-end security policy module and the back-end security policy module.
[0032] In this embodiment, the front-end security policy module and the back-end security policy module support asynchronous monitoring communication and synchronous communication. Exemplarily, the front-end and the back-end can establish communication based on Hypertext Transfer Protocol (HTTP), which is not limited in this application.
[0033] In an embodiment of the present application, through the above-mentioned steps S201 and S202, flexible configuration of the front-end security policy can be achieved through communication between the front-end security policy module and the back-end security policy module, thereby solving the problem that the security governance method in related technologies lacks flexibility in front-end security adaptation. While reducing the intrusiveness to the software, it can effectively meet the security needs of the front-end in different scenarios, and also reduce the workload of security governance research and development.
[0034] In some embodiments, the triggering conditions for the front-end policy update in step S202 may include: A, the front-end security policy module receives an indication of active front-end policy update generated based on human-computer interaction operations; and / or, B, the front-end security policy module monitors the policy update message actively pushed by the back-end security policy module.
[0035] In some embodiments, before the front-end security policy module obtains the security policy entry from the back-end security policy module in step S202, the method further includes:
[0036] Step S202A, upon receiving an indication of active front-end policy update based on human-computer interaction, the front-end security policy module sends a security policy synchronization request for querying the security policy entry to the back-end security policy module, wherein the security policy synchronization request is a synchronization message.
[0037] In some embodiments, step S202, in which the front-end security policy module obtains the security policy entry from the back-end security policy module, may include the following steps:
[0038] Step S2022, after receiving the security policy synchronization request, the back-end security policy module returns a security policy synchronization response to the front-end security policy module, wherein the security policy synchronization response carries the security policy entry;
[0039] Step S2024: the front-end security policy module receives the security policy synchronization response and obtains the security policy entry from the security policy synchronization response.
[0040] In some embodiments, after step S202, the method further includes:
[0041] Step S203: the front-end security policy module verifies the security policy entry. If the verification fails, the front-end security policy module continues to send the security policy synchronization request to the back-end security policy module until the security policy entry verification succeeds.
[0042] In an exemplary embodiment, the front-end security policy module can verify the format of the security policy entry, the integrity of the content, or whether the processing rules of the security policy conflict, etc. This application does not limit the verification method of the security policy entry.
[0043] In some embodiments, if the verification in step S203 succeeds, the security policy can be solidified by storage, and if the verification fails, the above steps S202A, S2022, S2024 and S203 are repeatedly executed until the verification in step S203 succeeds. In the embodiments of the present application, by verifying the security policy entries, it is possible to prevent the security policy entries from being incomplete or tampered with due to network anomalies and network security anomalies.
[0044] In some embodiments, before the front-end security policy module obtains the security policy entry from the back-end security policy module in step S202, the method further includes:
[0045] Step S202B: the front-end security policy module asynchronously monitors the push message of the back-end security policy module.
[0046] In some embodiments, after step S201, the method further includes: the back-end security policy module pushes a policy update message to at least one of the front-end security policy modules within a preset security policy issuance time period, wherein the policy update message is an asynchronous message and carries the security policy entry.
[0047] In an exemplary embodiment, the backend security policy module can push policy update messages to multiple frontend security policy modules in a broadcast manner, or can push policy update messages to each online frontend security policy module in a point-to-point manner. This application does not impose any restrictions on this.
[0048] In some embodiments, step S202, the front-end security policy module obtains the security policy entry from the back-end security policy module, including:
[0049] Step S2026: When the front-end security policy module monitors the policy update message actively pushed by the back-end security policy module, the front-end security policy module obtains the security policy entry from the policy update message.
[0050] In some embodiments, step S202B includes: at intervals of a preset first time, starting a monitoring period of a preset second time, wherein the difference between the preset first time and the preset second time is greater than a preset threshold; during the monitoring period, the front-end security policy module asynchronously monitors the push messages of the back-end security policy module.
[0051] In this embodiment, the preset first time is much longer than the preset second time. By setting a shorter monitoring duration and a longer monitoring interruption period, waste of resources caused by long-term monitoring can be avoided.
