Firewall policy data compression method and device, equipment, storage medium and program product

By splitting and compressing firewall policy data, the problem of increasing data scale and complexity in traditional management methods is solved, efficient storage and management is achieved, and network performance and operation and maintenance efficiency are improved.

CN119945796APending Publication Date: 2025-05-06INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510210616.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The traditional firewall strategy data management method faces the problem of increasing data scale and complexity, which leads to inefficient manual operations, information loss or duplication, increasing operation and maintenance difficulties and affecting the normal operation of the business.

Method used

By obtaining the initial firewall policy data, splitting the multi-port policy data into single-port policy data, expanding the source destination address as the subnet address, and determining whether to compress and merge according to the preset elements to generate the target policy data set.

Benefits of technology

It effectively reduces storage space usage, reduces the number of firewall rules, improves overall storage efficiency and network performance, simplifies firewall management and maintenance, and reduces the chance of errors and operation and maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945796A_ABST
    Figure CN119945796A_ABST
Patent Text Reader

Abstract

The invention provides a firewall policy data compression method, which can be used in the financial science and technology field or other fields, and comprises the following steps: obtaining initial firewall policy data, the initial firewall policy data comprising multi-port policy data and single-port policy data; splitting the multi-port policy data into single-port policy data based on the port configuration information to obtain intermediate firewall policy data containing the single-port policy data; expanding a source-destination address of the intermediate firewall policy data to obtain a plurality of source-destination subnet addresses of the intermediate firewall policy data; and when each source and target subnet address accords with a preset element, compressing and merging the intermediate firewall policy data under the condition of judging that the source and target subnet addresses are the same as the ports, and generating a target policy data set. The invention further provides a firewall policy data compression device and equipment, a storage medium and a program product.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of financial technology, and more specifically to a firewall policy data compression method, device, equipment, storage medium and program product. Background Art

[0002] With the rapid development of network technology, the complexity of information systems and network applications continues to increase. As an important part of network security, firewalls are responsible for monitoring and controlling network traffic. Effective management and optimization of firewall policy data is crucial to improving network security and performance. However, with the changes in the network environment and diversified application requirements, the scale and complexity of firewall policy data are also gradually increasing, resulting in many challenges for traditional firewall policy management methods, and operation and maintenance management has become a difficult point.

[0003] The current firewall policy data compression technology mainly relies on manual operation and judgment. The data compression process may cause information loss or duplication, affecting the quality and effectiveness of network operation and maintenance. In addition, manual operation is inefficient and there is a risk of omissions and misjudgment, which not only increases the difficulty of network operation and maintenance, but also affects the normal operation of the business. Summary of the invention

[0004] In view of the above problems, the present disclosure provides a firewall policy data compression method, apparatus, device, storage medium and program product.

[0005] According to a first aspect of the present disclosure, a firewall policy data compression method is provided, comprising: obtaining initial firewall policy data, the initial firewall policy data comprising multi-port policy data and single-port policy data; splitting the multi-port policy data into single-port policy data based on port configuration information to obtain intermediate firewall policy data comprising single-port policy data; extending the source and destination addresses of the intermediate firewall policy data to obtain multiple source and destination subnet addresses of the intermediate firewall policy data; and when each source and destination subnet address meets preset elements, compressing and merging the intermediate firewall policy data to generate a target policy data set by judging that the source and destination subnet address and the port are the same.

[0006] According to an embodiment of the present disclosure, the method also includes: when there is a source subnet address that does not meet the preset elements, by judging that the number of source subnet addresses is lower than a preset threshold, the intermediate firewall policy data is directly generated into a target policy data set.

[0007] According to an embodiment of the present disclosure, the method also includes: when there is a source subnet address that does not meet the preset elements, the source subnet address is split under the condition that the number of source subnet addresses is higher than a preset threshold; and the intermediate firewall policy data after the split operation is used to generate a target policy data set.

[0008] According to an embodiment of the present disclosure, based on the port configuration information, multi-port policy data is split into single-port policy data to obtain intermediate firewall policy data containing single-port policy data, wherein the multi-port policy data includes the source address, destination address, protocol type and corresponding multiple ports of the policy, including: parsing the multi-port policy data and identifying all ports; generating a list containing all single ports based on the parsed multi-port information; and generating corresponding single-port policy data for each single port in the list.

[0009] According to an embodiment of the present disclosure, the source and destination addresses of the intermediate firewall policy data are expanded to obtain multiple source and destination subnet addresses of the intermediate firewall policy data, wherein the source and destination addresses include a source address and a destination address, including: dividing the source address and the destination address in CIDR (Classless Inter-Domain Routing) notation according to the category of the IP address to determine the subnet mask; using the subnet mask to divide the source address and the destination address into multiple subnets, and generating corresponding subnet addresses.

