Method and device for configuring firewall of baseboard management controller, and medium

By conducting threat detection and risk assessment of BMC's network access data, and dynamically generating and updating firewall rules, the problem that traditional BMC firewall configuration solutions are difficult to adapt to rapidly changing network threats, significantly improving the security protection capabilities of the server.

CN120151081APending Publication Date: 2025-06-13JINAN INSPUR DATA TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510442569.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The traditional bottom board management controller (BMC) firewall configuration solution is difficult to update dynamically during operation, and cannot effectively deal with rapidly changing network threat environments, resulting in insufficient security protection capabilities.

Method used

By obtaining BMC's network access data, threat detection is carried out to identify network threats, conduct risk assessments, and generate corresponding firewall rules based on the evaluation results, and dynamically update the BMC's firewall configuration.

Benefits of technology

It realizes dynamic updates of BMC firewalls, which can more effectively deal with rapidly changing network threats and improve server security protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151081A_ABST
    Figure CN120151081A_ABST
Patent Text Reader

Abstract

The invention discloses a baseboard management controller firewall configuration method and device and a medium, relates to the technical field of data security, is used for realizing dynamic configuration of a BMC firewall, and aims to solve the problem that a traditional BMC firewall configuration scheme lacks an effective active defense mechanism so that the security protection capability is insufficient. The invention provides a baseboard management controller firewall configuration method. Threat detection is carried out on the network access data to identify network threats different from normal network behaviors, further risk assessment is carried out, and different response strategies are adopted based on the risk of the network threats. And finally, generating a corresponding firewall rule according to the response strategy matched with the network threat. And deploying the newly generated firewall rule into the BMC firewall to complete dynamic updating. According to the method, the BMC configuration setting efficiency of the server can be effectively improved, meanwhile, the cost and risk of manual intervention are reduced, and the overall safety of the server is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and in particular, to a method, device and medium for configuring a firewall of a baseboard management controller. Background Art

[0002] Nowadays, with the continuous evolution of network attack means, the security management of servers faces huge challenges. As a key component of a server, the security of the baseboard management controller (BMC) directly affects the overall security of the server.

[0003] However, most of the current BMC firewall configuration schemes are configured once during deployment and will not change unless redeployed during the subsequent operation of the BMC. Such a static configuration scheme is difficult to adapt to the rapidly changing network threat environment and is easily breached by illegal attackers. As a result, the BMC, as the core component of the server, has become a shortcoming in the server security field, which is not conducive to the improvement of the server security protection ability.

[0004] Therefore, those skilled in the art now urgently need a method for configuring a firewall of a baseboard management controller to solve the problem of insufficient security protection ability of the traditional BMC firewall configuration scheme. Summary of the Invention

[0005] The purpose of the present invention is to provide a method, device and medium for configuring a firewall of a baseboard management controller to solve the problem of insufficient security protection ability of the traditional BMC firewall configuration scheme.

[0006] To solve the above technical problems, the present invention provides a method for configuring a firewall of a baseboard management controller, including:

[0007] Obtaining network access data of the baseboard management controller;

[0008] Performing threat detection on the network access data to identify network threats;

[0009] Performing risk assessment on the network threats and generating corresponding firewall rules according to the risk assessment results;

[0010] Deploying the newly generated firewall rules to the firewall of the baseboard management controller.

[0011] In a possible embodiment, the performing threat detection on the network access data to identify network threats includes:

[0012] Analyze the behavior patterns of network entities in the network access data through a behavior analysis tool, and compare them with a preset normal behavior baseline to classify network behaviors into trusted network behaviors and untrusted network behaviors;

[0013] Identify suspicious behaviors in the trusted network behaviors through anomaly detection algorithms and signature matching algorithms;

[0014] Among them, the network threats include the untrusted network behaviors and the suspicious behaviors.

[0015] In a possible embodiment, the risk assessment of the network threats and the generation of corresponding firewall rules according to the risk assessment results include:

[0016] Conduct a risk assessment on the network threats to determine the threat level and threat type of the network threats;

[0017] Determine the threat level as the default risk level of the network threats; among them, the threat level and the risk level include, from low to high: the first level, the second level, and the third level;

[0018] Obtain a preset list of concerned threat types and a list of high-risk threat types;

[0019] If the threat type corresponding to the network threat belongs to the threat types in the list of concerned threat types, the risk level of the network threat is increased by one level on the basis of the threat level; among them, when the risk level is the third level, the risk level after the increase is still the third level;

[0020] If the threat type corresponding to the network threat belongs to the threat types in the list of high-risk threat types, the risk level of the network threat is updated to the third level;

[0021] According to the risk level, match corresponding response strategies for the network threats; among them, the response strategies include: the first strategy, the second strategy, and the third strategy; the risk level corresponding to the first strategy is the first level, and the first strategy includes: alarm; the risk level corresponding to the second strategy is the second level, and the second strategy includes: alarm and isolation; the risk level corresponding to the third strategy is the third level, and the third strategy includes: alarm and blocking;

[0022] Generate the firewall rules according to the corresponding response strategies.