[0052] In some embodiments, the asynchronous monitoring of the push message of the backend security policy module by the frontend security policy module in step S202B may include the following steps:
[0053] Step S202B-1, when the monitoring duration begins, the front-end security policy module opens an event message monitoring channel for the back-end security policy module;
[0054] Step S202B-2: During the monitoring duration, the front-end security policy module asynchronously monitors the push message of the back-end security policy module through the event message monitoring channel;
[0055] Step S202B-3: When the monitoring duration ends, the front-end security policy module closes the event message monitoring channel.
[0056] In some embodiments, a security administrator user may set security policy entries or a security policy entry list (including multiple security policy entries) in the ToB network management (NM) software, and trigger subsequent security policy effectiveness mechanisms (including synchronous mechanisms and asynchronous mechanisms).
[0057] In some embodiments, each of the security policy entries includes at least one of the following: an identification, a name, a content description, a processing type, a policy effective location, and a processing rule.
[0058] In an exemplary embodiment, the processing type may include but is not limited to setting, replacing, encoding (transcoding), etc. Exemplarily, setting may be setting a specific parameter in a service request, and replacing may be replacing an HTTP request method, such as replacing a DELETE method with a POST method.
[0059] In this embodiment, the policy effective position can be set according to the message format of the business request. For example, when the business request is an HTTP request, according to the message format of the HTTP request, the policy effective position can include the request line, request header and request body, which correspond to the three components of the HTTP request, respectively, to facilitate separate processing.
[0060] In some embodiments, after step S202, the method further includes: step S204, the front-end security policy module stores the security policy entry in the front-end storage to complete the configuration of the front-end security policy.
[0061] In some embodiments, after the front-end security policy module stores the security policy entry in the front-end storage in step S204 to complete the configuration of the front-end security policy, the method further includes the following steps:
[0062] Step S206, when the front-end service module sends a service request to the back-end, the front-end security policy module reads the front-end security policy from the front-end storage;
[0063] Step S207, the front-end security policy module processes the service request according to the front-end security policy;
[0064] Step S208: Send the processed service request to the backend service module via the backend security policy module.
[0065] In this embodiment, the front-end business module and the back-end business module are used to process business requests according to business logic. The business module can be the original business logic processing module of the application, website or server. The security policy module is separated from the business module, and the security policy configuration of the front-end can be implemented without invading the original business logic.
[0066] In some embodiments, step S208 sends the processed service request to the backend service module via the backend security policy module, including the following steps:
[0067] Step S2082, the front-end security policy module sends the processed service request to the back-end security policy module;
[0068] Step S2084, the backend security policy module performs a security policy check on the processed service request according to the security policy entry;
[0069] Step S2086: When the security policy verification is successful, the backend security policy module sends the processed business request to the backend business module.
[0070] In this embodiment, the purpose of performing security policy verification on the service request is to verify whether the security policy executed by the front end is consistent with the security policy stored in the back end. Exemplarily, the verification can be performed by determining whether the processed service request satisfies the security policy stored in the back end, or the identifier of the executed security policy item can be directly carried in the processed service request, and the verification can be performed by determining whether the identifiers are consistent.
[0071] In some embodiments, the method further comprises the steps of:
[0072] Step S2087, when the security policy verification fails, the back-end security policy module returns a policy exception message to the front-end security policy module;
[0073] Step S2088: After receiving the policy exception message, the front-end security policy module sends a security policy synchronization request for querying the security policy entry to the back-end security policy module, wherein the security policy synchronization request is a synchronization message.
[0074] In this embodiment, the purpose of performing security policy verification on the service request is to verify whether the security policy executed by the front end is consistent with the security policy stored in the back end. If the security policy verification fails, it means that the security policy executed by the front end is not the latest security policy, and the security policy of the front end needs to be updated through a synchronization request.
[0075] In an embodiment of the present application, independent security policy modules are set at the front end and the back end. The front end obtains the security policy from the back end through asynchronous listening communication and synchronous communication, which can realize flexible configuration of the front-end security policy, thereby solving the problem that the security management method in related technologies lacks flexibility in front-end security adaptation. It can effectively meet the security needs of the front end in different scenarios while reducing the intrusiveness of the software, and also reduces the workload of security management research and development.
