Method and device for adjusting access control list ACL, storage medium and electronic equipment
By obtaining and analyzing the business object attributes, topology and interaction information in the network system, and determining and adjusting the service connectivity mode of the access control list (ACL), the problems of resource waste and application scenario limitations caused by the complexity of ACL adjustment in the prior art are solved, and more efficient network management and policy adjustments are achieved.
Patent Information
- Application Number
- CN202412000542.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-06
AI Technical Summary
In the prior art, the need to use complex network models to adjust the access control list (ACL), which consumes a large amount of computing resources and has limited application scenarios.
By obtaining the attribute information, network topology information and business interaction information of the business object recorded in the access control list (ACL) in the target network system, the actual business connection method of the business object is determined, and the business connection method is re-determined in the event of inconsistency, and the target rule input constraint solver is converted to the target rule to adjust the ACL.
It reduces the use of computing resources, expands the application scenario of access control list (ACL) adjustment, and improves the efficiency of network management and the accuracy of policy adjustment.
Smart Images

Figure CN119946003A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of computers, and in particular, to a method, device, storage medium, electronic device, and program product for adjusting an access control list (ACL). Background Art
[0002] In the cloud computing environment, the growth of network scale and complexity has put forward higher requirements for the dynamic adjustment of access control policies. In the related technology, since it is usually necessary to use complex network models to adjust the access control list, it consumes a lot of computing resources and has very limited application scenarios. Summary of the invention
[0003] The embodiments of the present application provide a method, device, storage medium, electronic device and program product for adjusting an access control list (ACL) to at least solve the problem in the related art that a complex network model is usually required to adjust the access control list, resulting in excessive consumption of computing resources and limited application scenarios.
[0004] According to an embodiment of the present application, a method for adjusting an access control list (ACL) is provided, which is applied to a target server, wherein the target server interacts with a target network system through a switch, and the method comprises: obtaining attribute information of each first business object included in a plurality of first business objects recorded in a first access control list (ACL) in the target network system, network topology information of the target network system, and business interaction information of the target network system; performing the following operations for any first business object included in the plurality of first business objects to obtain a target business object: determining an actual business connectivity mode of the first business object according to the network topology information, the business interaction information, and the attribute information, and determining the first business object as the target business object when it is determined that the actual business connectivity mode of the first business object is inconsistent with a first business connectivity mode determined based on the business connectivity mode of the first business object recorded in the first ACL; re-determining a second business connectivity mode of the target business object; converting the second business connectivity mode into a target rule that allows a target constraint solver to recognize, and inputting the target rule into the target constraint solver to obtain a second ACL output by the target constraint solver; and adjusting the first ACL according to the second ACL to obtain a target ACL.
[0005] In an exemplary embodiment, determining the actual business connectivity mode of the first business object based on the network topology information, the business interaction information and the attribute information includes: determining the second business object that performs business interaction with the first business object, the business interaction mode between the first business object and the second business object, and business status information of the business performed by the first business object and the second business object based on the network topology information, the business interaction information and the attribute information; determining the actual business connectivity mode of the first business object based on the second business object, the business interaction mode and the business status information.
[0006] In an exemplary embodiment, redetermining the second business connectivity mode of the target business object includes: obtaining target information for configuring the business connectivity mode of the target business object from the target network system; determining the second business connectivity mode through the target information when there is one target information or when there are multiple target information and the business connectivity modes of the target business object included in the multiple target information are consistent; or, when there are multiple target information and the business connectivity modes of the target business object included in the multiple target information are inconsistent, determining a score for the business connectivity mode of the target business object configured by each target information according to the priority and issuance time of each target information, and determining the second business connectivity mode according to the business connectivity mode of the target business object with the highest score.
[0007] In an exemplary embodiment, before determining the first business object as the target business object, the method also includes: determining whether the actual business connectivity method is consistent with the first business connectivity method by: drawing a first business connectivity diagram of the first business object based on the actual business connectivity method, and drawing a second business connectivity diagram of the first business object based on the first business connectivity method; comparing the first business connectivity diagram and the second business connectivity diagram based on a target neural network to determine whether the actual business connectivity method is consistent with the first business connectivity method.
