Firewall rule and IPS intrusion feature parallel processing method and device, equipment, medium and program product
By implementing parallel processing of firewall rules and IPS intrusion characteristics at the kernel layer, the problems of long data processing chain, large system overhead and low hardware resource utilization in the prior art are solved, and efficient and real-time data processing and network security are achieved.
Patent Information
- Application Number
- CN202510430008.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2045-04-08
AI Technical Summary
In existing network security systems, firewall and intrusion detection equipment are two separate devices, resulting in long data processing chains, large system overhead, low hardware resource utilization, and low real-time data forwarding.
By implementing parallel processing of firewall rules and IPS intrusion features at the kernel layer, using memory mapping mechanism and DMA direct memory access, shortening the data processing chain, improving hardware resource utilization, and efficient data transmission and processing through public memory area queues.
It has achieved shortening the data processing chain, reducing system overhead, improving hardware resource utilization, improving real-time and efficiency of data processing, and ensuring network security.
Smart Images

Figure CN119966751A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a method, device, equipment, medium and program product for parallel processing of firewall rules and IPS intrusion features. Background Art
[0002] In traditional security networks, firewalls and intrusion detection devices are two separate devices. When a network data packet first enters the network, it first reaches the firewall, which processes it based on the set rule table. Only legal data packets can pass through the firewall and enter the internal network. The processed data packets then come to the IPS intrusion detection device, which will deeply analyze the content of the data packet. Once a potential attack is found, the IPS will prevent the data packet from continuing to transmit to ensure network security. After multiple layers of data filtering, the final data will reach the network user level. This security processing mechanism has a long data processing chain, high system overhead, and low hardware resource utilization. Summary of the invention
[0003] The purpose of the embodiments of the present application is to provide a method, device, equipment, medium and program product for parallel processing of firewall rules and IPS intrusion features, so as to solve the problems of time-consuming communication of existing telecommunication network elements and low real-time performance of data forwarding.
[0004] In a first aspect, an embodiment of the present application provides a method for parallel processing of firewall rules and IPS intrusion features, which is used for a first CPU, the first CPU is bound to a firewall system and the first CPU is arranged in a kernel layer, and the method includes: Based on the memory mapping mechanism, a memory mapping of the physical memory area is obtained through the first virtual address space; Accessing a network data packet in a physical memory area through a first virtual address in a first virtual address space, wherein the network data packet is written to the physical memory area through DMA direct memory access; Process the network data packet according to the five-tuple rule to determine whether the network data packet meets the release rule; If the network data packet meets the release rules, the network data packet is placed in the public memory area queue of the physical memory area based on the security monitoring rules; If the network data packet does not meet the release rules, the data packet is discarded.
[0005] In the above implementation process, the embodiment of the present application obtains the memory mapping of the physical memory area through the first virtual address space based on the memory mapping mechanism; accesses the network data packet of the physical memory area through the first virtual address space, wherein the network data packet is written to the physical memory area through DMA direct memory access; processes the network data packet according to the five-tuple rule to determine whether the network data packet complies with the release rule; if the network data packet complies with the release rule, the network data packet is placed in the public memory area queue of the physical memory area based on the security monitoring rule; if the network data packet does not comply with the release rule, the data packet is discarded; the firewall detection is directly processed from the kernel layer, and the network data packet in the physical memory area is directly accessed through the virtual address, and the firewall system places the filtered data packet into the public memory area queue, shortens the data processing chain, reduces system overhead, and has high hardware resource utilization.
[0006] Further, the processing of the network data packet according to the five-tuple rule to determine whether the network data packet complies with the release rule includes: When the five fields of the network data packet all meet the preset rules, the network data packet is judged to meet the release rules; wherein the five fields include: source IP address, destination IP address, source port, destination port and transport layer protocol; If one of the fields of the network data packet does not comply with the preset rule, it is determined that the network data packet does not comply with the release rule.
[0007] In the above implementation process, the network data packets are initially released and screened through the firewall system to ensure the security of the network.
[0008] Furthermore, the step of placing the network data packet into the public memory area queue of the physical memory area based on the security monitoring rule includes: Determine whether the network data packet has preset threat potential characteristics; If the network data packet does not have the preset threat potential characteristics, the network data packet is sent to the upper-layer application for processing; If the network data packet has preset threat potential characteristics, the obtained threat data packet is placed in the public memory area queue of the physical memory area for storage, so as to instruct the second CPU to obtain the threat data packet from the public memory area queue for intrusion defense detection.
[0009] In the above implementation process, the firewall system detects whether the network data packet has a threat risk, and sends it to the public memory area queue after screening to facilitate IPS extraction and processing, thereby improving the data processing flow.