[0076] Figure 3 is a block diagram of a front-end security control system according to an embodiment of the present application, such as Figure 3 As shown, the system includes the following structure:
[0077] A back-end security policy module 32, used to manage at least one security policy entry under the settings of the network management software interface, wherein the security policy entry is a combination of front-end security rules;
[0078] The front-end security policy module 34 is used to obtain the security policy entry from the back-end security policy module when the triggering condition for the front-end policy update is met, wherein the front-end security policy module and the back-end security policy module support asynchronous monitoring communication and synchronous communication.
[0079] In some embodiments, the backend security policy module may execute the steps of any of the above method embodiments in the background or server of the application software or website.
[0080] In some embodiments, the front-end security policy module can execute the steps in any of the above method embodiments at the front end of a mobile terminal or a computer terminal.
[0081] In some embodiments, the triggering conditions for the front-end policy update may include: A, the front-end security policy module receives an indication of active front-end policy update generated based on human-computer interaction operations; and / or, B, the front-end security policy module monitors the policy update message actively pushed by the back-end security policy module.
[0082] In some embodiments, one back-end security policy module may correspond to multiple front-end security policy modules, and the front-end security policies of multiple terminal devices may be centrally managed through the back-end security policy modules.
[0083] In some embodiments, the system also includes a network management software interface. The security administrator user can set the security policy items in the back-end security policy module through the front-end network management software interface, and then the back-end security policy module sends the security policy items to each operation and maintenance personnel's terminal device (specifically the front-end security policy module).
[0084] In the embodiment of the present application, the front end and the back end are mainly divided into two parts. The front end is responsible for the user interface presentation and the business logic processing visible to the user. The front end may include all front end systems capable of establishing asynchronous monitoring communication and synchronous communication with the back end. The back end may include all back end systems capable of establishing asynchronous monitoring communication and synchronous communication with the front end. Exemplarily, the communication between the front end and the back end may be asynchronous monitoring communication and synchronous communication based on the HTTP protocol.
[0085] In an exemplary embodiment, the front end may include a front end security policy module and a front end service module. The front end may also include a network management software interface, and the front end service module may be a service module of a ToB network management. The back end may include a back end security policy module and a back end service module.
[0086] In some embodiments, the front-end security policy module is also used to send a security policy synchronization request for querying the security policy entry to the back-end security policy module upon receiving an indication of active update of the front-end policy generated based on human-computer interaction operations, wherein the security policy synchronization request is a synchronization message.
[0087] In some embodiments, the back-end security policy module is further used to return a security policy synchronization response to the front-end security policy module after receiving the security policy synchronization request, wherein the security policy synchronization response carries the security policy entry; the front-end security policy module is also used to receive the security policy synchronization response and obtain the security policy entry from the security policy synchronization response.
[0088] In some embodiments, the front-end security policy module is also used to verify the security policy entry before the front-end security policy module stores the security policy entry in the front-end storage. If the verification fails, continue to send the security policy synchronization request to the back-end security policy module until the security policy entry is verified successfully.
[0089] In some embodiments, the front-end security policy module is also used to asynchronously monitor push messages from the back-end security policy module.
[0090] In some embodiments, the network management software interface is used to set security policy entries according to user operations and send the set security policy entries to the back-end security policy module. The back-end security policy module is also used to push a policy update message to at least one of the front-end security policy modules within a preset security policy delivery time period after receiving the security policy entry, wherein the policy update message is an asynchronous message and carries the security policy entry.
[0091] In some embodiments, the front-end security policy module is further used to obtain the security policy entry from the policy update message when the front-end security policy module monitors the policy update message actively pushed by the back-end security policy module.
[0092] In some embodiments, the front-end security policy module is also used to start a monitoring period of a preset second time at intervals of a preset first time, wherein the difference between the preset first time and the preset second time is greater than a preset threshold; during the monitoring period, the push messages of the back-end security policy module are asynchronously monitored.