[0023] In a possible embodiment, the steps of detecting threats to the network access data to identify network threats, and the steps of performing a risk assessment on the network threats and generating corresponding firewall rules according to the risk assessment results are implemented by a pre-trained unsupervised learning model;

[0024] And after deploying the newly generated firewall rules to the firewall of the baseboard management controller, the method further includes:

[0025] Obtaining the response result after the deployment of the firewall rules;

[0026] Adjusting the parameters and weight coefficients of the application algorithm in the unsupervised learning model according to the response result.

[0027] In a possible embodiment, during the training process of the unsupervised learning model, labeled data is added as training sample data;

[0028] Wherein, the labeled data includes: the network traffic data labeled as normal and the network traffic data labeled as abnormal.

[0029] In a possible embodiment, the obtaining of the network access data of the baseboard management controller includes:

[0030] Collecting the network traffic data, system logs, application logs and security events of the baseboard management controller as the network access data.

[0031] In a possible embodiment, after collecting the network traffic data, system logs, application logs and security events of the baseboard management controller, it further includes:

[0032] Cleaning the collected data to remove duplicate data and invalid data in the data;

[0033] Performing format conversion on the cleaned data to unify the formats of the data obtained from different data sources;

[0034] Performing feature extraction on the data after format conversion, and using the extracted data features as the network traffic data.

[0035] To solve the above technical problems, the present invention also provides a baseboard management controller firewall configuration device, including:

[0036] A data acquisition module, configured to acquire network access data of a baseboard management controller;

[0037] A threat detection module, configured to perform threat detection on the network access data to identify network threats;

[0038] A risk assessment module for performing a risk assessment on the network threats and generating corresponding firewall rules according to the risk assessment results;

[0039] A rule configuration module for deploying the newly generated firewall rules to the firewall of the baseboard management controller.

[0040] To solve the above technical problems, the present invention also provides a baseboard management controller firewall configuration device, including:

[0041] A memory for storing a computer program;

[0042] A processor for implementing the steps of the above-mentioned baseboard management controller firewall configuration method when executing the computer program.

[0043] To solve the above technical problems, the present invention also provides a non-volatile storage medium, on which a computer program is stored, and the computer program realizes the steps of the above-mentioned baseboard management controller firewall configuration method when executed by a processor.

[0044] The baseboard management controller firewall configuration method provided by the present invention obtains the network access data of the BMC, then performs threat detection on the network access data of the BMC to identify abnormal or suspicious behaviors different from normal network behaviors. Furthermore, these are used as network threats for further risk assessment to evaluate the risk level of each network threat, so as to adopt different response strategies for different network threats according to the risk level. Therefore, finally, corresponding firewall rules can be generated according to the response strategies matched for the network threats. And the newly generated firewall rules are deployed to the firewall of the BMC to complete the dynamic update of the BMC firewall. Thus, it solves the defects brought by the current static configuration scheme of the BMC firewall, such as being difficult to adapt to the rapidly changing network threat environment and being easily overcome by illegal attackers, and provides better protection for the security protection ability of the server.

[0045] The baseboard management controller firewall configuration device and the non-volatile storage medium provided by the present invention correspond to the above method and have the same effect. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] To more clearly illustrate the embodiments of the present invention, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0047] Figure 1 It is a flowchart of a baseboard management controller firewall configuration method provided by an embodiment of the present invention;

[0048] Figure 2 A flowchart of network threat identification provided by an embodiment of the present invention;

[0049] Figure 3 A structural diagram of a baseboard management controller firewall configuration device provided by an embodiment of the present invention;

[0050] Figure 4 A structural diagram of another baseboard management controller firewall configuration device provided by an embodiment of the present invention. Detailed implementation manners

[0051] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present invention.

[0052] The core of the present invention is to provide a baseboard management controller firewall configuration method, device and medium.

[0053] In order to enable those skilled in the art to better understand the solution of the present invention, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.

