Processing method and processing device for interconnection and intercommunication of network security products
By building a data acquisition interface and disposal control interface cluster for network security products and realizing interface mapping relationships, the interconnection problems caused by the independence of security products in the prior art are solved, and the ability to efficiently cooperate security products and quickly respond to network threats is achieved.
Patent Information
- Application Number
- CN202510172758.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-05-16
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The interfaces of existing network security products are independent and lack universality, making it difficult to achieve efficient interconnection between multiple security products, resulting in delays in information processing and the goal of integrated security protection.
By encapsulating the data acquisition interface and processing control interface of multiple security products, a data acquisition interface cluster and processing control interface cluster are built, and the call and control of the target security products are achieved through the mapping relationship of the interface.
It realizes efficient collaboration of multiple security products, reduces security vulnerabilities and blind spots, improves the interconnection capabilities of network security products, can share information faster and respond to network threats, and improves the timeliness of security protection.
Smart Images

Figure CN120017377A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a method and device for processing interconnection and intercommunication of network security products. Background Art
[0002] With the continuous advancement of network technology, network security threats are increasing, and various network security products have emerged. These network security products are usually developed by different manufacturers and use a variety of technologies and interfaces.
[0003] At present, the interfaces provided by various security product manufacturers are relatively independent, covering multiple standards such as WebAPI, Kafka, Syslog, etc. However, each interface has its own specific limitations and lacks universality, making it difficult to meet the needs of interconnection between multiple security products. This not only causes information processing delays, but also hinders the process of achieving the goal of comprehensive security protection integration. Summary of the invention
[0004] In view of this, the purpose of this application is to provide a processing method and processing device for interconnection of network security products, which realizes the calling and control of target security products through the mapping relationship between security products and interfaces in the interface cluster, ensures that all security products can collaborate efficiently, reduces security vulnerabilities and blind spots, and thus more effectively resists network attacks. By building an interface cluster, it is possible to quickly connect different security products and widely call various interfaces, achieve an out-of-the-box effect, realize efficient interconnection of network security products, share information and respond to network threats faster, and improve the timeliness of security protection.
[0005] In a first aspect, an embodiment of the present application provides a method for processing interconnection and interoperability of network security products, the method comprising:
[0006] Encapsulating data acquisition interfaces of a plurality of safety products to construct a data acquisition interface cluster, and encapsulating disposal control interfaces of a plurality of the safety products to construct a disposal control interface cluster;
[0007] Acquire information data of each safety product through the data acquisition interface cluster, and generate a mapping relationship between each safety product and each disposal control interface in the disposal control interface cluster based on the information data of each safety product; wherein the information data includes safety product information and interface information;
[0008] A control instruction is sent to the disposal control interface cluster so that the disposal control interface cluster determines a target safety product from the multiple safety products based on the control instruction and determines a target disposal control interface corresponding to the target safety product based on the mapping relationship, so as to control the target safety product by sending the control instruction to the target safety product through the target disposal control interface.
[0009] Furthermore, the processing method also includes:
[0010] The blacklist control information of each security product is obtained, and the first specific operation is encapsulated based on the blacklist control information to generate a blacklist control interface for the plurality of security products.
[0011] Furthermore, the processing method also includes:
[0012] The security policy control information of each security product is obtained, and the second specific operation is encapsulated based on the security policy control information to generate a security policy control interface for the plurality of security products.
[0013] Furthermore, the information data also includes data field information. After acquiring the information data of each safety product through the data acquisition interface cluster, the processing method further includes:
[0014] For each data field information of each security product, the data field information is matched with the metadata field of the data acquisition interface cluster. If the match fails, the data field information is normalized based on the field conversion mapping table to obtain the converted data field information;
[0015] The original product field information table is updated based on the converted data field information to obtain a target product field information table.
[0016] Furthermore, after obtaining the target product field information table, the processing method further includes:
[0017] When a data operation instruction is received, target field data is determined from the target product field information table based on the data operation instruction, and the target field data is updated based on the data operation instruction.