[0093] In some embodiments, the front-end security policy module is also used to open an event message monitoring channel for the back-end security policy module at the beginning of the monitoring duration; asynchronously monitor the push messages of the back-end security policy module through the event message monitoring channel during the monitoring duration; and close the event message monitoring channel at the end of the monitoring duration.
[0094] In some embodiments, the front-end security policy module is further used to store the security policy entries in the front-end storage to complete the configuration of the front-end security policy.
[0095] In some embodiments, the front-end security policy module is also used to read the front-end security policy from the front-end storage when the front-end business module sends a business request to the back-end; process the business request according to the front-end security policy; and send the processed business request to the back-end business module via the back-end security policy module.
[0096] In some embodiments, the front-end security policy module is also used to send the processed business request to the back-end security policy module; the back-end security policy module is also used to perform security policy verification on the processed business request according to the security policy entry; if the security policy verification is successful, the processed business request is sent to the back-end business module.
[0097] In some embodiments, the back-end security policy module is also used to return a policy exception message to the front-end security policy module when the security policy verification fails; the front-end security policy module is also used to send a security policy synchronization request for querying the security policy entry to the back-end security policy module after receiving the policy exception message, wherein the security policy synchronization request is a synchronization message.
[0098] The embodiment of the present application introduces a security policy module at the front end and the back end, and handles the management, issuance and effectiveness of the security policy through the security policy module, thereby avoiding intrusion into the business module and reducing the possibility of upgrading the business module for security governance.
[0099] Figure 4 is a schematic diagram of the processing flow of the front-end security control system according to an embodiment of the present application, such as Figure 4 As shown, the front-end security control system mainly includes the following processing procedures:
[0100] Security policy setting; security policy issuance; security policy inquiry; business request processing.
[0101] In this embodiment, the security manager can set the security policy through the front-end network management software interface. The security policy can be composed of a group of security policy items, which is a combination of front-end security processing rules. Each security policy item includes information such as name, description, type, and specific processing rules.
[0102] In this embodiment, the set security policy can be stored in the back end, and illustratively, can be stored in a storage module or database of the back end to realize the solidification of the back end security policy.
[0103] In this embodiment, the backend security policy module is responsible for managing security policy entries, and can support adding, modifying, deleting, and querying security policy entries. The backend security policy module is responsible for pushing security policies to the frontend and responding to security policy inquiries from the frontend.
[0104] In this embodiment, the front-end security policy module is responsible for executing the security policy at the front end, which may include setting, assembling, replacing, encoding and other operations on the front-end security parameters related to the service request, so that the front-end security parameters meet the security requirements of the current scenario. It is also responsible for sending the processed service request to the back-end system.
[0105] In an exemplary embodiment, after the security policy entries are set, the back-end security policy module will actively push the current security policy entries to the front-end to implement the security policy in a timely manner.
[0106] In another exemplary embodiment, the front-end security policy module can also actively initiate a security policy query to the back-end security policy module. For example, in the case of initial startup of the front-end application, initial login of the user, or refresh of the website page, the front-end security policy module can obtain the current security policy entry through the security policy query.
[0107] In this embodiment, the security policy is issued through an asynchronous monitoring mechanism, and the security policy query is implemented through a synchronous mechanism. Exemplarily, the asynchronous monitoring and synchronous query can be implemented based on the HTTP protocol.
[0108] In this embodiment, both the front end and the back end have business modules responsible for responding to and processing specific business requests.
[0109] In the embodiment of the present application, the front-end and back-end each introduce a security policy module to centrally process the setting, querying, issuing, solidifying, and taking effect of the security policy, without intruding on the network management business module. The business processing logic of the business module and the security control logic of the security policy module are independent of each other, and the front-end security policy can be flexibly set without intruding on the business logic, reducing the possibility of modifying the business program and reducing the workload of R&D personnel.
[0110] In this embodiment, there are two mechanisms for the effectiveness of the front-end security policy. One is that after the front-end starts monitoring the back-end events, the back-end pushes the security policy to the online front-end, and immediately starts the effectiveness of the relevant security policy on the front-end; the other is that for the newly started front-end, after logging into the network management, the front-end will actively inquire the back-end for the latest security policy. For example, after setting the security policy, the security administrator can send the policy to the currently online terminal through the first method. If a new terminal comes online later, the currently executed policy can be obtained through the second method.