[0010] In a second aspect, an embodiment of the present application further provides a method for parallel processing of firewall rules and IPS intrusion features, which is used for a second CPU, the second CPU is bound to an intrusion detection system IPS and the second CPU is arranged in a kernel layer, and the method includes: Based on the memory mapping mechanism, a memory mapping of the physical memory area is obtained through the second virtual address space; Accessing the public memory area queue of the physical memory area through the second virtual address of the second virtual address space to obtain a threat data packet; wherein the threat data packet is screened by the first CPU based on the security detection rule and placed in the public memory area queue; Process the threat data packet according to the intrusion detection rules to determine whether the threat data packet matches the intrusion signature; If the threat data packet does not match the intrusion signature, the network data packet is sent to the upper-layer application for processing; If the threat data packet matches the intrusion signature, the threat data packet is blocked, an alarm is issued, and a log is recorded.
[0011] In the above implementation process, the embodiment of the present application obtains the memory mapping of the physical memory area through the second virtual address space based on the memory mapping mechanism; accesses the public memory area queue of the physical memory area through the second virtual address space to obtain the threat data packet; wherein the threat data packet is screened by the first CPU based on the security detection rule and placed in the public memory area queue; the threat data packet is processed according to the intrusion detection rule to determine whether the threat data packet matches the intrusion feature; if the threat data packet does not match the intrusion feature, the network data packet is sent to the upper-level application for processing; if the threat data packet matches the intrusion feature, the threat data packet is blocked, and an alarm is issued and a log is recorded; IPS detection is directly processed from the kernel layer, and the threat data packet in the public memory area queue is directly accessed through the virtual address for processing, thereby shortening the data processing chain, reducing system overhead, and achieving high hardware resource utilization.
[0012] Further, the processing of the threat data packet according to the intrusion detection rule to determine whether the threat data packet matches the intrusion feature includes: Perform feature matching and behavior analysis on threat data packets to determine whether the threat data packets match the preset intrusion features.
[0013] In the above implementation process, it is realized to judge whether the threat data packet has intrusion characteristics.
[0014] In a third aspect, an embodiment of the present application further provides a method for parallel processing of firewall rules and IPS intrusion features, which is used in a network security system, wherein the network security system includes a first CPU and a second CPU, wherein the first CPU is bound to a firewall system, and the second CPU is bound to an intrusion detection system IPS, wherein the first CPU and the second CPU are both arranged in a kernel layer, and the method includes: Based on the memory mapping mechanism, the memory mapping of the physical memory area is mapped to the first virtual address space of the first CPU and the virtual address space of the second CPU respectively; Control DMA direct memory access to write network data packets into the physical memory area; Controlling a first virtual address of a first virtual address space to access a network data packet of a physical memory area; Processing the network data packet through the first CPU according to the five-tuple rule to determine whether the network data packet complies with the release rule; If the network data packet meets the release rule, the network data packet is placed into the public memory area queue of the physical memory area by the first CPU based on the security monitoring rule; Controlling the second virtual address of the second virtual address space to access the public memory area queue of the physical memory area to obtain the threat data packet; Processing the threat data packet through the second CPU according to the intrusion detection rule to determine whether the threat data packet matches the intrusion feature; If the threat data packet matches the intrusion signature, the threat data packet is blocked, an alarm is issued, and a log is recorded.
[0015] In the above implementation process, firewall detection and IPS detection are directly processed from the kernel layer, and the public memory area queue of the physical memory area is directly accessed through the virtual address. The firewall system puts the filtered data packets into the public memory area queue, and the IPS directly accesses the threat data packets in the public memory area queue through the virtual address for processing, shortening the data processing chain, reducing system overhead, and high hardware resource utilization.
[0016] Furthermore, after determining whether the network data packet meets the release rule, the process further includes: If the network data packet does not meet the release rules, the data packet is discarded.
[0017] After determining whether the threat data packet matches the intrusion feature, the method further includes: If the threat data packet does not match the intrusion signature, the network data packet is sent to the upper-layer application for processing.
[0018] Further, the processing of the network data packet by the first CPU according to the five-tuple rule to determine whether the network data packet complies with the release rule includes: When the five fields of the network data packet all meet the preset rules, the first CPU determines that the network data packet meets the release rule; wherein the five fields include: source IP address, destination IP address, source port, destination port and transport layer protocol; If one of the fields of the network data packet does not comply with the preset rule, it is determined that the network data packet does not comply with the release rule.
[0019] Furthermore, the step of placing the network data packet into the public memory area queue of the physical memory area based on the security monitoring rule by the first CPU includes: Determine, by the first CPU, whether the network data packet has a preset threat potential feature; If the network data packet does not have the preset threat potential characteristics, the network data packet is sent to the upper-layer application for processing; If the network data packet has preset threat potential characteristics, the obtained threat data packet is placed in the public memory area queue of the physical memory area for storage, so as to instruct the second CPU to obtain the threat data packet from the public memory area queue for intrusion defense detection.
[0020] Further, the processing of the threat data packet by the second CPU according to the intrusion detection rule to determine whether the threat data packet matches the intrusion feature includes: The second CPU performs feature matching and behavior analysis on the threat data packet to determine whether the threat data packet matches a preset intrusion feature.
