Firewall redundancy policy processing method and device, storage medium and electronic equipment
By automatically identifying redundant policies in the firewall and adjusting them according to the policy hit rate, the problem of inefficient management of firewall redundant policies in the existing technology is solved, and the performance and redundant policy management efficiency of the firewall are improved.
Patent Information
- Application Number
- CN202510212699.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-05-30
AI Technical Summary
In the existing technology, the management of firewall redundancy policies mainly relies on manual audits, which are inefficient in processing, and there are risks such as error deletion and missed deletion, resulting in unsatisfactory processing of firewall redundancy policies.
By determining the verification dimensions corresponding to the N policies set in the firewall, redundant policies are determined in the N policies based on these dimensions, the policy hit rate of the redundant policies used to verify the traffic data in a predetermined time period, and the redundant policies are adjusted according to the hit rate to obtain the adjusted N policies.
It realizes automatic identification and optimization of firewall redundancy policies, improves the performance of firewall and the redundancy policy management efficiency, and solves the inefficiency and risk problems caused by manual audits.
Smart Images

Figure CN120074911A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of big data, and in particular, to a method, device, storage medium, and electronic device for processing firewall redundancy policies. Background Art
[0002] With the advancement of digital transformation, the scale of network devices has grown exponentially, and the complexity of their configurations has also been continuously increasing. Among them, as an important device for wide area network border security, the complexity, scale, and quantity of firewall policy configurations are often relatively large. At the same time, due to the lack of a good means to sort out the application access relationships, it is difficult to sort out the access relationships and track and migrate policies; moreover, with the expansion and development of the business, when applications request firewall services, there are situations where access relationships are requested multiple times, the scopes of access are inconsistent, and other access requirements are submitted together, resulting in a large number of redundant policies in the firewall, increasing the complexity of firewall redundant policy management and optimization. In related technologies, the management of firewall redundant policies mainly relies on manual review, with low processing efficiency and risks such as incorrect deletion and missed deletion, resulting in unsatisfactory processing effects of firewall redundant policies.
[0003] In view of the problem of unsatisfactory processing effects of firewall redundant policies in related technologies, no effective solution has been proposed yet. Summary of the Invention
[0004] The main purpose of this application is to provide a method, device, storage medium, and electronic device for processing firewall redundancy policies to solve the problem of unsatisfactory processing effects of firewall redundant policies in related technologies.
[0005] To achieve the above objective, according to one aspect of this application, a method for processing firewall redundancy policies is provided. The method includes: determining the verification dimensions corresponding to N policies set in the firewall, where the N policies respectively use the corresponding verification dimensions to verify the traffic data passing through the firewall; determining redundant policies among the N policies based on the verification dimensions corresponding to the N policies; determining the policy hit rate of the redundant policies being used to verify traffic data in a predetermined time period; and adjusting the redundant policies according to the policy hit rate to obtain the adjusted N policies.
[0006] Optionally, among the N policies, there are a first policy and a second policy. Determining redundant policies among the N policies based on the verification dimensions corresponding to the N policies includes: determining the first policy as a redundant policy when the verification dimension corresponding to the first policy is less than the verification dimension corresponding to the second policy.
[0007] Optionally, adjust the redundant policies according to the policy hit rate to obtain N adjusted policies, including: comparing the first priority of the first policy and the second priority of the second policy; in the case where the first priority is lower than the second priority and the policy hit rate indicates a miss, perform a deletion process on the first policy to obtain N adjusted policies.
[0008] Optionally, the method further includes: comparing the first priority of the first policy and the second priority of the second policy; in the case where the first priority is higher than the second priority and the policy hit rate indicates a hit, determine the hit count of the first policy; in the case where the hit count is less than a predetermined count threshold, merge the first policy into the second policy to obtain N adjusted policies.
[0009] Optionally, determine the verification dimensions corresponding to the N policies set in the firewall, including: determining the policy effective time corresponding to each of the N policies, and the invoked services required when verifying each of the N policies; based on the policy effective time and the invoked services corresponding to each of the N policies, determine the verification dimensions corresponding to each of the N policies.
[0010] Optionally, determine the policy hit rate at which the redundant policy is used to verify traffic data in a predetermined time period, including: in the case where there are redundant policies among the N policies, enable the traffic log of the firewall, where the traffic log is used to record the log information of the traffic data passing through the firewall; based on the traffic log, determine the policy hit rate.
[0011] Optionally, the method further includes: determining the network topology of the network device where the firewall is located and the access mode of the firewall; in the case where any one of the network topology or the access mode is detected to change, reset the policy hit rate in the predetermined time period.
[0012] To achieve the above object, according to another aspect of the present application, there is provided a firewall redundant policy processing apparatus. The apparatus includes: a verification dimension determination module, configured to determine the verification dimensions corresponding to the N policies set in the firewall, where each of the N policies uses the corresponding verification dimension to verify the traffic data passing through the firewall; a redundant policy determination module, configured to determine redundant policies among the N policies based on the verification dimensions corresponding to each of the N policies; a hit rate determination module, configured to determine the policy hit rate at which the redundant policy is used to verify traffic data in a predetermined time period; and an adjustment module, configured to adjust the redundant policies according to the policy hit rate to obtain N adjusted policies.
[0013] Optionally, among the N policies, there are a first policy and a second policy. The redundant policy determination module includes: a first determination module, configured to determine the first policy as a redundant policy in the case where the verification dimension corresponding to the first policy is less than the verification dimension corresponding to the second policy.
[0014] Optionally, the adjustment module includes: a first comparison module for comparing the first priority of the first policy and the second priority of the second policy; a deletion module for deleting the first policy when the first priority is lower than the second priority and the policy hit rate indicates a miss, so as to obtain N adjusted policies.
[0015] Optionally, the apparatus further includes: a second comparison module for comparing the first priority of the first policy and the second priority of the second policy; a hit count determination module for determining the hit count of the first policy when the first priority is higher than the second priority and the policy hit rate indicates a hit; a merging module for merging the first policy into the second policy when the hit count is less than a predetermined count threshold, so as to obtain N adjusted policies.
