Disaster recovery firewall control method, device and equipment, storage medium and program product

By simultaneously obtaining disaster recovery requirements and building firewall policies when the application system is put into production or updated, the problem of low firewall policy management efficiency in the existing technology is solved, and efficient and accurate disaster recovery drills are achieved.

CN120074919APending Publication Date: 2025-05-30INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510219827.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing technology has low efficiency in firewall strategy management in disaster recovery drills. Business personnel need to manually sort out the requirements and send them to network operation and maintenance personnel, resulting in high time consumption and easy omissions, affecting the accuracy and efficiency of the drill.

Method used

When the application system is put into production or updated, the disaster recovery requirements are obtained simultaneously and a firewall policy is built to adapt to the disaster recovery scenario, and the firewall equipment is issued. During the disaster recovery drill, you only need to issue policy implementation instructions to make the firewall policy effective and complete access control.

Benefits of technology

It improves the accuracy and efficiency of disaster recovery drills, reduces firewall management time, and avoids the tedious process of business personnel manually sorting out the needs and strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074919A_ABST
    Figure CN120074919A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a disaster recovery firewall control method and device, equipment, a storage medium and a program product, and relates to the field of financial science and technology or other related fields. The method comprises the following steps: when an application system is put into production or updated, acquiring a disaster recovery demand of the application system; based on the disaster recovery demand, determining a disaster recovery scene corresponding to the disaster recovery demand; based on the disaster recovery demand, constructing a firewall policy adapted to the disaster recovery scene; issuing the firewall policy to firewall equipment corresponding to the application system; and if the disaster recovery scene is a disaster recovery drilling scene, issuing a strategy effective instruction to the firewall equipment when drilling of the disaster recovery scene is carried out on the application system, so as to trigger the firewall strategy to take effect, and enable the firewall equipment to carry out access control based on the firewall strategy. According to the method, the efficiency of disaster recovery drill is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of fintech or other related fields, and in particular, to a disaster recovery firewall control method, device, equipment, storage medium, and program product. Background Art

[0002] During the production process of an application system, in order to ensure the uninterrupted operation of the application system, a production environment and a disaster recovery environment are required. Among them, the production environment is used to undertake the daily operation of the application system, and the disaster recovery environment is used to undertake the operation of the application system when the production environment fails. In order to ensure that the disaster recovery environment can operate normally when the production environment fails, it is necessary to conduct drills on the disaster recovery environment. During the drill of the disaster recovery environment, the firewall plays a key role. On the one hand, based on the requirements of the drill, the firewall needs to open policies to ensure the normal progress of the drill; on the other hand, the firewall can prevent potential risks during the drill from threatening the production environment.

[0003] Currently, the main method for managing firewall policies is that before the drill, business personnel manually sort out access requirements, and network operation and maintenance personnel open policies manually based on these requirements. In this method, it is time-consuming and laborious for business personnel to manually sort out requirements and it is easy to miss some. It takes time for network operation and maintenance personnel to manually open policies, and the efficiency is low, which may lead to the failure of the drill.

[0004] Therefore, how to improve the efficiency of disaster recovery drills is an urgent problem to be solved. Summary of the Invention

[0005] The present application provides a disaster recovery firewall control method, device, equipment, storage medium, and program product to improve the efficiency of disaster recovery drills.

[0006] In a first aspect, the present application provides a disaster recovery firewall control method, including:

[0007] When an application system is put into production or updated, obtaining the disaster recovery requirements of the application system;

[0008] Based on the disaster recovery requirements, determining the disaster recovery scenario corresponding to the disaster recovery requirements;

[0009] Based on the disaster recovery requirements, constructing a firewall policy adapted to the disaster recovery scenario;

[0010] Sending the firewall policy to the firewall device corresponding to the application system;

[0011] If the disaster recovery scenario is a disaster recovery drill scenario, when conducting a drill on the disaster recovery scenario of the application system, sending a policy activation instruction to the firewall device to trigger the activation of the firewall policy, so that the firewall device performs access control based on the firewall policy.

[0012] In a second aspect, the present application provides a disaster recovery firewall control device, including:

[0013] An acquisition module, configured to acquire the disaster recovery requirements of the application system when the application system is put into production or updated;

[0014] A determination module, configured to determine a disaster recovery scenario corresponding to the disaster recovery requirements based on the disaster recovery requirements;

[0015] A construction module, configured to construct a firewall policy adapted to the disaster recovery scenario based on the disaster recovery requirements;

[0016] A first distribution module, configured to distribute the firewall policy to the firewall device corresponding to the application system;

[0017] A second distribution module, configured to, when the disaster recovery scenario is a disaster recovery drill scenario, during the drill of the disaster recovery scenario for the application system, send a policy effectiveness instruction to the firewall device to trigger the firewall policy to take effect, so that the firewall device performs access control based on the firewall policy.