[0054] With the continuous evolution of network attack means, the security management of servers faces huge challenges. As a key component of the server, the security of the baseboard management controller (BMC) directly affects the overall security of the server. Traditional network security measures are difficult to meet the current security requirements, and the BMC as a server component has become a shortcoming in the security field. Currently, most of the BMC firewall configuration methods are static configurations, which will not change after being configured once, too passive to adapt to the rapidly changing network threat environment, and are easily conquered by illegal attackers, which is not conducive to ensuring the data security of the server.

[0055] To solve the above problems, the present invention provides a baseboard management controller firewall configuration method, as Figure 1 shown, including:

[0056] S11: Obtain the network access data of the baseboard management controller.

[0057] S12: Perform threat detection on the network access data to identify network threats.

[0058] S13: Perform risk assessment on the network threats and generate corresponding firewall rules according to the risk assessment results.

[0059] S14: Deploy the newly generated firewall rules to the firewall of the baseboard management controller.

[0060] Among them, the network access data obtained in step S11 can specifically be the network traffic data of the BMC. By collecting the network access data of the BMC in real time, it is possible to analyze whether there are network threats, which is conducive to dynamically updating the firewall rules of the BMC in the subsequent steps.

[0061] Furthermore, in addition to network traffic data, other data that can reflect the network security or network data interaction of the BMC can also be used to assist in identifying network threats. Based on this, this embodiment provides a possible implementation solution for network access data. The above step S11 is specifically:

[0062] Collect the network traffic data, system logs, application logs, and security events of the baseboard management controller as network access data.

[0063] That is, as Figure 2 shown, this embodiment integrates various data information related to BMC network communication, such as network traffic data, system logs, application logs, and security events, as the intelligence source to obtain network access data that is more comprehensive and closer to the actual network situation during the operation of the BMC. Thus, when identifying network threats and updating firewall rules through network access data subsequently, it is possible to more accurately identify the network threats currently faced by the BMC and update the firewall rules accordingly to bring a better security protection effect.

[0064] Furthermore, since this embodiment ensures that the network access data used for network threat analysis and firewall rule update contains more comprehensive and accurate BMC network data by integrating multiple data sources. However, precisely because multiple intelligence sources are involved simultaneously, there may be differences in data formats between different intelligence sources, which brings difficulties to the subsequent network threat identification work. In addition, the same data may be recorded between different intelligence sources, and this duplicate and redundant data is also not conducive to subsequent network threat analysis, which will greatly slow down the efficiency of network threat identification. Even in the implementation solution of training a model through machine learning algorithms to identify network threats, a large amount of duplicate data in the sample data will seriously affect the training effect of the model, resulting in the inability to guarantee the identification accuracy when identifying network threats in network access data subsequently, that is, resulting in insufficient protection capabilities for the BMC to update firewall rules. In addition, the large amount of data brought by multiple intelligence sources also poses a great challenge to the subsequent network threat identification work in terms of data volume.

[0065] Based on the above problems, this embodiment also provides a possible implementation. After step S11 and before step S12, the method further includes:

[0066] S141: Clean the collected data to remove duplicate and invalid data from the data.

[0067] S142: Perform format conversion on the cleaned data to unify the formats of the data obtained from different data sources.

[0068] S143: Extract features from the data after format conversion, and use the extracted data features as network traffic data.

[0069] In this embodiment, after obtaining the network access data, the obtained network access data is also preprocessed. Specifically, the preprocessing process includes three steps: data cleaning, format conversion, and feature extraction. Among them, data cleaning is used to clean the duplicate and invalid data in the data obtained from the above four intelligence sources. On the one hand, it can effectively reduce the data volume of the obtained network access data and reduce the load size of the subsequent step S12 for network threat analysis. On the other hand, clearing the redundant and invalid data in the data is also beneficial to preventing these data from contaminating the sample data. In the implementation scenario of network threats through machine learning models and other methods, it can improve the training effect of the model and ensure the accuracy of network threat recognition. Format conversion is used to unify the formats of the data obtained from different intelligence sources, so as to facilitate the subsequent identification of network threats. For feature extraction, it is to further extract features from the data after cleaning and format conversion. Extract features that are helpful for threat detection, thereby further reducing the data volume and making the data features more obvious, which is beneficial to the accuracy of subsequent network threat identification.

[0070] In addition, for step S12. Step S12 is one of the core steps of this method, and it is used to identify the real-time and dynamically changing network threats faced by the BMC during actual operation by analyzing the network access data obtained in the above step S11.