[0016] Optionally, the verification dimension determination module includes: an effective time determination module for determining the policy effective times respectively corresponding to the N policies, and the invoked services required when the N policies are executed for verification; a second determination module for determining the verification dimensions respectively corresponding to the N policies based on the policy effective times and the invoked services respectively corresponding to the N policies.
[0017] Optionally, the hit rate determination module includes: a traffic log enabling module for enabling the traffic log of the firewall when there are redundant policies among the N policies, where the traffic log is used to record the log information of the traffic data passing through the firewall; a third determination module for determining the policy hit rate based on the traffic log.
[0018] Optionally, the apparatus further includes: a fourth determination module for determining the network topology of the network device where the firewall is located and the access mode of the firewall; a reset module for resetting the policy hit rate in a predetermined time period when any one of the network topology or the access mode is detected to change.
[0019] To achieve the above object, according to another aspect of the present application, there is provided a computer-readable storage medium, where the computer-readable storage medium includes an executable program stored therein, and when the executable program runs, it controls the device where the computer-readable storage medium is located to execute the firewall redundancy policy processing method of any one of the above.
[0020] To achieve the above object, according to another aspect of the present application, there is provided an electronic device, including: a memory storing an executable program; a processor for running the program, where when the program runs, it executes the firewall redundancy policy processing method of any one of the above.
[0021] Through the present application, the following steps are adopted: determining the verification dimensions corresponding to N policies set in the firewall, where the N policies respectively adopt the corresponding verification dimensions to verify the traffic data passing through the firewall; determining redundant policies among the N policies based on the verification dimensions corresponding to the N policies; determining the policy hit rate of the redundant policies used to verify the traffic data in a predetermined time period; and adjusting the redundant policies according to the policy hit rate to obtain the adjusted N policies. The purpose of automatically identifying and optimizing the firewall redundant policies is achieved, and the problem that the processing effect of the firewall redundant policies in the related art is not ideal is solved. Furthermore, the effect of improving the performance of the firewall and the management efficiency of the redundant policies is achieved. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The accompanying drawings that form a part of this application are used to provide a further understanding of this application. The schematic embodiments of this application and their descriptions are used to explain this application and do not constitute an improper limitation to this application. In the drawings:
[0023] Figure 1 shows a hardware structure block diagram of a computer terminal for implementing a method for processing firewall redundant policies;
[0024] Figure 2 is a flowchart of a method for processing firewall redundant policies provided by an embodiment of this application;
[0025] Figure 3 is a schematic diagram of a method for processing firewall redundant policies provided by an embodiment of this application;
[0026] Figure 4 is a schematic diagram of a device for processing firewall redundant policies provided by an embodiment of this application;
[0027] Figure 5 is a structure block diagram of an electronic device according to an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0028] In order to enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.
[0029] It should be noted that the terms "first", "second", etc. in the description, claims and the above-mentioned drawings of this application are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0030] First, some nouns or terms that appear in the process of describing the embodiments of this application are applicable to the following explanations:
[0031] IP (Internet Protocol) address, short for Internet Protocol address, is a unique digital label assigned to each device on the Internet for locating and addressing these devices in the network. The IP address enables data packets to be transmitted on the Internet and finally reach the correct destination. In Internet communication, each data packet carries the source IP address and the destination IP address to ensure the correct sending and receiving of data.
[0032] A firewall is a network security system used to establish a barrier between an internal network and an external network to control network traffic in and out of the network and protect the internal network from external threats. The working principle of a firewall is based on a set of preset security rules that define the types and sources of data packets allowed to pass through, as well as the types and sources of data packets to be intercepted or rejected.
[0033] Application Inter-communication Relationships refer to the patterns of mutual access and communication between different application systems or services in a network. In an enterprise, organization or any complex network environment, application systems often need to exchange data with other applications to achieve the automation of business processes or the sharing and processing of data. These inter-communication relationships may involve communication between internal applications or may also include the interaction between internal applications and external services.
[0034] Firewall policy redundancy means that all the matching scopes of a certain policy are a subset of another policy, and deleting this policy will not affect the forwarding behavior of the firewall, then this policy is recorded as a redundant policy.
[0035] It should be noted that the information collected in this application (including but not limited to user device information, user personal information, firewall configuration information, five-tuple information, policy invocation service information, etc.) and data (including but not limited to data for display, data for analysis, traffic logs, etc.) are information and data authorized by the user or fully authorized by all parties. Moreover, the processing of relevant data, such as collection, storage, use, processing, transmission, provision, disclosure, and application, complies with relevant laws, regulations, and standards, adopts necessary confidentiality measures, does not violate public order and good customs, and provides corresponding operation entrances for users to choose to authorize or refuse. For example, an interface is set up between this system and relevant users or institutions to provide corresponding operation entrances for users to choose to agree or refuse the results of automated decision-making; if the user chooses to refuse, the expert decision-making process will be entered.
[0036] Embodiment 1
[0037] According to an embodiment of the present application, there is also provided a method embodiment of a firewall redundancy policy processing method. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0038] The method embodiment provided by the first embodiment of the present application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Figure 1 The hardware structure block diagram of a computer terminal (or mobile device) for implementing the firewall redundancy policy processing method is shown. As Figure 1 shown, the computer terminal 10 (or mobile device) may include one or more processors 102 (shown as 102a, 102b,..., 102n in the figure) (the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a field programmable gate array FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which can be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components than those Figure 1 shown, or have a different configuration from that Figure 1 shown.
[0039] It should be noted that the above one or more processors 102 and / or other data processing circuits can generally be referred to as "data processing circuits" herein. The data processing circuit can be embodied in whole or in part as software, hardware, firmware, or any combination thereof. In addition, the data processing circuit can be a single independent processing module, or be incorporated in whole or in part into any one of other elements in the computer terminal 10 (or mobile device). As involved in the embodiments of the present application, the data processing circuit is a kind of processor control (such as the selection of a variable resistance terminal path connected to an interface).