[0018] In a third aspect, the present application provides an electronic device, including: a processor and a memory communicatively connected to the processor;

[0019] The memory stores computer-executable instructions;

[0020] The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of the first aspect.

[0021] In a fourth aspect, the present application provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, they are used to implement the method according to any one of the first aspect.

[0022] In a fifth aspect, the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the method according to any one of the first aspect.

[0023] The disaster recovery firewall control method, device, equipment, storage medium and program product provided by the present application synchronously distribute the firewall policy required for the disaster recovery environment to the firewall device when the application system is put into production or updated, and only need to make the firewall policy take effect during the disaster recovery drill to complete the disaster recovery drill. Compared with the prior art method in which business personnel need to sort out requirements before the drill and send this requirement to network operation and maintenance personnel for manual activation, the present application improves the accuracy of the disaster recovery drill, and can reduce the management time of the disaster recovery drill firewall, improving the efficiency of the disaster recovery drill. Description of the Drawings

[0024] The accompanying drawings here are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with this application, and are used together with the specification to explain the principles of this application.

[0025] Figure 1 It is a schematic diagram of the network architecture of an application system;

[0026] Figure 2 It is a schematic flowchart of a disaster recovery firewall control method provided by this application;

[0027] Figure 3 It is a schematic structural diagram of a disaster recovery firewall control device provided by an embodiment of this application;

[0028] Figure 4 It is a schematic structural diagram of an electronic device provided by an embodiment of this application.

[0029] Through the above-mentioned accompanying drawings, specific embodiments of this application have been shown, and there will be more detailed descriptions hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of this application in any way, but to illustrate the concept of this application to those skilled in the art by referring to specific embodiments. Detailed Embodiments

[0030] Exemplary embodiments will be described in detail here, and the examples are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. On the contrary, they are merely examples of devices and methods consistent with some aspects of this application as detailed in the appended claims.

[0031] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Moreover, the processing of relevant data, such as collection, storage, use, processing, transmission, provision, disclosure, and application, all comply with the relevant laws, regulations, and standards of relevant countries and regions, adopt necessary confidentiality measures, do not violate public order and good customs, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0032] Moreover, the present application involves big data analysis of user information (including but not limited to personal biometric features, identity data, consumption data, asset data, electronic terminal operation data, etc.), and uses artificial intelligence technology for automated decision-making. For a technical solution that makes a decision having a significant impact on personal rights and interests based on the results of automated decision-making, an operation entry is provided for the user to choose to agree or reject the results of automated decision-making; if the user chooses to reject, the expert decision-making process will be entered.

[0033] It should be noted that a disaster recovery firewall control method, device, equipment, storage medium and program product provided by the present application can be used in the field of financial technology or other related fields, and the application fields of a disaster recovery firewall control method, device, equipment, storage medium and program product in the present application are not limited.

[0034] First, the terms and concepts involved in the embodiments of the present application will be described and explained as follows:

[0035] Application system: An application system can be a comprehensive information processing platform integrating high-performance hardware and advanced software technologies, aiming to meet specific business needs and provide efficient and reliable services.

[0036] Production environment: The production environment refers to the environment that undertakes the daily business operation of the application system. The production environment is responsible for key tasks such as processing requests, storing and updating data.

[0037] Disaster recovery environment: The disaster recovery environment is an environment specifically designed to undertake the business operation of the application system when the production environment fails. It usually maintains a data state that is synchronized or nearly synchronized with the production environment to ensure that it can quickly take over the business when needed, guarantee the continuity of the application system business and the integrity of data. Usually, the disaster recovery environment does not undertake daily business to reduce resource occupancy and potential interference. However, when problems occur in the production environment, the disaster recovery environment will be quickly started to ensure the normal operation of the application system.

[0038] Live drill: A live drill is a drill method carried out in the disaster recovery environment, which undertakes the real business process. During the live drill, the disaster recovery environment will simulate the actual business scenarios of the production environment, process real business data, and simulate various possible failure situations. Through the live drill, the performance of the disaster recovery environment in real business scenarios can be tested, including the processing capacity of the system, the integrity of data and the continuity of business. This drill method helps to discover potential problems and bottlenecks, and provides valuable experience and data for actual disaster recovery.