[0008] In an exemplary embodiment, after adjusting the first ACL according to the second ACL to obtain the target ACL, the method further includes: determining the resource occupancy rate of the target network system according to the load status information in the target network system; when the resource occupancy rate is greater than a first threshold, determining the time for the next adjustment of the ACL according to the current time and a first time period corresponding to the first threshold, and determining that when the ACL is adjusted next time, the actual business connectivity mode of the first business object is determined through the first information of the business interaction between the first business object and the second business object included in the network topology information, the attribute information, and the business interaction information, wherein the first information includes the network protocol used when the first business object and the second business object perform business interaction, the source port of the business interaction, and the destination port , the source IP and destination IP of the business interaction; when the resource occupancy rate is less than the second threshold, determine the time for adjusting the ACL next time according to the current time and the second time period corresponding to the second threshold, and determine the actual business connection mode of the first business object through the network topology information, the attribute information and the second information of the business interaction between the first business object and the second business object included in the business interaction information, wherein the second information includes the network protocol and application layer protocol used when the first business object and the second business object interact with each other, the source port and destination port of the business interaction, the source IP and destination IP of the business interaction, the asset information of the first business object and the asset information of the second business object, wherein the second time period is less than the first time period. In an exemplary embodiment, adjusting the first ACL according to the second ACL to obtain the target ACL includes: replacing the configuration information of the target business object included in the first ACL with the configuration information of the target business object included in the second ACL to obtain the target ACL.
[0009] In an exemplary embodiment, adjusting the first ACL according to the second ACL to obtain a target ACL includes: replacing configuration information of the target business object included in the first ACL with configuration information of the target business object included in the second ACL to obtain the target ACL.
[0010] According to another embodiment of the present application, there is provided an adjustment device for an access control list (ACL), which is applied to a target server, wherein the target server interacts with a target network system through a switch, and the device comprises: an acquisition module, which is used to acquire attribute information of each of a plurality of first business objects recorded in a first access control list (ACL) in the target network system, network topology information of the target network system, and business interaction information of the target network system; a processing module, which is used to perform the following operations on any one of the plurality of first business objects to obtain a target business object: determining the first business object according to the network topology information, the business interaction information, and the attribute information; an actual business connectivity mode of a business object, and when it is determined that the actual business connectivity mode of the first business object is inconsistent with a first business connectivity mode determined based on the business connectivity mode of the first business object recorded in the first ACL, determining the first business object as the target business object; a first determination module, used to redetermine a second business connectivity mode of the target business object; a conversion module, used to convert the second business connectivity mode into a target rule that allows a target constraint solver to recognize, and input the target rule into the target constraint solver to obtain a second ACL output by the target constraint solver; and an adjustment module, used to adjust the first ACL according to the second ACL to obtain a target ACL.
[0011] According to another embodiment of the present application, a computer-readable storage medium is provided, in which a computer program is stored, wherein the computer program is configured to execute the steps of any of the above method embodiments when run.
[0012] According to another embodiment of the present application, an electronic device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0013] According to another embodiment of the present application, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the steps in any of the above method embodiments are implemented.
