Intelligent access method for multi-element network security equipment

By establishing a device protocol library and plug-in library, automatic adaptation and protocol expansion of network security devices are achieved, and the complexity and scalability problems of device access management in the prior art are solved, and the connection management efficiency and security are improved.

CN119996047APending Publication Date: 2025-05-13HUANENG INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510279550.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-10
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing network security equipment access management solutions lack unified standards and specifications, resulting in high difficulty in equipment integration, high maintenance costs and poor scalability.

Method used

By establishing a device protocol library and a plug-in library, the connection sub-protocols in the device to be connected traversed by the device to be connected for automatic adaptation. If there is no adaptation protocol, the unified policy description language of the plug-in is called to perform protocol expansion to achieve fast access, and security vulnerability scanning and performance tuning is performed by periodically evaluating the call status of the connection sub-protocol and plug-in.

Benefits of technology

It improves the connection management efficiency of network security equipment, ensures the secure connection of equipment, and reduces the complexity and cost of equipment integration and maintenance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996047A_ABST
    Figure CN119996047A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security equipment, in particular to an intelligent access method for multi-element network security equipment. Comprising the steps of establishing an equipment protocol library and a plug-in library based on historical parameters; obtaining identity data packets of all the to-be-connected devices, and setting a connection mode of each to-be-connected device according to all the identity data packets; and judging whether to generate a correction instruction of the equipment protocol library and the plug-in library or not according to the preset feedback time node. The to-be-connected device traverses all the connection sub-protocols in the device protocol library for automatic adaptation, quick access of the to-be-connected device is achieved by calling the corresponding connection sub-protocols, if no adaptation protocol exists, the corresponding plug-in unified strategy description language is called, the access protocol is expanded without recompiling the whole program code, and the access efficiency is improved. Therefore, the connection efficiency of the network security equipment is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of network security equipment, and in particular to a method for intelligent access to multiple network security equipment. Background Art

[0002] At present, the access management of network security devices in large-scale distributed information systems faces huge challenges. The main reason is that the network security management system manages a wide variety of network security devices, such as firewalls, intrusion detection systems, Web application firewalls, etc., and these devices often come from different manufacturers, and their protocols and interface standards are uneven. Traditional network security management methods require separate configuration and management for different network security devices, which is not only complicated and cumbersome, but also difficult to ensure the uniformity and flexibility of strategies.

[0003] Most existing solutions for network security device access management rely on specific interfaces or protocols provided by manufacturers and lack unified standards and specifications, which leads to problems such as high difficulty in device integration, high maintenance costs, and poor scalability. Summary of the invention

[0004] The purpose of this application is: to solve the above technical problems, this application provides a multi-network security device intelligent access method, aiming to improve the connection management efficiency of network security devices.

[0005] In some embodiments of the present application, the device to be connected traverses all connection sub-protocols in the device protocol library for automatic adaptation, and achieves fast access to the device to be connected by calling the corresponding connection sub-protocol. If there is no adaptation protocol, the corresponding plug-in unified policy description language is called to extend the access protocol without recompiling the entire program code, thereby improving the connection efficiency of the network security device.

[0006] In some embodiments of the present application, by periodically evaluating the calling status of each connection sub-protocol and each plug-in, security vulnerability scanning and penetration testing are performed, potential security risks are discovered and repaired in a timely manner, and performance tuning is performed on each plug-in, thereby improving the connection management efficiency of network security devices and ensuring the secure connection of each network security device.

[0007] In some embodiments of the present application, a method for intelligently accessing a multi-network security device is provided, including: Establish device protocol library and plug-in library based on historical parameters; Obtaining identity data packets of all devices to be connected, and setting a connection mode for each device to be connected according to all identity data packets; Determine whether to generate correction instructions for the device protocol library and the plug-in library according to the preset feedback time node; Among them, establishing the device protocol library and plug-in library includes: Establish a sequence of plug-ins A, A = (a1, a2... a i ... a n1 ), where a i is the i-th plug-in; n1 is the number of plug-ins; Establish a sequence of connection sub-protocols B, B = (b1, b2... b i ... b n2 ), where b i is the i-th connection sub-protocol; n2 is the number of connection sub-protocols.