[0039] Pressure test drill: The pressure test drill simulates the pressure situation of the production environment by playing back the recorded real traffic in the disaster recovery environment. Before the drill, the real traffic data for a period of time in the production environment will be recorded, including various request types, data volume, response time, etc. Then, these data are played back in the disaster recovery environment to simulate the pressure scenario of the production environment. Through the pressure test drill, the performance of the disaster recovery environment under pressure can be tested, including the system's response time, throughput, resource utilization, etc. This drill method helps to evaluate the pressure resistance of the disaster recovery environment and provides guidance for optimizing system performance.

[0040] Firewall: The firewall can be deployed at the boundary of the application system and can include hardware firewalls and / or software firewalls. A hardware firewall is a physical device, and a software firewall is a software program installed on the hardware device. The firewall can protect the security of the application system by monitoring and controlling network traffic and ensuring that only legal and authorized traffic can access the application system according to predefined security rules.

[0041] Figure 1 As a schematic diagram of the network architecture of an application system, as Figure 1 shown, this network architecture includes: a production environment, a disaster recovery environment, and a firewall device. The application system can be deployed on a server cluster and can run either in the production environment or in the disaster recovery environment. The firewall device enables the switching between the production environment and the disaster recovery environment through policy activation.

[0042] During the disaster recovery drill, the firewall plays a crucial role. On the one hand, as a key component of network security, the firewall can activate relevant access requirements according to the policies constructed for the disaster recovery drill; on the other hand, the firewall can also ensure the isolation between the drill environment and the production environment, avoiding any potential risks during the drill from threatening the production environment. Therefore, the management of the disaster recovery drill firewall is of great importance.

[0043] Currently, the management method of the disaster recovery drill firewall mainly relies on the cumbersome steps before the drill. First, the business personnel carefully sort out the access requirements of the disaster recovery drill and send this requirement to the network operation and maintenance personnel, who then activate the corresponding firewall policies based on this requirement.

[0044] During this process, due to the complexity and diversity of the application system, its access requirements often involve multiple levels and details. Therefore, it is not only time-consuming and laborious for the business personnel to sort out the access requirements of the disaster recovery drill before the drill, but also very easy to miss something, which will then affect the accuracy of the disaster recovery drill.

[0045] Moreover, after receiving the access requirements for the disaster recovery drill, network operation and maintenance personnel need to manually open policies according to the access requirements of the disaster recovery drill, which takes a long time and results in low efficiency of the disaster recovery drill.

[0046] Therefore, a disaster recovery firewall control method, device, equipment, storage medium and program product provided by this application synchronously send the firewall policies required for the disaster recovery environment to the firewall device when the application system is put into production or updated. During the disaster recovery drill, only making the firewall policies effective can complete the disaster recovery drill. Compared with the prior art method in which business personnel need to sort out requirements before the drill and send this requirement to network operation and maintenance personnel for manual opening, this application improves the accuracy of the disaster recovery drill, and can reduce the management time of the disaster recovery drill firewall, improving the efficiency of the disaster recovery drill.

[0047] The execution subject of the disaster recovery firewall control method provided by this application can be a management device or system that manages the firewall, or a device or system that processes the production or update of the application system. The following takes the management device as an example for illustration.

[0048] The following uses specific embodiments to elaborate in detail on the technical solution of this application and how the technical solution of this application solves the above technical problems. These several specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of this application will be described below in conjunction with the drawings.

[0049] Figure 2 It is a schematic flowchart of a disaster recovery firewall control method provided by this application, as Figure 2 shown, this method includes:

[0050] S101. When the application system is put into production or updated, obtain the disaster recovery requirements of the application system.

[0051] Optionally, the production of the application system can be the process of deploying the developed and tested application system to the production environment. The update of the application system can be operations such as function upgrade, performance optimization or security repair for the already produced application system.

[0052] Optionally, the disaster recovery requirements may include any one or more of a source address, a target address, a timestamp, etc. Optionally, the source address may be the address of the device that initiates communication or data transmission during a disaster recovery drill. The target address may be the address of the device that receives communication or data transmission during a disaster recovery drill. The address mentioned here may be, for example, an Internet Protocol (IP) address, or a MAC address, etc., which uniquely identifies the device. Optionally, the timestamp may be the time period of the disaster recovery drill. For example, 4:00 - 16:00, or it may not be time - limited and have such disaster recovery requirements at any time.