[0111] Figure 5 is a schematic diagram of the process of timely effectiveness of the security policy according to the embodiment of the present application, such as Figure 5 As shown in the figure, the process of timely implementation of security policies may include the following steps:
[0112] Step S502, the security administrator user sets security policies in the network management software interface;
[0113] Step S504: the backend security policy module pushes the security policy to all online listening frontend security policy modules through messages, thereby implementing the distribution of the frontend security policy;
[0114] Step S506: After the front-end security policy module receives the security policy update message pushed by the back-end, it takes effect immediately and solidifies the security policy in the front-end storage.
[0115] In this embodiment, there can be multiple front-end security policy modules, which are located in different terminals. The security administrator sets the security policy in the network management interface through the management terminal. The operation and maintenance personnel can monitor the back-end events on multiple terminals to obtain the security policy that takes effect immediately.
[0116] In this embodiment, asynchronous monitoring communication is adopted between the front-end and the back-end. The front-end monitors the back-end events, and the back-end sends the policy update message through the asynchronous message (such as HTTP broadcast message). For example, the asynchronous monitoring can be realized through the websocket (network socket) or server event (service event).
[0117] In an exemplary embodiment, the front end can set a shorter monitoring duration, perform asynchronous monitoring during the monitoring duration, and set a longer time interval between two monitoring durations, thereby saving the connection resources that the back end would have spent on making the front-end security policy effective. Under the condition of a certain bandwidth, the network management service runs more smoothly.
[0118] In an exemplary embodiment, the security policy setting process may also include processes such as front-end and back-end communication, back-end storage solidification, etc. The front-end network management (or front-end security policy module) sends the set security policy items (list) to the back-end (back-end program or server) according to user operations, and the back-end security policy module may solidify the security policy items into the back-end storage.
[0119] In the embodiment of the present application, the latest security policy can be sent to all online operation and maintenance terminals in a timely manner through the security policy timely effectiveness mechanism, thereby improving the flexibility and timeliness of security policy adjustment in different scenarios. The embodiment of the present application can send the security policy to all online operation and maintenance terminals in real time by asynchronous push messages to avoid message blocking. The embodiment of the present application can also avoid wasting a large amount of connection resources by long-term monitoring while ensuring that the security policy takes effect in a timely manner by setting a shorter monitoring duration.
[0120] Figure 6 Flowchart showing the timely effectiveness of the security policy of the front-end security policy module according to an embodiment of the present application, such as Figure 6 As shown, the process includes the following steps:
[0121] Step S602, monitoring the backend push message;
[0122] Step S604, determining whether it is a policy update message;
[0123] Step S606: If it is a policy update message, update the front-end security policy.
[0124] In this embodiment, in step S602, the front-end security policy module triggers the start of the process when the front-end monitors the back-end push message. If step S604 determines that the push message is not a policy update message, the process ends directly.
[0125] In an exemplary embodiment, updating the front-end security policy may include updating the internal cache of the front-end security policy module. In another exemplary embodiment, the front-end security policy module may solidify the received security policy into a storage module outside the front-end security policy module, such as a browser cache, which is not limited in this application. In a scenario where the frequency of front-end security policy updates is low, solidified storage may enable the terminal to directly obtain the available front-end security policy at the next startup.
[0126] Figure 7 is a schematic diagram of the security policy query validation process according to an embodiment of the present application, such as Figure 7 As shown, the security policy query process may include the following steps:
[0127] Step S702: the front-end security policy module sends a security policy synchronization request to the back-end security policy module to inquire about the security policy;
[0128] Step S704, the back-end security policy module sends the security policy to the front-end security policy module through a security policy synchronization response;
[0129] Step S706: The front-end security policy module parses and verifies the security policy synchronization response and solidifies the security policy.
[0130] In this embodiment, the security policy synchronization request may be an HTTP request (Request), and the security policy synchronization response may be an HTTP response (Response).