[0071] Among them, for how to identify network threats from network access data, it can be achieved through behavior analysis tools, anomaly detection algorithms, signature matching algorithms, etc. This embodiment does not limit this. However, this embodiment provides a possible implementation. The above step S12 is specifically

[0072] S121: Analyze the behavior patterns of network entities in the network access data through a behavior analysis tool, and compare them with a preset normal behavior baseline to classify the network behavior into trusted network behavior and untrusted network behavior.

[0073] S122: Identify suspicious behaviors in trusted network behaviors through anomaly detection algorithms and signature matching algorithms.

[0074] Among them, as Figure 2 shown, network threats include untrusted network behaviors and suspicious behaviors.

[0075] In this embodiment, three methods, namely behavior analysis, anomaly detection, and signature matching, are adopted to identify network threats. First, use a behavior analysis tool to analyze the behavior patterns of each network entity in the network access data and compare them with a preset normal behavior baseline, so as to identify abnormal behaviors that are different from normal behaviors. That is, as in the above step S121, the network behaviors of all network entities in the network access data are specifically divided into trusted network behaviors and untrusted network behaviors. Among them, trusted network behaviors are network behaviors that conform to the normal behavior baseline, while untrusted network behaviors are network behaviors that do not conform to the normal behavior baseline.

[0076] Furthermore, after the network behaviors in the network access data are initially screened and distinguished by the behavior analysis tool in step S121. This embodiment further performs network threat identification on the trusted network behaviors that have been screened once in step S121. Specifically, as in step S122, potential threats are further identified through anomaly detection algorithms and signature matching algorithms, and the suspicious behaviors in the trusted network behaviors are screened out, and together with the untrusted network behaviors, they are used as the identified network threats.

[0077] This embodiment uses multiple network threat analysis methods to identify network threats in network access data at multiple levels, with higher accuracy. And the efficiency is higher than that of several network threat analysis methods implemented separately. This improvement in efficiency brings about an improvement in the timeliness of subsequent firewall rule updates, so as to adapt to the constantly changing actual situation during the real-time operation of BMC, and prevent the analyzed network threats from being "outdated" due to too low network threat analysis efficiency, which is beneficial to ensuring the security protection effect of the subsequent firewall rules generated based on network threats.

[0078] Then, it corresponds to step S13. Step S13 is the step of generating corresponding firewall rules according to the network threats analyzed in step S12, and is also one of the core steps of this method. It is not difficult to understand that there are already mature solutions for common network threats. Therefore, when the identified network threats belong to common network threats, the specific firewall rules can be converted through existing solutions to achieve the purpose of step S13.

[0079] Furthermore, for step S13, this embodiment also provides another possible implementation scheme. The above step S13 specifically further includes:

[0080] S131: Conduct a risk assessment on network threats to determine the threat level and threat type of the network threats.

[0081] S132: Determine the threat level as the default risk level of the network threat.

[0082] Among them, the threat level and the risk level include, from low to high: the first level, the second level, and the third level.

[0083] S133: Obtain a preset list of concerned threat types and a list of high-risk threat types.

[0084] S134: If the threat type corresponding to the network threat belongs to the threat types in the list of concerned threat types, the risk level of the network threat is raised by one level on the basis of the threat level.

[0085] Among them, when the risk level is the third level, the risk level after the increase is still the third level.

[0086] S135: If the threat type corresponding to the network threat belongs to the threat types in the list of high-risk threat types, the risk level of the network threat is updated to the third level.

[0087] S136: According to the risk level, match corresponding response strategies for the network threat.

[0088] Among them, the response strategies include: the first strategy, the second strategy, and the third strategy. The risk level corresponding to the first strategy is the first level, and the first strategy includes: alarm. The risk level corresponding to the second strategy is the second level, and the second strategy includes: alarm and isolation. The risk level corresponding to the third strategy is the third level, and the third strategy includes: alarm and blocking.

[0089] S137: Generate firewall rules according to the corresponding response strategies.

[0090] As can be seen from the above steps, a BMC firewall rule generation solution provided in this embodiment obtains specific risk levels by conducting a risk assessment on specific network threats. Adaptive processing is performed for different risk levels through preset different response strategies, that is, firewall rules for the network threat are generated based on the response strategy matched with the network threat. After all the network threats identified in step S12 are generated corresponding firewall rules through the above process, the overall firewall rules are the firewall rules finally deployed to the BMC in step S14.