[0040] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the firewall redundancy policy processing method in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above-mentioned firewall redundancy policy processing method. The memory 104 can include a high-speed random access memory, and can also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 can further include a memory remotely disposed relative to the processor 102, and these remote memories can be connected to the computer terminal 10 through a network. Examples of the above network include but are not limited to the Internet, enterprise intranet, local area network, mobile communication network, and combinations thereof.
[0041] The transmission device 106 is used to receive or send data via a network. Specific examples of the above network can include a wireless network provided by a communication provider of the computer terminal 10. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station and thus can communicate with the Internet. In one instance, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0042] The display can be, for example, a touch-screen liquid crystal display (LCD), which enables a user to interact with the user interface of the computer terminal 10 (or mobile device).
[0043] Under the above operating environment, the present application provides a firewall redundancy policy processing method as Figure 2 shown. Figure 2 It is a flowchart of the firewall redundancy policy processing method provided according to the embodiments of the present application.
[0044] Step S201: Determine the verification dimensions corresponding to the N policies set in the firewall. Among them, the N policies respectively adopt the corresponding verification dimensions to verify the traffic data passing through the firewall.
[0045] It can be understood that the detailed configuration information of the N policies obtained from the firewall is acquired, and based on the configuration information, the verification dimension information corresponding to the N policies is determined. Among them, the above verification dimension information is used to verify the traffic data passing through the firewall to determine which traffic can pass through the firewall and which traffic is intercepted by the firewall. By automatically obtaining the verification dimension information of the firewall policies, the loopholes and errors caused by manual operations can be avoided, the processing speed of the firewall can be improved, and the automation level of the firewall policy management can be enhanced.
[0046] Optionally, the verification dimension information of the above policies includes the five-tuple information of the policies (such as the source IP address, destination IP address, source port, destination port, and protocol type), the policy effective time, the invoked service, and the order, etc. Among them, the source IP address is the IP address of the source-end device of the data packet initiating the communication. The destination IP address is the IP address of the destination-end device of the data packet. The source port is the port number on the source-end device of the data packet initiating the communication. The destination port is the port number on the destination-end device of the data packet where the data is expected to be received. The protocol type is the transport layer protocol used by the data packet. The policy effective time indicates when the policy starts to take effect and when it may end. The invoked service refers to the specific service or application specified in the firewall policy, and the traffic of these services or applications is allowed or restricted to pass through the firewall. The order is the priority, which is used to determine which rule will be executed first when multiple policy rules may match a certain data packet simultaneously.
[0047] Optionally, in the firewall redundancy policy processing method provided in the embodiments of the present application, determining the verification dimensions corresponding to the N policies set in the firewall includes: determining the policy effective moments corresponding to the N policies respectively, and the invoked services required when the N policies perform verification; based on the policy effective moments and the invoked services corresponding to the N policies respectively, determining the verification dimensions corresponding to the N policies respectively.
[0048] It can be understood that the policy effective moments corresponding to the N policies in the firewall respectively, the invoked services required when the N policies perform verification, as well as the five-tuple information and priority information corresponding to the N policies respectively are acquired. Based on the effective moments, the invoked services, the five-tuple information, and the priority information corresponding to the N policies respectively, the verification dimensions corresponding to the N policies are determined. By obtaining the effective moments, the invoked services, the five-tuple information, and the priority information of the firewall policies, the applicable scope and the usage priority of the policies can be judged, which provides a judgment basis for subsequent determination of whether the policies are redundant policies.
[0049] Step S202: Based on the verification dimensions corresponding to the N policies respectively, determine the redundant policies among the N policies;
[0050] It can be understood that based on the verification dimension information corresponding to the obtained N policies respectively, determine the applicable scopes corresponding to the N policies respectively. Based on the applicable scopes, determine the policies among the N policies that belong to the redundant policies. Through automated policy analysis, the management process of firewall policies is greatly simplified, the workload of manual review is reduced, and the automation degree and efficiency of policy management are improved.
[0051] Optionally, in the firewall redundant policy processing method provided in the embodiments of the present application, among the N policies, there are a first policy and a second policy. Determining the redundant policies among the N policies based on the verification dimensions corresponding to the N policies respectively includes: when the verification dimension corresponding to the first policy is less than the verification dimension corresponding to the second policy, determining the first policy as the redundant policy.
[0052] It can be understood that for the first policy and the second policy among the N policies, through the verification dimension information corresponding to the first policy and the second policy respectively, determine the applicable scopes corresponding to the first policy and the second policy respectively. If the applicable scope corresponding to the first policy is less than the applicable scope corresponding to the second policy, that is, the effective time, called service, and five-tuple information corresponding to the first policy are all included in the effective time, called service, and five-tuple information corresponding to the second policy, then determine the first policy as the redundant policy. Using the verification dimension information corresponding to the policy can automatically judge the policy that belongs to the redundant policy, avoid the error caused by manual judgment, improve the recognition accuracy and judgment efficiency of firewall redundant policies, and then improve the management efficiency of the firewall and reduce the redundancy degree of firewall policies.
[0053] Optionally, a redundant policy tool can be used to obtain the verification dimension information of the policy and perform redundant discrimination. The redundant policy tool extracts the verification dimension information corresponding to the firewall policy, that is, five-tuple information, firewall policy effective time, called service, order, etc. Through the above verification dimension information, compare whether there is an inclusion relationship between policies. For example, for policy a and policy b, if a is included in b (that is, the five-tuple information, policy effective time, and called service of a are all included in those of b), then a is called a redundant policy, that is, a is deleted, and it has no impact on the forwarding behavior of the firewall. Mark policy a as a redundant policy.
[0054] Step S203: Determine the policy hit rate of the redundant policy used to verify traffic data in a predetermined time period;
[0055] It can be understood that by querying the traffic logs, the hit count of the redundancy policy (i.e., the number of times the redundancy policy is used to verify traffic data) is determined during a predetermined time period. Based on the hit count, the policy hit rate of the redundancy policy is determined. Through the quantitative analysis of the policy hit rate, the redundancy of the policy can be judged more accurately, avoiding subjective judgments based only on configuration information, increasing the objectivity and accuracy of decision-making. At the same time, the policy hit rate provides an objective basis for confirming and deleting redundant policies, thereby effectively improving the operation efficiency and network security of the firewall.