[0018] Furthermore, after obtaining the target product field information table, the processing method further includes:
[0019] The target product field information table is dispersed into various data tables in the data acquisition interface cluster for distributed storage.
[0020] In a second aspect, an embodiment of the present application further provides a processing device for interconnecting network security products, the processing device comprising:
[0021] An interface cluster building module, used to encapsulate the data acquisition interfaces of multiple security products to build a data acquisition interface cluster, and to encapsulate the disposal control interfaces of multiple security products to build a disposal control interface cluster;
[0022] A mapping relationship generating module, used to obtain information data of each safety product through the data acquisition interface cluster, and generate a mapping relationship between each safety product and each disposal control interface in the disposal control interface cluster based on the information data of each safety product; wherein the information data includes safety product information and interface information;
[0023] A control module is used to send a control instruction to the disposal control interface cluster, so that the disposal control interface cluster determines a target safety product from a plurality of the safety products based on the control instruction and determines a target disposal control interface corresponding to the target safety product based on the mapping relationship, so as to control the target safety product by sending the control instruction to the target safety product through the target disposal control interface.
[0024] Furthermore, the processing device further includes a first interface generating module, and the first interface generating module is used to:
[0025] The blacklist control information of each security product is obtained, and the first specific operation is encapsulated based on the blacklist control information to generate a blacklist control interface for the plurality of security products.
[0026] In the third aspect, an embodiment of the present application also provides an electronic device, comprising: a processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the memory communicate through the bus, and when the machine-readable instructions are executed by the processor, the steps of the processing method for interconnection and interoperability of network security products as described above are performed.
[0027] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the processing method for interconnection and interoperability of network security products as described above are executed.
[0028] An embodiment of the present application provides a processing method and a processing device for interconnection and interoperability of network security products. First, data acquisition interfaces of multiple security products are encapsulated to construct a data acquisition interface cluster, and disposal control interfaces of multiple security products are encapsulated to construct a disposal control interface cluster; then, information data of each security product is obtained through the data acquisition interface cluster, and a mapping relationship between each security product and each disposal control interface in the disposal control interface cluster is generated based on the information data of each security product; wherein the information data includes security product information and interface information; finally, a control instruction is sent to the disposal control interface cluster, so that the disposal control interface cluster determines a target security product from the multiple security products based on the control instruction and determines a target disposal control interface corresponding to the target security product based on the mapping relationship, so as to send the control instruction to the target security product through the target disposal control interface to control the target security product.
[0029] This application encapsulates the data acquisition interfaces and disposal control interfaces of multiple security products to form a data acquisition interface cluster and a disposal control interface cluster, and realizes the call and control of the target security product through the mapping relationship between the security product and the interface in the interface cluster, ensuring that all security products can collaborate efficiently, reduce security vulnerabilities and blind spots, and thus more effectively resist network attacks. And through interface clusters and automated processing, the workload of security operation and maintenance personnel is also reduced, and management complexity and costs are reduced. By building an interface cluster, rapid docking of different security products and extensive calls to various interfaces can be achieved, achieving an out-of-the-box effect, realizing efficient interconnection of network security products, being able to share information and respond to network threats faster, and improving the timeliness of security protection.
[0030] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, preferred embodiments are specifically cited below and described in detail with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0032] Figure 1 A flowchart of a method for processing interconnection and intercommunication of network security products provided in an embodiment of the present application;
[0033] Figure 2One of the structural schematic diagrams of a processing device for interconnecting network security products provided in an embodiment of the present application;
[0034] Figure 3 A second structural diagram of a processing device for interconnecting network security products provided in an embodiment of the present application;
[0035] Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0036] To make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application usually described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, each other embodiment obtained by those skilled in the art without making creative work belongs to the scope of protection of the present application.
[0037] First, the application scenarios to which the present application is applicable are introduced. The present application can be applied in the field of network security technology.
[0038] With the continuous advancement of network technology, network security threats are increasing, and various network security products have emerged. These network security products are usually developed by different manufacturers and use a variety of technologies and interfaces.