[0021] In a fourth aspect, an embodiment of the present application further provides a firewall rule and IPS intrusion feature parallel processing device, which is used for a first CPU, the first CPU is bound to a firewall system and the first CPU is arranged in a kernel layer, and the device includes: A first mapping module, configured to obtain a memory mapping of a physical memory area through a first virtual address space based on a memory mapping mechanism; A first access module, configured to access a network data packet in a physical memory area through a first virtual address in a first virtual address space, wherein the network data packet is written to the physical memory area through DMA direct memory access; A release detection module is used to process the network data packet according to the five-tuple rule to determine whether the network data packet complies with the release rule; A data storage module, for placing the network data packet into a public memory area queue of the physical memory area based on a security monitoring rule if the network data packet meets the release rule; The data discarding module is used to discard the data packet if the network data packet does not meet the release rules.
[0022] In a fifth aspect, an embodiment of the present application further provides a firewall rule and IPS intrusion feature parallel processing device, which is used for a second CPU, the second CPU is bound to an intrusion detection system IPS and the second CPU is arranged in a kernel layer, and the device includes: A second mapping module, configured to obtain a memory mapping of a physical memory area through a second virtual address space based on a memory mapping mechanism; A second access module is used to access the public memory area queue of the physical memory area through the second virtual address of the second virtual address space to obtain a threat data packet; wherein the threat data packet is screened by the first CPU based on the security detection rule and placed in the public memory area queue; A threat judgment module is used to process the threat data packet according to the intrusion detection rules to determine whether the threat data packet matches the intrusion feature; A threat determination module is used to send the network data packet to an upper layer application for processing if the threat data packet does not match the intrusion signature; The threat matching module is used to block the threat data packet, issue an alarm and record a log if the threat data packet matches the intrusion feature.
[0023] In a sixth aspect, an embodiment of the present application further provides a firewall rule and IPS intrusion feature parallel processing device for a network security system, wherein the network security system includes a first CPU and a second CPU, wherein the first CPU is bound to a firewall system, and the second CPU is bound to an intrusion detection system IPS, wherein the first CPU and the second CPU are both arranged in a kernel layer, and the device includes: A memory mapping module, used for mapping the memory mapping of the physical memory area to the first virtual address space of the first CPU and the virtual address space of the second CPU respectively based on the memory mapping mechanism; The memory access module is used to control DMA direct memory access to write network data packets into the physical memory area; An access control module, used for controlling a first virtual address in a first virtual address space to access a network data packet in a physical memory area; A first processing module, used to process the network data packet through the first CPU according to the five-tuple rule to determine whether the network data packet complies with the release rule; A release processing module, configured to place the network data packet into a public memory area queue of the physical memory area through the first CPU based on a security monitoring rule if the network data packet meets the release rule; A threat acquisition module, used for controlling the second virtual address of the second virtual address space to access the public memory area queue of the physical memory area to acquire a threat data packet; A threat processing module, used to process the threat data packet through the second CPU according to the intrusion detection rule, and determine whether the threat data packet matches the intrusion feature; The security response module is used to block the threat data packet, issue an alarm and record a log if the threat data packet matches the intrusion feature.
[0024] In a seventh aspect, an embodiment of the present application provides an electronic device, including: A processor, a memory and a bus, wherein the processor is connected to the memory via the bus, and the memory stores computer-readable instructions. When the computer-readable instructions are executed by the processor, they are used to implement the firewall rule and IPS intrusion feature parallel processing method as described above.
[0025] In an eighth aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a server, the method for parallel processing of firewall rules and IPS intrusion features as described above is implemented.
[0026] In a ninth aspect, an embodiment of the present invention provides a computer program product, which includes instructions, and when the instructions are executed by a computer, the computer implements the firewall rule and IPS intrusion feature parallel processing method as described above. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0028] Figure 1 A flowchart of a method for parallel processing of firewall rules and IPS intrusion features provided in an embodiment of the present application; Figure 2 A flowchart of another method for parallel processing of firewall rules and IPS intrusion features provided in an embodiment of the present application; Figure 3 A flowchart of another method for parallel processing of firewall rules and IPS intrusion features provided in an embodiment of the present application; Figure 4 A schematic diagram of the system architecture of a method for parallel processing of firewall rules and IPS intrusion features provided in an embodiment of the present application; Figure 5A schematic diagram of a common memory area queue of a method for parallel processing of firewall rules and IPS intrusion features provided in an embodiment of the present application; Figure 6 A schematic diagram of a business processing flow of a method for parallel processing of firewall rules and IPS intrusion features provided in an embodiment of the present application; Figure 7 A flowchart of a device for parallel processing of firewall rules and IPS intrusion features provided in an embodiment of the present application; Figure 8 A flowchart of a device for parallel processing of firewall rules and IPS intrusion features provided in an embodiment of the present application; Fig. 9 A flowchart of a device for parallel processing of firewall rules and IPS intrusion features provided in an embodiment of the present application; Fig.10 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0029] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.
[0030] It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.
[0031] DMA: Direct Memory Access allows external devices (such as disk drives, network cards, etc.) to exchange data directly with system memory without frequent intervention from the CPU.