[0056] Optionally, in the firewall redundancy policy processing method provided in the embodiments of the present application, determining the policy hit rate at which the redundancy policy is used to verify traffic data during a predetermined time period includes: when there is a redundancy policy among the N policies, enabling the traffic logs of the firewall, where the traffic logs are used to record the log information of the traffic data passing through the firewall; determining the policy hit rate based on the traffic logs.
[0057] It can be understood that if there is a redundancy policy among the N policies of the firewall, the traffic logs of the firewall are enabled, that is, the traffic logs are used to record the information of all traffic data passing through the firewall within a period of time. According to the log information recorded in the traffic logs, the policy hit rate of the redundancy policy is determined within the above-mentioned period of time. Through the recording of the traffic logs and the calculation of the policy hit rate, it is possible to accurately identify which policies are redundant in actual operation, avoiding misdeleting or omitting necessary policies, ensuring the rationality of the network configuration, and improving the overall operation efficiency and network security of the firewall.
[0058] Optionally, when there is a redundancy policy, enable log type traffic enable (i.e., the command to enable traffic log recording on the firewall device), and perform real-time detection on the marked redundancy policy. If a redundant policy is detected to be hit, the logs will be accumulated in the storage medium. After a long period (i.e., the predetermined time period, which can be half a year, one year, or customized), according to the traffic logs, the hit rate of the redundancy policy is determined, and according to the hit rate, the processing method for the redundancy policy is determined. After detecting the traffic logs for a long period (half a year / one year / customizable), if the hit rate of the redundant policy is 0, the redundant policy is deleted; if the hit rate of the redundant policy is not 0, retention or merging processing is performed according to the size of the hit rate.
[0059] Step S204, adjust the redundant policies according to the policy hit rate to obtain the adjusted N policies.
[0060] It can be understood that based on the policy hit rate of the redundancy policy, the processing method for the redundancy policy is determined, such as deletion and merging. The redundancy policy is adjusted using the determined processing method to obtain N adjusted policies. Using the policy hit rate as the adjustment basis can effectively streamline the firewall configuration, simplify management, enhance security, optimize resource utilization, and improve the overall performance of the network.
[0061] Optionally, in the firewall redundancy policy processing method provided in the embodiments of the present application, the redundancy policy is adjusted according to the policy hit rate to obtain N adjusted policies, including: comparing the first priority of the first policy and the second priority of the second policy; when the first priority is lower than the second priority and the policy hit rate indicates a miss, performing a deletion process on the first policy to obtain N adjusted policies.
[0062] It can be understood that in addition to comparing the applicable scopes of the policies, the priorities of the policies also need to be compared. For the first policy and the second policy among the N policies, compare the first priority of the first policy and the second priority of the second policy. If the first priority is lower than the second priority and the policy hit rate of the first policy indicates no hit, then the first policy is deleted, and then N adjusted policies are obtained. By deleting redundant policies with low priority and no hit, the size of the firewall policy table is significantly reduced, the processing speed of data packets is accelerated, the forwarding efficiency of the firewall is improved, which helps to reduce the potential attack surface of the firewall, improve the network security protection level, and avoid security vulnerabilities caused by multiple policies covering the same network traffic.
[0063] Optionally, in the firewall redundancy policy processing method provided in the embodiments of the present application, the method further includes: comparing the first priority of the first policy and the second priority of the second policy; when the first priority is higher than the second priority and the policy hit rate indicates a hit, determining the hit count of the first policy; when the hit count is less than the predetermined count threshold, merging the first policy into the second policy to obtain N adjusted policies.
[0064] It can be understood that in addition to the applicable scope of the comparison policy, the priority of the comparison policy is also required. For the first policy and the second policy among N policies, compare the first priority of the first policy and the second priority of the second policy. If the first priority is higher than the second priority and the policy hit rate indication of the first policy indicates a hit, determine the hit count of the first policy. Compare the hit count of the first policy with a predetermined count threshold. If the hit count is less than the predetermined count threshold, merge the first policy into the second policy, thereby obtaining the adjusted N policies. Through policy merging, the entries in the firewall policy table are reduced, the processing speed of data packets is accelerated, the operating efficiency of network devices is improved, and policy merging helps to simplify the policy configuration of the firewall, making the configuration clearer, easier to manage and understand, and reducing the possibility of configuration errors.
[0065] Optionally, in the firewall redundancy policy processing method provided in the embodiments of the present application, the method further includes: determining the network topology of the network device where the firewall is located and the access mode of the firewall; resetting the policy hit rate in a predetermined time period when any one of the network topology or the access mode is detected to change.
[0066] It can be understood that the network topology structure of the network device where the firewall is located and the access mode of the firewall are determined. The network topology structure of the firewall and the access mode of the firewall are detected in real time. If any one of the network topology structure or the access mode is detected to change, reset the hit rate of the redundancy policy in a predetermined time period, that is, clear the hit count and start recording the hit count again. Changes in the network topology or access mode may introduce new security threats. Timely adjusting the evaluation of the policy hit rate helps to discover and handle new redundant policies, strengthen network defense, and reduce potential security risks. At the same time, by dynamically adjusting the policy hit rate, the firewall policy can be managed more flexibly, avoiding policy management lag caused by network changes, ensuring that the firewall policy can dynamically adapt to changes in the network environment, and improving the effectiveness and timeliness of the policy.
[0067] Optionally, network topology refers to the geometric arrangement of nodes and the links (such as cables, optical fibers, wireless connections, etc.) connecting these nodes in a network. Network topology describes the physical connections and logical relationships among the various components in a network, and has an important impact on the performance, reliability, security, and management of the network. If the network topology structure of the firewall changes, such as adding new devices or gateways, or the usage environment changes, that is, the security level of the associated devices changes, it will affect the judgment of the firewall redundancy policy. Therefore, when the network topology structure of the network device where the firewall is located changes, it is necessary to reset the policy hit rate in the predetermined time period before the change. The access mode of the firewall refers to the way the firewall processes data packets or network requests, such as the packet filtering mode, etc. These modes determine how the firewall decides which data packets can be released, which need to be blocked or further inspected.