[0039] According to research, the interfaces provided by various security product vendors are relatively independent, covering multiple standards such as WebAPI, Kafka, and Syslog. However, each interface has its own specific limitations and lacks universality, making it difficult to meet the needs of interconnection between multiple security products. This not only causes information processing delays, but also hinders the process of achieving the goal of comprehensive security protection integration.
[0040] Based on this, the embodiments of the present application provide a processing method and a processing device for the interconnection and interoperability of network security products, which realize efficient interconnection and interoperability of network security products, can share information and respond to network threats more quickly, and improve the timeliness of security protection.
[0041] See also Figure 1 , Figure 1 A flowchart of a method for processing interconnection and intercommunication of network security products provided in an embodiment of the present application. Figure 1As shown in , the processing method provided in the embodiment of the present application includes:
[0042] S101 , encapsulating data acquisition interfaces of a plurality of security products to construct a data acquisition interface cluster, and encapsulating handling control interfaces of a plurality of the security products to construct a handling control interface cluster.
[0043] Here, according to the embodiment provided by the present application, the interface cluster is divided into a data acquisition interface cluster and a disposal control interface cluster in terms of attributes. Specifically, the data acquisition interface cluster supports security products to use a unified interface to transmit data and automatically dispose. The disposal control interface cluster supports the encapsulation of disposal product interfaces, meeting the out-of-the-box use of disposal security products.
[0044] In the specific implementation of step S101, the data acquisition interfaces of multiple security products are encapsulated using common interface technology to construct a data acquisition interface cluster. The disposal control interfaces of multiple security products are encapsulated using common interface technology to construct a disposal control interface cluster.
[0045] Specifically, for the encapsulation of the data acquisition interface, it is first necessary to define a unified data acquisition interface specification for collecting information data of each security product. Then, according to different security products, write corresponding adapters, which are responsible for calling the specific data acquisition interface of each security product. Finally, integrate all adapters together to form a data acquisition interface cluster, and provide a unified data acquisition interface to the outside world. For the encapsulation of the disposal control interface, first define a unified disposal control interface specification for receiving various disposal instructions. Then write corresponding adapters for each security product. These adapters are responsible for calling the specific disposal control interface of each security product. Finally, integrate all adapters together to form a disposal control interface cluster, and provide a unified disposal control interface to the outside world.
[0046] According to the embodiment provided by the present application, the automatic disposal strategy of the data acquisition interface cluster includes the following functions: testing whether the blocker interface is connected: fwLink(); getting a group: fwGetGroup(); adding a group: fwAddGroup(); deleting a group: fwDeleteGroup(); adding a blacklist: fwAddBlackList(); deleting a blacklist: fwDeleteBlackList(); getting a blacklist or a hit count: fwGetBlackList(); testing whether the blocker interface is connected: fwLink(); getting an address object: fwGetAddrObject(); adding an address object: fwAddAddrObject(); modifying an address object: fw UpdateAddrObject(); delete address object: fwDeleteAddrObject(); get service object: fwGetServicesObject(); add service object: fwAddServicesObject(); modify service object: fwUpdateServicesObject(); delete service object: fwDeleteServicesObject(); get time object: fwGetTimeObject(); add time object: fwAddTimeObject(); modify time object: fwUpdateTimeObject(); delete time object: fwDeleteTimeObjec t(); get security policy: fwGetSecruityPolicy(); add security policy: fwAddSecruity Policy(); modify security policy: fwUpdateSecuityPolicy(); delete package security policy: fwDeleteSecruityPolicy(); delete address from disposal table: fwDeleteAddr().
[0047] S102, acquiring information data of each safety product through the data acquisition interface cluster, and generating a mapping relationship between each safety product and each disposal control interface in the disposal control interface cluster based on the information data of each safety product.
[0048] Here, the information data includes security product information and interface information. Specifically, the security product information includes basic information of the security product, product ID and authorization information, etc., and the interface information includes service type, transmission protocol, action command and interface ID, etc.