[0053] Optionally, the disaster recovery requirements may be provided by business personnel. There is no limitation on how the management device obtains the disaster recovery requirements provided by business personnel. For example, during the production launch phase of an application system, the disaster recovery requirements of the application system may be carried in the production launch configuration of the application system. That is, the management device may receive the production launch configuration of the application system, and the production launch configuration includes the disaster recovery requirements. During the application system update phase, the disaster recovery requirements of the application system may be carried in the application system update configuration. That is, the management device may receive the update configuration of the application system, and the update configuration includes the disaster recovery requirements.

[0054] For another example, the disaster recovery requirements of the application system may also be indicated to the management device through a separate message or information. Or, they are synchronized between business personnel and the managers corresponding to the management device through other synchronization channels and manually input into the management device by the managers, etc.

[0055] S102. Based on the disaster recovery requirements, determine the disaster recovery scenario corresponding to the disaster recovery requirements.

[0056] Optionally, the disaster recovery scenario may be a scenario of normal operation in the disaster recovery environment. For example, it may be a regular scenario that undertakes the daily business operations of the application system, or a drill scenario required for a disaster recovery drill.

[0057] Optionally, the drill scenario required for a disaster recovery drill may be set according to the requirements of the disaster recovery drill. As mentioned above, the drill scenario required for a disaster recovery drill may be a drill scenario of a live drill that undertakes a real business process, or a drill scenario of a pressure drill that replays the recorded real traffic in the disaster recovery environment to simulate the pressure situation of the production environment.

[0058] Through the disaster recovery drill, potential problems existing in the disaster recovery environment can be discovered in a timely manner, so that the problems existing in the disaster recovery environment can be corrected in a timely manner, enabling the disaster recovery environment to run the application system instead of the production environment when a failure occurs in the production environment, and ensuring the normal operation of the business of the application system.

[0059] Optionally, the information carried in the disaster recovery requirement may be the disaster recovery scenario corresponding to the disaster recovery requirement. This information may be, for example, specific parameters or information specifically used to indicate the disaster recovery scenario.

[0060] For example, the disaster recovery scenario corresponding to the disaster recovery requirement can be determined based on the source address in the disaster recovery requirement. For example, the disaster recovery scenario corresponding to the disaster recovery requirement within the specified source address range is the on-load drill scenario; the disaster recovery scenario corresponding to the disaster recovery requirement can also be determined based on the timestamp in the disaster recovery requirement. For example, the disaster recovery scenario that is available at any time without time limitation is the regular scenario.

[0061] For example, the disaster recovery requirement carries a disaster recovery scenario label, and different labels correspond to different disaster recovery scenarios. Therefore, the corresponding disaster recovery scenario can be determined through the disaster recovery scenario label.

[0062] It should be understood that the present application does not limit the division dimension of the above-mentioned disaster recovery scenario. For example, the disaster recovery scenario can be a scenario for the entire disaster recovery environment, a disaster recovery scenario divided based on the business line of the application system, or a disaster recovery scenario divided based on other dimensions. Taking the business line as an example, when the disaster recovery scenario refers to the disaster recovery scenario of a certain business line, in this implementation manner, it can be configured separately for the business line. That is, based on the disaster recovery requirement, the management device can construct a firewall policy that adapts to the disaster recovery scenario of the business line.

[0063] Exemplarily, the management device can determine the disaster recovery scenario corresponding to the disaster recovery requirement and the business line based on the disaster recovery requirement. The method for determining the business line based on the disaster recovery requirement is not limited. For example, the disaster recovery requirement may carry a label representing the business line, or the corresponding business line can be identified through specific target parameters, etc.

[0064] The embodiments of the present application can determine the disaster recovery scenario corresponding to the disaster recovery requirement and the business line based on the disaster recovery requirement, and construct an adapted firewall policy for each business line, which can ensure that each business line has a targeted firewall policy to protect its data security and business continuity, ensure the accuracy of the disaster recovery drill, and improve the efficiency of the disaster recovery drill.

[0065] S103. Based on the disaster recovery requirement, construct a firewall policy that adapts to the disaster recovery scenario.

[0066] The above-mentioned firewall policy refers to the policy used by the firewall device for access control of the application system. For example, the management device can search for a firewall policy that meets the disaster recovery requirement from the firewall policy library based on the disaster recovery requirement. If it cannot be found, the firewall policy close to the disaster recovery requirement can be rewritten to obtain a firewall policy that meets the disaster recovery requirement.

[0067] The above-mentioned firewall policy library can be a policy library constructed by experts based on their experience, or a library constructed based on the firewall policies configured for the firewall devices of multiple systems in the past, or a library constructed based on the firewall policies used by the application system in the past, etc.

[0068] Optionally, the management device can also generate a firewall policy adapted to the disaster recovery scenario by adopting the generation method of the firewall policy based on the disaster recovery requirements.