[0068] Optionally, through two judgment processes of the redundancy policy tool and the traffic log, the redundant policies in the firewall policy are determined. The redundant policies determined through the above two judgments are then subject to a manual review to finally determine whether they are redundant policies that need to be deleted. If the judgment result is that deletion is required, the redundant policies are deleted to improve the forwarding efficiency of the firewall.
[0069] Optionally, the above-mentioned manual review can be implemented through a manual interface, that is, in the firewall redundancy policy detection process, a dedicated user interface (usually a graphical interface or a command-line interface) is used to assist the reviewer in manually reviewing the redundant policies identified by the automated tool. To implement the manual review, the above-mentioned manual interface should have functions such as policy display and analysis, traffic log analysis, review decision support, and execution and recording. Through a well-designed manual review interface, the reviewer can complete the review of redundant policies more efficiently and accurately, ensuring that the optimization of network policies does not affect business continuity and does not reduce network security.
[0070] Policy display and analysis include policy list display, context information, and comparison view. Policy list display means providing a clear policy list to show all the policies identified as redundant, including key information such as source IP, destination IP, port, protocol, etc. Context information means showing the context of the policy, such as creation time, modification history, associated business or service, and any relevant notes or descriptions. The comparison view means allowing the reviewer to view the redundant policy and its covered "main" policy simultaneously, intuitively comparing the differences and inclusion relationships between the two.
[0071] Flow log analysis includes log query, log statistics, and anomaly detection. Log query means providing a log query function, allowing auditors to query flow logs based on specific policies to confirm whether the policies are actually hit in practice. Log statistics means presenting the traffic statistics of the marked policies, including the number of hits, time distribution, traffic types, etc., to help auditors quickly judge the actual usage of the policies. Anomaly detection means that if there are anomalies or data inconsistent with expectations in the flow logs, the system should be able to automatically mark them to prompt auditors for in-depth investigation.
[0072] Audit decision support includes risk assessment and decision recommendations. Risk assessment is based on policy details and flow logs, and the system can provide risk assessment tools to help auditors quantify the risks and potential impacts of deleting redundant policies. Decision recommendations mean that the system can provide suggestions such as "delete", "retain", or "further analyze" for auditors based on factors such as the redundancy level of the policy, business impact, and security risks.
[0073] Execution and recording include policy operations and operation records. Policy operations mean providing an interface that enables auditors to directly perform operations such as "delete", "modify", or "mark as non-redundant" from this interface. Operation records mean recording all audit and operation processes, including auditors' decisions, operation times, operation results, etc., for subsequent auditing and traceability.
[0074] Through the above step S201, determine the verification dimensions corresponding to the N policies set in the firewall. Among them, the N policies respectively adopt the corresponding verification dimensions to verify the traffic data passing through the firewall; step S202, based on the verification dimensions corresponding to the N policies, determine the redundant policies among the N policies; step S203, determine the policy hit rate of the redundant policies used to verify traffic data in a predetermined time period; step S204, adjust the redundant policies according to the policy hit rate to obtain the adjusted N policies. It can achieve the technical effect of improving the performance of the firewall and the management efficiency of redundant policies, and further solve the technical problem of the unsatisfactory processing effect of firewall redundant policies.
[0075] Based on the above embodiments and optional embodiments, the present application proposes an optional implementation method, using the firewall redundant policy processing method to perform redundancy judgment and processing on the immediately extracted firewall policies. Figure 3 It is a schematic diagram of the firewall redundant policy processing method provided by the embodiment of the present application. As Figure 3 shown, the process of performing redundancy judgment and processing on the immediately extracted firewall policies is as follows.
[0076] Step S1, immediately extract part of the firewall configuration, perform redundancy judgment and processing on the firewall policies through the immediately extracted part of the firewall configuration, and import the configuration into the redundant policy tool.
[0077] Obtain the detailed configuration information of N policies obtained from the firewall. Based on the configuration information, determine the verification dimension information corresponding to each of the N policies. Among them, the above verification dimension information is used to verify the traffic data passing through the firewall to determine which traffic can pass through the firewall and which traffic is intercepted by the firewall. By automatically obtaining the verification dimension information of the firewall policies, loopholes and errors caused by manual operations can be avoided, the processing speed of the firewall can be improved, and the automation level of the management of the firewall policies can be enhanced.
[0078] The verification dimension information of the above policies includes the five-tuple information of the policy (i.e., source IP address, destination IP address, source port, destination port, and protocol type), the policy effective time, the invoked service, and the order, etc. Among them, the source IP address is the IP address of the source-end device of the data packet initiating the communication. The destination IP address is the IP address of the destination-end device of the data packet. The source port is the port number on the source-end device of the data packet initiating the communication. The destination port is the port number on the destination-end device of the data packet where the data is expected to be received. The protocol type is the transport layer protocol used by the data packet. The policy effective time indicates when the policy starts to take effect and when it may end. The invoked service refers to the specific service or application specified in the firewall policy, and the traffic of these services or applications is allowed or restricted to pass through the firewall. The order is the priority, which is used to determine which rule will be executed first when multiple policy rules may match a certain data packet simultaneously.
[0079] In step S2, a redundant policy tool can be used to obtain the verification dimension information of the policy and perform redundancy discrimination. The redundant policy tool extracts the verification dimension information corresponding to the firewall policy, i.e., the five-tuple information, the firewall policy effective time, the invoked service, the order, etc. Through the above verification dimension information, it is compared whether there is an inclusion relationship between the policies. For example, for policy a and policy b, if a is included by b (i.e., the five-tuple information, the policy effective time, and the invoked service of a are all included by those of b), then a is called a redundant policy, and policy a is marked as a redundant policy. At the same time, if the priority of a is lower than that of b, then a can be deleted, and the deletion has no impact on the forwarding behavior of the firewall.
