Firewall policy management method based on risk prediction

By establishing a risk sub-model of communication paths and dynamically correcting firewall policies, the risk problems of cumbersome management processes and misconfiguration of traditional firewall policies are solved, and the security of data access is improved.

CN120200826APending Publication Date: 2025-06-24HUANENG INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510468995.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The traditional firewall policy management process is cumbersome, resulting in a reduced policy adjustment effect. As the network size and complexity increase, the risk of configuration errors increases, affecting timeliness, and may even lead to data breaches and property losses.

Method used

By establishing a risk sub-model of each communication path, the attack risk is periodically predicted, and the firewall policy is dynamically corrected according to the prediction results, the abnormal conflict rules are eliminated, and the sub-firewall policy setting order is adjusted.

Benefits of technology

Improves the efficiency of firewall policy management, enhances the security of data access, reduces the risk of configuration errors, and avoids data leakage and property losses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200826A_ABST
    Figure CN120200826A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of firewalls, in particular to a firewall policy management method based on risk prediction. Comprising the following steps: establishing a plurality of data sub-domains, and establishing a plurality of communication paths according to all the data sub-domains; generating an expected risk parameter of each communication path according to a preset risk prediction model; setting firewall parameters of each communication path according to all the expected risk parameters, periodically predicting attack risks of each communication path by establishing a risk sub-model of each communication path, and dynamically correcting firewall policies on each communication path according to a plan result; therefore, the risk identification and filtering efficiency of each communication path is ensured, when the firewall parameter of a single communication path is set, the selected sub-firewall strategy is preprocessed, abnormal conflict rules in the sub-firewall strategy are eliminated, and the setting sequence of each sub-firewall strategy is dynamically adjusted, so that the risk identification and filtering efficiency of each communication path is ensured. The filtering efficiency and the filtering precision of the access data are ensured, and the security of data access is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of firewalls, and particularly to a firewall policy management method based on risk prediction. Background Art

[0002] The application of firewalls is currently very extensive. As an important part of the network security infrastructure, firewalls play an irreplaceable role in security protection work. However, due to the continuous changes in the business environment, firewalls need to flexibly adjust their configuration parameters and policy parameters according to new threats, business requirements, and the evolution of the network topology structure to ensure the security and effectiveness of the network.

[0003] Currently, in the management process of traditional firewall policies, it usually relies on technicians to perform manual operations for addition. However, when technicians add firewall policies manually, due to the cumbersome process, the effectiveness of the adjusted firewall policies may be reduced. In addition, with the continuous increase in the scale and complexity of the network, the risk of firewall policy configuration errors also increases accordingly, affecting its timeliness and even causing problems such as the leakage of company data and property losses. Summary of the Invention

[0004] The purpose of this application is: To solve the above technical problems, this application provides a firewall policy management method based on risk prediction, aiming to improve the management efficiency of firewall policies and enhance the security of data access.

[0005] In some embodiments of this application, by establishing risk sub-models for each communication path to periodically predict the attack risks of each communication path, and dynamically correcting the firewall policies on each communication path according to the prediction results, the risk identification and filtering efficiency of each communication path are ensured, and the security of data access is improved.

[0006] In some embodiments of this application, when setting the firewall parameters of a single communication path, preprocess the selected sub-firewall policies, eliminate the abnormal conflict rules therein, and at the same time, by dynamically adjusting the setting order of each sub-firewall policy, ensure the filtering efficiency and filtering accuracy for accessing data, and improve the security of data access.

[0007] In some embodiments of this application, a firewall policy management method based on risk prediction is provided, including: Establish multiple data sub-domains, and establish multiple communication paths based on all the data sub-domains; Generate the expected risk parameters of each communication path according to a preset risk prediction model; Set the firewall parameters of each communication path according to all the expected risk parameters; Among them, it further includes: Establish a sequence of sub - firewall policies A, A=(a1, a2…a i …a n ), where a i is the i - th sub - firewall policy; n is the number of sub - firewall policies; Each single sub - firewall policy includes multiple filtering rules; Establish a sequence of communication paths B, B=(b1, b2…b i …b m ), where b i is the i - th communication path; m is the number of communication paths.

[0008] In some embodiments of the present application, when presetting the risk prediction model, it includes: Set bi as the target communication path in sequence according to the communication path sequence B; Establish a risk sub - model of the target communication path according to historical parameters; Generate risk sub - models of each communication path in sequence; Establish a sequence of risk sub - models C, C=(c1, c2…c i …c m ), where c i is the risk sub - model of the i - th communication path; m is the number of communication paths; Establish a risk prediction model according to the sequence of risk sub - models C.

[0009] In some embodiments of the present application, when generating the expected risk parameters of each communication path, it includes: Set b i as the target communication path in sequence according to the communication path sequence B; Generate a prediction evaluation value f of the target communication path at the current prediction time node; Set the time interval between the current prediction time node and the next prediction time node according to the prediction evaluation value f; Establish an adjustment period of the target communication path at the current prediction time node; Generate the expected risk parameters of the target communication path within the adjustment period according to the risk prediction model.

[0010] In some embodiments of the present application, generating the prediction evaluation value f at the current prediction time node includes: f = e1*Q1* (β 1i *p i ) + e2*Q2* (β 2i *j i )]; Wherein, e1 is a preset first weight coefficient; e2 is a preset second weight coefficient; Q1 is a preset first fixed coefficient; Q2 is a preset second fixed coefficient; is the number of model evaluation indicators; β1i is the influence factor of the i-th model evaluation indicator; p i is the reference value of the i-th model evaluation indicator in the risk sub-model corresponding to the target communication path at the current prediction time node; is the number of path evaluation indicators; β 2i is the influence factor of the i-th path evaluation indicator; j i is the reference value of the i-th path evaluation indicator in the target communication path.