[0032] User level: User-level programs and processes are started and run by applications. They run in a restricted permission environment and cannot directly access the underlying hardware resources of the system. They can only use the standard interfaces and services provided by the operating system to complete tasks. These program codes are written with more emphasis on ease of use and business process implementation, and are relatively independent of the underlying hardware details.
[0033] Kernel level: The kernel is the core of the operating system and has the highest authority. It directly interacts with the hardware. The kernel is responsible for coordinating the scheduling, control and data interaction of hardware devices such as the CPU, memory, hard disk, and network card. Taking process management as an example, the kernel determines which process gets CPU resources to run and when; in memory management, the kernel must reasonably divide physical memory for different processes to use and recycle memory when the process ends.
[0034] First, see Figure 1 , Figure 1 A flowchart of a method for parallel processing of firewall rules and IPS intrusion features provided in an embodiment of the present application. The method for parallel processing of firewall rules and IPS intrusion features is used for a first CPU, the first CPU is bound to a firewall system and the first CPU is located in the kernel layer, and the method includes: 110. Based on a memory mapping mechanism, a memory mapping of the physical memory area is obtained through the first virtual address space.
[0035] 120. Access a network data packet in a physical memory area through a first virtual address in a first virtual address space, wherein the network data packet is written to the physical memory area through DMA direct memory access.
[0036] 130. Process the network data packet according to the five-tuple rule to determine whether the network data packet complies with the release rule.
[0037] 131. When the five fields of a network data packet all meet the preset rules, the network data packet is judged to meet the release rules; wherein the five fields include: source IP address, destination IP address, source port, destination port and transport layer protocol.
[0038] 132. If one of the fields of the network data packet does not comply with the preset rule, it is determined that the network data packet does not comply with the release rule.
[0039] Therefore, the firewall system performs preliminary screening on network data packets to ensure the security of the network.
[0040] 140. If the network data packet meets the release rule, the network data packet is placed into the public memory area queue of the physical memory area based on the security monitoring rule.
[0041] 141. Determine whether the network data packet has preset threat potential characteristics.
[0042] 142. If the network data packet does not have the preset threat potential characteristics, the network data packet will be sent to the upper-level application for processing.
[0043] 143. If the network data packet has a preset threat potential feature, the obtained threat data packet is placed in a public memory area queue of the physical memory area for storage, so as to instruct the second CPU to obtain the threat data packet from the public memory area queue for intrusion defense detection.
[0044] Thus, the firewall system detects whether the network data packets contain potential threats, and after screening, sends them to the public memory area queue for IPS extraction and processing, thereby improving the data processing flow.
[0045] 150. If the network data packet does not meet the release rules, the data packet will be discarded.
[0046] As described above, the embodiment of the present application is based on a memory mapping mechanism, and obtains a memory mapping of a physical memory area through a first virtual address space; accesses a network data packet in the physical memory area through a first virtual address in the first virtual address space, wherein the network data packet is written to the physical memory area through direct memory access via DMA; processes the network data packet according to a five-tuple rule to determine whether the network data packet complies with the release rule; if the network data packet complies with the release rule, the network data packet is placed in a public memory area queue of the physical memory area based on security monitoring rules; if the network data packet does not comply with the release rule, the data packet is discarded; firewall detection is directly processed from the kernel layer, and network data packets in the physical memory area are directly accessed through virtual addresses. The firewall system places the filtered data packets in the public memory area queue, shortens the data processing chain, reduces system overhead, and has high hardware resource utilization.
[0047] Second, see Figure 2 , Figure 2 A flowchart of another method for parallel processing of firewall rules and IPS intrusion features provided in an embodiment of the present application. The method for parallel processing of firewall rules and IPS intrusion features is used for a second CPU, the second CPU is bound to an intrusion detection system IPS and the second CPU is located in the kernel layer, and the method includes: 210. Based on the memory mapping mechanism, obtain the memory mapping of the physical memory area through the second virtual address space.
[0048] 220. Access the public memory area queue of the physical memory area through the second virtual address of the second virtual address space to obtain a threat data packet; wherein the threat data packet is screened by the first CPU based on the security detection rule and placed in the public memory area queue.
[0049] 230. Process the threat data packet according to the intrusion detection rule to determine whether the threat data packet matches the intrusion feature.
[0050] Specifically, feature matching and behavior analysis are performed on the threat data packet to determine whether the threat data packet matches a preset intrusion feature; thereby, determining whether the threat data packet has an intrusion feature.
[0051] 240. If the threat data packet does not match the intrusion signature, the network data packet is sent to an upper layer application for processing.
[0052] 250. If the threat data packet matches the intrusion signature, the threat data packet is blocked, and an alarm is issued and a log is recorded.