[0080] Step S3: Enable the traffic log and compare it within a certain period. When there is a redundant policy, enable log type traffic enable (i.e., the command to enable traffic log recording on the firewall device), and perform real-time detection on the marked redundant policy. If a redundant policy is detected to be hit, the log will be accumulated in the storage medium. After a long period (i.e., a predetermined time period, which can be half a year, one year, or customized), determine whether this policy is actually redundant. If hits are found after a long period (half a year / one year / customizable) of accumulation, it means that this policy is not actually redundant; if no hits are found after a long period (half a year / one year / customizable) of accumulation, it means that this policy is actually redundant, that is, a redundant policy that is actually redundant should theoretically not be hit.
[0081] Based on the above traffic log, determine the hit rate of the redundant policy, and based on the hit rate, determine the processing method for the redundant policy. After detecting the traffic log for a long period (half a year / one year / customizable), if the hit rate of the redundant policy is 0, delete the redundant policy; if the hit rate of the redundant policy is not 0, perform retention or merging processing according to the size of the hit rate.
[0082] For the first policy and the second policy among N policies, if the first policy is included in the second policy, compare the first priority of the first policy and the second priority of the second policy. If the first priority is lower than the second priority and the policy hit rate of the first policy indicates no hit, then delete the first policy, and then obtain the adjusted N policies. By deleting redundant policies with low priority and no hits, the size of the firewall policy table is significantly reduced, the processing speed of data packets is accelerated, the forwarding efficiency of the firewall is improved, which helps to reduce the potential attack surface of the firewall, improve the network security protection level, and avoid security vulnerabilities caused by multiple policies covering the same network traffic.
[0083] For the first policy and the second policy among N policies, if the first policy is included in the second policy, compare the first priority of the first policy and the second priority of the second policy. If the first priority is higher than the second priority and the policy hit rate of the first policy indicates a hit, determine the number of hits of the first policy. Compare the number of hits of the first policy with a predetermined number threshold. If the number of hits is less than the predetermined number threshold, merge the first policy into the second policy, and then obtain the adjusted N policies. Through policy merging, the number of entries in the firewall policy table is reduced, the processing speed of data packets is accelerated, the operating efficiency of network devices is improved, and policy merging helps to simplify the policy configuration of the firewall, making the configuration clearer, easier to manage and understand, and reducing the possibility of configuration errors.
[0084] Step S4, through two judgment processes of the redundancy policy tool and traffic logs, the redundant policies in the firewall policy are determined. The redundant policies determined through the above two judgments are then subject to a manual review to finally determine whether they are the redundant policies to be deleted.
[0085] The above-mentioned manual review can be implemented through a manual interface. That is, in the firewall redundant policy detection process, a dedicated user interface (usually a graphical interface or a command-line interface) is used to assist the reviewer in manually reviewing the redundant policies identified by the automated tool. To implement the manual review, the above-mentioned manual interface should have functions such as policy display and analysis, traffic log analysis, review decision support, and execution and recording. Through a well-designed manual review interface, the reviewer can complete the review of redundant policies more efficiently and accurately, ensuring that the optimization of network policies will neither affect business continuity nor reduce network security.
[0086] Step S5, delete the redundant policies. If the redundant policies are determined to be deleted after two judgments, the redundant policies are deleted to improve the forwarding efficiency of the firewall.
[0087] Through the above process, the redundant policies of the firewall can be found, and the firewall's passing efficiency can be improved.
[0088] The above-mentioned firewall redundant policy processing method has achieved the following effects: By combining the redundancy policy tool with manual review, it effectively detects and optimizes the redundant policies of the firewall, not only reducing the complexity of policy management, improving the policy configuration efficiency, but also enhancing the forwarding performance of network devices; By using traffic logs to record and detect the hit rate of redundant policies in real time, it can accurately identify which policies are redundant in actual operation, avoiding misdeletion or omission of necessary policies, ensuring the rationality of network configuration, and enhancing the overall operation efficiency and network security of the firewall.
[0089] The firewall redundant policy processing method provided by the embodiment of the present application determines the verification dimensions corresponding to N policies set in the firewall, where the N policies respectively use the corresponding verification dimensions to verify the traffic data passing through the firewall; based on the verification dimensions corresponding to the N policies, redundant policies are determined among the N policies; the policy hit rate of the redundant policies used to verify traffic data in a predetermined time period is determined; according to the policy hit rate, the redundant policies are adjusted to obtain the adjusted N policies. It solves the problem that the processing effect of firewall redundant policies in the related technology is not ideal. Furthermore, it achieves the effect of improving the performance of the firewall and the management efficiency of redundant policies.
[0090] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0091] Embodiment 2
[0092] The embodiment of the present application also provides a firewall redundancy policy processing device. It should be noted that the firewall redundancy policy processing device in the embodiment of the present application can be used to execute the firewall redundancy policy processing method provided by the embodiment of the present application. The following introduces the firewall redundancy policy processing device provided by the embodiment of the present application.
[0093] According to the embodiment of the present application, there is also provided a device for implementing the above firewall redundancy policy processing method. Figure 4 is a schematic diagram of the firewall redundancy policy processing device provided by the embodiment of the present application, as Figure 4 shown, the device includes: a verification dimension determination module 401, configured to determine the verification dimensions corresponding to N policies set in the firewall, where the N policies respectively use the corresponding verification dimensions to verify the traffic data passing through the firewall; a redundancy policy determination module 402, connected to the verification dimension determination module 401, configured to determine a redundancy policy among the N policies based on the verification dimensions corresponding to the N policies; a hit rate determination module 403, connected to the redundancy policy determination module 402, configured to determine the policy hit rate of the redundancy policy being used to verify traffic data in a predetermined time period; an adjustment module 404, connected to the hit rate determination module 403, configured to adjust the redundancy policy according to the policy hit rate to obtain the adjusted N policies.