[0014] Through the present application, since it is determined whether the actual business connectivity mode of the business object is consistent with the business connectivity mode recorded in the access control list based on the attribute information, network topology information and business interaction information of the business object included in the access control list, and in the case of inconsistency, the business connectivity mode is re-determined, and the access control list is adjusted according to the re-determined business connectivity mode, it is possible to solve the problem of excessive consumption of computing resources and limited application scenarios in related technologies due to the need to adopt complex network models to adjust the access control list, thereby achieving the effect of reducing the occupation of computing resources and expanding application scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 It is a hardware structure block diagram of a server device according to the method for adjusting the access control list ACL in an embodiment of the present application;
[0016] Figure 2 The following is a flow chart of a method for adjusting an access control list (ACL) according to an embodiment of the present application. Figure 1 ;
[0017] Figure 3 The following is a flow chart of a method for adjusting an access control list (ACL) according to an embodiment of the present application. Figure 2 ;
[0018] Figure 4 is a schematic diagram of information acquisition according to an embodiment of the present application;
[0019] Figure 5 is a schematic diagram of a data structure according to an embodiment of the present application;
[0020] Figure 6 It is a structural block diagram of a device for adjusting an access control list ACL according to an embodiment of the present application. DETAILED DESCRIPTION
[0021] The embodiments of the present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0022] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0023] The method embodiments provided in the embodiments of the present application can be executed in a server device or a similar computing device. Taking running on a server device as an example, Figure 1 FIG. 1 is a hardware structure diagram of a server device according to a method for adjusting an access control list ACL according to an embodiment of the present application. Figure 1 As shown, the server device may include one or more ( Figure 1Only one is shown in the figure) a processor 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data, wherein the server device may also include a transmission device 106 and an input / output device 108 for communication functions. It can be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above server device. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations are shown.
[0024] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the method for adjusting the access control list ACL in the embodiment of the present application. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, to implement the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories may be connected to the server device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0025] The transmission device 106 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider of the server device. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, referred to as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0026] In this embodiment, a method for adjusting an access control list ACL is provided, which is applied to a target server, wherein the target server interacts with a target network system through a switch. Figure 2 The following is a flow chart of a method for adjusting an access control list (ACL) according to an embodiment of the present application. Figure 1 ,like Figure 2 As shown, the process includes the following steps:
[0027] Step S202, obtaining attribute information of each of the first business objects included in the multiple first business objects recorded in the first access control list ACL in the target network system, network topology information of the target network system, and business interaction information of the target network system;
[0028] Step S204: performing the following operations for any first business object included in the plurality of first business objects to obtain a target business object: determining an actual business connectivity mode of the first business object according to the network topology information, the business interaction information, and the attribute information; and determining the first business object as the target business object when it is determined that the actual business connectivity mode of the first business object is inconsistent with a first business connectivity mode determined based on the business connectivity mode of the first business object recorded in the first ACL;
[0029] Step S206, re-determining the second service connection mode of the target service object;
[0030] Step S208, converting the second service connectivity mode into a target rule that allows a target constraint solver to identify, and inputting the target rule into the target constraint solver to obtain a second ACL output by the target constraint solver;
[0031] Step S210: Adjust the first ACL according to the second ACL to obtain a target ACL.
[0032] In the above steps, the attribute information of the first business object includes but is not limited to: the MAC address, service type (for example, the service type is determined by the Label attribute in the Pod in the k8s cluster), IP address and port information of the first business object; the network topology information includes but is not limited to: the device list, connection relationship, path information, subnet division, interface status, link status, etc. of the devices included in the target network system; the business interaction information includes but is not limited to: the traffic type, communication frequency, transmission data packet size, error rate in business interaction, network delay and throughput of business interaction, access mode between business objects, session information in business interaction, etc. The target constraint solver includes but is not limited to: satisfiability modal theory solver, integer linear programming solver, constraint programming solver, Boolean formula solver, graph algorithm solver, logic programming solver, etc.
[0033] In the above steps, by determining whether the actual business connectivity mode of the business object is consistent with the business connectivity mode recorded in the access control list based on the attribute information, network topology information and business interaction information of the business object included in the access control list, and in the event of inconsistency, redetermining the business connectivity mode, and adjusting the access control list based on the redetermined business connectivity mode, the problem of excessive consumption of computing resources and limited application scenarios in related technologies due to the need to usually adopt a complex network model to adjust the access control list is solved, the occupation of computing resources is reduced, and the application scenarios are expanded.
[0034] In an optional embodiment, determining the actual business connectivity mode of the first business object based on the network topology information, the business interaction information and the attribute information includes: determining the second business object that performs business interaction with the first business object, the business interaction mode between the first business object and the second business object, and business status information of the business performed by the first business object and the second business object based on the network topology information, the business interaction information and the attribute information; determining the actual business connectivity mode of the first business object based on the second business object, the business interaction mode and the business status information.