[0010] According to an embodiment of the present disclosure, a subnet mask is used to divide a source address and a destination address into multiple subnets, and corresponding subnet addresses are generated, including: checking whether there are overlapping subnet addresses, and merging and optimizing them.

[0011] According to an embodiment of the present disclosure, when each source subnet address meets the preset elements, the intermediate firewall policy data is compressed and merged by judging that the source subnet address and the port are the same, and a target policy data set is generated, including: defining the preset elements, and determining that each source subnet address meets the preset elements, wherein the preset elements include direction, state, action, firewall ID and policy_id; classifying and grouping the intermediate firewall policy data according to the categories of the source subnet address and the port; deduplicating the intermediate firewall policy data of the same source subnet address and port in each group, and retaining the unique policy item; when the condition that the source subnet address and the port are the same is met, the intermediate firewall policy data of different groups with the same source subnet address and port are merged and combined to generate a compressed target policy data set.

[0012] A second aspect of the present disclosure provides a firewall policy data compression device, including: a policy data acquisition module, used to acquire initial firewall policy data, the initial firewall policy data including multi-port policy data and single-port policy data; a policy data splitting module, used to split the multi-port policy data into single-port policy data based on port configuration information, and obtain intermediate firewall policy data containing all single-port policy data; a policy data expansion module, used to expand the source and destination addresses of the intermediate firewall policy data, and obtain multiple source and destination subnet addresses of the intermediate firewall policy data; a policy data compression module, used to compress and merge the intermediate firewall policy data when each source and destination subnet address meets the preset elements, by judging that the source and destination subnet address and the port are the same, to generate a target policy data set.

[0013] According to an embodiment of the present disclosure, the policy data compression module also includes: when there is a source subnet address that does not meet the preset elements, by judging that the number of source subnet addresses is lower than a preset threshold, the intermediate firewall policy data set is directly generated.

[0014] According to an embodiment of the present disclosure, the policy data compression module also includes: when there is a source subnet address that does not meet the preset elements, by judging that the number of source subnet addresses is higher than a preset threshold, splitting the source subnet address; and generating a target policy data set from the intermediate firewall policy data after the splitting operation.

[0015] A third aspect of the present disclosure provides an electronic device, comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the above method.

[0016] The fourth aspect of the present disclosure further provides a computer-readable storage medium having a computer program or instructions stored thereon, which implements the steps of the above method when the above computer program or instructions are executed by a processor.

[0017] The fifth aspect of the present disclosure further provides a computer program product, including a computer program or instructions, which implement the steps of the above method when the above computer program or instructions are executed by a processor. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The above contents and other purposes, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:

[0019] Figure 1 The application scenario diagram of the firewall policy data compression method according to the embodiment of the present disclosure is schematically shown;

[0020] Figure 2 A flowchart of a method for compressing firewall policy data according to an embodiment of the present disclosure is schematically shown;

[0021] Figure 3 A flowchart for obtaining intermediate firewall policy data according to an embodiment of the present disclosure is schematically shown;

[0022] Figure 4 Schematically shows a flow chart of policy data expansion according to an embodiment of the present disclosure;

[0023] Figure 5 Schematically shows a flow chart of policy data compression according to an embodiment of the present disclosure;

[0024] Figure 6 A schematic diagram showing a structural block diagram of a firewall policy data compression device according to an embodiment of the present disclosure; and

[0025] Figure 7 A block diagram of an electronic device suitable for implementing a firewall policy data compression method according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION

[0026] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the present disclosure. In the following detailed description, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of known structures and technologies are omitted to avoid unnecessary confusion of the concepts of the present disclosure.

[0027] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "comprise", "include", etc. used herein indicate the existence of features, steps, operations and / or components, but do not exclude the existence or addition of one or more other features, steps, operations or components.

[0028] All terms (including technical and scientific terms) used herein have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0029] When using expressions such as "at least one of A, B, and C, etc.", they should generally be interpreted according to the meaning of the expression commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).

[0030] It should be noted that the firewall policy data compression method and device disclosed herein can be used in the field of financial technology, and can also be used in any field other than the field of financial technology. The application field of the firewall policy data compression method and device disclosed herein is not limited.

