Feature library upgrading method and device
Through the dual IPS feature library mechanism and atomic switching strategy, the problem of the IPS system entering the bypass mode during the feature library upgrade process is solved, seamless switching and effective management of the IPS feature library are realized, and network security is improved.
Patent Information
- Application Number
- CN202510295984.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-12
- Publication Date
- 2025-06-20
AI Technical Summary
During the upgrade of the feature library, the IPS system needs to enter the bypass mode, causing network traffic to bypass IPS directly, lose real-time detection and defense capabilities, and increase network security risks.
Using the dual IPS feature library mechanism and atomic switching strategy, after obtaining and verifying the feature library file, atomic switching operations are performed to switch network traffic from the current second link to the first link, ensuring that network traffic is always subject to intrusion prevention detection during the upgrade process.
It realizes seamless switching and effective management of IPS feature library to prevent security vulnerabilities during the upgrade process, ensures that the intrusion prevention system can continuously detect and intercept malicious traffic and attacks, and improves overall network security.
Smart Images

Figure CN120185874A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a method and device for upgrading a feature library. Background Art
[0002] During the feature library upgrade process of an IPS (Intrusion Prevention System), the system usually needs to enter the bypass mode, that is, network traffic bypasses the IPS and passes directly, so that the IPS cannot provide effective attack protection for a certain period of time. This interruption will not only increase network security risks, but may also damage the internal system due to undetected threats. Therefore, how to maintain the protection ability of the system during the feature library update process is a challenge that needs to be solved urgently in the industry. Summary of the Invention
[0003] To overcome the problems in the related art, this application provides a method and device for upgrading a feature library.
[0004] According to the first aspect of the embodiments of this application, a method for upgrading a feature library is provided. The method is applied to a network device, and the method includes:
[0005] Obtain a feature library file, and perform a target verification operation on the feature library file;
[0006] If the feature library file passes the target verification, upgrade the first IPS feature library according to the feature library file;
[0007] Perform an atomic switching operation to switch the network traffic flowing through the network device from the current second link to the first link, where the first link performs intrusion prevention detection on network traffic based on the first IPS feature library, and the second link performs intrusion prevention detection on network traffic based on the second IPS feature library.
[0008] According to the second aspect of the embodiments of this application, a device for upgrading a feature library is provided. The device is applied to a network device, and the device includes:
[0009] A file acquisition module, configured to obtain a feature library file and perform a target verification operation on the feature library file;
[0010] A file verification module, configured to upgrade the first IPS feature library according to the feature library file if the feature library file passes the target verification;
[0011] A switching module, configured to perform an atomic switching operation to switch the network traffic flowing through the network device from the current second link to the first link, where the first link performs intrusion prevention detection on the network traffic based on the first IPS feature library, and the second link performs intrusion prevention detection on the network traffic based on the second IPS feature library.
[0012] According to a third aspect of the embodiments of the present application, there is provided an electronic device, including:
[0013] A memory and one or more processors; the memory is coupled to the processor; wherein, computer program code is stored in the memory, and the computer program code includes computer instructions. When the computer instructions are executed by the processor, the electronic device executes the method as described above.
[0014] According to a fourth aspect of the embodiments of the present application, there is provided a computer-readable storage medium, including computer instructions. When the computer instructions run on an electronic device, the electronic device is caused to execute the method as described above.
[0015] According to a fifth aspect of the embodiments of the present application, there is provided a computer program product. When the computer program product runs on a computer, the computer is caused to execute the method as described above.
[0016] The technical solutions provided by the embodiments of the present application may include the following beneficial effects:
[0017] In the embodiments of the present application, through the dual IPS feature library mechanism and the atomic switching strategy, it is ensured that the intrusion prevention system can load and apply a new IPS feature library without interrupting the service, realizing the effective management and seamless switching of the IPS feature library, preventing security vulnerabilities from occurring during the upgrade process, and ensuring that the intrusion prevention system can continuously detect and intercept malicious traffic and attacks, thereby improving the overall network security.