[0049] For the above step S102, in the specific implementation, first use a unified data acquisition interface cluster to send a data acquisition request to each security product to obtain its information data. Then, the information data of each security product is obtained through the data acquisition interface cluster. Here, the data acquisition interface supports multiple transmission protocols for security products, including: Syslog, files, Kafka, WebAPI and other methods. Then parse the information data obtained from each security product to extract the required security product information and interface information. Based on the parsed information data, establish a mapping relationship between each security product and its corresponding disposal control interface. For example, for a certain security product, determine its corresponding disposal control interface from the disposal control interface cluster based on the security product information and interface information corresponding to the security product. In this way, the security product is automatically paired to the corresponding interface cluster for processing, and the security product information is bound to the interface information in the disposal control interface cluster to reduce the number of repeated adaptations.
[0050] Furthermore, the data collection interface cluster also supports the collection of various business type data of security products. The business type data here may include: log analysis data, traffic analysis data, threat detection data and disposal data, etc., which is not specifically limited in this application.
[0051] S103, sending a control instruction to the disposal control interface cluster, so that the disposal control interface cluster determines a target safety product from the multiple safety products based on the control instruction and determines a target disposal control interface corresponding to the target safety product based on the mapping relationship, so as to control the target safety product by sending the control instruction to the target safety product through the target disposal control interface.
[0052] For the above step S103, in the specific implementation, firstly, a control instruction is constructed according to the security product to be controlled and the function to be implemented, and then the control instruction is sent to the disposal control interface cluster. After the disposal control interface cluster receives the control instruction, the cluster will first parse the control instruction, determine the target security product that currently needs to execute the instruction from multiple security products, and then find the target disposal control interface corresponding to the target security product according to the previously established mapping relationship, so as to send the control instruction to the target security product through the target disposal control interface, and the target security product can perform corresponding processing according to the received control instruction. In this way, the control of multiple security products can be realized through the disposal control interface cluster, and the intercommunication of multiple security products is realized, ensuring that all security products can collaborate efficiently, reducing security vulnerabilities and blind spots, and thus more effectively resisting network attacks.
[0053] As an example, the control instructions may include blacklist disposal instructions, packet filtering disposal instructions, and SNMP command execution instructions, etc., which are not specifically limited in this application. Blacklist disposal instructions are used to block or limit communication or access to specific objects (such as IP addresses, domain names, users, devices, etc.). Blacklists are usually used to prevent malicious behavior or unauthorized access. The IP is sent to the blacklist table of the blocker by means of commands or interfaces to achieve the purpose of disposal. Packet filtering disposal instructions are used to filter network data packets according to specific rules to determine whether to allow or block the transmission of data packets. Packet filtering is usually based on conditions such as source IP address, target IP address, port number, protocol type, etc. The IP is sent to the address object of the firewall by means of commands or interfaces, a security policy is constructed, and the address object is associated to enable and top the policy. SNMP (Simple Network Management Protocol) is a protocol for managing and monitoring network devices. SNMP command execution instructions are used to send management commands to network devices through the SNMP protocol to query device status, modify configuration, or perform specific operations. Based on SNMP service monitoring service indicators, including system information, memory, CPU, hard disk, network card, directory, online status, etc.
[0054] As an optional embodiment, the information data also includes data field information. After acquiring the information data of each safety product through the data acquisition interface cluster, the processing method further includes:
[0055] A: For each data field information of each security product, the data field information is matched with the metadata field of the data acquisition interface cluster. If the match is not successful, the data field information is normalized based on the field conversion mapping table to obtain the converted data field information.
[0056] Here, metadata fields refer to common fields used to describe and define data interfaces, data fields, security product information, and interface operations. These fields provide unified structured information for interface clusters, making them easier to parse, manage, and automate.