[0053] As described above, the embodiment of the present application is based on a memory mapping mechanism, and obtains a memory mapping of a physical memory area through a second virtual address space; accesses a public memory area queue of a physical memory area through a second virtual address space to obtain a threat data packet; wherein the threat data packet is screened by the first CPU based on security detection rules and placed in a public memory area queue; the threat data packet is processed according to the intrusion detection rules to determine whether the threat data packet matches an intrusion feature; if the threat data packet does not match the intrusion feature, the network data packet is sent to an upper-layer application for processing; if the threat data packet matches the intrusion feature, the threat data packet is blocked, and an alarm is issued and a log is recorded; IPS detection is directly processed from the kernel layer, and the threat data packet in the public memory area queue is directly accessed through a virtual address for processing, thereby shortening the data processing chain, reducing system overhead, and achieving high hardware resource utilization.
[0054] Third, see Figure 3 , Figure 3 A flowchart of another method for parallel processing of firewall rules and IPS intrusion features provided in an embodiment of the present application. The method for parallel processing of firewall rules and IPS intrusion features is used in a network security system, wherein the network security system includes a first CPU and a second CPU, wherein the first CPU is bound to a firewall system, and the second CPU is bound to an intrusion detection system IPS, wherein the first CPU and the second CPU are both located in the kernel layer, and the method includes: 310. Based on a memory mapping mechanism, map the memory mapping of the physical memory area to the first virtual address space of the first CPU and the virtual address space of the second CPU respectively.
[0055] 320. Control DMA direct memory access to write network data packets into the physical memory area.
[0056] 330. Control a first virtual address in a first virtual address space to access a network data packet in a physical memory area.
[0057] Exemplarily, the network card receives external network data and directly writes it into the specified memory area through DMA. Through the memory mapping mechanism provided by the system, the same physical memory is mapped to the virtual address space of the two CPUs. In this way, the two CPUs can access the same physical memory through their respective virtual addresses. In this case, DMA can transfer data directly to the shared memory area under the control of one of the CPUs, and the other CPU can read the data in the shared memory at an appropriate time. In order to ensure that only one CPU can access the shared memory at the same time, mutual exclusion and synchronization mechanisms such as semaphores and mutex locks can be used to prevent access conflicts.
[0058] 340. Process the network data packet through the first CPU according to the five-tuple rule to determine whether the network data packet complies with the release rule.
[0059] 341. When the five fields of the network data packet all meet the preset rules, the first CPU determines that the network data packet meets the release rules; wherein the five fields include: source IP address, destination IP address, source port, destination port and transport layer protocol.
[0060] 342. If one of the fields of the network data packet does not comply with the preset rule, it is determined that the network data packet does not comply with the release rule.
[0061] 350. If the network data packet meets the release rule, the first CPU puts the network data packet into the public memory area queue of the physical memory area based on the security monitoring rule.
[0062] 351. Determine, by the first CPU, whether the network data packet has a preset threat potential feature.
[0063] 352. If the network data packet does not have the preset threat potential characteristics, the network data packet will be sent to the upper-level application for processing.
[0064] 353. If the network data packet has a preset threat potential feature, the obtained threat data packet is placed in the public memory area queue of the physical memory area for storage, so as to instruct the second CPU to obtain the threat data packet from the public memory area queue for intrusion defense detection.
[0065] 354. If the network data packet does not meet the release rules, the data packet will be discarded.
[0066] 360. Control the second virtual address of the second virtual address space to access the public memory area queue of the physical memory area to obtain the threat data packet.
[0067] like Figure 5 As shown in the figure, the firewall and IPS applications are bound to two CPUs respectively, and a queue is added between the two CPUs. The firewall first processes the network data, and then puts the threat data that needs to be processed by the IPS into the queue. The IPS module processes and analyzes it and performs the next step.
[0068] 370. Process the threat data packet through the second CPU according to the intrusion detection rule to determine whether the threat data packet matches the intrusion feature. The second CPU performs feature matching and behavior analysis on the threat data packet to determine whether the threat data packet matches a preset intrusion feature.
[0069] 380. If the threat data packet matches the intrusion signature, the threat data packet is blocked, and an alarm is issued and a log is recorded.
[0070] If the threat data packet does not match the intrusion signature, the network data packet is sent to the upper-layer application for processing.
[0071] For example, the specific business processing flow of the embodiment of the present application is as follows: Figure 6 As shown. It should be explained that after the firewall releases the message according to the pre-defined rules, it needs to determine the destination of the released message, and the threatening message needs to be further handed over to the IPS for processing. How to judge whether to hand over to the IPS for processing can be based on marking high-risk ports (such as common malware communication ports), and specific ports of key services may also be sent to the IPS to ensure data security and integrity, prevent potential attacks on the business application, certain special protocol types, traffic patterns (sudden abnormal increase in traffic in a short period of time), based on threat intelligence (malicious domain names, source addresses, etc.), these data can pass the firewall release rules, but there are potential risks. Handing over to the IPS module for processing at the kernel layer can handle threats as early and as quickly as possible, providing a more basic and comprehensive security protection.
[0072] As described above, the firewall detection and IPS detection in the embodiment of the present application are directly processed from the kernel layer, and the public memory area queue of the physical memory area is directly accessed through the virtual address. The firewall system puts the filtered data packets into the public memory area queue, and the IPS directly accesses the threat data packets in the public memory area queue through the virtual address for processing, thereby shortening the data processing chain, reducing system overhead, and achieving high hardware resource utilization.