[0018] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The accompanying drawings herein are incorporated into the specification and constitute a part of the present application, showing embodiments consistent with the present application and used together with the specification to explain the principles of the present application.
[0020] Figure 1 It is a schematic flowchart of a feature library upgrade method provided by an embodiment of the present application;
[0021] Figure 2 It is a schematic diagram of the implementation process of a feature library upgrade method provided by an embodiment of the present application;
[0022] Figure 3 A structural schematic diagram of a feature library upgrade device provided by an embodiment of the present application;
[0023] Figure 4 A structural schematic diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0024] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application. Among them, in the description of the embodiments of the present application, the terms used in the following embodiments are only for the purpose of describing specific embodiments, and are not intended to limit the present application.
[0025] It should be noted that "at least one" in the present application means one or more, and "a plurality" means two or more than two. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B may be singular or plural. The terms "first", "second", "third", etc. (if any) in the specification, claims and drawings of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence.
[0026] In the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific manner.
[0027] IPS plays a crucial role in modern network security. It detects and prevents potential security threats by real-time monitoring and analyzing network traffic. Among them, the IPS feature library is a resource library used to perform application identification, URL filtering, virus detection, intrusion prevention, and Web application protection on the application layer traffic passing through the device. The IPS feature library contains definitions of known attack patterns and malicious behaviors to ensure that the system can timely identify and respond to new security threats. As network attacks continue to change and develop, it is necessary to regularly update the IPS feature library to cope with newly emerging threats.
[0028] When performing an upgrade operation on the IPS feature library, the system will enter the Bypass mode. The Bypass mode allows network traffic to bypass the processing logic of the device and directly transmit at the physical level, that is, the network traffic bypasses the IPS and directly passes through, and the device only performs the forwarding function without performing intrusion prevention detection, losing the real-time detection and defense capabilities.
[0029] In view of the above problems, the present application provides a method and apparatus for upgrading a feature library.
[0030] Next, the embodiments of the present application will be described in detail.
[0031] An embodiment of the present application provides a method for upgrading a feature library, which is applied to a network device, such as Figure 1 As shown, the method may include the following steps:
[0032] Step 110: Obtain a feature library file and perform a target verification operation on the feature library file;
[0033] Step 120: If the feature library file passes the target verification, upgrade the first IPS feature library according to the feature library file;
[0034] Step 130: Perform an atomic switching operation to switch the network traffic flowing through the network device from the current second link to the first link, where the first link performs intrusion prevention detection on the network traffic based on the first IPS feature library, and the second link performs intrusion prevention detection on the network traffic based on the second IPS feature library.
[0035] The network device in this embodiment is provided with two IPS feature libraries, including the currently running second IPS feature library and the first IPS feature library for preparing and receiving new feature library files. Correspondingly, this embodiment is provided with two links. The first link performs intrusion prevention detection on the network traffic based on the first IPS feature library, and the second link performs intrusion prevention detection on the network traffic based on the second IPS feature library.
[0036] As Figure 2 As shown, before performing the feature library upgrade operation, the network traffic flows into the network device through the second link (solid arrow), and the network device performs intrusion prevention detection on the network traffic flowing in from the second link based on the second IPS feature library. After performing the atomic switching operation, the network traffic flowing through the network device is switched from the current second link to the first link, and the network device performs intrusion prevention detection on the network traffic flowing in from the first link based on the first IPS feature library.
[0037] Next, the feature library upgrade process will be introduced.