[0008] In some embodiments of the present application, when setting the connection mode of each device to be connected, it includes: Establish a sequence of devices to be connected P, P = (p1, p2... p i ... p m ), where p i is the i-th device to be connected; m is the number of devices to be connected; Set p i as the target device to be connected in sequence according to the sequence of devices to be connected P; Obtain the identity data packet of the target device to be connected, and generate a primary adaptation value between the target device to be connected and each connection sub-protocol; Establish a sequence of primary adaptation values C1, C1 = (c 11 , c 12 ... c 1i ... c 1n2 ), where c 1i is the primary adaptation value between the target device to be connected and the i-th connection sub-protocol; Select the maximum value c 1max in the sequence of primary adaptation values C1; Preset a primary adaptation value threshold W1; If c 1max > C1, set the target device to be connected to the primary connection mode; If c 1max < C1, set the target device to be connected to the secondary connection mode; Among them, the primary connection mode includes: Set the connection sub-protocol corresponding to the maximum value c 1max as the sub-protocol to be called; Access the target sub-device to be accessed through the sub-protocol to be called.

[0009] In some embodiments of the present application, establishing the sequence of primary adaptation values C1 includes: Set bi as the target connection sub-protocol in sequence according to the sequence of connection sub-protocols B; Generate a primary adaptation value c1 between the target device to be connected and the target connection sub-protocol; c1=U1*[ β 1i *(j i -j' i ) 2 ]; in, Number of device identity indicators; β 1i is the influencing factor of the i-th device identity indicator; j i is the reference value of the ith device identity indicator generated based on the identity data packet of the target device to be connected; j' i is the standard reference value of the ith device identity indicator in the target connection sub-protocol; U1 conversion coefficient; Generate the first-level adaptation value of each connection sub-protocol and the target device to be connected in turn.

[0010] In some embodiments of the present application, the secondary connection mode includes: Generate secondary adaptation values ​​for each plug-in according to the identity data packet of the target device to be connected; Establish the secondary adaptation value sequence C2, C2=(c 21 , c 22 …c 2i …c 2n1 ), where c 2i is the secondary adaptation value between the target device to be connected and the i-th plug-in; Set the maximum value c in the secondary adaptation value sequence C2 2max The corresponding plug-in is the plug-in to be called; Access the target device to be connected through the plug-in to be called.

[0011] In some embodiments of the present application, establishing a secondary adaptation value sequence C2 includes: Set a in sequence according to the plug-in sequence A i For the target plugin; Generate a secondary adaptation value c2 between the target device to be connected and the target plug-in; c2=U2*[ β 2i *(k i -k' i ) 2 ]; in, is the number of plug-in indicators; β 2i is the impact factor of the i-th plug-in indicator; k i k' is the reference value of the i-th plug-in indicator generated based on the identity data packet of the target device to be connected; i is the standard reference value of the i-th plug-in indicator in the target plug-in; U2 is the conversion coefficient; Generate the secondary adaptation value of the target device to be established and each plug-in in turn.

[0012] In some embodiments of the present application, determining whether to generate a correction instruction for the device protocol library and the plugin library includes: Set b in sequence according to the connection sub-protocol sequence B i As the sub-protocol to be monitored; Obtain the monitoring data packet of the sub-protocol to be monitored at the current feedback time node; Generate the operation evaluation value d of the sub-protocol to be monitored; Generate the operation evaluation values of each connection sub-protocol at the current feedback time node in sequence; Establish the operation evaluation value sequence D at the current feedback time node, D = (d1, d2... d i …d n2 ), where d i Is the operation evaluation value of the i-th sub-protocol to be monitored at the current feedback time node; Preset the first operation evaluation value threshold D1; If d i < D1, generate the first-level correction strategy for the i-th connection sub-protocol at the current feedback time node; If d i > D1, do not correct the i-th connection sub-protocol at the current feedback time node; Obtain all the first-level correction strategies at the current feedback time node, and generate the first-level correction instruction at the current feedback time node according to all the first-level correction strategies.

[0013] In some embodiments of the present application, generating the operation evaluation value d of the sub-protocol to be monitored includes: d = e1 * Q1 * η 1i * t i + e2 * Q2 * Y(i) * (h i - h'); Where, e1 is the preset first weight coefficient; e2 is the preset second weight coefficient; Q1 is the preset first fixed coefficient; Q2 is the preset second fixed coefficient; r1 is the number of protocol call indicators; η 1i Is the influence factor of the i-th protocol call indicator; t i Is the reference value for the i-th protocol call indicator generated by the monitoring data packet of the sub-protocol to be monitored; w is the number of calls within the time interval between the previous feedback time node and the current feedback time node of the sub-protocol to be monitored; h i Is the call risk value for the i-th time; h' is the call risk value threshold; Y(i) is the selection coefficient; if (h i - h') > 0; Y(i) = 1; (h i - h') < 0; Y(i) = 0.