[0031] In the technical solution of the present disclosure, the user information (including but not limited to user personal information, user image information, user device information, such as location information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved are all information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with relevant laws, regulations and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0032] In the scenario of using personal information for automated decision-making, the methods, devices, and systems provided by the embodiments of the present disclosure provide users with corresponding operation portals for users to choose to agree or reject the automated decision-making results; if the user chooses to reject, the expert decision-making process will be entered. The expression "automated decision-making" here refers to the activity of automatically analyzing and evaluating a person's behavioral habits, interests and hobbies, or economic, health, credit status, etc. through computer programs, and making decisions. The expression "expert decision-making" here refers to the activity of making decisions by people who specialize in a certain field, have specialized experience, knowledge and skills, and have reached a certain level of professionalism.

[0033] An embodiment of the present disclosure provides a firewall policy data compression method, the method comprising: obtaining initial firewall policy data, the initial firewall policy data comprising multi-port policy data and single-port policy data; splitting the multi-port policy data into single-port policy data based on port configuration information to obtain intermediate firewall policy data comprising single-port policy data; extending the source and destination addresses of the intermediate firewall policy data to obtain multiple source and destination subnet addresses of the intermediate firewall policy data; when each source and destination subnet address meets preset elements, compressing and merging the intermediate firewall policy data to generate a target policy data set by judging that the source and destination subnet address and the port are the same.

[0034] Through the embodiments of the present disclosure, by splitting and compressing the firewall policy data, the storage space occupied is effectively reduced, and the merged target policy data set can significantly reduce the number of firewall rules, thereby improving the overall storage efficiency; through effective policy data integration, the resource waste caused by repeated policies is reduced, network resources are more efficiently utilized, the overall network performance is improved, the firewall can be more easily managed and maintained, the error rate is reduced, and the operation and maintenance efficiency is improved. In addition, according to the preset elements of the source and destination subnet addresses, flexible processing can be performed to adapt to different network environments and security requirements, so that the firewall policy can be dynamically adjusted according to the actual traffic situation, which not only enhances the adaptability of the system, but also improves the scalability of subsequent policies.

[0035] Figure 1 The application scenario diagram of the firewall policy data compression method according to the embodiment of the present disclosure is schematically shown.

[0036] like Figure 1 As shown, the application scenario 100 according to this embodiment may include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is used to provide a medium for communication links between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired, wireless communication links, or optical fiber cables, etc.

[0037] The user can use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 through the network 104 to receive or send messages, etc. Various communication client applications can be installed on the first terminal device 101, the second terminal device 102, and the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (only for example).

[0038] The first terminal device 101, the second terminal device 102, and the third terminal device 103 may be various electronic devices having display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, and the like.

[0039] The server 105 may be a server that provides various services, such as a background management server (only as an example) that provides support for websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103. The background management server may analyze and process the received data such as user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal device.

[0040] It should be noted that the firewall policy data compression method provided in the embodiment of the present disclosure can generally be executed by the server 105. Accordingly, the firewall policy data compression device provided in the embodiment of the present disclosure can generally be set in the server 105. The firewall policy data compression method provided in the embodiment of the present disclosure can also be executed by a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105. Accordingly, the firewall policy data compression device provided in the embodiment of the present disclosure can also be set in a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105.

[0041] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is only for illustration. Any number of terminal devices, networks and servers may be provided according to implementation requirements.

[0042] The following will be based on Figure 1 The scene described by Figure 2~Figure 5 The firewall policy data compression method of the disclosed embodiment is described in detail.

[0043] Figure 2 A flowchart of a method for compressing firewall policy data according to an embodiment of the present disclosure is schematically shown.

[0044] like Figure 2 As shown, in an embodiment of the present disclosure, the firewall policy data compression method specifically includes operations S210 to S240.

[0045] In operation S210, initial firewall policy data is acquired, where the initial firewall policy data includes multi-port policy data and single-port policy data.

[0046] In the embodiments of the present disclosure, the enterprise software is provided with corresponding firewall devices during use, which are used to monitor and control the traffic in and out of the software and protect the computer network from unauthorized access and network attacks. In order to effectively collect and analyze the configuration and policy of the firewall, in the process of obtaining the initial firewall policy data, the purpose of obtaining the initial firewall policy data is first determined, such as managing the firewall devices that exceed the preset threshold.

[0047] Furthermore, for those firewall devices that have exceeded the threshold, by accessing the firewall management interface, for example, using a management account to log in to the firewall device through a Web interface or SSH, the recorded initial firewall policy data can be exported in the policy configuration management interface.

[0048] In operation S220, based on the port configuration information, the multi-port policy data is split into single-port policy data to obtain intermediate firewall policy data including single-port policy data.

[0049] Figure 3 A flowchart for obtaining intermediate firewall policy data according to an embodiment of the present disclosure is schematically shown.