[0035] In the above steps, illustratively, the actual service connectivity mode may be detected by a network diagnostic tool (eg, ping).
[0036] In an optional embodiment, after determining the second business object that performs business interaction with the first business object, the business interaction mode between the first business object and the second business object, and business status information of the business performed by the first business object and the second business object based on the network topology information, the business interaction information, and the attribute information, the method further includes: organizing the business interaction mode between the first business object and the second business object and the business status information (for example, business delay, error rate, smoothness, packet loss rate, etc.) in the form of a table, and determining the actual business connectivity mode based on the information organized in the table.
[0037] In an optional embodiment, the method further includes: determining a third business object that has not performed business interaction with the first business object based on the network topology information, the business interaction information and the attribute information; obtaining the attribute information of the third business object; determining the business association between the third business object and the first business object based on the attribute information of the third business object; and when the business association is greater than a predetermined threshold, outputting the attribute information of the third business object and the attribute information of the first business object to the target object, and requesting the target object to determine whether it is necessary to modify the information of the first business object in the first ACL.
[0038] In the above step, the attribute information of the third business object includes but is not limited to: MAC address, service type, IP address and port information of the third business object, etc. The predetermined threshold can be preset and adjusted according to different application scenarios and business objects.
[0039] In the above steps, by analyzing the business correlation between the first business object and the third business object, and when the correlation exceeds a preset threshold, the query process of the target object is automatically triggered to determine whether it is necessary to adjust the configuration information of the first business object in the access control list (ACL), thereby automatically identifying and prompting potential optimization points of the ACL configuration, reducing human intervention, and improving the automation level of network security policies.
[0040] In an optional embodiment, redetermining the second business connectivity mode of the target business object includes: obtaining target information for configuring the business connectivity mode of the target business object from the target network system; determining the second business connectivity mode through the target information when there is one target information or when there are multiple target information and the business connectivity modes of the target business object included in the multiple target information are consistent; or, when there are multiple target information and the business connectivity modes of the target business object included in the multiple target information are inconsistent, determining a score for the business connectivity mode of the target business object configured by each target information according to the priority and issuance time of each target information, and determining the second business connectivity mode according to the business connectivity mode of the target business object with the highest score.
[0041] In the above steps, illustratively, the higher the priority of the target information and the later the sending time, the higher the score of the target information.
[0042] In the above steps, the second business connectivity mode is determined by using the target information when there is one target information or multiple consistent target information, and the second business connectivity mode is determined by using the business connectivity mode with the highest score when there are multiple consistent target information, thereby achieving automatic determination of the connectivity mode of the business object.
[0043] In an optional embodiment, before determining the first business object as the target business object, the method further includes: determining whether the actual business connectivity method is consistent with the first business connectivity method by: drawing a first business connectivity diagram of the first business object based on the actual business connectivity method, and drawing a second business connectivity diagram of the first business object based on the first business connectivity method; comparing the first business connectivity diagram and the second business connectivity diagram based on a target neural network to determine whether the actual business connectivity method is consistent with the first business connectivity method.
[0044] In the above steps, the business connectivity mode is first drawn as a schematic diagram that is intuitive and easy to be understood by the neural network, and then the consistency of the business connectivity mode is judged based on the schematic diagram through the neural network model, thereby achieving accurate and efficient automatic identification of the consistency of the business connectivity mode through the neural network.
[0045] In an optional embodiment, after adjusting the first ACL according to the second ACL to obtain the target ACL, the method further includes: determining the resource occupancy rate of the target network system according to the load status information in the target network system; when the resource occupancy rate is greater than a first threshold, determining the time for the next adjustment of the ACL according to the current time and a first time period corresponding to the first threshold, and determining the actual business connectivity mode of the first business object when the ACL is adjusted next time through the network topology information, the attribute information, and the first information of the business interaction information in which the first business object and the second business object perform business interaction, wherein the first information includes the network protocol used when the first business object and the second business object perform business interaction, the source port and the destination port of the business interaction , the source IP and destination IP of the business interaction; when the resource occupancy rate is less than the second threshold, determine the time for the next adjustment of the ACL according to the current time and the second time period corresponding to the second threshold, and determine the next time to adjust the ACL, through the network topology information, the attribute information and the second information of the business interaction between the first business object and the second business object included in the business interaction information to determine the actual business connectivity mode of the first business object, wherein the second information includes the network protocol and application layer protocol used when the first business object and the second business object perform business interaction, the source port and destination port of the business interaction, the source IP and destination IP of the business interaction, the asset information of the first business object and the asset information of the second business object, wherein the second time period is less than the first time period.