[0014] In some embodiments of the present application, determining whether to generate a correction instruction for the device protocol library and the plugin library further includes: Set a i as the plugin to be monitored in sequence according to the plugin sequence A; Obtain the feedback data packet of the plugin to be monitored at the current feedback time node; Generate a call evaluation value f for the plugin to be monitored according to the feedback data packet; Generate call evaluation values for each plugin in sequence; Establish a call evaluation value sequence F, F = (f1, f2... f i ... f n1 ), where f i is the call evaluation value of the i-th plugin at the current feedback time node; Preset a first call evaluation value threshold F1 and a second call evaluation value threshold F2, and F1 < F2; If f i > F2, set the i-th plugin as a first-level plugin; If F1 < f i < F2, do not correct the i-th plugin at the current feedback time node; If f i < F1, generate a secondary correction strategy for the i-th plugin at the current feedback time node; Generate a secondary correction instruction for the current feedback time node according to all secondary correction strategies.

[0015] In some embodiments of the present application, determining whether to generate a correction instruction for the device protocol library and the plugin library further includes: Obtain all first-level plugins at the current feedback time node; Establish a first-level plugin sequence A1, A1 = (a 11 , a 12 ... a 1i ... a 1n3 ), where a 1i is the i-th first-level plugin at the current feedback time node; n3 is the number of first-level plugins; Set a i as the target first-level plugin in sequence according to the first-level plugin sequence A1; Generate a new sub-protocol according to the running parameters of the target first-level plugin; Generate new sub-protocols corresponding to each first-level plugin in sequence; Generate an update instruction for the device protocol library according to all new sub-protocols.

[0016] In some embodiments of the present application, generating a call evaluation value f for the plugin to be monitored according to the feedback data packet includes: f=e3*Q3*[ η 2i *g i ]+e4*Q4*[ V(i)*(s i -s')]; Among them, e3 is the preset third weight coefficient; e4 is the preset fourth weight coefficient; Q3 is the preset third fixed coefficient; Q4 is the preset fourth fixed coefficient; r2 is the number of plug-in call indicators; η 2i is the impact factor of the i-th plug-in call indicator; g i Generate a reference value for the i-th plug-in call indicator based on the feedback data packet of the plug-in to be monitored; x is the number of calls of the plug-in to be monitored in the time interval between the last feedback time node and the current feedback time node; s i is the plug-in running value of the i-th call; s' is the plug-in running value threshold; V(i) is the selection coefficient; if (s i -s')>0,V(i)=1; if (s i -s')<0,V(i)=0.

[0017] Compared with the prior art, the intelligent access method for multiple network security devices in the embodiment of the present application has the following beneficial effects: The device to be connected traverses all the connection sub-protocols in the device protocol library for automatic adaptation, and realizes fast access to the device to be connected by calling the corresponding connection sub-protocol. If there is no adaptation protocol, the corresponding plug-in unified policy description language is called to expand the access protocol without recompiling the entire program code, thereby improving the connection efficiency of network security devices.

[0018] By periodically evaluating the calling status of each connection sub-protocol and each plug-in, performing security vulnerability scanning and penetration testing, timely discovering and fixing potential security risks, and optimizing the performance of each plug-in, the connection management efficiency of network security devices is improved, ensuring the secure connection of each network security device. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 It is a flow chart of a method for intelligent access of multiple network security devices in a preferred embodiment of the present application. DETAILED DESCRIPTION

[0020] The specific implementation methods of the present application are further described in detail below in conjunction with the accompanying drawings and examples. The following examples are used to illustrate the present application but are not intended to limit the scope of the present application.

[0021] In the description of the present application, it should be understood that the terms "center", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", etc., indicating orientations or positional relationships, are based on the orientations or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be understood as a limitation on the present application.

[0022] The terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of this application, unless otherwise specified, "plurality" means two or more.

[0023] In the description of this application, it should be noted that, unless otherwise clearly specified and limited, the terms "installed", "connected", and "connected" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection, or it can be indirectly connected through an intermediate medium, or it can be the internal communication of two components. For ordinary technicians in this field, the specific meanings of the above terms in this application can be understood according to specific circumstances.