[0091] In addition, in the risk assessment, this embodiment also incorporates the consideration that different scenarios have different protection requirements for different types of network threats. It is not difficult to understand that even the same BMC has different levels of emphasis on different network threats in different application scenarios. Based on this characteristic, when this embodiment conducts a risk assessment of network threats, in addition to the threat level that is the default risk level, it also analyzes and obtains the threat types of network threats. Based on the actual scenario requirements during the current operation of the BMC (i.e., the list of threat types to be concerned about and the list of high-risk threat types), it is determined whether the threat type of the network threat is a high-risk threat type that the current operation scenario is concerned about or attaches importance to. If so, the risk level of the network threat is adaptively adjusted so that the risk assessment result of the network threat can better meet the different needs of the actual application scenario and bring better security protection capabilities.

[0092] In addition, it should be noted that since the threat level is the default risk level, its level order is the same as the risk level. And when it is necessary to increase the risk level of the current network threat based on the threat type, there may be a situation where the threat level of the current network threat has reached the highest level, that is, the third level. At this time, there is no higher level for the risk level, so it remains the third level after the increase.

[0093] It is not difficult to understand that the number of different levels in the risk level and the threat level corresponds to the preset response strategies. There can be as many different risk levels as there are response strategies corresponding to different risk levels. However, it should be noted that the one-to-one relationship between the above-mentioned response strategies and risk levels is only one possible implementation. In other embodiments, the relationship between the response strategies and risk levels can also be one-to-many or many-to-one, and this embodiment does not limit this here.

[0094] On the other hand, similar to the above embodiment, if the risk level can be increased to adapt to the actual scenario needs based on the threat level, then the risk level can also be decreased to adapt to the actual scenario needs based on the threat level. Based on this, this embodiment also provides a possible implementation:

[0095] Step S133 further includes: obtaining a preset list of low-risk threat types and a list of expert strategy threat types.

[0096] And before step S137 of this method, it further includes:

[0097] S138: If the threat type corresponding to the network threat belongs to the threat types in the list of low-risk threat types, the risk level of this network threat is decreased by one level based on the threat level.

[0098] Among them, when the risk level is the first level, the risk level remains the first level after the decrease.

[0099] S139: If the threat type corresponding to the network threat belongs to the threat types in the expert strategy threat type list, skip generating the firewall rule for this network threat.

[0100] Among them, the low-risk threat type list is similar to the above-mentioned concerned threat type list in principle. The difference is that one raises the risk level and the other lowers the risk level. However, for the expert strategy threat type list, it should be noted that in the actual application process, special strategy designs for certain threat types may be made by experts based on some special needs. That is, more effective firewall rules have been adopted for some specific threat types in the current BMC. In the above process, in order to adapt to more network threats with fewer response strategies, several preset response strategies have made certain concessions in terms of protection capabilities for generality considerations. The protection effect for specific network threats is usually not as good as that of the firewall rules designed specifically by experts or other means. At this time, for these network threats for which the firewall rules have been specifically configured, this embodiment no longer updates the BMC firewall rules through several preset general response strategies to avoid covering or destroying the original firewall rules designed specifically by experts, which can better ensure the security protection capabilities.

[0101] Finally, for step S14, it is the step of deploying the firewall rules generated in step S13 to the BMC to take effect. Since there are currently various mature technical solutions for the firewall deployment and update of the BMC, and the present invention does not involve the improvement of the BMC firewall deployment process itself, this embodiment will not elaborate on it here.

[0102] In summary, a method for configuring a baseboard management controller firewall provided by the present invention can effectively improve the efficiency of server BMC configuration settings by real-time monitoring network threats and analyzing threat information based on multiple algorithms, automatically generating and deploying firewall rules. This method can also reduce the cost and risk of manual intervention, avoid the deficiency in security protection capabilities of manually statically configuring the BMC firewall, significantly improve the security and response speed of the BMC, and increase the overall security of the server.

[0103] On the other hand, for the identification of network threats, risk assessment, and generation of firewall rules in the above embodiments, this embodiment also provides a further implementation:

[0104] The above steps S12 and S13, as well as the further methods of steps S12 and S13 in some embodiments, are all implemented through a pre-trained unsupervised learning model.

[0105] Moreover, after step S14 of this method, it further includes:

[0106] S15: Obtain the response result after the firewall rules are deployed.

[0107] S16: Adjust the parameters and weight coefficients of the applied algorithms in the unsupervised learning model according to the response result.