[0038] Specifically, the feature library file of the latest version or the execution version can be obtained from the upgrade server. After obtaining the feature library file, some verification work is usually performed on the feature library file. The verification content may specifically include any one or more of the following:
[0039] File integrity: Ensure that the file is not damaged during the download process by verifying the file size and hash value (such as MD5 or SHA-256);
[0040] Version information: Verify whether the version of the downloaded feature library is the latest version / specified version, and compare it with the current version;
[0041] System compatibility: Verify the compatibility of the feature library file with the current system configuration to ensure that the network device can operate normally after the feature library is upgraded;
[0042] File format: Ensure that the feature library file format is correct and not tampered with to prevent maliciously tampered or damaged files from being installed;
[0043] Dependency: Check whether the feature library file depends on other components or versions to ensure that the device environment meets the requirements.
[0044] The specific verification content can be set or adjusted according to actual needs, and this embodiment does not limit it.
[0045] It is worth mentioning that the process of verifying the feature library file mentioned above does not affect the network device from performing intrusion prevention detection on the network traffic flowing in from the second link based on the second IPS feature library.
[0046] In practical applications, a scheduled task can be set to perform the feature library upgrade, or the feature library upgrade can be performed in real time according to the user's feature library upgrade instruction. Therefore, step 110 above can be specifically executed in the following manner: When the system time reaches the preset upgrade time, or when a feature library upgrade command is received, obtain the feature library file.
[0047] For step 120, that is, the operation of upgrading the first IPS feature library according to the feature library file, after the upgrade is completed, the feature library information of the first IPS feature library can be queried, such as the version number, version release time, etc.
[0048] After step 120, the timing of performing the network traffic link switch can also be flexibly set according to the actual scenario requirements. For example, the feature library file can be obtained in advance and after passing the verification, first upgrade the first IPS feature library according to the feature library file, and then do not immediately perform the network traffic link switch operation, but wait until the appropriate time to perform the atomic switch operation, such as when the network device is idle, so as to switch the network traffic from the second link to the first link.
[0049] Therefore, as a specific implementation manner, this embodiment specifically switches the network traffic from the current second link to the first link in the following manner: When the preset condition is met, perform the atomic switch operation to switch the network traffic flowing through the network device from the current second link to the first link.
[0050] It should be noted that, to ensure the normal operation of the intrusion prevention detection system of the network device and prevent service interruption due to the upgrade of the IPS feature library, in this embodiment, the operation of switching the network traffic from the second link to the first link is designed as an atomic switching operation, that is, an indivisible switching operation that will not be interrupted or interfered with.
[0051] Finally, after the link switching is completed, as a preferred implementation manner, a function test will be run inside the network device to verify whether the first IPS feature library is working properly, such as whether it can detect known attack patterns, or whether there are problems such as too high a false alarm rate, detection anomalies, or abnormal device operation. If any problems are found during the function test, the first IPS feature library can be restored to the previous version or the factory version through the fallback mechanism, or the network traffic can be switched back from the first link to the second link. Through the function test and the fallback mechanism in this embodiment, it is ensured that the network device after switching the link can effectively perform intrusion prevention detection.
[0052] Specifically, after step 130, this embodiment further includes: monitoring the target metrics of the network device; if the target metrics reach the target threshold, then switch the network traffic flowing through the network device back from the first link to the second link.
[0053] Next, taking a specific application as an example, the feature library upgrade method of this application will be further described. It mainly includes the following steps:
[0054] Step 1: Download and verify the feature library file:
[0055] When performing the feature library upgrade, download the new version of the feature library file to the network device. Perform integrity verification (MD5) on the downloaded feature library file to ensure the accuracy and security of the data. Perform conflict detection and compatibility check on the feature library file to automatically detect compatibility issues between the new feature library and the current system configuration.
[0056] Step 2: Load the feature library file:
[0057] If all verifications pass, then load the feature library file into the first IPS feature library, and this loading process does not affect the operation of the second IPS feature library.
[0058] Step 3: Atomically switch the link:
[0059] Perform an atomic switching operation to smoothly switch the network traffic on the network device from the second link to the first link. This switching process is designed as an indivisible transaction to prevent staying in a semi-updated state in case of any errors. Before the switch, the network traffic flows into the network device from the second link, and the network device performs intrusion prevention detection on the network traffic based on the second IPS feature library. After the switch, the network traffic flows into the network device from the first link, and the network device performs intrusion prevention detection on the network traffic based on the first IPS feature library.