[0046] In the above steps, the load status information includes but is not limited to: CPU usage, memory usage, network traffic, system load average, process status, etc., the first threshold includes but is not limited to: 70%, 75%, 80%, etc., the first time period includes but is not limited to: 1 day, 2 days, 3 days, etc., the second threshold includes but is not limited to: 40, 45%, 50%, etc., the second time period includes but is not limited to: 12 hours, 15 hours, 20 hours, etc., the first threshold, the second threshold, the first time period and the second time period can be pre-set, and the first threshold, the second threshold, the first time period and the second time period can be adjusted according to the application scenario and the target network system.
[0047] Through the above steps, when the resource occupancy rate of the target network system is greater than the first threshold, the frequency of adjusting the ACL can be reduced and the types of information obtained for determining the actual business connectivity mode can be reduced, thereby reducing the network resources occupied when adjusting the ACL, optimizing resource allocation, and ensuring the operation of key businesses. In addition, when the resource occupancy rate of the target network system is less than the second threshold, the frequency of adjusting the ACL can be increased and the types of information obtained for determining the actual business connectivity mode can be increased, thereby achieving more refined network management when the resource occupancy rate is low and improving the accuracy and timeliness of policy adjustment.
[0048] In an optional embodiment, adjusting the first ACL according to the second ACL to obtain the target ACL includes: replacing the configuration information of the target business object included in the first ACL with the configuration information of the target business object included in the second ACL to obtain the target ACL.
[0049] The following is an exemplary description of the solution in this application in conjunction with specific embodiments:
[0050] Figure 3 The following is a flow chart of a method for adjusting an access control list (ACL) according to an embodiment of the present application. Figure 2 , applied to observable modules in the target network system, such as Figure 3 As shown, the process includes the following steps:
[0051] Step S302, obtaining network topology information, network connectivity information, and asset attribute information of the target network system;
[0052] Step S304, comparing the above information with the current network policy ACL to determine the business object with problems;
[0053] Step S306, determining whether to adjust the ACL, if so, executing step S308, if not, jumping to step S302;
[0054] Step S308, converting the instruction information for adjusting the ACL of the problematic business object into a data structure having an intent description attribute;
[0055] Step S310, inputting the converted indication information, all ACL sets and current network topology information into the SMT solver module to obtain the latest ACL of the problematic business object;
[0056] Step S312, performing conflict merging and conflict detection on the latest ACL of the problematic business object;
[0057] Step S314, the ACL obtained after conflict merging and conflict detection is sent to a technician for verification and then sent to the target network system after verification.
[0058] In the above step S302, illustratively, Figure 4 is a schematic diagram of information acquisition according to an embodiment of the present application, such as Figure 4 As shown, the required information includes but is not limited to: sIp (source IP address), dIp (destination IP address), sport (source port), dport (destination port), TCP (Transmission Control Protocol), network connectivity information, etc., and the optional information includes but is not limited to source service information (for example, Web service), destination service information (for example, MySQL database service), etc.