[0050] like Figure 3 As shown, in an embodiment of the present disclosure, based on the port configuration information, the multi-port policy data is split into single-port policy data to obtain intermediate firewall policy data containing single-port policy data, wherein the multi-port policy data includes the source address, destination address, protocol type and corresponding multiple ports of the policy, specifically including operations S310 to S330.

[0051] In operation S310, multi-port policy data is parsed and all ports are identified.

[0052] In operation S320, a list including all single ports is generated according to the parsed multi-port information.

[0053] In operation S330, corresponding single-port policy data is generated for each single port in the list.

[0054] Specifically, after obtaining the initial firewall policy data, which includes multi-port policy data and single-port policy data, first determine which policy data is multi-port, which policy data usually lists multiple ports in the "Port" field, which may be separated by commas, hyphens or other separators.

[0055] Furthermore, for each multi-port policy data, all single ports are parsed out, for example, a regular expression or a string segmentation method may be used to extract each single port number and generate a list containing all single ports.

[0056] Further, for each parsed single port in the list, a new single port policy entry is created. Each new entry should retain other key information of the original policy (such as source address, destination address, protocol, etc.), but set the port field to a single port.

[0057] Through the embodiments of the present disclosure, comprehensive analysis of multi-port policy data can ensure that all port information is accurately identified; in addition, corresponding single-port policy data is automatically generated for each single port in the list, thereby automating policy generation, reducing the need for manual intervention, reducing the possibility of errors, and improving work efficiency.

[0058] In operation S230, the source destination address of the intermediate firewall policy data is expanded to obtain multiple source destination subnet addresses of the intermediate firewall policy data.

[0059] Figure 4 The flowchart of policy data expansion according to an embodiment of the present disclosure is schematically shown.

[0060] like Figure 4 As shown, in an embodiment of the present disclosure, the source-destination address of the intermediate firewall policy data is expanded to obtain multiple source-destination subnet addresses of the intermediate firewall policy data, wherein the source-destination address includes a source address and a destination address, specifically including operations S410 to S420.

[0061] In operation S410 , a source address and a destination address are divided according to a class of an IP address in CIDR (Classless Inter-Domain Routing) notation to determine a subnet mask.

[0062] In operation S420, the source address and the destination address are divided into a plurality of subnets using a subnet mask, and corresponding subnet addresses are generated.

[0063] Specifically, the source address and the destination address are extracted from the existing intermediate firewall policy data, and these addresses are usually expressed in IP format. According to the category of the IP address, for example, including A, B, C, D and E. According to the determined category, a suitable CIDR representation is selected for the source address and the destination address, and the subnet mask is obtained by converting the CIDR representation. Among them, the subnet mask is used to divide the network, and an IP address can be divided into multiple subnets. For example, for a class C address, the default subnet mask is 255.255.255.0.

[0064] Furthermore, the source and destination addresses are bitwise ANDed with the subnet mask to obtain the subnet address, and an available subnet range is generated based on the subnet address and its mask.

[0065] It should be noted that after the subnet addresses are generated, it is necessary to check whether there are overlapping subnet addresses, and merge and optimize them.

[0066] Through the embodiments of the present disclosure, CIDR notation and subnet masks are effectively used to classify and divide IP addresses to obtain multiple source and destination subnet addresses of firewall policy data, thereby achieving optimized management of network resources and improved efficiency.

[0067] In operation S240, when each source subnet address meets the preset elements, the intermediate firewall policy data is compressed and merged to generate a target policy data set by judging that the source subnet address and the port are the same.

[0068] Figure 5The flowchart of policy data compression according to an embodiment of the present disclosure is schematically shown.

[0069] like Figure 5 As shown, in an embodiment of the present disclosure, when each source subnet address meets the preset elements, the intermediate firewall policy data is compressed and merged under the condition that the source subnet address and the port are the same to generate a target policy data set, specifically including operations S510 to S540.

[0070] In operation S510, preset elements are defined, and it is determined that each source-destination subnet address meets the preset elements, wherein the preset elements include direction, state, action, firewall ID, and policy_id.

[0071] In operation S520, the intermediate firewall policy data is classified and grouped according to the categories of the source subnet address and the port.

[0072] In operation S530, the intermediate firewall policy data with the same source destination subnet address and port in each group is deduplicated, and unique policy items are retained.

[0073] In operation S540, when the condition that the source destination subnet address and the port are the same is met, the intermediate firewall policy data of different groups with the same source destination subnet address and port are merged and combined to generate a compressed target policy data set.