[0024] like Figure 1 As shown, a method for intelligent access to a multi-network security device according to a preferred embodiment of the present application includes: S101: Establishing a device protocol library and a plug-in library based on historical parameters; S102: Acquire identity data packets of all devices to be connected, and set a connection mode of each device to be connected according to all identity data packets; S103: Determine whether to generate correction instructions for the device protocol library and the plug-in library according to the preset feedback time node; Among them, establishing the device protocol library and plug-in library includes: Create a plug-in array A, A=(a1, a2…a i …a n1 ), where a i is the i-th plug-in; n1 is the number of plug-ins; Establish a connection sub-protocol sequence B, B = (b1, b2…b i …b n2 ), where b i is the i-th connection subprotocol; n2 is the number of connection subprotocols.

[0025] Specifically, by traversing the historical network security devices connected to the network, multiple device categories are established, and the operation characteristics of each device category are integrated with protocols such as API, syslog, and SNMP in the network management protocol library, so as to construct the connection sub-protocols corresponding to each device category. The connection sub-protocols include protocols such as API, syslog, and SNMP and data security filtering policies set for the current device category, thus ensuring the connection efficiency and security of each network security device.

[0026] Specifically, by traversing the historical network security devices connected to the network, multiple plugins are established. Different plugins correspond to different device categories. Through the plugins, the access protocols can be extended, so that the devices to be connected that cannot adapt to the device protocol library can access the network without recompiling the entire program code, improving the connection management efficiency of the network security devices.

[0027] Specifically, when setting the connection modes of the devices to be connected, it includes: Establish a sequence of devices to be connected P, P = (p1, p2…p i …p m ), where p i is the i-th device to be connected; m is the number of devices to be connected; Set p i as the target device to be connected in sequence according to the sequence of devices to be connected P; Obtain the identity data packet of the target device to be connected, and generate the first-level adaptation value of the target device to be connected and each connection sub-protocol; Establish a sequence of first-level adaptation values C1, C1 = (c 11 , c 12 …c 1i …c 1n2 ), where c 1i is the first-level adaptation value of the target device to be connected and the i-th connection sub-protocol; Select the maximum value c 1max in the sequence of first-level adaptation values C1; Preset the first-level adaptation value threshold W1; If c 1max > C1, set the target device to be connected as the first-level connection mode; If c 1max < C1, set the target device to be connected as the second-level connection mode; Among them, the first-level connection mode includes: Set the connection sub-protocol corresponding to the maximum value c 1max as the sub-protocol to be called; Access the target sub-device to be connected through the sub-protocol to be called.

[0028] Specifically, the devices to be connected include but are not limited to firewalls, switches, routers, etc., and a sequence of devices to be connected is established by traversing all devices to be connected.

[0029] Specifically, the higher the first-level adaptation value is, the higher the adaptability between the corresponding connection sub-protocol and the device to be connected is, and the device to be connected can be connected to the network by calling the connection sub-protocol.

[0030] Specifically, the first-level adaptation value threshold can be set according to historical parameters. If the maximum value c1max is less than the first-level adaptation value threshold, it means that the current device to be connected cannot be automatically adapted to the device protocol library. At this time, the device to be connected is connected to the network by calling the plug-in.

[0031] Specifically, the first-level connection mode refers to the automatic adaptation of the connection protocol in the device protocol library. The second-level connection mode refers to the automatic adaptation of the device access specification by calling the plug-in and pre-defining the interface specification.

[0032] Specifically, by obtaining the identity data packet of the target device to be connected, the IP address, MAC address, version and other parameters of the target device to be connected are obtained.

[0033] Specifically, a first-level adaptation value sequence C1 is established, including: According to the connection sub-protocol sequence B, set bi as the target connection sub-protocol in sequence; Generate a first-level adaptation value c1 between the target device to be connected and the target connection subprotocol; c1=U1*[ β 1i *(j i -j' i ) 2 ]; in, Number of device identity indicators; β 1i is the influencing factor of the i-th device identity indicator; j i is the reference value of the ith device identity indicator generated based on the identity data packet of the target device to be connected; j' i is the standard reference value of the ith device identity indicator in the target connection sub-protocol; U1 conversion coefficient; Generate the first-level adaptation value of each connection sub-protocol and the target device to be connected in turn.

[0034] Specifically, the device identity indicators include but are not limited to parameters such as IP address, MAC address, version, etc. The device identity indicators of different device categories are quantified by traversing historical parameters, thereby generating reference values ​​for each corresponding device identity indicator of the target device to be connected.