[0057] For the above step A, in the specific implementation, after obtaining the data field information of each security product, for each data field information of each security product, the data field information is matched with the metadata field of the data acquisition interface cluster. As an example, the matching process can be carried out in the following ways: Direct string matching: Check whether the data field name of the security product is exactly the same as the metadata field name. Regular expression matching: Use regular expressions to match similar field names. Semantic matching: Use natural language processing technology to understand the semantics of field names and match field names with the same semantics. If a data field information successfully matches the metadata field, the successfully matched data field information is marked. If a data field information fails to successfully match the metadata field, it is necessary to use the field conversion mapping table for normalization processing. The field conversion mapping table is a predefined mapping relationship table that records the mapping relationship between field names from different sources and standard metadata fields. Specifically, the unmatched data fields are searched in the field conversion mapping table, and then the unmatched data fields are converted into standard metadata fields according to the rules in the field conversion mapping table to obtain the converted data field information. These converted data field information should comply with the standard format of the metadata field.
[0058] B: Based on the converted data field information, the original product field information table is updated to obtain a target product field information table.
[0059] The product field information table is a database table used to store and manage security product interfaces, data fields, and their mapping relationships. Its main function is to provide unified metadata support for the interface cluster to ensure that data from different security products can be correctly parsed, processed, and stored. Record the interface information, data fields, and their mapping relationships of different security products.
[0060] In the specific implementation of step B, the original product field information table is updated using the converted data field information obtained in step A to obtain a new product field information table, i.e., the target product field information table. In this way, the data fields generated by the security product can be flexibly maintained according to the target product field information table.
[0061] Furthermore, after obtaining the target product field information table, the processing method further includes:
[0062] When a data operation instruction is received, target field data is determined from the target product field information table based on the data operation instruction, and the target field data is updated based on the data operation instruction.
[0063] Here, the data operation instruction generally includes a data identifier to be modified, a specific operation type, and a new value. As an example, the operation type may be addition, deletion, and modification, which is not specifically limited in this application.
[0064] For the above steps, during the specific implementation, key data fields are monitored. When data operation instructions are received, the target field data is determined from the target product field information table based on the data operation instructions, and corresponding data operation actions are performed, including adding, deleting or modifying, to update the target field data.
[0065] Furthermore, after obtaining the target product field information table, the processing method further includes:
[0066] The target product field information table is dispersed into various data tables in the data acquisition interface cluster for distributed storage.
[0067] Regarding the above steps, during the specific implementation, the target product field information table is dispersed into various data tables in the data acquisition interface cluster for distributed storage, which can reduce the problem of large data storage usage.
[0068] As an optional embodiment, the processing method provided in the present application also includes:
[0069] The blacklist control information of each security product is obtained, and the first specific operation is encapsulated based on the blacklist control information to generate a blacklist control interface for the plurality of security products.
[0070] Here, the first specific operation may include GET, INSERT and DELETE operations, wherein the GET operation is to query the blacklist, the INSERT operation is to add a new blacklist entry, and the DELETE operation is to delete a blacklist entry.
[0071] For the above steps, in the specific implementation, extract the information of blacklist control of different security products, and encapsulate GET, INSERT and DELETE operations based on the blacklist control information to generate a unified blacklist control interface for multiple security products. In this way, the blacklist of security equipment is controlled by a unified blacklist control interface, so that disposal-type security products can be used out of the box. Specifically, the Get operation is to call the security product regularly to obtain the group and blacklist IP data of the corresponding blocker, and update the local blacklist table; the Insert operation is to continuously loop through the disposal strategy association analysis strategy, obtain the data in the analysis table, if the IP has been issued, no longer process it, if it has not been issued or has expired, call the add interface of the security product to insert it into the blocker, and update the blacklist table and disposal table; the Delete operation is to continuously loop through the data in the disposal table, with the current system time (sysTime)-blocking duration (inteval) ≥ insertion (ban) time (insert_time), call the delete interface of the security product, delete the corresponding IP, and update the blacklist table and disposal table.
[0072] As an optional embodiment, the processing method provided in the present application also includes:
[0073] The security policy control information of each security product is obtained, and the second specific operation is encapsulated based on the security policy control information to generate a security policy control interface for the plurality of security products.