[0059] In the above step S308, the data structure with the intention description attribute can be determined according to the core elements that need to be clarified when executing specific business, such as the target subject, execution process, result orientation, etc. Exemplarily, the data structure with the intention description attribute includes the target object, expected behavior and execution method. Among them, the target object includes the object that deviates from the expected behavior and needs attention. Figure 5 is a schematic diagram of a data structure according to an embodiment of the present application, such as Figure 5 As shown, if the core security service node A is directly accessed by the non-security node C bypassing the necessary verification node B, or the expected access relationship between the service node D and the service node E is missing in the network topology, A, B, C, D, and E are determined as target objects. The above expected behavior directly reflects the expectations of the operation and maintenance experts for the network access relationship. It clearly defines the allowed or prohibited access mode based on the intention of the experts. For example, the expected behavior may include: node C accesses node A through node B, and node A is prohibited from being accessed by any node except node B; node D's access to node E should be allowed. Exemplarily, the implementation of network policies can be carried out in two main ways: check and correct and direct update. The check and correct method requires a detailed review and necessary adjustments to the existing ACL to ensure that it is consistent with the expected behavior. The direct update method generates new ACL rules based on the current network topology to achieve the expected network behavior.
[0060] In the above step S310, the constraint solver first creates symbolic variables based on the target object and creates constraint conditions based on the expected behavior, and then solves the results under the constraint conditions and outputs them.
[0061] In the above step S312, illustratively, conflict merging and conflict detection of the latest ACL of the problematic business object include but are not limited to: detecting whether there is overlap of port domains, IP and protocol conflicts.
[0062] Through the above embodiments, a network policy verification method based on observability technology is proposed. By executing the acquisition of observable data, editing the intent description data structure, using the constraint solver, and merging and conflict checking of ACL rules, the automatic judgment and recommendation of network policies are realized, which significantly improves the efficiency and accuracy of formulating, updating and correcting network policy ACLs in large and complex network environments, and solves the problems of low efficiency and insufficient availability faced by the industry in the field of network verification.
[0063] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of the present application.
[0064] In this embodiment, there is also provided an adjustment device for an access control list ACL, which is applied to a target server, wherein the target server interacts with a target network system through a switch, and the device is used to implement the above-mentioned embodiments and preferred implementation modes, which have been described and will not be repeated here. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.
[0065] Figure 6 is a structural block diagram of an access control list ACL adjustment device according to an embodiment of the present application, such as Figure 6As shown, the device includes: an acquisition module 602, which is used to acquire the attribute information of each of the first business objects included in the multiple first business objects recorded in the first access control list ACL in the target network system, the network topology information of the target network system and the business interaction information of the target network system; a processing module 604, which is used to perform the following operations for any first business object included in the multiple first business objects to obtain the target business object: determine the actual business connectivity mode of the first business object according to the network topology information, the business interaction information and the attribute information, and determine the first business object as the target business object when it is determined that the actual business connectivity mode of the first business object is inconsistent with the first business connectivity mode determined based on the business connectivity mode of the first business object recorded in the first ACL; a first determination module 606, which is used to re-determine the second business connectivity mode of the target business object; a conversion module 608, which is used to convert the second business connectivity mode into a target rule that allows a target constraint solver to recognize, and input the target rule into the target constraint solver to obtain a second ACL output by the target constraint solver; an adjustment module 610, which is used to adjust the first ACL according to the second ACL to obtain the target ACL.
[0066] In an optional embodiment, the processing module 604 includes: a first determination unit, used to determine the second business object that performs business interaction with the first business object, the business interaction mode between the first business object and the second business object, and business status information of the business performed by the first business object and the second business object based on the network topology information, the business interaction information and the attribute information; a second determination unit, used to determine the actual business connectivity mode of the first business object based on the second business object, the business interaction mode and the business status information.
[0067] In an optional embodiment, the first determination module 606 includes: an acquisition unit, used to acquire target information for configuring the business connectivity mode of the target business object from the target network system; a third determination unit, used to determine the second business connectivity mode through the target information, when the target information is one piece or the target information is multiple pieces and the business connectivity modes of the target business object included in the multiple pieces of target information are consistent; or, a fourth determination unit, used to determine the score of the business connectivity mode of the target business object configured by each piece of the target information according to the priority and issuance time of each piece of the target information, when the target information is multiple pieces and the business connectivity modes of the target business object included in the multiple pieces of the target information are inconsistent, and determine the second business connectivity mode according to the business connectivity mode of the target business object with the highest score.