[0035] Specifically, by setting the conversion coefficient U1, the higher the primary adaptation value is, the higher the adaptability between the corresponding connection sub-protocol and the device to be connected is.

[0036] In a preferred embodiment of the present application, the secondary connection mode includes: Generate secondary adaptation values ​​for each plug-in according to the identity data packet of the target device to be connected; Establish the secondary adaptation value sequence C2, C2=(c 21 , c 22 …c 2i …c 2n1 ), where c 2i is the secondary adaptation value between the target device to be connected and the i-th plug-in; Set the maximum value c in the secondary adaptation value sequence C2 2max The corresponding plug-in is the plug-in to be called; Access the target device to be connected through the plug-in to be called.

[0037] Specifically, a secondary adaptation value sequence C2 is established, including: Set a in sequence according to the plug-in sequence A i For the target plugin; Generate a secondary adaptation value c2 between the target device to be connected and the target plug-in; c2=U2*[ β 2i *(k i -k' i ) 2 ]; in, is the number of plug-in indicators; β 2i is the impact factor of the i-th plug-in indicator; k i k' is the reference value of the i-th plug-in indicator generated based on the identity data packet of the target device to be connected; i is the standard reference value of the i-th plug-in indicator in the target plug-in; U2 is the conversion coefficient; Generate the secondary adaptation value of the target device to be established and each plug-in in turn.

[0038] Specifically, by setting the conversion coefficient U2, the larger the secondary adaptation value is, the higher the adaptability between the target device to be connected and the target plug-in is.

[0039] Specifically, by calling plug-ins, the policy description language is unified, and the access protocol is extended without recompiling the entire program code, thereby improving the connection efficiency of network security devices.

[0040] Specifically, the plug-in includes programs such as device data language conversion strategy and device data filtering strategy.

[0041] Specifically, the plug-in metrics include, but are not limited to, multiple parameters such as device data types, device categories, device identity tags, etc.

[0042] In the preferred embodiment of the present application, determining whether to generate a correction instruction for the device protocol library and the plug-in library includes: Set b in sequence according to the connection sub-protocol sequence B i As the sub-protocol to be monitored; Obtain the monitoring data packet of the sub-protocol to be monitored at the current feedback time node; Generate the operation evaluation value d of the sub-protocol to be monitored; Generate the operation evaluation values of each connection sub-protocol at the current feedback time node in sequence; Establish the operation evaluation value sequence D at the current feedback time node, D = (d1, d2... d i …d n2 ), where d i Is the operation evaluation value of the i-th sub-protocol to be monitored at the current feedback time node; Preset the first operation evaluation value threshold D1; If d i < D1, generate the first-level correction strategy for the i-th connection sub-protocol at the current feedback time node; If d i > D1, do not correct the i-th connection sub-protocol at the current feedback time node; Obtain all the first-level correction strategies at the current feedback time node, and generate the first-level correction instruction at the current feedback time node according to all the first-level correction strategies.

[0043] Specifically, the larger the operation evaluation value, the smaller the possibility of operation risks of the network security device accessing the network through the sub-protocol to be monitored, and the higher its overall operation security.

[0044] Specifically, the first-level correction strategy refers to analyzing all device parameters connected through the sub-protocol to be monitored during the time interval between the previous feedback time node and the current feedback time node, so as to generate an optimization strategy for the sub-protocol to be monitored, and improve the adaptability and connection efficiency between the sub-protocol to be monitored and the corresponding type of device.

[0045] Specifically, generate the optimization strategies for each connection sub-protocol through the first-level correction strategy.

[0046] Specifically, by periodically monitoring the call status of each sub-protocol to be monitored, performing security vulnerability scanning and penetration testing, timely discovering and fixing potential security risks, ensuring the safe operation of the network, and improving the management efficiency of each network security device.

[0047] Specifically, generating the operation evaluation value d of the sub-protocol to be monitored includes: d=e1*Q1*[ η 1i *t i ]+e2*Q2*[ Y(i)*(h i -h')]; Wherein, e1 is the preset first weight coefficient; e2 is the preset second weight coefficient; Q1 is the preset first fixed coefficient; Q2 is the preset second fixed coefficient; r1 is the number of protocol call indicators; η 1i is the influencing factor of the i-th protocol call index; t i is the reference value of the monitoring data packet of the monitored sub-protocol to generate the i-th protocol call index; w is the number of calls of the monitored sub-protocol in the time interval between the last feedback time node and the current feedback time node; h i is the risk value of the i-th call; h' is the call risk value threshold; Y(i) is the selection coefficient; if (h i -h')>0;Y(i)=1;(h i -h')<0;Y(i)=0.