[0069] S104. Send the firewall policy to the firewall device corresponding to the application system.

[0070] Optionally, the sending process can include any one or more of locating the firewall device, importing the firewall policy adapted to the disaster recovery scenario into the firewall device, checking whether there are errors or warning messages in the firewall policy, and testing the firewall policy to verify the effectiveness of the firewall policy.

[0071] It should be noted that this sending process can be to store the firewall policy in the firewall device corresponding to the application system, and the activation of the firewall policy can be indicated by other instructions to trigger its activation when the firewall policy needs to be executed.

[0072] S105. If the disaster recovery scenario is a disaster recovery drill scenario, when conducting a disaster recovery scenario drill on the application system, send a policy activation instruction to the firewall device to trigger the activation of the firewall policy, so that the firewall device performs access control based on the firewall policy.

[0073] The policy activation methods of different types of firewalls are different. Therefore, the policy activation instruction can be sent according to the type of the firewall device.

[0074] Exemplarily, if the firewall of the application system is a hardware firewall, a policy activation instruction carrying the disaster recovery firewall policy activation timestamp is sent to the firewall device. The concept of the timestamp is the same as that mentioned above and will not be elaborated here. That is, in this implementation manner, after receiving the activation instruction, the firewall device updates the timestamp carried in the instruction to the corresponding firewall policy to trigger the activation of the firewall policy.

[0075] If the firewall of the application system is a software firewall, a policy activation instruction carrying the disaster recovery firewall policy activation label is sent to the firewall device. For example, the policy activation instruction of the disaster recovery firewall policy activation label can be a label of activation or non-activation.

[0076] The embodiments of the present application can issue different disaster recovery firewall policy activation instructions to the firewall device according to the firewall type of the application system, improving the applicability of disaster recovery drills, enabling precise control and flexible management of the activation of disaster recovery firewall policies, and ensuring that the disaster recovery firewall policies can be automatically activated according to the predetermined time and conditions.

[0077] When the application system is put into production or updated, the embodiments of the present application synchronously issue the firewall policies required for the disaster recovery environment to the firewall device. During the disaster recovery drill, only activating the firewall policies can complete the disaster recovery drill. Compared with the prior art method where business personnel need to sort out requirements before the drill and send this requirement to network operation and maintenance personnel for manual activation, the present application adjusts the sorting of requirements and the operation of policy configuration from before the drill to the time of production or update. Thus, during the disaster recovery drill, only activating the firewall policies can smoothly and correctly conduct the disaster recovery drill, improving the accuracy of the disaster recovery drill and reducing the management time for the disaster recovery drill firewall, thereby improving the efficiency of the disaster recovery drill.

[0078] The following further illustrates how to construct firewall policies adapted to disaster recovery scenarios based on disaster recovery requirements through several disaster recovery scenarios:

[0079] The first scenario: The disaster recovery scenario is a live drill scenario.

[0080] As described above, in the live drill scenario, the disaster recovery environment will simulate the actual business scenario of the production environment, process real business data, and simulate various possible failure situations. Therefore, when the disaster recovery scenario is a live drill scenario, the firewall load-bearing configuration and firewall general configuration historically constructed by the firewall device may include the target configuration for this live drill scenario.

[0081] Therefore, if the disaster recovery scenario is a live drill scenario, the management device can obtain the firewall load-bearing configuration and firewall general configuration historically constructed by the firewall device from the firewall's database.

[0082] Optionally, the historically constructed firewall load-bearing configuration may be the firewall load-bearing configuration included in the firewall's database before constructing the firewall policy adapted to the disaster recovery scenario this time. The historically constructed firewall general configuration may be the firewall general configuration included in the firewall's database before constructing the firewall policy adapted to the disaster recovery scenario this time.

[0083] After obtaining the historically constructed firewall load-bearing configuration and firewall general configuration, the management device can determine whether there is a target configuration in the historically constructed firewall load-bearing configuration and firewall general configuration that meets the disaster recovery requirements.

[0084] Optionally, the target configuration can be compared with the firewall on-load configuration and the firewall general configuration built historically. If the firewall on-load configuration and the firewall general configuration built historically contain the target configuration, the management device can build a disaster recovery firewall policy adapted to the on-load drill scenario based on the target configuration.

[0085] If the firewall on-load configuration and the firewall general configuration built historically do not contain the target configuration, the management device generates a firewall on-load configuration based on the disaster recovery requirements, and builds a disaster recovery firewall policy adapted to the on-load drill scenario based on the generated firewall on-load configuration.