[0108] As can be seen from the above, this embodiment uses a feedback learning mechanism to optimize the accuracy of the above method in identifying network threats, evaluating risk levels, and generating firewall rules. Specifically, the above steps S12 and S13 are implemented through an unsupervised learning model to adapt to deep learning scenarios such as network threat identification, risk assessment, and firewall rule generation, where it is not easy to pre-annotate training data in advance. Furthermore, the unsupervised learning algorithm can adapt to changes in the network environment and automatically adjust the detection model to cope with new threats. This enables the firewall to continuously protect the network from evolving cyberattacks, thereby reducing false positives (misidentifying normal behavior as a threat) and false negatives (failing to detect a real threat), and improving the accuracy of threat detection. Moreover, it can continuously improve the protection effect of the corresponding firewall rules generated based on network threats, thereby further enhancing the overall security protection ability of the server.

[0109] In addition, the implementation scheme of using the unsupervised learning algorithm to implement the above steps S12 and S13 provided in this embodiment also well adapts to the above needs for network threat identification. Specifically, one of the unsupervised learning algorithms - the clustering algorithm - can cluster network traffic data into different groups, and each group represents a specific network behavior pattern. In this way, it is easier to identify abnormal network behaviors because they usually do not belong to any known normal behavior groups. That is, the unsupervised learning model based on the clustering algorithm can well meet the requirements of analyzing the behavior patterns of each network entity in the network access data through a behavior analysis tool in the above step S12, and then comparing with the normal behavior baseline to identify network threats, bringing a more accurate identification effect.

[0110] In addition, since the unsupervised learning model in this embodiment uses other algorithms in addition to network threat identification (and even other methods are used in network threat identification besides the behavior analysis tool), this embodiment can also combine multiple unsupervised learning algorithms (such as statistical-based methods, distance-based methods, density-based methods, etc.) to establish an unsupervised learning model when designing the unsupervised learning model, providing better algorithms for different functions (network threat identification, risk assessment, firewall rule generation) that the unsupervised learning model needs to perform, thereby bringing more accurate calculation results and being beneficial to further enhancing the security protection ability of the server.

[0111] On the other hand, based on the implementation of the above embodiments, which realizes network threat identification, risk assessment, and firewall rule generation involved in steps S12 and S13 through an unsupervised learning model, this embodiment further provides a possible implementation:

[0112] During the training process of the unsupervised learning model, labeled data is added as training sample data.

[0113] Among them, the labeled data includes: network traffic data labeled as normal and network traffic data labeled as abnormal.

[0114] As can be seen from the above, this method further combines the supervised learning method on the basis of the unsupervised learning method, thereby realizing a semi-supervised learning algorithm. It can take into account the advantages of higher accuracy of supervised learning and the advantage that the unsupervised learning algorithm does not rely on pre-data annotation. That is, it can use a small amount of labeled data to guide the unsupervised learning process to further improve the accuracy of the prediction results of the unsupervised learning model, and will not bring too much data annotation pressure to the operation and maintenance personnel, better meeting the needs of the actual application scenario.

[0115] In addition to the embodiments of the method for configuring the firewall of the baseboard management controller provided in the above embodiments, the present invention also provides an embodiment corresponding to a computer program product. A computer program product includes computer programs / instructions, and when the computer programs / instructions are executed by a processor, the steps of the method for configuring the firewall of the baseboard management controller described in any of the above embodiments can be implemented.

[0116] Since the embodiments of the computer program product part correspond to the embodiments of the method part, for the embodiments of the computer program product part, please refer to the description of the embodiments of the method part, and will not be elaborated here for the time being.

[0117] In the above embodiments, a method for configuring the firewall of the baseboard management controller is described in detail. The present invention also provides an embodiment corresponding to a device for configuring the firewall of the baseboard management controller. It should be noted that the present invention describes the embodiments of the device part from two perspectives, one is from the perspective of functional modules, and the other is from the perspective of hardware.

[0118] From the perspective of functional modules, this embodiment provides a device for configuring the firewall of the baseboard management controller, as Figure 3 shown, including:

[0119] A data acquisition module 11, configured to acquire network access data of the baseboard management controller;

[0120] A threat detection module 12, configured to perform threat detection on the network access data to identify network threats;

[0121] A risk assessment module 13 for performing a risk assessment on network threats and generating corresponding firewall rules according to the risk assessment results;

[0122] A rule configuration module 14 for deploying the newly generated firewall rules to the firewall of the baseboard management controller.

[0123] Since the embodiments in the device part correspond to the embodiments in the method part, for the descriptions of the embodiments in the device part, please refer to the descriptions of the embodiments in the method part, which will not be elaborated here.