[0074] Here, the second specific operation may include GET, INSERT and DELETE operations, wherein the GET operation is to query the security policy list, the INSERT operation is to add a new security policy, and the DELETE operation is to delete a security policy.
[0075] For the above steps, in the specific implementation, the information of security policy control of different security products is extracted, and GET, INSERT and DELETE operations are encapsulated based on the security policy control information to generate a security policy control interface for multiple security products. In this way, a unified interface is provided for the security policy control of disposal products. Specifically, the GET operation is to periodically call the security product to obtain the security policy, address object, time object, and service object data of the corresponding security product, and update the local dp table. The INSERT operation is to continuously loop through the disposal strategy association analysis strategy, obtain the data in the analysis table, and if the IP has been issued, it will no longer be processed. If it has not been issued or has expired, the add or update interface of the security product will be called to insert it into the blocker, and the dp table and disposal table will be updated. Here, when adding or updating, it should be noted that the insertion strategy determines whether there is an address object. If it does not exist, the address object should be created first, and the address object add interface should be called. After success, the time object interface is added, and the policy add interface is called to add the policy; if the address object exists, it is necessary to determine whether the address object quantity limit has reached the maximum. If it has not reached, the update interface is called. If it has reached, the address object needs to be recreated and the policy update interface is called. The DELETE operation is to continuously loop through the data in the disposal table, and when the current system time (sysTime) - blocking duration (inteval) ≥ insertion (ban) time (insert_time), the deletion interface of the security product will be called to delete the corresponding IP, and the dp table and disposal table will be updated. Here, when deleting an address, it should be noted that if the policy has only one address object, and if the address object has only one IP, delete the policy directly, and then delete the address object; if the policy has multiple address objects, and the address object has only one IP, delete the address object and update the policy; if the policy has one or more address objects, and the address object has multiple IPs, only update the address object.
[0076] In this way, according to the above two steps, the blacklist control and security policy control of multiple security products are abstracted into a universal disposal control interface, so that disposal-type security products can be used out of the box. By abstracting the control interface of security devices and encapsulating the GET, INSERT, and DELETE operations of blacklist control and security policy control, unified control of disposal-type security products can be achieved. After extracting the universal disposal control interface cluster, users can use it out of the box without having to adapt the interface separately for each device, which significantly improves the flexibility and scalability of the system.
[0077] The processing method for interconnecting and interoperating network security products provided in the embodiment of the present application is as follows: first, data acquisition interfaces of multiple security products are encapsulated to construct a data acquisition interface cluster, and disposal control interfaces of multiple security products are encapsulated to construct a disposal control interface cluster; then, information data of each security product is obtained through the data acquisition interface cluster, and a mapping relationship between each security product and each disposal control interface in the disposal control interface cluster is generated based on the information data of each security product; wherein the information data includes security product information and interface information; finally, a control instruction is sent to the disposal control interface cluster, so that the disposal control interface cluster determines a target security product from the multiple security products based on the control instruction and determines a target disposal control interface corresponding to the target security product based on the mapping relationship, so as to control the target security product by sending the control instruction to the target security product through the target disposal control interface.
[0078] This application encapsulates the data acquisition interfaces and disposal control interfaces of multiple security products to form a data acquisition interface cluster and a disposal control interface cluster, and realizes the call and control of the target security product through the mapping relationship between the security product and the interface in the interface cluster, ensuring that all security products can collaborate efficiently, reduce security vulnerabilities and blind spots, and thus more effectively resist network attacks. And through interface clusters and automated processing, the workload of security operation and maintenance personnel is also reduced, and management complexity and costs are reduced. By building an interface cluster, rapid docking of different security products and extensive calls to various interfaces can be achieved, achieving an out-of-the-box effect, realizing efficient interconnection of network security products, being able to share information and respond to network threats faster, and improving the timeliness of security protection.