[0048] Specifically, the protocol call indicators include, but are not limited to, the protocol call volume, call frequency, the probability of operational risks in connected devices and other parameters. The larger the call risk value, the greater the operational risk of the security device that currently calls the monitored sub-protocol to connect to the network system, and the higher the possibility of security vulnerabilities.

[0049] Specifically, all parameters in the model are normalized by presetting the first fixed coefficient and the second fixed coefficient, so that each parameter in the model is within the same value range.

[0050] In a preferred embodiment of the present application, the correction instruction for determining whether to generate a device protocol library and a plug-in library further includes: Set a in sequence according to the plug-in sequence A i The plugin to be monitored; Obtain the feedback data packet of the plug-in to be monitored at the current feedback time node; Generate a call evaluation value f of the plug-in to be monitored according to the feedback data packet; Generate the call evaluation value of each plug-in in turn; Establish a call evaluation value sequence F, F=(f1, f2…f i …f n1 ), where f i is the call evaluation value of the i-th plug-in at the current feedback time node; A first call evaluation value threshold F1 and a second call evaluation value threshold F2 are preset, and F1 <F2; If f i > F2, set the i-th plugin as a first-level plugin; If F1 < f i < F2, do not correct the i-th plugin at the current feedback time node; If f i < F1, generate a second-level correction strategy for the i-th plugin at the current feedback time node; Generate a second-level correction instruction at the current feedback time node according to all the second-level correction strategies.

[0051] Specifically, the second-level correction strategy means that the lower the efficiency of the current plugin in device recognition and data standardization, the internal parameters of the plugin need to be optimized in a timely manner to improve its efficiency in device recognition and data standardization.

[0052] Specifically, by optimizing the performance of each plugin, the connection management efficiency for network security devices is improved, and the secure connection of each network security device is ensured.

[0053] Specifically, determining whether to generate correction instructions for the device protocol library and the plugin library also includes: Obtain all the first-level plugins at the current feedback time node; Establish a first-level plugin sequence A1, A1 = (a 11 , a 12 … a 1i … a 1n3 ), where a 1i is the i-th first-level plugin at the current feedback time node; n3 is the number of first-level plugins; Set a i as the target first-level plugin in sequence according to the first-level plugin sequence A1; Generate a new sub-protocol according to the operating parameters of the target first-level plugin; Generate the new sub-protocols corresponding to each first-level plugin in sequence; Generate an update instruction for the device protocol library according to all the new sub-protocols.

[0054] Specifically, by periodically evaluating each plugin, processing the frequently called plugins, generating new connection sub-protocols, continuously updating the device protocol library, improving the connection management efficiency for network security devices, and ensuring the secure connection of each network security device Specifically, generating a call evaluation value f for the plugin to be monitored according to the feedback data packet includes: f = e3 * Q3 * η 2i * g i + e4 * Q4 * V(i) * (s i-s')]; Among them, e3 is the preset third weight coefficient; e4 is the preset fourth weight coefficient; Q3 is the preset third fixed coefficient; Q4 is the preset fourth fixed coefficient; r2 is the number of plug-in call indicators; η 2i is the impact factor of the i-th plug-in call indicator; g i Generate a reference value for the i-th plug-in call indicator based on the feedback data packet of the plug-in to be monitored; x is the number of calls of the plug-in to be monitored in the time interval between the last feedback time node and the current feedback time node; s i is the plug-in running value of the i-th call; s' is the plug-in running value threshold; V(i) is the selection coefficient; if (s i -s')>0,V(i)=1; if (s i -s')<0,V(i)=0.

[0055] Specifically, all parameters in the model are normalized by presetting the third fixed coefficient and the fourth fixed coefficient, so that each parameter is within the same value range.

[0056] Specifically, the higher the call evaluation value, the higher the calling frequency of the current plug-in and the higher the security during operation.

[0057] According to the first concept of the present application, the device to be connected traverses all the connection sub-protocols in the device protocol library for automatic adaptation, and realizes fast access of the device to be connected by calling the corresponding connection sub-protocol. If there is no adaptation protocol, the corresponding plug-in unified policy description language is called to extend the access protocol without recompiling the entire program code, thereby improving the connection efficiency of the network security device.