[0124] A baseboard management controller firewall configuration device provided in this embodiment obtains the network access data of the BMC, then performs threat detection on the network access data of the BMC to identify abnormal or suspicious behaviors different from normal network behaviors. Further, these are used as network threats for further risk assessment to evaluate the risk level of each network threat, so as to adopt different response strategies for different network threats according to the risk level. Therefore, finally, corresponding firewall rules can be generated according to the response strategies matched for the network threats. And the newly generated firewall rules are deployed to the firewall of the BMC to complete the dynamic update of the BMC firewall. Thus, the defects caused by the current static configuration scheme of the BMC firewall, such as being difficult to adapt to the rapidly changing network threat environment and being easily breached by illegal attackers, are solved, and better protection is provided for the security protection ability of the server.

[0125] Figure 4 The structural diagram of a baseboard management controller firewall configuration device provided in another embodiment of the present invention is as Figure 4 shown. A baseboard management controller firewall configuration device includes: a memory 20 for storing computer programs;

[0126] A processor 21 for implementing the steps of a baseboard management controller firewall configuration method as described in the above embodiment when executing the computer program.

[0127] A baseboard management controller firewall configuration device provided in this embodiment may include, but is not limited to, a mobile terminal, a personal computer, a workstation, etc.

[0128] Among them, the processor 21 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 21 may be implemented in at least one hardware form of a digital signal processor (DSP), a field-programmable gate array (FPGA), and a programmable logic array (PLA). The processor 21 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the wake state, also known as the central processing unit (CPU); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 21 may be integrated with a graphics processing unit (GPU), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 21 may further include an artificial intelligence (AI) processor, and the AI processor is used to process computational operations related to machine learning.

[0129] The memory 20 may include one or more computer-readable storage media, and the computer-readable storage media may be non-transitory. The memory 20 may further include high-speed random access memory and non-volatile memory, such as one or more disk storage devices and flash storage devices. In this embodiment, the memory 20 is at least used to store the following computer program 201. After the computer program is loaded and executed by the processor 21, it can implement the relevant steps of a baseboard management controller firewall configuration method disclosed in any of the foregoing embodiments. In addition, the resources stored in the memory 20 may further include an operating system 202 and data 203, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system 202 may include Windows, Unix, Linux, etc. The data 203 may include, but is not limited to, a baseboard management controller firewall configuration method, etc.

[0130] In some embodiments, a baseboard management controller firewall configuration device may further include a display screen 22, an input / output interface 23, a communication interface 24, a power supply 25, and a communication bus 26.

[0131] Those skilled in the art can understand that Figure 4 the structure shown in

[0132] A baseboard management controller firewall configuration device provided by an embodiment of the present invention includes a memory and a processor. When the processor executes the program stored in the memory, the following method can be implemented: a baseboard management controller firewall configuration method.

[0133] A baseboard management controller firewall configuration device provided in this embodiment realizes, by the processor executing a computer program stored in the memory, obtaining network access data of the BMC, then performing threat detection on the network access data of the BMC to identify abnormal or suspicious behaviors different from normal network behaviors therein. Furthermore, taking them as network threats for further risk assessment, evaluating the risk level of each network threat, so as to adopt different response strategies for different network threats according to the risk level. Therefore, finally, according to the response strategies matched for the network threats as described above, corresponding firewall rules can be generated. And deploy the newly generated firewall rules to the firewall of the BMC to complete the dynamic update of the BMC firewall. Thus, it solves the defects brought by the current static configuration scheme of the BMC firewall, such as being difficult to adapt to the rapidly changing network threat environment and being easily conquered by illegal attackers, and brings better protection for the security protection ability of the server.

[0134] Finally, the present invention also provides an embodiment corresponding to a non-volatile storage medium. A computer program is stored on the non-volatile storage medium, and when the computer program is executed by the processor, the steps recorded in the method embodiment as described above are implemented.

[0135] It can be understood that if the method in the above embodiment is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a non-volatile storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and executes all or part of the steps of the methods described in various embodiments of the present invention. And the aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0136] A non-volatile storage medium provided in this embodiment, when the computer program stored therein is executed, can obtain the network access data of the BMC, and then perform threat detection on the network access data of the BMC to identify abnormal or suspicious behaviors different from normal network behaviors. Furthermore, use them as network threats for further risk assessment to evaluate the risk level of each network threat, so as to adopt different response strategies for different network threats according to the risk level. Therefore, finally, according to the response strategies matched for the network threats as described above, corresponding firewall rules can be generated. And deploy the newly generated firewall rules to the firewall of the BMC to complete the dynamic update of the BMC firewall. Thus, it solves the defects brought by the current static configuration scheme of the BMC firewall, such as being difficult to adapt to the rapidly changing network threat environment and being easily overcome by illegal attackers, and brings better protection for the security protection ability of the server.