[0086] Optionally, the construction of the disaster recovery firewall policy adapted to the on-load drill scenario is the same as described above, and will not be elaborated here.

[0087] In the embodiment of this application, taking the on-load drill scenario as an example, based on the disaster recovery requirements, the target configuration of the disaster recovery requirements is compared with the firewall on-load configuration and the firewall general configuration built historically, and then a firewall policy adapted to the disaster recovery scenario is built. Compared with the method in the prior art that each time it is necessary to sort out the disaster recovery requirements for different disaster recovery requirements and then open the policy, this application utilizes the existing firewall configuration information, avoids repetitive work, and improves efficiency.

[0088] The second scenario: The disaster recovery scenario is a pressure drill scenario.

[0089] As described above, the pressure drill simulates the pressure situation of the production environment by playing back the recorded real traffic in the disaster recovery environment. In order to prevent data from flowing into the disaster recovery environment from the production environment, if the disaster recovery scenario is a pressure drill scenario, the management device generates a rejection policy between the disaster recovery environment and the production environment based on the disaster recovery requirements.

[0090] Optionally, the rejection policy can ensure that during the pressure drill, the data in the disaster recovery environment will not accidentally flow into the production environment, ensuring the data security of the production environment.

[0091] The management device inserts the rejection policy before the regular policy to build a disaster recovery firewall policy adapted to the pressure drill scenario.

[0092] Optionally, the instruction to insert this rejection policy before the regular policy can be included in the rejection policy. This rejection policy and the regular policy together constitute a disaster recovery firewall policy adapted to the pressure drill scenario.

[0093] In the embodiment of this application, taking the pressure drill scenario as an example, based on the disaster recovery requirements, a rejection policy is generated between the disaster recovery environment and the production environment, effectively isolating the data flow between the disaster recovery environment and the production environment, preventing the risk of data leakage or contamination that may be brought by the drill, and thus ensuring the data security of the production environment.

[0094] The third scenario: The disaster recovery scenario is a regular scenario.

[0095] If the disaster recovery scenario is a live drill scenario, the management device can obtain the firewall regular configuration historically built by the firewall device from the firewall's database. This historically built firewall regular configuration is the same as the above and will not be elaborated here.

[0096] Optionally, the management device can compare the configuration required for this regular scenario with the historically built firewall regular configuration. If the historically built firewall regular configuration contains the configuration required for this regular scenario, then based on the configuration required for this regular scenario, a regular firewall policy adapted to the regular drill scenario is built.

[0097] If the historically built firewall regular configuration does not have the configuration required for this regular scenario, the management device generates a firewall regular configuration based on the disaster recovery requirements, and based on the generated firewall regular configuration, builds a regular firewall policy adapted to the regular drill scenario.

[0098] The regular firewall policy adapted to the regular drill scenario is sent to the firewall device corresponding to the application system, and a policy activation instruction is sent to the firewall device to trigger the activation of the regular firewall policy. Optionally, the method of sending the disaster recovery firewall policy to the firewall device corresponding to the application system is the same as the above and will not be elaborated here.

[0099] In the embodiment of the present application, taking the regular scenario as an example, a regular firewall policy adapted to the regular drill scenario is built according to the disaster recovery requirements, and these policies are sent to the firewall device corresponding to the application system, and at the same time, a policy activation instruction is sent to ensure that the regular firewall policy takes effect immediately, which can ensure that in the disaster recovery drill, the firewall device of the application system has the correct security policy configuration. Compared with the problem of missing requirements in the process of business personnel sorting out disaster recovery requirements in the prior art, the present application can have complete disaster recovery requirements, improve the accuracy of disaster recovery requirements in the disaster recovery drill, and ensure the smooth progress of the disaster recovery drill.

[0100] The present application exemplarily provides the above three scenarios. It should be noted that the present application does not limit the disaster recovery scenario corresponding to the disaster recovery requirements.

[0101] The above is the method embodiment provided by the present application. Next, the device provided by the present application will be described.

[0102] Figure 3 It is a schematic structural diagram of a disaster recovery firewall control device provided by an embodiment of the present application. As Figure 3 shown, the disaster recovery firewall control device 200 may include, for example: an acquisition module 201, a determination module 202, a construction module 203, a first sending module 204, and a second sending module 205.

[0103] An acquisition module 201, configured to acquire the disaster recovery requirements of an application system when the application system is put into production or updated.

[0104] A determination module 202, configured to determine a disaster recovery scenario corresponding to the disaster recovery requirements based on the disaster recovery requirements.