[0058] According to the second concept of the present application, by periodically evaluating the calling status of each connection sub-protocol and each plug-in, performing security vulnerability scanning and penetration testing, timely discovering and repairing potential security risks, and performing performance tuning on each plug-in, the connection management efficiency of network security devices is improved, thereby ensuring the secure connection of each network security device.

[0059] The above is only a preferred implementation of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and substitutions can be made without departing from the technical principles of the present application. These improvements and substitutions should also be regarded as the scope of protection of the present application.

Claims

1. A method for intelligent access to multiple network security devices, characterized in that: include: Establish device protocol library and plug-in library based on historical parameters; Obtaining identity data packets of all devices to be connected, and setting a connection mode for each device to be connected according to all identity data packets; Determine whether to generate correction instructions for the device protocol library and the plug-in library according to the preset feedback time node; Among them, establishing the device protocol library and plug-in library includes: Create a plug-in array A, A=(a1, a2…a i …a n1 ), where a i is the i-th plug-in; n1 is the number of plug-ins; Establish a connection sub-protocol sequence B, B = (b1, b2…b i …b n2 ), where b i is the i-th connection subprotocol; n2 is the number of connection subprotocols.

2. The intelligent access method for multiple network security devices according to claim 1, characterized in that: When setting the connection mode of each device to be connected, include: Establish a sequence of devices to be connected, P = (p1, p2…p i …p m ), where p i is the i-th device to be connected; m is the number of devices to be connected; Set p in sequence according to the number of devices to be connected P i The target device to be connected; Obtaining the identity data packet of the target device to be connected, and generating the first-level adaptation value between the target device to be connected and each connection sub-protocol; Establish the first-level adaptation value sequence C1, C1=(c 11 , c 12 …c 1i …c 1n2 ), where c 1i is the first-level adaptation value between the target device to be connected and the i-th connection subprotocol; Select the maximum value c in the first-level adaptation value sequence C1 1max ; Preset first-level adaptation value threshold W1; If c 1max >C1, set the target device to be connected to the first-level connection mode; If c 1max <C1, set the target device to be connected to the secondary connection mode; Among them, the first-level connection mode includes: Set the maximum value c 1max The corresponding connection sub-protocol is the sub-protocol to be called; Access the target sub-device to be accessed through the sub-protocol to be called.

3. The intelligent access method for multiple network security devices as claimed in claim 2, characterized in that: Establish a first-level adaptation value sequence C1, including: According to the connection sub-protocol sequence B, set bi as the target connection sub-protocol in sequence; Generate a first-level adaptation value c1 between the target device to be connected and the target connection subprotocol; c1=U1*[ β 1i *(j i -j' i ) 2 ]; in, Number of device identity indicators; β 1i is the influencing factor of the i-th device identity indicator; j i is the reference value of the ith device identity indicator generated based on the identity data packet of the target device to be connected; j' i is the standard reference value of the ith device identity indicator in the target connection sub-protocol; U1 conversion coefficient; Generate the first-level adaptation value of each connection sub-protocol and the target device to be connected in turn.

4. The intelligent access method for multiple network security devices according to claim 2, characterized in that: The secondary connection mode includes: Generate secondary adaptation values ​​for each plug-in according to the identity data packet of the target device to be connected; Establish the secondary adaptation value sequence C2, C2=(c 21 , c 22 …c 2i …c 2n1 ), where c 2i is the secondary adaptation value between the target device to be connected and the i-th plug-in; Set the maximum value c in the secondary adaptation value sequence C2 2max The corresponding plug-in is the plug-in to be called; Access the target device to be connected through the plug-in to be called.

5. The intelligent access method for multiple network security devices as claimed in claim 4, characterized in that: Establish a secondary adaptation value sequence C2, including: Set a in sequence according to the plug-in sequence A i For the target plugin; Generate a secondary adaptation value c2 between the target device to be connected and the target plug-in; c2=U2*[ β 2i *(k i -k' i ) 2 ]; in, is the number of plug-in indicators; β 2i is the impact factor of the i-th plug-in indicator; k i k' is the reference value of the i-th plug-in indicator generated based on the identity data packet of the target device to be connected; i is the standard reference value of the i-th plug-in indicator in the target plug-in; U2 is the conversion coefficient; Generate the secondary adaptation value of the target device to be established and each plug-in in turn.