[0131] In an exemplary embodiment, step S706 can verify the security policy, such as policy integrity, policy format, whether there are conflicts in the rules contained in the policy, etc. This application does not limit this. If the policy verification is successful, the policy will take effect and be solidified into the front-end storage. If the policy verification fails, it is necessary to resend the security policy synchronization request to the back-end for policy inquiry.
[0132] In an exemplary embodiment, the security policy query process can also be initiated during the business request processing process. For example, the front-end security policy module processes the business request according to the front-end policy, and sends the processed business request to the back-end business module through the back-end security policy module. At this time, the back-end security policy module will also verify the security policy of the processed business request to verify whether the security policy executed by the front-end is the same as the security policy stored in the back-end. If the two policies are inconsistent, the back-end will notify the front-end, and then the front-end will initiate the security policy query process through an HTTP request.
[0133] Through this embodiment, the front end can actively obtain policies from the back end in scenarios such as initial startup, login, page refresh, or security policy exception of the terminal device. The policy synchronization query mechanism can make up for the application scenario gap of the asynchronous monitoring mechanism, ensuring that the effectiveness of the front-end security policy can cover different application scenarios.
[0134] Figure 8 is a flowchart of a security policy query of a front-end security policy module according to an embodiment of the present application, such as Figure 8 As shown, the process may include the following steps:
[0135] Step S802: The business personnel starts the front end and logs into the system or refreshes the page if already logged in;
[0136] Step S804, the front end sends a security policy synchronization request (HTTP Request) to the back end to inquire about the security policy;
[0137] Step S806, determining whether the security policy is obtained and verified successfully, if the security policy is obtained and verified successfully, proceeding to the next step, otherwise repeating step S804;
[0138] Step S808: The front end updates the security policy and saves it to the front end storage.
[0139] Through the embodiments of the present application, the front end can actively obtain policies from the back end in scenarios such as initial startup, login, page refresh, or security policy exceptions of the terminal device. The policy synchronization query mechanism can make up for the application scenario gap of the asynchronous monitoring mechanism, and build a complete security policy setting and effectiveness mechanism to help the on-site operation and maintenance team customize security policies and perform unified effectiveness operations. The security policy setting is more flexible and can meet the differentiated security requirements of different industries.
[0140] Fig. 9 is a schematic diagram of the monitoring duration in the asynchronous monitoring mechanism according to an embodiment of the present application, such as Fig. 9 As shown, the front-end establishes an event message channel with the back-end during the monitoring period and monitors the back-end push messages.
[0141] In this embodiment, the front end can actively open the monitoring channel at a preset time. If there is a security policy update on the back end, the policy update message will be pushed within the preset security policy delivery time period. During the time period that coincides with the monitoring duration of the front end, the front end can obtain the security policy through the push message from the back end. Regardless of whether the front end monitors the push message, the front end will actively close the monitoring channel at the end of the duration.
[0142] In this embodiment, the duration of the monitoring duration is less than the time interval between two durations. For example, the duration can be set to 5 minutes, and the time interval can be set to 1 hour. The front end will start the monitoring duration again after each preset time interval. This application does not limit the duration and interval time of the duration, and the time can also be set in seconds or millimeters.
[0143] In some embodiments, the security policy delivery time period may be greater than the duration of the monitoring duration.
[0144] In the embodiment of the present application, the immediate effect mechanism uses a short-duration time slice for communication, which can reduce the time of occupying system resources, avoid long-term and unlimited occupation of conventional business channels, and save communication resources.
[0145] Fig.10 is a flowchart of the business processing flow of the front-end security policy module according to an embodiment of the present application, such as Fig.10 As shown, the process may include the following steps:
[0146] Step S1000: the front end triggers the security policy execution process by sending a service request to the back end;
[0147] Step S1002, the front end reads the security policy from the storage;
[0148] Step S1004, the front end parses and executes the security policy to send a service request;
[0149] Step S1006: If an exception occurs, a security policy synchronization request is sent to the backend to query the policy;
[0150] Step S1008: The front end updates the security policy and saves it to the front end storage, and then re-enters step S1002.
[0151] In this embodiment, after the security policy takes effect, during normal business operation, the front-end security policy module executes the security policy to process the business request and then sends it to the back-end.