[0073] The security processing module of the existing common network security equipment system architecture is at the user layer. The data received by the network card in the application layer needs to be copied multiple times at the user layer and the kernel layer, resulting in high context switching overhead.
[0074] The embodiment of the present application processes the firewall and IPS intrusion detection application at the kernel layer. Figure 4 Applications can interact directly with the network card NIC (network driver), and the kernel-layer firewall or IPS can directly read data packets from the NIC buffer and write them directly to the output buffer after processing. There is no need to copy data packets from kernel space to user space first, and then copy them back to kernel space after processing like user-layer applications, thereby significantly improving the data packet processing speed, especially when processing a large number of small data packets in a high-traffic network environment. Hardware resources can be used more efficiently for fast data packet parsing and matching operations, improving overall processing efficiency. For example, for some network security functions based on hardware acceleration (such as encryption / decryption, packet filtering, etc.), kernel-layer processing can work better with hardware to give full play to the hardware performance advantages.
[0075] It can be understood that the present application adopts a multi-way CPU mode, that is, the network security system includes two CPUs, which are used for firewall detection and IPS detection respectively. Optionally, the network security system may also include a CPU, in which different cores are used to detect firewalls and IPS.
[0076] The above steps are not to be performed in a strict order as described in the numbers, but should be understood as an overall solution.
[0077] In a fourth aspect, based on the above embodiments, the embodiments of the present application further provide a firewall rule and IPS intrusion feature parallel processing device for a first CPU, the first CPU is bound to a firewall system and the first CPU is arranged in a kernel layer, referring to Figure 7 The firewall rule and IPS intrusion feature parallel processing device provided in this embodiment specifically includes: a first mapping module 701, a first access module 702, a release detection module 703, a data storage module 704 and a data discarding module 705.
[0078] Among them, the first mapping module 701 is used to obtain the memory mapping of the physical memory area through the first virtual address space based on the memory mapping mechanism; the first access module 702 is used to access the network data packet in the physical memory area through the first virtual address of the first virtual address space, wherein the network data packet is written to the physical memory area through DMA direct memory access; the release detection module 703 is used to process the network data packet according to the five-tuple rule to determine whether the network data packet complies with the release rule; the data storage module 704 is used to put the network data packet into the public memory area queue of the physical memory area based on the security monitoring rule if the network data packet complies with the release rule; the data discard module 705 is used to discard the data packet if the network data packet does not comply with the release rule.
[0079] In a fifth aspect, based on the above embodiments, the embodiments of the present application further provide a firewall rule and IPS intrusion feature parallel processing device for a second CPU, the second CPU is bound to an intrusion detection system IPS and the second CPU is arranged in the kernel layer, referring to Figure 8 The firewall rule and IPS intrusion feature parallel processing device provided in this embodiment specifically includes: a second mapping module 801, a second access module 802, a threat judgment module 803, a threat determination module 804 and a threat matching module 805.
[0080] Among them, the second mapping module 801 is used to obtain the memory mapping of the physical memory area through the second virtual address space based on the memory mapping mechanism; the second access module 802 is used to access the public memory area queue of the physical memory area through the second virtual address of the second virtual address space to obtain the threat data packet; wherein, the threat data packet is screened by the first CPU based on the security detection rule and placed in the public memory area queue; the threat judgment module 803 is used to process the threat data packet according to the intrusion detection rule to determine whether the threat data packet matches the intrusion feature; the threat judgment module 804 is used to send the network data packet to the upper-level application for processing if the threat data packet does not match the intrusion feature; the threat matching module 805 is used to block the threat data packet if the threat data packet matches the intrusion feature, and issue an alarm and record a log.
[0081] In a sixth aspect, based on the above embodiments, the embodiments of the present application further provide a firewall rule and IPS intrusion feature parallel processing device for a network security system, wherein the network security system comprises a first CPU and a second CPU, wherein the first CPU is bound to a firewall system, and the second CPU is bound to an intrusion detection system IPS, wherein the first CPU and the second CPU are both arranged in a kernel layer, and the network security system comprises a first CPU and a second CPU ... Fig. 9 The firewall rule and IPS intrusion feature parallel processing device provided in this embodiment specifically includes: The memory mapping module 901 is used to map the memory mapping of the physical memory area to the first virtual address space of the first CPU and the virtual address space of the second CPU respectively based on the memory mapping mechanism; The memory access module 902 is used to control DMA direct memory access to write network data packets into the physical memory area; The access control module 903 is used to control the first virtual address of the first virtual address space to access the network data packet of the physical memory area; The first processing module 904 is used to process the network data packet through the first CPU according to the five-tuple rule to determine whether the network data packet meets the release rule; The release processing module 905 is used to put the network data packet into the public memory area queue of the physical memory area based on the security monitoring rule through the first CPU if the network data packet meets the release rule; The threat acquisition module 906 is used to control the second virtual address of the second virtual address space to access the public memory area queue of the physical memory area to acquire the threat data packet; The threat processing module 907 is used to process the threat data packet through the second CPU according to the intrusion detection rule to determine whether the threat data packet matches the intrusion feature; The security response module 908 is used to block the threat data packet, issue an alarm and record a log if the threat data packet matches the intrusion feature.