[0074] In the embodiment of the present disclosure, it is first determined whether the multiple source destination subnet addresses obtained meet the preset elements, which include direction, state, action, firewall ID and policy_id, that is, each of these source destination subnet addresses meets these 5 elements. For example, the source subnet is 192.168.1.0 / 24, the target subnet is 10.1.1.0 / 24, and the following attributes are set: direction: inbound; state: new; action: allow; firewall ID: FW-001; policy_id: POLICY-1234.

[0075] Furthermore, these intermediate firewall policy data are classified according to source address, destination address and port to form different groups.

[0076] Furthermore, for each entry in each group, check whether the source address, destination address and port are the same. If they are the same, deduplicate them and retain one of them to generate a deduplicated data set.

[0077] Furthermore, when the condition that the source subnet address and the port are the same is met, the intermediate firewall policy data of different groups with the same source subnet address and port are merged and combined to generate a compressed target policy data set.

[0078] Exemplarily, when it is found that the policy data in multiple groups have the same source destination subnet address and port, they are merged. For example: the first group of policies: {"source": "192.168.1.0 / 24", "destination": "10.1.1.0 / 24", "port": 80, "action": "allow"} The second group of policies: {"source": "192.168.1.0 / 24", "destination": "10.1.1.0 / 24", "port": 80, "action": "deny"}, merge the policies to generate a new target policy data set. In this way, a compressed target policy data set is generated, which contains the firewall policies that have been deduplicated and merged, effectively reducing the number of policies.

[0079] Through the embodiments of the present disclosure, by compressing the firewall policy data, the storage space occupied is effectively reduced, and the merged target policy data set can significantly reduce the number of firewall rules, thereby improving the overall storage efficiency; through effective policy data integration, the resource waste caused by repeated policies is reduced, network resources are used more efficiently, the overall network performance is improved, the firewall can be more easily managed and maintained, the error probability is reduced, and the operation and maintenance efficiency is improved.

[0080] In an embodiment of the present disclosure, when there is a source subnet address that does not meet the preset elements, the intermediate firewall policy data is directly generated into a target policy data set by judging that the number of source subnet addresses is lower than a preset threshold.

[0081] Specifically, when there are source subnet addresses that do not meet the preset elements, and the number of source subnet addresses is lower than the preset threshold, it means that the traffic that does not meet the conditions is small, and the system can simplify the processing flow. After confirming that the number of source subnet addresses is lower than the threshold, the system will directly generate the target policy data set from the existing intermediate firewall policy data.

[0082] In an embodiment of the present disclosure, when there is a source subnet address that does not meet the preset elements, the source subnet address is split under the condition that the number of source subnet addresses is higher than a preset threshold; and the intermediate firewall policy data after the split operation is used to generate a target policy data set.

[0083] Specifically, when there are source subnet addresses that do not meet the preset elements, and the number of source subnet addresses is higher than the preset threshold, it means that there is a large amount of non-compliant traffic, and the system needs to perform more in-depth processing.

[0084] Furthermore, for source subnet addresses that do not meet the preset elements, the firewall will perform a split operation. For example, the source subnet addresses that do not meet the requirements are divided according to certain rules (such as IP segments, CIDR, etc.) to form multiple small subnet address segments. After the split operation is completed, the system will generate intermediate firewall policy data based on the new source subnet address information, and further convert it into the target policy data set.

[0085] Through the embodiments of the present disclosure, by splitting the non-compliant source subnet addresses, it is helpful to analyze the traffic in a more fine-grained manner and adjust the strategy in time to deal with potential threats; in addition, when facing a large amount of abnormal traffic, the firewall strategy can be dynamically adjusted to enhance the adaptability of the network.

[0086] Through the embodiments of the present disclosure, by splitting and compressing the firewall policy data, the storage space occupied is effectively reduced, and the merged target policy data set can significantly reduce the number of firewall rules, thereby improving the overall storage efficiency; through effective policy data integration, the resource waste caused by repeated policies is reduced, network resources are more efficiently utilized, the overall network performance is improved, the firewall can be more easily managed and maintained, the error rate is reduced, and the operation and maintenance efficiency is improved. In addition, according to the preset elements of the source and destination subnet addresses, flexible processing can be performed to adapt to different network environments and security requirements, so that the firewall policy can be dynamically adjusted according to the actual traffic situation, which not only enhances the adaptability of the system, but also improves the scalability of subsequent policies.

[0087] Based on the above-mentioned firewall policy data compression method, the present disclosure also provides a firewall policy data compression device. Figure 6 The device is described in detail.

[0088] Figure 6 The structural block diagram of the firewall policy data compression device according to the embodiment of the present disclosure is schematically shown.