[0152] In this embodiment, the service request is initiated by the operation and maintenance personnel through the front-end service module. The front-end security policy module performs security processing on the service request according to the front-end security policy, and sends the processed service request to the back-end service module through the back-end security policy module. The back-end security policy module verifies the service request after security processing, mainly to verify whether the security policies executed by the front and back ends are consistent. The judgment can be made based on the identifier, processing type or specific processing rules in the executed security policy entry.
[0153] In an exemplary embodiment, the processing rule of the security policy is to replace the DELETE method with the POST method. If the back-end security policy module detects that the processed business request is the DELETE method, it means that the front-end and back-end security policies are inconsistent. The back-end returns a policy exception message to the front-end, and the front-end re-initiates a policy query after receiving the message.
[0154] In some embodiments, the security administrator user sets security policy entries in the ToB network management (NM) software. In the ToB NM software, the security policy setting can be completed based on a security policy entry or a list of security policy entries, thereby triggering a subsequent effectiveness mechanism.
[0155] In some embodiments, as shown in Table 1, the security policy entry includes but is not limited to one or more of the following combinations: the security policy entry's identifier, name, content description, processing type, effective location, and specific processing rules.
[0156] Table 1:
[0157] Security policy entry ID Security policy entry ID Security policy entry name The name of the security policy entry Description Security implications and application scenarios of security policy entries Processing Type Security policy processing types such as: set, replace, encode Policy effective location The location of the security policy entry corresponding to the HTTP protocol request Security policy entry specific rules Different security policies have different configured policy values
[0158] In an exemplary embodiment, the processing types of the security policy entry include setting, replacing, encoding, etc. The effective positions of the security policy entry include the request line, request header and request body, which correspond to the three components of the HTTP request respectively, so as to facilitate separate processing.
[0159] In an exemplary embodiment, as shown in Table 2, the security policy entry list may include multiple security policy entries.
[0160] Table 2:
[0161]
[0162]
[0163] Through the embodiments of this application, different requirements of customers in different industries for front-end security scanning can be met, and flexible adaptation of security policies for front-end security parameters can be achieved, providing more personalized security management. This application does not need to modify the front-end and back-end codes according to industry security specifications, reducing the workload and complexity of system security management.
[0164] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored, wherein the computer program executes the steps of any of the above method embodiments when executed by a processor.
[0165] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.
[0166] An embodiment of the present application further provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0167] In an exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.
[0168] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.
[0169] Obviously, those skilled in the art should understand that the above modules or steps of the present application can be implemented by a general computing device, they can be concentrated on a single computing device, or distributed on a network composed of multiple computing devices, they can be implemented by a program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be executed in a different order from that herein, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. Thus, the present application is not limited to any specific combination of hardware and software.
[0170] The above description is only the preferred embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the principles of the present application shall be included in the protection scope of the present application.
Claims
1. A front-end security control method, characterized in that: The method comprises: Setting at least one security policy entry in the back-end security policy module through the network management software interface, wherein the security policy entry is a combination of front-end security rules; When the triggering conditions for the front-end policy update are met, the front-end security policy module obtains the security policy entry from the back-end security policy module so as to perform security control on the front end based on the security policy entry, wherein asynchronous listening communication and synchronous communication are supported between the front-end security policy module and the back-end security policy module.
2. The method according to claim 1, characterized in that The triggering conditions for the front-end policy update include: The front-end security policy module receives an indication of active front-end policy update generated based on human-computer interaction operation; And / or, the front-end security policy module monitors the policy update message actively pushed by the back-end security policy module.
3. The method according to claim 2, characterized in that Before the front-end security policy module obtains the security policy entry from the back-end security policy module, the method further includes: Upon receiving an indication of active front-end policy update based on human-computer interaction, the front-end security policy module sends a security policy synchronization request for querying the security policy entry to the back-end security policy module, wherein the security policy synchronization request is a synchronization message.