[0082] In a seventh aspect, an embodiment of the present application further provides an electronic device that can integrate the firewall rules of the user-mode polling mechanism and the IPS intrusion feature parallel processing device provided in the embodiment of the present application. Fig.10 Schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Fig.10 The electronic device includes: an input device 43, an output device 44, a memory 42 and one or more processors 41; the memory 42 is used to store one or more programs; when the one or more programs are executed by the one or more processors 41, the one or more processors 41 implement the firewall rules and IPS intrusion feature parallel processing method of the user-mode polling mechanism provided in the above embodiment. The input device 43, the output device 44, the memory 42 and the processor 41 can be connected by a bus or other means. Fig.10 The example of connecting through bus is taken in the following.
[0083] The processor 41 executes various functional applications and data processing of the device by running software programs, instructions and modules stored in the memory 42, that is, implements the firewall rules of the user-mode polling mechanism and the IPS intrusion feature parallel processing method.
[0084] The electronic device provided above can be used to execute the firewall rules of the user-mode polling mechanism and the IPS intrusion feature parallel processing method provided in the above embodiment, and has corresponding functions and beneficial effects.
[0085] In an eighth aspect, an embodiment of the present application also provides a computer-readable storage medium, the computer-readable storage medium including a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the firewall rules and IPS intrusion feature parallel processing method as described above, and can achieve the same beneficial effects.
[0086] Of course, the storage medium containing computer executable instructions provided in an embodiment of the present application is not limited to the firewall rules and IPS intrusion feature parallel processing method described above, and can also execute related operations in the firewall rules and IPS intrusion feature parallel processing method provided in any embodiment of the present application.
[0087] In the ninth aspect, the embodiments of the present application also provide a computer program product, and the methods described in the various embodiments of the present application can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instruction is loaded and executed on a computer, the processes or functions described in the various embodiments of the present application are executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, a core network device, an OAM (Open Application Model) or other programmable device.
[0088] The computer program or instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer program or instructions may be transmitted from one website, computer, server or data center to another website, computer, server or data center by wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it may also be an optical medium, such as a digital video disk; it may also be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both volatile and non-volatile types of storage media.
[0089] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of a code, and the module, a program segment or a part of a code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.
[0090] In addition, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.
[0091] If the function is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, and other media that can store program codes.
[0092] The above description is only an embodiment of the present application and is not intended to limit the scope of protection of the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings.
[0093] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
[0094] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.
Claims
1. A method for parallel processing of firewall rules and IPS intrusion features, characterized in that: For a first CPU, the first CPU is bound to a firewall system and the first CPU is arranged in a kernel layer, the method comprising: Based on the memory mapping mechanism, a memory mapping of the physical memory area is obtained through the first virtual address space; Accessing a network data packet in a physical memory area through a first virtual address in a first virtual address space, wherein the network data packet is written to the physical memory area through DMA direct memory access; Process the network data packet according to the five-tuple rule to determine whether the network data packet meets the release rule; If the network data packet meets the release rules, the network data packet is placed in the public memory area queue of the physical memory area based on the security monitoring rules; If the network data packet does not meet the release rules, the data packet is discarded.
2. The method for parallel processing of firewall rules and IPS intrusion features according to claim 1, characterized in that: The processing of the network data packet according to the five-tuple rule to determine whether the network data packet complies with the release rule includes: When the five fields of the network data packet all meet the preset rules, the network data packet is judged to meet the release rules; wherein the five fields include: source IP address, destination IP address, source port, destination port and transport layer protocol; If one of the fields of the network data packet does not comply with the preset rule, it is determined that the network data packet does not comply with the release rule.
3. The method for parallel processing of firewall rules and IPS intrusion features according to claim 1, characterized in that: The method of placing the network data packet into the public memory area queue of the physical memory area based on the security monitoring rule includes: Determine whether the network data packet has preset threat potential characteristics; If the network data packet does not have the preset threat potential characteristics, the network data packet is sent to the upper-layer application for processing; If the network data packet has preset threat potential characteristics, the obtained threat data packet is placed in the public memory area queue of the physical memory area for storage, so as to instruct the second CPU to obtain the threat data packet from the public memory area queue for intrusion defense detection.