[0089] like Figure 6 As shown, the firewall policy data compression device 600 of this embodiment includes a policy data acquisition module 610 , a policy data splitting module 620 , a policy data expansion module 630 and a policy data compression module 640 .

[0090] The policy data acquisition module 610 is used to acquire initial firewall policy data, which includes multi-port policy data and single-port policy data. In one embodiment, the policy data acquisition module 610 can be used to perform the operation S210 described above, which will not be described in detail here.

[0091] The policy data splitting module 620 is used to split the multi-port policy data into single-port policy data based on the port configuration information to obtain the intermediate firewall policy data including all single-port policy data. In one embodiment, the policy data splitting module 620 can be used to perform the operation S220 described above, which will not be repeated here.

[0092] The policy data expansion module 630 is used to expand the source destination address of the intermediate firewall policy data to obtain multiple source destination subnet addresses of the intermediate firewall policy data. In one embodiment, the policy data expansion module 630 can be used to perform the operation S230 described above, which will not be repeated here.

[0093] The policy data compression module 640 is used to compress and merge the intermediate firewall policy data to generate a target policy data set by judging that the source subnet address and the port are the same when each source subnet address meets the preset elements. In one embodiment, the policy data compression module 640 can be used to perform the operation S240 described above, which will not be repeated here.

[0094] In an embodiment of the present disclosure, the policy data compression module also includes: when there is a source subnet address that does not meet the preset elements, by judging that the number of source subnet addresses is lower than a preset threshold, the intermediate firewall policy data set is directly generated.

[0095] In an embodiment of the present disclosure, the policy data compression module also includes: when there is a source subnet address that does not meet the preset elements, by judging that the number of source subnet addresses is higher than a preset threshold, splitting the source subnet address; and generating a target policy data set from the intermediate firewall policy data after the splitting operation.

[0096] In the embodiment of the present disclosure, the policy data splitting module 620 includes a port identification unit, a list generation unit and a single-port policy data generation unit.

[0097] The port identification unit is used to parse the multi-port policy data and identify all ports. In one embodiment, the port identification unit can be used to perform the operation S310 described above, which will not be described in detail here.

[0098] The list generation unit is used to generate a list including all single ports according to the parsed multi-port information. In one embodiment, the list generation unit can be used to perform the operation S320 described above, which will not be described in detail here.

[0099] The single-port policy data generating unit is used to generate corresponding single-port policy data for each single port in the list. In one embodiment, the single-port policy data generating unit can be used to perform the operation S330 described above, which will not be described in detail here.

[0100] In an embodiment of the present disclosure, the policy data extension module 630 includes a subnet mask determination unit and a subnet address generation unit.

[0101] The subnet mask determination unit is used to divide the source address and the destination address according to the category of the IP address in CIDR (Classless Inter-Domain Routing) notation to determine the subnet mask. In one embodiment, the subnet mask determination unit can be used to perform the operation S410 described above, which will not be described in detail here.

[0102] The subnet address generation unit is used to divide the source address and the destination address into multiple subnets using the subnet mask and generate corresponding subnet addresses. In one embodiment, the subnet address generation unit can be used to perform the operation S420 described above, which will not be described in detail here.

[0103] In an embodiment of the present disclosure, the policy data compression module 640 includes an element presetting unit, a classification unit, a deduplication unit and a compression unit.

[0104] The element preset unit is used to define preset elements and determine whether each source destination subnet address meets the preset elements, wherein the preset elements include direction, state, action, firewall ID and policy_id. In one embodiment, the element preset unit can be used to perform the operation S510 described above, which will not be repeated here.

[0105] The classification unit is used to classify and group the intermediate firewall policy data according to the source subnet address and the port category. In one embodiment, the classification unit can be used to perform the operation S520 described above, which will not be repeated here.

[0106] The deduplication unit is used to deduplicate the intermediate firewall policy data of the same source destination subnet address and port in each group, and retain the unique policy item. In one embodiment, the deduplication unit can be used to perform the operation S530 described above, which will not be repeated here.

[0107] The compression unit is used to combine the intermediate firewall policy data of different groups with the same source subnet address and port when the source subnet address and port are the same, and generate a compressed target policy data set. In one embodiment, the compression unit can be used to perform the operation S540 described above, which will not be repeated here.