[0094] The firewall redundancy policy processing device provided by the embodiment of the present application, through the verification dimension determination module 401, is configured to determine the verification dimensions corresponding to N policies set in the firewall, where the N policies respectively use the corresponding verification dimensions to verify the traffic data passing through the firewall; the redundancy policy determination module 402, connected to the verification dimension determination module 401, is configured to determine a redundancy policy among the N policies based on the verification dimensions corresponding to the N policies; the hit rate determination module 403, connected to the redundancy policy determination module 402, is configured to determine the policy hit rate of the redundancy policy being used to verify traffic data in a predetermined time period; the adjustment module 404, connected to the hit rate determination module 403, is configured to adjust the redundancy policy according to the policy hit rate to obtain the adjusted N policies. Solves the problem that the firewall redundancy policy processing effect in the related art is not ideal. Furthermore, it achieves the effect of improving the performance of the firewall and the management efficiency of the redundancy policy.
[0095] Optionally, in the firewall redundancy policy processing device provided in the embodiments of the present application, among the N policies, there are a first policy and a second policy. The redundancy policy determination module includes: a first determination module, configured to determine the first policy as a redundant policy when the verification dimension corresponding to the first policy is less than the verification dimension corresponding to the second policy.
[0096] Optionally, in the firewall redundancy policy processing device provided in the embodiments of the present application, the adjustment module includes: a first comparison module, configured to compare the first priority of the first policy and the second priority of the second policy; a deletion module, configured to perform a deletion process on the first policy when the first priority is lower than the second priority and the policy hit rate indicates a miss, to obtain the adjusted N policies.
[0097] Optionally, in the firewall redundancy policy processing device provided in the embodiments of the present application, the device further includes: a second comparison module, configured to compare the first priority of the first policy and the second priority of the second policy; a hit count determination module, configured to determine the hit count of the first policy when the first priority is higher than the second priority and the policy hit rate indicates a hit; a merging module, configured to merge the first policy into the second policy when the hit count is less than a predetermined count threshold, to obtain the adjusted N policies.
[0098] Optionally, in the firewall redundancy policy processing device provided in the embodiments of the present application, the verification dimension determination module includes: an effective time determination module, configured to determine the policy effective times respectively corresponding to the N policies, and the call services required when the N policies are executed for verification; a second determination module, configured to determine the verification dimensions respectively corresponding to the N policies based on the policy effective times and call services respectively corresponding to the N policies.
[0099] Optionally, in the firewall redundancy policy processing device provided in the embodiments of the present application, the hit rate determination module includes: a traffic log enabling module, configured to enable the traffic log of the firewall when there is a redundant policy among the N policies, where the traffic log is used to record the log information of the traffic data passing through the firewall; a third determination module, configured to determine the policy hit rate based on the traffic log.
[0100] Optionally, in the firewall redundancy policy processing device provided in the embodiments of the present application, the device further includes: a fourth determination module, configured to determine the network topology of the network device where the firewall is located and the access mode of the firewall; a reset module, configured to reset the policy hit rate in a predetermined time period when it is detected that any one of the network topology or the access mode changes.
[0101] It should be noted here that the above verification dimension determination module 401, redundancy policy determination module 402, hit rate determination module 403, and adjustment module 404 correspond to steps S201 to S204 in Embodiment 1. The functions and application scenarios implemented by the two modules and the corresponding steps are the same, but are not limited to the content disclosed in the above Embodiment 1. It should be noted that the above modules or units may be hardware components or software components stored in a memory (for example, memory 104) and processed by one or more processors (for example, processors 102a, 102b,..., 102n). The above modules may also be part of a device and can run in the computer terminal 10 provided in Embodiment 1.
[0102] Embodiment 3
[0103] An embodiment of the present application may provide an electronic device. Figure 5 It is a structural block diagram of an electronic device according to an embodiment of the present application. As Figure 5 shown, the electronic device may include: one or more ( Figure 5 only one is shown in the figure) processors 502, a memory 504, a storage controller, and a peripheral interface. Among them, the peripheral interface is connected to a radio frequency module, an audio module, and a display.
[0104] Among them, the memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the methods and devices in the embodiments of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, implements the above methods. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely set relative to the processor, and these remote memories can be connected to the terminal through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0105] The processor can call the information and application programs stored in the memory through a transmission device to perform the following steps: determining the verification dimensions corresponding to N policies set in the firewall, where the N policies respectively adopt corresponding verification dimensions to verify the traffic data passing through the firewall; determining a redundancy policy among the N policies based on the verification dimensions corresponding to the N policies; determining the policy hit rate of the redundancy policy used to verify the traffic data in a predetermined time period; and adjusting the redundancy policy according to the policy hit rate to obtain the adjusted N policies.
[0106] The processor can also call the information and application programs stored in the memory through the transmission device to execute the following steps: when the verification dimension corresponding to the first policy is less than the verification dimension corresponding to the second policy, determine that the first policy is a redundant policy.
[0107] The processor can also call the information and application programs stored in the memory through the transmission device to execute the following steps: compare the first priority of the first policy and the second priority of the second policy; when the first priority is lower than the second priority and the policy hit rate indicates a miss, perform a deletion process on the first policy to obtain N adjusted policies.
[0108] The processor can call the information and application programs stored in the memory through the transmission device to execute the following steps: compare the first priority of the first policy and the second priority of the second policy; when the first priority is higher than the second priority and the policy hit rate indicates a hit, determine the hit count of the first policy; when the hit count is less than the predetermined count threshold, merge the first policy into the second policy to obtain N adjusted policies.
[0109] The processor can call the information and application programs stored in the memory through the transmission device to execute the following steps: determine the policy effective time corresponding to each of the N policies, and the call services required when the N policies perform verification; based on the policy effective time and call services corresponding to each of the N policies, determine the verification dimension corresponding to each of the N policies.
[0110] The processor can call the information and application programs stored in the memory through the transmission device to execute the following steps: when there is a redundant policy among the N policies, turn on the traffic log of the firewall, where the traffic log is used to record the log information of the traffic data passing through the firewall; based on the traffic log, determine the policy hit rate.