4. A method for parallel processing of firewall rules and IPS intrusion features, characterized in that: Used in a network security system, the network security system includes a first CPU and a second CPU, the first CPU is bound to a firewall system, the second CPU is bound to an intrusion detection system IPS, the first CPU and the second CPU are both arranged in a kernel layer, the method includes: Based on the memory mapping mechanism, the memory mapping of the physical memory area is mapped to the first virtual address space of the first CPU and the virtual address space of the second CPU respectively; Control DMA direct memory access to write network data packets into the physical memory area; Controlling a first virtual address of a first virtual address space to access a network data packet of a physical memory area; Processing the network data packet through the first CPU according to the five-tuple rule to determine whether the network data packet complies with the release rule; If the network data packet meets the release rule, the network data packet is placed into the public memory area queue of the physical memory area by the first CPU based on the security monitoring rule; Controlling the second virtual address of the second virtual address space to access the public memory area queue of the physical memory area to obtain the threat data packet; Processing the threat data packet through the second CPU according to the intrusion detection rule to determine whether the threat data packet matches the intrusion feature; If the threat data packet matches the intrusion signature, the threat data packet is blocked, an alarm is issued, and a log is recorded.
5. The method for parallel processing of firewall rules and IPS intrusion features according to claim 4, characterized in that: After determining whether the network data packet complies with the release rule, the method further includes: If the network data packet does not meet the release rules, the data packet is discarded; After determining whether the threat data packet matches the intrusion feature, the method further includes: If the threat data packet does not match the intrusion signature, the network data packet is sent to the upper-layer application for processing.
6. The method for parallel processing of firewall rules and IPS intrusion features according to claim 4, characterized in that: The processing of the network data packet by the first CPU according to the five-tuple rule to determine whether the network data packet complies with the release rule includes: When the five fields of the network data packet all meet the preset rules, the first CPU determines that the network data packet meets the release rule; wherein the five fields include: source IP address, destination IP address, source port, destination port and transport layer protocol; If one of the fields of the network data packet does not comply with the preset rule, it is determined that the network data packet does not comply with the release rule.
7. The method for parallel processing of firewall rules and IPS intrusion features according to claim 4, characterized in that: The step of placing the network data packet into the public memory area queue of the physical memory area based on the security monitoring rule by the first CPU includes: Determine, by the first CPU, whether the network data packet has a preset threat potential feature; If the network data packet does not have the preset threat potential characteristics, the network data packet is sent to the upper-layer application for processing; If the network data packet has preset threat potential characteristics, the obtained threat data packet is placed in the public memory area queue of the physical memory area for storage, so as to instruct the second CPU to obtain the threat data packet from the public memory area queue for intrusion defense detection.
8. The method for parallel processing of firewall rules and IPS intrusion features according to claim 4, characterized in that: The processing of the threat data packet by the second CPU according to the intrusion detection rule to determine whether the threat data packet matches the intrusion feature includes: The second CPU performs feature matching and behavior analysis on the threat data packet to determine whether the threat data packet matches a preset intrusion feature.
9. A device for parallel processing of firewall rules and IPS intrusion features, characterized in that: Used for a first CPU, the first CPU is bound to a firewall system and the first CPU is arranged in a kernel layer, the device comprises: A first mapping module, configured to obtain a memory mapping of a physical memory area through a first virtual address space based on a memory mapping mechanism; A first access module, configured to access a network data packet in a physical memory area through a first virtual address in a first virtual address space, wherein the network data packet is written to the physical memory area through DMA direct memory access; A release detection module is used to process the network data packet according to the five-tuple rule to determine whether the network data packet complies with the release rule; A data storage module, for placing the network data packet into a public memory area queue of the physical memory area based on a security monitoring rule if the network data packet meets the release rule; The data discarding module is used to discard the data packet if the network data packet does not meet the release rules.
10. A device for parallel processing of firewall rules and IPS intrusion features, characterized in that: Used in a network security system, the network security system includes a first CPU and a second CPU, the first CPU is bound to a firewall system, the second CPU is bound to an intrusion detection system IPS, the first CPU and the second CPU are both arranged in a kernel layer, and the device includes: A memory mapping module, used for mapping the memory mapping of the physical memory area to the first virtual address space of the first CPU and the virtual address space of the second CPU respectively based on the memory mapping mechanism; The memory access module is used to control DMA direct memory access to write network data packets into the physical memory area; An access control module, used for controlling a first virtual address in a first virtual address space to access a network data packet in a physical memory area; A first processing module, used to process the network data packet through the first CPU according to the five-tuple rule to determine whether the network data packet complies with the release rule; A release processing module, configured to place the network data packet into a public memory area queue of the physical memory area through the first CPU based on a security monitoring rule if the network data packet meets the release rule; A threat acquisition module, used for controlling the second virtual address of the second virtual address space to access the public memory area queue of the physical memory area to acquire a threat data packet; A threat processing module, used to process the threat data packet through the second CPU according to the intrusion detection rule, and determine whether the threat data packet matches the intrusion feature; The security response module is used to block the threat data packet, issue an alarm and record a log if the threat data packet matches the intrusion feature.
Citation Information
Patent Citations
Multifunctional comprehensive security gateway system
CN101714958A
Network protocol reassembly accelaration
CN101827071A
Firewall based on intrusion detection system feedback in cloud environment and implementation method thereof
CN110572412A
Network data packet reading method, device and equipment and readable storage medium
CN111371759A
Firewall management system based on network security
CN115941264A