[0079] See also Figure 2 , Figure 3 , Figure 2 This is one of the structural schematic diagrams of a processing device for interconnecting network security products provided in an embodiment of the present application. Figure 3 The second structural diagram of a processing device for interconnecting network security products provided in the embodiment of the present application is shown in FIG. Figure 2 As shown in , the processing device 200 includes:
[0080] The interface cluster construction module 201 is used to encapsulate the data acquisition interfaces of multiple security products to construct a data acquisition interface cluster, and to encapsulate the disposal control interfaces of multiple security products to construct a disposal control interface cluster;
[0081] A mapping relationship generating module 202, configured to obtain information data of each safety product through the data acquisition interface cluster, and generate a mapping relationship between each safety product and each disposal control interface in the disposal control interface cluster based on the information data of each safety product; wherein the information data includes safety product information and interface information;
[0082] The control module 203 is used to send a control instruction to the disposal control interface cluster, so that the disposal control interface cluster determines the target safety product from the multiple safety products based on the control instruction and determines the target disposal control interface corresponding to the target safety product based on the mapping relationship, so as to send the control instruction to the target safety product through the target disposal control interface to control the target safety product.
[0083] Further, such as Figure 3 As shown, the processing device 200 further includes a first interface generating module 204, and the first interface generating module 204 is used to:
[0084] The blacklist control information of each security product is obtained, and the first specific operation is encapsulated based on the blacklist control information to generate a blacklist control interface for the plurality of security products.
[0085] Further, such as Figure 3 As shown, the processing device 200 further includes a second interface generating module 205, and the second interface generating module 205 is used to:
[0086] The security policy control information of each security product is obtained, and the second specific operation is encapsulated based on the security policy control information to generate a security policy control interface for the plurality of security products.
[0087] Further, such as Figure 3 As shown, the processing device 200 further includes a field information matching module 206, and the information data further includes data field information. After the information data of each security product is acquired through the data acquisition interface cluster, the field information matching module 206 is used to:
[0088] For each data field information of each security product, the data field information is matched with the metadata field of the data acquisition interface cluster. If the match fails, the data field information is normalized based on the field conversion mapping table to obtain the converted data field information;
[0089] The original product field information table is updated based on the converted data field information to obtain a target product field information table.
[0090] Further, such as Figure 3 As shown, the processing device 200 further includes a field data updating module 207. After obtaining the target product field information table, the field data updating module 207 is used to:
[0091] When a data operation instruction is received, target field data is determined from the target product field information table based on the data operation instruction, and the target field data is updated based on the data operation instruction.
[0092] Further, such as Figure 3 As shown, the processing device 200 further includes a storage module 208. After obtaining the target product field information table, the storage module 208 is used to:
[0093] The target product field information table is dispersed into various data tables in the data acquisition interface cluster for distributed storage.
[0094] See also Figure 4 , Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Figure 4 As shown in , the electronic device 400 includes a processor 410 , a memory 420 and a bus 430 .
[0095] The memory 420 stores machine-readable instructions executable by the processor 410. When the electronic device 400 is running, the processor 410 communicates with the memory 420 via the bus 430. When the machine-readable instructions are executed by the processor 410, the above-mentioned Figure 1 The steps of the processing method for interconnection and interoperability of network security products in the method embodiment shown are specifically implemented in accordance with the method embodiment and will not be described in detail here.
[0096] The present application also provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the computer program can execute the above-mentioned Figure 1 The steps of the processing method for interconnection and interoperability of network security products in the method embodiment shown are specifically implemented in accordance with the method embodiment and will not be described in detail here.
[0097] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0098] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, and the indirect coupling or communication connection of devices or units can be electrical, mechanical or other forms.
[0099] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0100] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0101] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium that is executable by a processor. Based on this understanding, the technical solution of the present application can essentially be embodied in the form of a software product, or in other words, the part that contributes to the prior art or the part of the technical solution. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0102] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present application, which are used to illustrate the technical solutions of the present application, rather than to limit them. The protection scope of the present application is not limited thereto. Although the present application is described in detail with reference to the above-mentioned embodiments, ordinary technicians in the field should understand that any technician familiar with the technical field can still modify the technical solutions recorded in the above-mentioned embodiments within the technical scope disclosed in the present application, or can easily think of changes, or make equivalent replacements for some of the technical features therein; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application. Therefore, the protection scope of the present application shall be based on the protection scope of the claims.