[0105] A construction module 203, configured to construct a firewall policy adapted to the disaster recovery scenario based on the disaster recovery requirements.

[0106] A first distribution module 204, configured to distribute the firewall policy to the firewall device corresponding to the application system.

[0107] A second distribution module 205, configured to, when the disaster recovery scenario is a disaster recovery drill scenario, during the drill of the disaster recovery scenario of the application system, send a policy activation instruction to the firewall device to trigger the activation of the firewall policy, so that the firewall device performs access control based on the firewall policy.

[0108] Optionally, the acquisition module 201 is specifically configured to receive the production configuration or update configuration of the application system, where the production configuration or the update configuration includes disaster recovery requirements.

[0109] Optionally, the construction module 203 is specifically configured to, when the disaster recovery scenario is a live drill scenario, obtain the historical firewall live configuration and firewall normal configuration constructed by the firewall device from a database; determine whether there is a target configuration that meets the disaster recovery requirements among the historical firewall live configuration and firewall normal configuration; when there is a target configuration that meets the disaster recovery requirements among the historical firewall live configuration and firewall normal configuration, construct a disaster recovery firewall policy adapted to the live drill scenario based on the target configuration; when there is no target configuration that meets the disaster recovery requirements among the historical firewall live configuration and firewall normal configuration, generate a firewall live configuration based on the disaster recovery requirements, and construct a disaster recovery firewall policy adapted to the live drill scenario based on the generated firewall live configuration.

[0110] Optionally, the construction module 203 is specifically configured to, when the disaster recovery scenario is a stress drill scenario, generate a rejection policy between the disaster recovery environment and the production environment based on the disaster recovery requirements; insert the rejection policy before the normal policy to construct a disaster recovery firewall policy adapted to the stress drill scenario.

[0111] Optionally, the construction module 203 is specifically configured to, when the disaster recovery scenario is a normal scenario, construct a normal firewall policy adapted to the normal drill scenario based on the disaster recovery requirements; the first distribution module 204 is specifically configured to distribute the normal firewall policy to the firewall device corresponding to the application system, and the second distribution module 205 is specifically configured to send a policy activation instruction to the firewall device to trigger the activation of the normal firewall policy.

[0112] Optionally, the second sending module 205 is specifically configured to send a policy activation instruction carrying a disaster recovery firewall policy activation timestamp to the firewall device when the firewall of the application system is a hardware firewall; and send a policy activation instruction carrying a disaster recovery firewall policy activation label to the firewall device when the firewall of the application system is a software firewall.

[0113] Optionally, the determination module 202 is specifically configured to determine, based on the disaster recovery requirement, the disaster recovery scenario corresponding to the disaster recovery requirement and the business line; and the construction module 203 is specifically configured to construct a firewall policy for the business line to adapt to the disaster recovery scenario based on the disaster recovery requirement.

[0114] The disaster recovery firewall control device provided in this embodiment can execute the method provided in any of the above method embodiments, and its implementation principle and technical effects are similar, which will not be elaborated here in this embodiment.

[0115] Figure 4 This is a schematic structural diagram of an electronic device provided in an embodiment of the present application. As Figure 4 shown, the electronic device 400 may include: a memory 401 and a processor 402. Optionally, the electronic device may further include a transceiver 403. Among them, the memory 401 and the processor 402 communicate with each other; exemplarily, the memory 401, the processor 402, and the transceiver 403 may communicate through a communication bus 404. The memory 401 is used to store a computer program, and the processor 402 executes the computer program to implement the method of the above embodiment.

[0116] Optionally, the above-mentioned processor may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. Combining the steps in the method embodiments disclosed in the present application can be directly embodied as being executed by a hardware processor, or implemented by a combination of hardware and software modules in the processor.

[0117] The embodiment of the present application also provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, the methods in any of the above method embodiments are implemented.

[0118] The embodiments of the present application also provide a computer program product, including a computer program which, when executed by a processor, implements the methods in any of the above method embodiments.

[0119] All or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a readable memory. When the program is executed, it performs the steps including the above method embodiments; and the foregoing memory (storage medium) includes: read-only memory (ROM), RAM, flash memory, hard disk, solid-state drive, magnetic tape, floppy disk, optical disc, and any combination thereof.

[0120] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processing unit of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processing unit of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0121] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0122] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are performed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0123] Obviously, those skilled in the art can make various modifications and variations to the embodiments of this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of the embodiments of this application fall within the scope of the claims of this application and their equivalent technologies, this application also intends to include these modifications and variations.