[0060] Step 4, Automatic rollback and recovery mechanism:
[0061] After the link switch is completed, verify the first IPS feature library (such as version, features, integrity verification). If the verification is successful, return a value, and then the system enters the monitoring period to monitor the device running status, whether the attack detection is normal, etc. If an exception occurs during the monitoring period, such as the board card restarts abnormally, the CPU is too high, or the memory occupancy is too large after the upgrade, etc., then roll back to the previous feature library version or switch the network traffic from the first link back to the second link. If any verification fails, also roll back to the previous version or switch the network traffic from the first link back to the second link.
[0062] In addition, the process of performing the feature library upgrade requires detailed logging of each operation to ensure that comprehensive auditing and traceability analysis can be carried out when problems occur.
[0063] In summary, the feature library upgrade method provided in this application aims to solve the problem that the intrusion prevention system (IPS) enters the bypass mode during the feature library upgrade, and ensure the continuity and availability of the IPS during the entire feature library update process. Specifically, this application uses a dual IPS feature library mechanism and an atomic switching strategy to ensure that the IPS can load and apply the new IPS feature library without interrupting the service. Through the effective management and seamless switching of the IPS feature library, security vulnerabilities are prevented during the upgrade process, ensuring that the intrusion prevention system can continuously detect and intercept malicious traffic and attacks, thereby enhancing the overall network security.
[0064] Through the above technologies, intrusion prevention detection can still be carried out when upgrading the feature library, which can greatly improve the stability and reliability of the device.
[0065] Based on the same inventive concept, this application also provides a feature library upgrade device. The device is applied to a network device, and its structural schematic diagram is as Figure 3 shown, and specifically includes:
[0066] A file acquisition module 310, configured to acquire a feature library file and perform a target verification operation on the feature library file;
[0067] A file verification module 320, which is configured to upgrade the first IPS feature library according to the feature library file if the feature library file passes the target verification.
[0068] A switching module 330, which is configured to perform an atomic switching operation to switch the network traffic flowing through the network device from the current second link to the first link, where the first link performs intrusion prevention detection on the network traffic based on the first IPS feature library, and the second link performs intrusion prevention detection on the network traffic based on the second IPS feature library.
[0069] As a specific implementation manner, the file verification module 320 specifically includes:
[0070] An integrity verification unit, which is configured to perform an integrity verification operation on the feature library file;
[0071] And / or, a compatibility verification unit, which is configured to perform a system compatibility verification operation on the feature library file;
[0072] And / or, a version verification unit, which is configured to perform a version verification operation on the feature library file;
[0073] And / or, a file format verification unit, which is configured to perform a file format verification operation on the feature library file.
[0074] As a specific implementation manner, the file acquisition module 310 specifically acquires the feature library file in the following manner:
[0075] When the system time reaches the preset upgrade time, or when a feature library upgrade command is received, the feature library file is acquired.
[0076] As a specific implementation manner, the switching module 330 specifically switches the network traffic from the current second link to the first link in the following manner:
[0077] When a preset condition is met, an atomic switching operation is performed to switch the network traffic flowing through the network device from the current second link to the first link.
[0078] As a specific implementation manner, the device further includes:
[0079] A fallback module, which is configured to monitor the target metrics of the network device; if the target metrics reach the target threshold, the network traffic flowing through the network device is switched back from the first link to the second link.
[0080] An embodiment of the present application provides an electronic device, which may include: a memory and one or more processors. The memory is used to store computer program code, and the computer program code includes computer instructions. When the processor executes the computer instructions, the electronic device can execute each function or step of the above method embodiment.
[0081] The structure of the electronic device may refer to Figure 4 the structure of the electronic device 100 shown.