4. The method according to claim 3, characterized in that The front-end security policy module obtains the security policy entry from the back-end security policy module, including: After receiving the security policy synchronization request, the back-end security policy module returns a security policy synchronization response to the front-end security policy module, wherein the security policy synchronization response carries the security policy entry; The front-end security policy module receives the security policy synchronization response and obtains the security policy entry from the security policy synchronization response.
5. The method according to claim 4, characterized in that After the front-end security policy module obtains the security policy entry from the back-end security policy module, the method further includes: The front-end security policy module verifies the security policy entry; If the verification fails, the security policy synchronization request continues to be sent to the back-end security policy module until the security policy entry is verified successfully.
6. The method according to claim 2, characterized in that Before setting at least one security policy item in the back-end security policy module through the network management software interface, the method further includes: The front-end security policy module asynchronously monitors the push message of the back-end security policy module.
7. The method according to claim 6, characterized in that After setting at least one security policy item in the back-end security policy module through the network management software interface, the method further includes: The back-end security policy module pushes a policy update message to at least one of the front-end security policy modules within a preset security policy issuance time period, wherein the policy update message is an asynchronous message and carries the security policy entry.
8. The method according to claim 7, characterized in that The front-end security policy module obtains the security policy entry from the back-end security policy module, including: In the case where the front-end security policy module monitors the policy update message actively pushed by the back-end security policy module, the front-end security policy module obtains the security policy entry from the policy update message.
9. The method according to claim 6, characterized in that The front-end security policy module asynchronously monitors the push message of the back-end security policy module, including: At each preset first time interval, a monitoring duration of a preset second time is started, wherein the difference between the preset first time and the preset second time is greater than a preset threshold; During the monitoring duration, the front-end security policy module asynchronously monitors the push messages of the back-end security policy module.
10. The method according to claim 9, characterized in that During the monitoring duration, the front-end security policy module asynchronously monitors the push message of the back-end security policy module, including: When the monitoring duration begins, the front-end security policy module opens an event message monitoring channel for the back-end security policy module; During the monitoring duration, the front-end security policy module asynchronously monitors the push messages of the back-end security policy module through the event message monitoring channel; When the monitoring duration ends, the front-end security policy module closes the event message monitoring channel.
11. The method according to claim 1, characterized in that: Each of the security policy entries includes at least one of the following: an identifier, a name, a content description, a processing type, a policy effective location, and a processing rule.
12. The method according to claim 1, characterized in that After the front-end security policy module obtains the security policy entry from the back-end security policy module, the method further includes: The front-end security policy module stores the security policy entries in the front-end storage to complete the configuration of the front-end security policy.
13. The method according to claim 12, characterized in that After the front-end security policy module stores the security policy entry in the front-end storage to complete the configuration of the front-end security policy, the method further includes: When the front-end service module sends a service request to the back-end, the front-end security policy module reads the front-end security policy from the front-end storage; The front-end security policy module processes the service request according to the front-end security policy; The processed service request is sent to the back-end service module via the back-end security policy module.
14. The method according to claim 13, characterized in that Sending the processed service request to the back-end service module via the back-end security policy module includes: The front-end security policy module sends the processed service request to the back-end security policy module; The back-end security policy module performs security policy verification on the processed service request according to the security policy entry; When the security policy verification is successful, the back-end security policy module sends the processed service request to the back-end service module.
15. The method according to claim 14, characterized in that The method further comprises: In the event that the security policy verification fails, the back-end security policy module returns a policy exception message to the front-end security policy module; After receiving the policy exception message, the front-end security policy module sends a security policy synchronization request for querying the security policy entry to the back-end security policy module, wherein the security policy synchronization request is a synchronization message.
16. A front-end safety control system, characterized in that: The system comprises: A back-end security policy module, used to manage at least one security policy entry under the settings of the network management software interface, wherein the security policy entry is a combination of front-end security rules; The front-end security policy module is used to obtain the security policy entry from the back-end security policy module when the triggering condition of the front-end policy update is met, wherein the front-end security policy module and the back-end security policy module support asynchronous monitoring communication and synchronous communication.
17. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, wherein the computer program executes the method described in any one of claims 1 to 15 when executed by a processor.
18. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to perform the method according to any one of claims 1 to 15.