[0137] The above has introduced in detail a method, device and medium for configuring a firewall of a baseboard management controller provided by the present invention. The various embodiments in the specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method part. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements and modifications can still be made to the present invention, and these improvements and modifications also fall within the protection scope of the present invention.

[0138] It should also be noted that in this specification, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.

Claims

1. A method for configuring a baseboard management controller firewall, characterized in that: include: Get the network access data of the baseboard management controller; Performing threat detection on the network access data to identify network threats; Performing risk assessment on the network threats and generating corresponding firewall rules according to the risk assessment results; The newly generated firewall rules are deployed to the firewall of the baseboard management controller.

2. The baseboard management controller firewall configuration method according to claim 1, characterized in that: The performing threat detection on the network access data to identify the network threat includes: Analyzing the behavior patterns of network entities in the network access data by using a behavior analysis tool, and comparing them with a preset normal behavior baseline to classify the network behaviors into trusted network behaviors and untrusted network behaviors; Identify suspicious behaviors in the trusted network behaviors through anomaly detection algorithms and signature matching algorithms; The network threats include the untrusted network behaviors and the suspicious behaviors.

3. The baseboard management controller firewall configuration method according to claim 1, characterized in that: The performing risk assessment on the network threat and generating corresponding firewall rules according to the risk assessment result includes: Conducting risk assessment on the network threat to determine the threat level and threat type of the network threat; Determine the threat level as the default risk level of the network threat; wherein the threat level and the risk level include, from low to high, a first level, a second level, and a third level; Get the preset list of threat types of concern and the list of high-risk threat types; If the threat type corresponding to the network threat belongs to the threat type in the list of concerned threat types, the risk level of the network threat is increased by one level based on the threat level; wherein, when the risk level is the third level, the risk level after the increase is still the third level; If the threat type corresponding to the network threat belongs to the threat type in the high-risk threat type list, the risk level of the network threat is updated to the third level; According to the risk level, a corresponding response strategy is matched for the network threat; wherein the response strategy includes: a first strategy, a second strategy and a third strategy; the risk level corresponding to the first strategy is the first level, and the first strategy includes: alarm; the risk level corresponding to the second strategy is the second level, and the second strategy includes: alarm and isolation; the risk level corresponding to the third strategy is the third level, and the third strategy includes: alarm and blocking; The firewall rules are generated according to the corresponding response strategy.

4. The baseboard management controller firewall configuration method according to claim 1, characterized in that: The step of performing threat detection on the network access data to identify network threats, and the step of performing risk assessment on the network threats and generating corresponding firewall rules according to the risk assessment results are implemented by a pre-trained unsupervised learning model; After deploying the newly generated firewall rule to the firewall of the baseboard management controller, the method further includes: Obtaining a response result after the firewall rule is deployed; The parameters and weight coefficients of the algorithm applied in the unsupervised learning model are adjusted according to the response results.

5. The baseboard management controller firewall configuration method according to claim 4, characterized in that: In the training process of the unsupervised learning model, adding labeled data as training sample data; The marked data includes: the network traffic data marked as normal and the network traffic data marked as abnormal.

6. The method for configuring a baseboard management controller firewall according to any one of claims 1 to 5, characterized in that: The obtaining of network access data of the baseboard management controller comprises: The network traffic data, system logs, application logs and security events of the baseboard management controller are collected as the network access data.

7. The baseboard management controller firewall configuration method according to claim 6, characterized in that: After collecting the network traffic data, system logs, application logs and security events of the baseboard management controller, the following steps are also included: Clean the collected data to remove duplicate and invalid data; Convert the cleaned data into a unified format to unify the data formats obtained from different data sources; Feature extraction is performed on the format-converted data, and the extracted data features are used as the network traffic data.

8. A baseboard management controller firewall configuration device, characterized in that: include: A data acquisition module, used to acquire network access data of the baseboard management controller; A threat detection module, used to perform threat detection on the network access data to identify network threats; A risk assessment module, used to perform risk assessment on the network threat and generate corresponding firewall rules according to the risk assessment results; A rule configuration module is used to deploy the newly generated firewall rules to the firewall of the baseboard management controller.

9. A baseboard management controller firewall configuration device, characterized in that: include: Memory for storing computer programs; A processor is used to implement the steps of the baseboard management controller firewall configuration method as described in any one of claims 1 to 7 when executing the computer program.

10. A non-volatile storage medium, characterized in that: The non-volatile storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the baseboard management controller firewall configuration method according to any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Security configuration information updating method and electronic equipment

    CN121530772A