[0108] According to an embodiment of the present disclosure, any multiple modules of the policy data acquisition module 610, the policy data splitting module 620, the policy data expansion module 630 and the policy data compression module 640 can be combined into one module for implementation, or any one of the modules can be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules can be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present disclosure, at least one of the policy data acquisition module 610, the policy data splitting module 620, the policy data expansion module 630 and the policy data compression module 640 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application specific integrated circuit (ASIC), or can be implemented by hardware or firmware such as any other reasonable way of integrating or packaging the circuit, or implemented in any one of the three implementation methods of software, hardware and firmware or in a suitable combination of any of them. Alternatively, at least one of the policy data acquisition module 610, the policy data splitting module 620, the policy data expansion module 630 and the policy data compression module 640 may be at least partially implemented as a computer program module, and when the computer program module is executed, the corresponding function may be executed.

[0109] Figure 7 A block diagram of an electronic device suitable for implementing a firewall policy data compression method according to an embodiment of the present disclosure is schematically shown.

[0110] like Figure 7 As shown, the electronic device 700 according to an embodiment of the present disclosure includes a processor 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage part 708 to a random access memory (RAM) 703. The processor 701 may include, for example, a general-purpose microprocessor (such as a CPU), an instruction set processor and / or a related chipset and / or a special-purpose microprocessor (for example, an application-specific integrated circuit (ASIC)), etc. The processor 701 may also include an onboard memory for caching purposes. The processor 701 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0111] In RAM 703, various programs and data required for the operation of electronic device 700 are stored. Processor 701, ROM 702 and RAM 703 are connected to each other via bus 704. Processor 701 performs various operations of the method flow according to the embodiment of the present disclosure by executing the program in ROM 702 and / or RAM 703. It should be noted that the program can also be stored in one or more memories other than ROM 702 and RAM 703. Processor 701 can also perform various operations of the method flow according to the embodiment of the present disclosure by executing the program stored in one or more memories.

[0112] According to an embodiment of the present disclosure, the electronic device 700 may further include an input / output (I / O) interface 705, which is also connected to the bus 704. The electronic device 700 may further include one or more of the following components connected to the input / output (I / O) interface 705: an input portion 706 including a keyboard, a mouse, etc.; an output portion 707 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage portion 708 including a hard disk, etc.; and a communication portion 709 including a network interface card such as a LAN card, a modem, etc. The communication portion 709 performs communication processing via a network such as the Internet. A drive 710 is also connected to the input / output (I / O) interface 705 as needed. A removable medium 711, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 710 as needed, so that a computer program read therefrom is installed into the storage portion 708 as needed.

[0113] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist independently without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed, the method according to the embodiment of the present disclosure is implemented.

[0114] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system, an apparatus or a device. For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include the ROM 702 and / or RAM 703 described above and / or one or more memories other than ROM 702 and RAM 703.

[0115] The embodiment of the present disclosure also includes a computer program product, which includes a computer program, and the computer program contains program code for executing the method shown in the flowchart. When the computer program product is run in a computer system, the program code is used to enable the computer system to implement the firewall policy data compression method provided by the embodiment of the present disclosure.

[0116] The above functions defined in the system / device of the embodiment of the present disclosure are performed when the computer program is executed by the processor 701. According to the embodiment of the present disclosure, the system, device, module, unit, etc. described above can be implemented by a computer program module.

[0117] In one embodiment, the computer program may rely on tangible storage media such as optical storage devices, magnetic storage devices, etc. In another embodiment, the computer program may also be transmitted and distributed in the form of signals on a network medium, and downloaded and installed through the communication part 709, and / or installed from the removable medium 711. The program code contained in the computer program may be transmitted using any appropriate network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0118] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 709, and / or installed from the removable medium 711. When the computer program is executed by the processor 701, the above functions defined in the system of the embodiment of the present disclosure are performed. According to the embodiment of the present disclosure, the system, device, means, module, unit, etc. described above can be implemented by a computer program module.

[0119] According to an embodiment of the present disclosure, the program code for executing the computer program provided by the embodiment of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level process and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, Java, C++, python, "C" language or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on the remote computing device, or entirely on the remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect through the Internet).

[0120] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flow chart or block diagram can represent a module, a program segment, or a part of a code, and the above-mentioned module, program segment, or a part of a code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flow chart, and the combination of the boxes in the block diagram or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0121] It will be appreciated by those skilled in the art that the features described in the various embodiments of the present disclosure may be combined and / or combined in a variety of ways, even if such combinations or combinations are not explicitly described in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features described in the various embodiments of the present disclosure may be combined and / or combined in a variety of ways. All of these combinations and / or combinations fall within the scope of the present disclosure.

[0122] The embodiments of the present disclosure are described above. However, these embodiments are only for illustrative purposes and are not intended to limit the scope of the present disclosure. Although the embodiments are described above, this does not mean that the measures in the various embodiments cannot be used in combination to advantage. Without departing from the scope of the present disclosure, those skilled in the art may make a variety of substitutions and modifications, which should all fall within the scope of the present disclosure.