[0111] The processor can call the information and application programs stored in the memory through the transmission device to execute the following steps: determine the network topology of the network device where the firewall is located and the access mode of the firewall; when it is detected that any one of the network topology or the access mode changes, reset the policy hit rate within a predetermined time period.
[0112] An embodiment of the present application provides a solution for a firewall redundancy policy processing method. By determining the verification dimensions corresponding to N policies set in the firewall, where the N policies respectively adopt the corresponding verification dimensions to verify the traffic data passing through the firewall; based on the verification dimensions corresponding to the N policies, determining redundant policies among the N policies; determining the policy hit rate of the redundant policies being used to verify traffic data in a predetermined time period; and adjusting the redundant policies according to the policy hit rate to obtain the adjusted N policies. Thus, the purpose of improving the performance of the firewall and the management efficiency of redundant policies is achieved, and furthermore, the technical problem of the processing effect of firewall redundant policies caused by manual review is solved.
[0113] Those of ordinary skill in the art can understand that Figure 5 the structure shown is only for illustration, and the electronic device can also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a handheld computer, and a Mobile Internet Devices (MID), a PAD and other terminal devices. Figure 5 It does not limit the structure of the above-mentioned electronic device. For example, the electronic device may further include more or fewer components (such as a network interface, a display device, etc.) than those shown Figure 5 in the figure, or have a different configuration from that shown Figure 5 in the figure.
[0114] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the relevant hardware of the terminal device through a program, and the program can be stored in a computer-readable storage medium. The storage medium may include: a flash drive, a Read-Only Memory (ROM), a Random Access Memory (RAM), a magnetic disk or an optical disc, etc.
[0115] Embodiment 4
[0116] The embodiment of the present application further provides a storage medium. Optionally, in this embodiment, the above storage medium can be used to save the program code executed by the firewall redundancy policy processing method provided in the above Embodiment 1.
[0117] Optionally, in this embodiment, the above storage medium can be located in any one of the computer terminals in the computer terminal group in the computer network, or in any one of the mobile terminals in the mobile terminal group.
[0118] The present application also provides a computer program product, which is suitable for executing a program of the steps of the firewall redundancy policy processing method when executed on a data processing device.
[0119] The serial numbers of the embodiments of the present application above are only for description and do not represent the advantages or disadvantages of the embodiments.
[0120] In the above embodiments of the present application, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0121] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the above division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.
[0122] The units described above as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0123] In addition, the functional units in each embodiment of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0124] If the above integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the above methods in each embodiment of the present application. And the aforementioned storage medium includes: USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks or optical discs and other various media that can store program codes.
[0125] The above are only the preferred embodiments of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.
Claims
1. A firewall redundancy policy processing method, characterized in that: include: Determine verification dimensions corresponding to N policies set in the firewall, wherein the N policies respectively use corresponding verification dimensions to verify traffic data passing through the firewall; Determining a redundant strategy among the N strategies based on the verification dimensions respectively corresponding to the N strategies; Determining a policy hit rate of the redundant policy being used to verify traffic data in a predetermined time period; According to the strategy hit rate, the redundant strategy is adjusted to obtain N adjusted strategies.
2. The method according to claim 1, characterized in that The N strategies include a first strategy and a second strategy, and determining a redundant strategy among the N strategies based on verification dimensions respectively corresponding to the N strategies includes: When the verification dimension corresponding to the first policy is smaller than the verification dimension corresponding to the second policy, the first policy is determined to be the redundant policy.
3. The method according to claim 1, characterized in that The redundant strategies are adjusted according to the strategy hit rate to obtain the adjusted N strategies, including: comparing a first priority of the first policy and a second priority of the second policy; When the first priority is lower than the second priority and the policy hit rate indicates a miss, the first policy is deleted to obtain N adjusted policies.
4. The method according to claim 1, characterized in that: The method further comprises: comparing a first priority of the first policy and a second priority of the second policy; When the first priority is higher than the second priority and the policy hit rate indicates a hit, determining the number of hits of the first policy; When the number of hits is less than a predetermined number threshold, the first strategy is merged into the second strategy to obtain N adjusted strategies.
5. The method according to claim 1, characterized in that The verification dimensions corresponding to the N policies set in the firewall are determined, including: Determine the policy entry-into-force time corresponding to each of the N policies, and the calling services required when the N policies are executed for verification; Based on the policy effective times respectively corresponding to the N policies and the calling service, the verification dimensions respectively corresponding to the N policies are determined.
6. The method according to claim 1, characterized in that The determining of the strategy hit rate of the redundant strategy being used to verify the flow data in a predetermined time period includes: In the case where the redundant strategy exists in the N strategies, opening the traffic log of the firewall, wherein the traffic log is used to record log information of the traffic data passing through the firewall; Based on the traffic log, the policy hit rate is determined.
7. The method according to any one of claims 1 to 6, characterized in that: The method further comprises: Determine the network topology of the network device where the firewall is located, and the access mode of the firewall; When a change in either the network topology or the access mode is detected, the policy hit rate in the predetermined time period is reset.
8. A firewall redundancy policy processing device, characterized in that: include: A verification dimension determination module, used to determine verification dimensions corresponding to N policies set in the firewall, wherein the N policies respectively use corresponding verification dimensions to verify traffic data passing through the firewall; A redundant strategy determination module, configured to determine a redundant strategy among the N strategies based on the verification dimensions respectively corresponding to the N strategies; A hit rate determination module, used to determine the strategy hit rate of the redundant strategy used to verify the flow data in a predetermined time period; The adjustment module is used to adjust the redundant strategies according to the strategy hit rate to obtain N adjusted strategies.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored executable program, wherein when the executable program is running, the device where the computer-readable storage medium is located is controlled to execute the firewall redundancy policy processing method according to any one of claims 1 to 7.
10. An electronic device, characterized in that: include: A memory storing an executable program; A processor, configured to run the program, wherein the program executes the method according to any one of claims 1 to 7 when running.