[0068] In an optional embodiment, the device also includes: a second determination module, used to determine whether the actual business connectivity mode is consistent with the first business connectivity mode before determining the first business object as the target business object by: drawing a first business connectivity diagram of the first business object based on the actual business connectivity mode, and drawing a second business connectivity diagram of the first business object based on the first business connectivity mode; comparing the first business connectivity diagram and the second business connectivity diagram based on a target neural network to determine whether the actual business connectivity mode is consistent with the first business connectivity mode.
[0069] In an optional embodiment, the device further includes: a third determination module, which is used to determine the resource occupancy rate of the target network system according to the load status information in the target network system after adjusting the first ACL according to the second ACL to obtain the target ACL; a fourth determination module, which is used to determine the time for the next adjustment of the ACL according to the current time and the first time period corresponding to the first threshold value when the resource occupancy rate is greater than the first threshold value, and determine the actual business connectivity mode of the first business object when the ACL is adjusted next time through the network topology information, the attribute information and the first information of the business interaction information in which the first business object and the second business object perform business interaction, wherein the first information includes the network protocol used when the first business object and the second business object perform business interaction, the source port of the business interaction and Destination port, source IP and destination IP of business interaction; a fifth determination module, used to determine the time for the next adjustment of the ACL according to the current time and a second time period corresponding to the second threshold value when the resource occupancy rate is less than the second threshold value, and determine the next time the ACL is adjusted, through the network topology information, the attribute information and the second information of the business interaction between the first business object and the second business object included in the business interaction information to determine the actual business connectivity mode of the first business object, wherein the second information includes the network protocol and application layer protocol used when the first business object and the second business object perform business interaction, the source port and destination port of the business interaction, the source IP and destination IP of the business interaction, the asset information of the first business object and the asset information of the second business object, wherein the second time period is less than the first time period.
[0070] In an optional embodiment, the adjustment module 610 includes: an adjustment unit, configured to replace the configuration information of the target business object included in the first ACL with the configuration information of the target business object included in the second ACL to obtain the target ACL.
[0071] It should be noted that the above modules can be implemented by software or hardware. For the latter, it can be implemented in the following ways, but not limited to: the above modules are all located in the same processor; or the above modules are located in different processors in any combination.
[0072] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored, wherein the computer program is configured to execute the steps of any of the above method embodiments when running.
[0073] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.
[0074] An embodiment of the present application further provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.
[0075] In an exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.
[0076] An embodiment of the present application further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the steps in any one of the above method embodiments are implemented.
[0077] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.
[0078] Obviously, those skilled in the art should understand that the above modules or steps of the present application can be implemented by a general computing device, they can be concentrated on a single computing device, or distributed on a network composed of multiple computing devices, they can be implemented by a program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be executed in a different order from that herein, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. Thus, the present application is not limited to any specific combination of hardware and software.
[0079] The above description is only the preferred embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the principles of the present application shall be included in the protection scope of the present application.
Claims
1. A method for adjusting an access control list (ACL), characterized in that: Applied in a target server, wherein the target server interacts with a target network system through a switch, the method comprising: Acquire attribute information of each of the first service objects included in the plurality of first service objects recorded in the first access control list ACL in the target network system, network topology information of the target network system, and service interaction information of the target network system; The following operations are performed for any first business object included in the plurality of first business objects to obtain a target business object: determining an actual service connectivity mode of the first service object according to the network topology information, the service interaction information and the attribute information, and determining the first service object as the target service object when the actual service connectivity mode of the first service object is inconsistent with the first service connectivity mode determined based on the service connectivity mode of the first service object recorded in the first ACL; Re-determining the second service connection mode of the target service object; Converting the second service connectivity mode into a target rule that allows a target constraint solver to identify, and inputting the target rule into the target constraint solver to obtain a second ACL output by the target constraint solver; The first ACL is adjusted according to the second ACL to obtain a target ACL.
2. The method according to claim 1, characterized in that Determining the actual service connectivity mode of the first service object according to the network topology information, the service interaction information, and the attribute information includes: Determine, according to the network topology information, the service interaction information, and the attribute information, a second service object that performs service interaction with the first service object, a service interaction mode between the first service object and the second service object, and service status information of the service performed by the first service object and the second service object; An actual service connectivity mode of the first service object is determined based on the second service object, the service interaction mode, and the service status information.