Claims

1. A method for compressing firewall policy data, characterized in that: The method comprises: Acquire initial firewall policy data, wherein the initial firewall policy data includes multi-port policy data and single-port policy data; Based on the port configuration information, the multi-port policy data is split into single-port policy data to obtain intermediate firewall policy data including single-port policy data; Expanding the source destination address of the intermediate firewall policy data to obtain multiple source destination subnet addresses of the intermediate firewall policy data; When each of the source subnet addresses meets the preset elements, the intermediate firewall policy data is compressed and merged to generate a target policy data set by judging that the source subnet addresses and ports are the same.

2. The method for compressing firewall policy data according to claim 1, characterized in that: The method further comprises: When there is a source subnet address that does not meet the preset elements, by judging that the number of the source subnet addresses is lower than a preset threshold, the intermediate firewall policy data is directly generated into a target policy data set.

3. The method for compressing firewall policy data according to claim 1 or 2, characterized in that: The method further comprises: When there is a source subnet address that does not meet the preset elements, under the condition that the number of the source subnet addresses is higher than a preset threshold, the source subnet address is split; and The intermediate firewall policy data after the split operation is generated into a target policy data set.

4. The method for compressing firewall policy data according to claim 1, characterized in that: Based on the port configuration information, the multi-port policy data is split into single-port policy data to obtain intermediate firewall policy data containing single-port policy data, wherein the multi-port policy data includes a source address, a destination address, a protocol type, and a corresponding plurality of ports of the policy, including: Parse multi-port policy data and identify all ports; Generate a list of all single ports based on the parsed multi-port information; For each single port in the list, corresponding single port policy data is generated.

5. The method for compressing firewall policy data according to claim 1, characterized in that: The extending the source-destination address of the intermediate firewall policy data to obtain a plurality of source-destination subnet addresses of the intermediate firewall policy data, wherein the source-destination address includes a source address and a destination address, comprises: According to the class of the IP address, the source address and the destination address are divided in CIDR (Classless Inter-Domain Routing) notation to determine a subnet mask; The source address and the destination address are divided into multiple subnets using a subnet mask, and corresponding subnet addresses are generated.

6. The method for compressing firewall policy data according to claim 5, characterized in that: The method of using a subnet mask to divide the source address and the destination address into multiple subnets and generating corresponding subnet addresses includes: Check whether there are overlapping subnet addresses, and merge and optimize them.

7. The method for compressing firewall policy data according to claim 1, characterized in that: When each of the source subnet addresses meets the preset elements, the intermediate firewall policy data is compressed and merged to generate a target policy data set by judging that the source subnet addresses and ports are the same, including: Define preset elements, and determine that each source-destination subnet address meets the preset elements, wherein the preset elements include direction, state, action, firewall ID, and policy_id; Classifying and grouping the intermediate firewall policy data according to the categories of the source subnet addresses and ports; De-duplicate the intermediate firewall policy data with the same source and destination subnet addresses and ports in each group, and retain unique policy items; When the condition that the source subnet address and the port are the same is met, the intermediate firewall policy data of different groups with the same source subnet address and port are merged and combined to generate a compressed target policy data set.

8. A firewall policy data compression device, characterized in that: The device comprises: A policy data acquisition module, used to acquire initial firewall policy data, wherein the initial firewall policy data includes multi-port policy data and single-port policy data; A policy data splitting module is used to split the multi-port policy data into single-port policy data based on the port configuration information, and obtain intermediate firewall policy data containing all single-port policy data; A policy data extension module, used to extend the source destination address of the intermediate firewall policy data to obtain multiple source destination subnet addresses of the intermediate firewall policy data; The policy data compression module is used to compress and merge the intermediate firewall policy data to generate a target policy data set when each source subnet address meets the preset elements and the source subnet address and port are the same.

9. The firewall policy data compression device according to claim 8, characterized in that: The policy data compression module further includes: When the source subnet address does not meet the preset elements, the intermediate firewall policy data is directly generated into a target policy data set by judging that the number of the source subnet addresses is lower than a preset threshold.

10. The firewall policy data compression device according to claim 8, characterized in that: The policy data compression module further includes: When there is a source subnet address that does not meet the preset elements, by judging that the number of the source subnet addresses is higher than a preset threshold, splitting the source subnet address; and The intermediate firewall policy data after the split operation is generated into a target policy data set.

11. An electronic device, comprising: one or more processors; a memory for storing one or more computer programs, It is characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 7.

12. A computer-readable storage medium having a computer program or instruction stored thereon, characterized in that: When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

13. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.