[0082] The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0083] An embodiment of the present application also provides a computer-readable storage medium, which includes computer instructions. When the computer instructions run on an electronic device, the electronic device is enabled to execute each function or step of the above method embodiment.
[0084] The above-mentioned computer-readable storage medium includes, but is not limited to, any one of the following: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc, etc., which are various media that can store program code.
[0085] An embodiment of the present application also provides a computer program product. When the computer program product runs on a computer, the computer is enabled to execute each function or step of the above method embodiment.
[0086] Among them, the electronic device, the computer-readable storage medium, and the computer program product provided by the embodiments of the present application are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be elaborated here.
[0087] Through the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and brevity of description, only the division of the above function modules is used as an example. In actual applications, the above functions can be allocated to different function modules according to needs, that is, the internal structure of the device is divided into different function modules to complete all or part of the functions described above.
[0088] In several embodiments provided in the present application, it should be understood that the disclosed method can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of the modules or units is only a logical function division, and there can be other division methods in actual implementation; for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of the modules or units can be in electrical, mechanical or other forms.
[0089] In addition, each functional unit in various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0090] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method for updating a feature library, characterized in that: The method is applied to a network device, and the method comprises: Obtaining a signature library file, and performing a target verification operation on the signature library file; If the signature library file passes the target verification, the first IPS signature library is upgraded according to the signature library file; Perform an atomic switching operation to switch the network traffic flowing through the network device from the current second link to the first link, wherein the first link performs intrusion prevention detection on the network traffic based on the first IPS feature library, and the second link performs intrusion prevention detection on the network traffic based on the second IPS feature library.
2. The method according to claim 1, characterized in that The method specifically performs a target verification operation on the feature library file in the following manner: Performing an integrity check operation on the signature library file; and / or, performing a system compatibility check operation on the feature library file; and / or, performing a version verification operation on the feature library file; And / or, performing a file format verification operation on the feature library file.
3. The method according to claim 1, characterized in that The method specifically obtains the feature library file in the following manner: When the system time reaches the preset upgrade time, or when a signature database upgrade command is received, the signature database file is obtained.
4. The method according to claim 1, characterized in that: The method specifically switches the network traffic from the current second link to the first link in the following manner: When a preset condition is met, an atomic switching operation is performed to switch the network traffic flowing through the network device from the current second link to the first link.
5. The method according to claim 1, characterized in that The method further comprises: Monitoring target indicators of the network device; If the target indicator reaches the target threshold, the network traffic flowing through the network device is switched from the first link back to the second link.
6. A feature library upgrade device, characterized in that: The device is applied to a network device, and the device comprises: A file acquisition module, used to acquire a feature library file and perform a target verification operation on the feature library file; A file verification module, configured to upgrade the first IPS signature library according to the signature library file if the signature library file passes the target verification; A switching module is used to perform an atomic switching operation to switch the network traffic flowing through the network device from the current second link to the first link, wherein the first link performs intrusion prevention detection on the network traffic based on the first IPS feature library, and the second link performs intrusion prevention detection on the network traffic based on the second IPS feature library.
7. The device according to claim 6, characterized in that The file verification module specifically includes: An integrity checking unit, used to perform an integrity checking operation on the signature library file; and / or, a compatibility checking unit, configured to perform a system compatibility checking operation on the feature library file; and / or, a version verification unit, configured to perform a version verification operation on the feature library file; And / or, a file format verification unit, used to perform a file format verification operation on the feature library file.
8. An electronic device, characterized in that: include: A memory and one or more processors; the memory is coupled to the processor; wherein the memory stores computer program code, the computer program code includes computer instructions, and when the computer instructions are executed by the processor, the electronic device executes the method as described in any one of claims 1-5.
9. A computer-readable storage medium comprising computer instructions, characterized in that: When the computer instructions are executed on an electronic device, the electronic device is caused to execute the method according to any one of claims 1 to 5.
10. A computer program product, characterized in that When the computer program product is executed on a computer, the computer is caused to execute the method according to any one of claims 1 to 5.