6. The intelligent access method for multiple network security devices according to claim 4, characterized in that: Determine whether to generate correction instructions for the device protocol library and plug-in library, including: Set b in sequence according to the connection sub-protocol sequence B i is the sub-protocol to be monitored; Obtain the monitoring data packet of the sub-protocol to be monitored at the current feedback time node; Generate the operation evaluation value d of the sub-protocol to be monitored; Generate the operation evaluation value of each connection sub-protocol at the current feedback time node in sequence; Establish the operation evaluation value sequence D of the current feedback time node, D=(d1, d2…d i …d n2 ), where d i is the running evaluation value of the i-th sub-protocol to be monitored at the current feedback time node; Preset the first operation evaluation value threshold D1; If d i <D1, generate the first-level correction strategy for the i-th connection sub-protocol at the current feedback time node; If d i >D1, the current feedback time node does not modify the i-th connection sub-protocol; Obtain all first-level correction strategies for the current feedback time node, and generate first-level correction instructions for the current feedback time node based on all first-level correction strategies.

7. The intelligent access method for multiple network security devices according to claim 6, characterized in that: Generate the operation evaluation value d of the sub-protocol to be monitored, including: d=e1*Q1*[ η 1i *t i ]+e2*Q2*[ Y(i)*(h i -h')]; Wherein, e1 is the preset first weight coefficient; e2 is the preset second weight coefficient; Q1 is the preset first fixed coefficient; Q2 is the preset second fixed coefficient; r1 is the number of protocol call indicators; η 1i is the influencing factor of the i-th protocol call index; t i is the reference value of the monitoring data packet of the monitored sub-protocol to generate the i-th protocol call index; w is the number of calls of the monitored sub-protocol in the time interval between the last feedback time node and the current feedback time node; h i is the risk value of the i-th call; h' is the call risk value threshold; Y(i) is the selection coefficient; if (h i -h')>0;Y(i)=1;(h i -h')<0;Y(i)=0.

8. The intelligent access method for multiple network security devices according to claim 6, characterized in that: The correction instructions for determining whether to generate the device protocol library and the plug-in library also include: Set a in sequence according to the plug-in sequence A i The plugin to be monitored; Obtain the feedback data packet of the plug-in to be monitored at the current feedback time node; Generate a call evaluation value f of the plug-in to be monitored according to the feedback data packet; Generate the call evaluation value of each plug-in in turn; Establish a call evaluation value sequence F, F=(f1, f2…f i …f n1 ), where f i is the call evaluation value of the i-th plug-in at the current feedback time node; A first call evaluation value threshold F1 and a second call evaluation value threshold F2 are preset, and F1 <F2; If f i >F2, set the i-th plug-in as a first-level plug-in; If F1 < f i <F2, do not correct the i-th plug-in at the current feedback time node; If f i <F1, generate the secondary correction strategy of the i-th plugin at the current feedback time node; Generate the secondary correction instruction for the current feedback time node based on all secondary correction strategies.

9. The intelligent access method for multiple network security devices according to claim 8, characterized in that: The correction instructions for determining whether to generate the device protocol library and the plug-in library also include: Get all first-level plug-ins of the current feedback time node; Create a first-level plug-in array A1, A1=(a 11 ,a 12 …a 1i …a 1n3 ), where a 1i is the i-th first-level plug-in at the current feedback time node; n3 is the number of first-level plug-ins; According to the first-level plug-in sequence A1, set a i It is the target level one plugin; Generate a new sub-protocol based on the operating parameters of the target first-level plug-in; Generate new sub-protocols corresponding to each first-level plug-in in turn; Generate update instructions for the device protocol library based on all newly added sub-protocols.

10. The intelligent access method for multiple network security devices according to claim 9, characterized in that: Generate the call evaluation value f of the plug-in to be monitored according to the feedback data packet, including: f=e3*Q3*[ η 2i *g i ]+e4*Q4*[ V(i)*(s i -s')]; Among them, e3 is the preset third weight coefficient; e4 is the preset fourth weight coefficient; Q3 is the preset third fixed coefficient; Q4 is the preset fourth fixed coefficient; r2 is the number of plug-in call indicators; η 2i is the impact factor of the i-th plug-in call indicator; g i Generate a reference value for the i-th plug-in call indicator based on the feedback data packet of the plug-in to be monitored; x is the number of calls of the plug-in to be monitored in the time interval between the last feedback time node and the current feedback time node; s i is the plug-in running value of the i-th call; s' is the plug-in running value threshold; V(i) is the selection coefficient; if (s i -s')>0,V(i)=1; if (s i -s')<0,V(i)=0.