3. The method according to claim 1, characterized in that The second service connection mode of re-determining the target service object includes: Acquire target information for configuring a service connectivity mode of the target service object from the target network system; In a case where the target information is one piece or the target information is multiple pieces and the service connectivity modes of the target service objects included in the multiple pieces of target information are consistent, determining the second service connectivity mode through the target information; or, In the case that there are multiple target information and the business connectivity modes of the target business objects included in the multiple target information are inconsistent, the score of the business connectivity mode of the target business object configured for each target information is determined according to the priority and issuance time of each target information, and the second business connectivity mode is determined according to the business connectivity mode of the target business object with the highest score.
4. The method according to claim 2, characterized in that: Before determining the first business object as the target business object, the method further includes: Determine whether the actual service connection mode is consistent with the first service connection mode by: Draw a first service connectivity diagram of the first service object based on the actual service connectivity mode, and draw a second service connectivity diagram of the first service object based on the first service connectivity mode; The first service connectivity diagram and the second service connectivity diagram are compared based on a target neural network to determine whether the actual service connectivity mode is consistent with the first service connectivity mode.
5. The method according to claim 2, characterized in that: After adjusting the first ACL according to the second ACL to obtain a target ACL, the method further includes: Determine the resource occupancy rate of the target network system according to the load status information in the target network system; In the case where the resource occupancy rate is greater than a first threshold, determining the time for adjusting the ACL next time according to the current time and a first time period corresponding to the first threshold, and determining the actual service connectivity mode of the first service object through the network topology information, the attribute information, and the first information of the service interaction between the first service object and the second service object included in the service interaction information, wherein the first information includes the network protocol used when the first service object and the second service object perform service interaction, the source port and the destination port of the service interaction, and the source IP and the destination IP of the service interaction; When the resource occupancy rate is less than a second threshold, the time for the next adjustment of the ACL is determined according to the current time and a second time period corresponding to the second threshold, and when the ACL is adjusted next time, the actual business connectivity mode of the first business object is determined through the network topology information, the attribute information, and the second information included in the business interaction information for business interaction between the first business object and the second business object, wherein the second information includes the network protocol and application layer protocol used when the first business object and the second business object perform business interaction, the source port and destination port of the business interaction, the source IP and destination IP of the business interaction, the asset information of the first business object, and the asset information of the second business object, wherein the second time period is less than the first time period.
6. The method according to claim 1, characterized in that Adjusting the first ACL according to the second ACL to obtain a target ACL includes: The configuration information of the target business object included in the first ACL is replaced with the configuration information of the target business object included in the second ACL to obtain the target ACL.
7. A device for adjusting an access control list ACL, characterized in that: Applied in a target server, wherein the target server interacts with a target network system through a switch, the device comprises: an acquisition module, configured to acquire attribute information of each of the first business objects included in the plurality of first business objects recorded in the first access control list ACL in the target network system, network topology information of the target network system, and business interaction information of the target network system; a processing module, configured to perform the following operations for any first business object included in the plurality of first business objects to obtain a target business object: determining an actual business connectivity mode of the first business object according to the network topology information, the business interaction information, and the attribute information, and determining the first business object as the target business object when it is determined that the actual business connectivity mode of the first business object is inconsistent with a first business connectivity mode determined based on the business connectivity mode of the first business object recorded in the first ACL; A first determining module, used to redetermine a second service connectivity mode of the target service object; a conversion module, used to convert the second service connectivity mode into a target rule that allows a target constraint solver to recognize, and input the target rule into the target constraint solver to obtain a second ACL output by the target constraint solver; and an adjustment module, used to adjust the first ACL according to the second ACL to obtain a target ACL.
8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program implements the steps of the method described in any one of claims 1 to 6 when executed by a processor.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method described in any one of claims 1 to 6 are implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method described in any one of claims 1 to 6 are implemented.