[0124] In this application, the term "including" and its variations may refer to non-limiting inclusion; the term "or" and its variations may refer to "and / or". In this application, terms such as "first", "second", etc. are used to distinguish similar objects and do not necessarily have to be used to describe a specific order or sequence. In this application, "a plurality of" means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally indicates that the associated objects before and after are in an "or" relationship.

Claims

1. A disaster recovery firewall control method, characterized in that: include: When an application system is put into production or updated, obtain the disaster recovery requirements of the application system; Based on the disaster recovery requirement, determining a disaster recovery scenario corresponding to the disaster recovery requirement; Based on the disaster recovery requirements, a firewall strategy adapted to the disaster recovery scenario is constructed; Sending the firewall policy to the firewall device corresponding to the application system; If the disaster recovery scenario is a disaster recovery drill scenario, when the disaster recovery scenario is drilled for the application system, a policy effectiveness instruction is issued to the firewall device to trigger the firewall policy to take effect, so that the firewall device performs access control based on the firewall policy.

2. The method according to claim 1, characterized in that The obtaining of the disaster recovery requirements of the application system includes: A production configuration or an updated configuration of the application system is received, wherein the production configuration or the updated configuration includes a disaster recovery requirement.

3. The method according to claim 1, characterized in that The step of constructing a firewall strategy adapted to the disaster recovery scenario based on the disaster recovery requirement includes: If the disaster recovery scenario is a load drill scenario, the firewall load configuration and firewall general configuration historically constructed by the firewall device are obtained from the database; Determine whether the historically constructed firewall load configuration and firewall conventional configuration meet the target configuration of the disaster recovery requirement; If yes, then based on the target configuration, a disaster recovery firewall strategy adapted to the load drill scenario is constructed; If not, a firewall load configuration is generated based on the disaster recovery requirement, and a disaster recovery firewall strategy adapted to the load drill scenario is constructed based on the generated firewall load configuration.

4. The method according to claim 1, characterized in that The step of constructing a firewall strategy adapted to the disaster recovery scenario based on the disaster recovery requirement includes: If the disaster recovery scenario is a stress drill scenario, a rejection strategy between the disaster recovery environment and the production environment is generated based on the disaster recovery requirements; The rejection policy is inserted before the conventional policy to construct a disaster recovery firewall policy adapted to the stress drill scenario.

5. The method according to claim 1, characterized in that The step of constructing a firewall strategy adapted to the disaster recovery scenario based on the disaster recovery requirement includes: If the disaster recovery scenario is a conventional scenario, then based on the disaster recovery requirements, a conventional firewall policy adapted to the conventional drill scenario is constructed; The step of sending the disaster recovery firewall policy to a firewall device corresponding to the application system includes: The conventional firewall policy is sent to the firewall device corresponding to the application system, and a policy effectiveness instruction is sent to the firewall device to trigger the conventional firewall policy to take effect.

6. The method according to any one of claims 1 to 5, characterized in that: The sending of the policy effectiveness instruction to the firewall device includes: If the firewall of the application system is a hardware firewall, a policy effectiveness instruction carrying a disaster recovery firewall policy effectiveness timestamp is issued to the firewall device; If the firewall of the application system is a software firewall, a policy effectiveness instruction carrying a disaster recovery firewall policy effectiveness tag is sent to the firewall device.

7. The method according to any one of claims 1 to 5, characterized in that: The determining, based on the disaster recovery requirement, a disaster recovery scenario corresponding to the disaster recovery requirement includes: Based on the disaster recovery requirement, determine the disaster recovery scenario and business line corresponding to the disaster recovery requirement; The step of constructing a firewall strategy adapted to the disaster recovery scenario based on the disaster recovery requirement includes: Based on the disaster recovery requirements, a firewall policy is constructed for the business line to adapt to the disaster recovery scenario.

8. A disaster recovery firewall control device, comprising: An acquisition module is used to acquire the disaster recovery requirements of the application system when the application system is put into production or updated; A determination module, used to determine a disaster recovery scenario corresponding to the disaster recovery requirement based on the disaster recovery requirement; A construction module, used to construct a firewall strategy adapted to the disaster recovery scenario based on the disaster recovery requirements; A first issuing module, used for issuing the firewall policy to the firewall device corresponding to the application system; The second sending module is used to send a policy effectiveness instruction to the firewall device when the disaster recovery scenario is a disaster recovery drill scenario and when the application system is rehearsing the disaster recovery scenario to trigger the firewall policy to take effect, so that the firewall device performs access control based on the firewall policy.

9. An electronic device, characterized in that: include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when executed by a processor.

11. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 7 when being executed by a processor.