Claims
1. A method for processing interconnection and interoperability of network security products, characterized in that: The processing method comprises: Encapsulating data acquisition interfaces of a plurality of safety products to construct a data acquisition interface cluster, and encapsulating disposal control interfaces of a plurality of the safety products to construct a disposal control interface cluster; Acquire information data of each safety product through the data acquisition interface cluster, and generate a mapping relationship between each safety product and each disposal control interface in the disposal control interface cluster based on the information data of each safety product; wherein the information data includes safety product information and interface information; A control instruction is sent to the disposal control interface cluster so that the disposal control interface cluster determines a target safety product from the multiple safety products based on the control instruction and determines a target disposal control interface corresponding to the target safety product based on the mapping relationship, so as to control the target safety product by sending the control instruction to the target safety product through the target disposal control interface.
2. The processing method according to claim 1, characterized in that: The processing method also includes: The blacklist control information of each security product is obtained, and the first specific operation is encapsulated based on the blacklist control information to generate a blacklist control interface for the plurality of security products.
3. The processing method according to claim 1, characterized in that: The processing method also includes: The security policy control information of each security product is obtained, and the second specific operation is encapsulated based on the security policy control information to generate a security policy control interface for the plurality of security products.
4. The processing method according to claim 1, characterized in that: The information data also includes data field information. After acquiring the information data of each safety product through the data acquisition interface cluster, the processing method further includes: For each data field information of each security product, the data field information is matched with the metadata field of the data acquisition interface cluster. If the match fails, the data field information is normalized based on the field conversion mapping table to obtain the converted data field information; The original product field information table is updated based on the converted data field information to obtain a target product field information table.
5. The processing method according to claim 4, characterized in that: After obtaining the target product field information table, the processing method further includes: When a data operation instruction is received, target field data is determined from the target product field information table based on the data operation instruction, and the target field data is updated based on the data operation instruction.
6. The processing method according to claim 4, characterized in that: After obtaining the target product field information table, the processing method further includes: The target product field information table is dispersed into various data tables in the data acquisition interface cluster for distributed storage.
7. A processing device for interconnection of network security products, characterized in that: The processing device comprises: An interface cluster building module, used to encapsulate the data acquisition interfaces of multiple security products to build a data acquisition interface cluster, and to encapsulate the disposal control interfaces of multiple security products to build a disposal control interface cluster; A mapping relationship generating module, used to obtain information data of each safety product through the data acquisition interface cluster, and generate a mapping relationship between each safety product and each disposal control interface in the disposal control interface cluster based on the information data of each safety product; wherein the information data includes safety product information and interface information; A control module is used to send a control instruction to the disposal control interface cluster, so that the disposal control interface cluster determines a target safety product from a plurality of the safety products based on the control instruction and determines a target disposal control interface corresponding to the target safety product based on the mapping relationship, so as to control the target safety product by sending the control instruction to the target safety product through the target disposal control interface.
8. The processing device according to claim 7, characterized in that The processing device further includes a first interface generating module, wherein the first interface generating module is configured to: The blacklist control information of each security product is obtained, and the first specific operation is encapsulated based on the blacklist control information to generate a blacklist control interface for the plurality of security products.
9. An electronic device, characterized in that: include: A processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the memory communicate through the bus, and the machine-readable instructions are executed by the processor to execute the steps of the processing method for interconnection and interoperability of network security products as described in any one of claims 1 to 6.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method for processing interconnection and interoperability of network security products as described in any one of claims 1 to 6 are executed.
Citation Information
Cited By
Automatic log abnormity analysis system
CN120415903A
Log anomaly automatic analysis system
CN120415903B