[0011] In some embodiments of the present application, firewall parameters for each communication path are set according to all expected risk parameters, including: Set b in sequence according to the communication path sequence B i is the target communication path; Generate the associated evaluation value of the target communication path and each sub-firewall policy at the current prediction time node; Establish an associated evaluation value sequence D, D = (d1, d2…d i …d n ), wherein, d i is the associated evaluation value of the target communication path and the i-th sub-firewall policy; n is the number of sub-firewall policies; Preset the first associated evaluation value threshold D1; If d i > D1, set the i-th sub-firewall policy as the associated sub-firewall policy of the target communication path; Obtain the associated sub-firewall policy of the target communication path, and establish an associated sub-firewall policy sequence A1, A1 = (a 11 , a 12 …a 1i …a 1n1 ), wherein, a 1i is the i-th associated sub-firewall policy of the target communication path at the current prediction time node; n1 is the number of associated sub-firewall policies; Generate the firewall parameters for the adjustment period corresponding to the target communication path at the current prediction time node according to the associated sub-firewall policy sequence A1.

[0012] In some embodiments of the present application, generating the associated evaluation value with each sub-firewall policy includes: Preprocess the expected risk parameters for the adjustment period corresponding to the target communication path at the current prediction time node; Generate a risk feature data packet for the target communication path according to the preprocessing result; Set a in sequence according to the sub-firewall policy sequence Ai is the target sub - firewall policy; Generate the association evaluation value d between the target sub - firewall policy and the target communication path according to the risk - characteristic data packet; Generate the association evaluation values with each sub - firewall policy in sequence.

[0013] In some embodiments of the present application, generating the association evaluation value d includes: d = Y * µ i *(w i - w')[[]] i ) 2 ; Wherein, is the number of risk - characteristic indexes of the target sub - firewall policy; µ i is the influence factor of the i - th risk - characteristic index of the target sub - firewall policy; w' i is the standard reference value of the i - th risk - characteristic index of the target sub - firewall policy; w i is the real - time reference value of the i - th risk - characteristic index of the target sub - firewall policy generated based on the risk - characteristic data packet; Y is the conversion coefficient.

[0014] In some embodiments of the present application, generating the firewall parameters within the adjustment period corresponding to the current prediction time node of the target communication path includes: Obtain the sequence A1 of associated sub - firewall policies; Correct all the associated sub - firewall policies in the sequence A1 of associated sub - firewall policies according to the preset rule - exception model; Generate multiple firewall plans according to the correction result; Establish the firewall - plan sequence H, H=(h1, h2…h i …h r ), where h i is the i - th firewall plan; r is the number of firewall plans; Generate the operation evaluation values of each firewall plan; Establish the operation - evaluation - value sequence G, G=(g1, g2…g i …g r ), where g i is the operation evaluation value of the i - th firewall plan; r is the number of firewall plans; Set the firewall plan corresponding to the maximum value g max in the operation - evaluation - value sequence G as the target firewall plan; Set the firewall parameters according to the target firewall plan.

[0015] In some embodiments of the present application, establishing the operation - evaluation - value sequence G includes: Set h sequentially according to the firewall plan sequence H i as the target firewall plan; Generate the operation evaluation value g of the target firewall plan; g = e3 * Q3 * s i * k i + e4 * Q4 * U; where, e3 is the preset third weight coefficient; e4 is the preset fourth weight coefficient; Q3 is the preset third fixed coefficient; Q4 is the preset fourth fixed coefficient; is the number of operation evaluation indicators; s i is the influence factor of the i-th operation evaluation indicator; k i is the reference value of the i-th operation evaluation indicator in the target firewall plan; U is the risk fluctuation evaluation value.

[0016] Compared with the prior art, the beneficial effect of the firewall policy management method based on risk prediction in the embodiments of the present application is that: By establishing risk sub-models for each communication path to periodically predict the attack risks of each communication path, and dynamically modifying the firewall policies on each communication path according to the budget results, the risk identification and filtering efficiency of each communication path are ensured, and the security of data access is improved.

[0017] When setting the firewall parameters of a single communication path, preprocess the selected sub-firewall policies, eliminate the abnormal conflict rules therein, and at the same time, by dynamically adjusting the setting order of each sub-firewall policy, the filtering efficiency and filtering accuracy for access data are ensured, and the security of data access is improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 is a flowchart of a firewall policy management method based on risk prediction in a preferred embodiment of the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0019] The following combines the drawings and embodiments to further describe in detail the specific embodiments of the present application. The following embodiments are used to illustrate the present application, but are not used to limit the scope of the present application.

[0020] In the description of the present application, it should be understood that the orientation or positional relationship indicated by the terms "center", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the present application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the present application.

[0021] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of this application, unless otherwise specified, the meaning of "a plurality" is two or more.

[0022] In the description of this application, it should be noted that, unless otherwise clearly specified and defined, the terms "installed", "connected", and "coupled" should be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or an integral connection; it may be a mechanical connection or an electrical connection; it may be directly connected or indirectly connected through an intermediate medium, and it may be the communication inside two components. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to specific circumstances.

[0023] As Figure 1 shown, a firewall policy management method based on risk prediction in a preferred embodiment of this application includes: S101: Establish a plurality of data sub-domains and establish a plurality of communication paths according to all the data sub-domains; S102: Generate the expected risk parameters of each communication path according to a preset risk prediction model; S103: Set the firewall parameters of each communication path according to all the expected risk parameters; Among them, it further includes: Establish a sub-firewall policy sequence A, A = (a1, a2... a i …a n ), where a i is the i-th sub-firewall policy; n is the number of sub-firewall policies; Each sub-firewall policy includes a plurality of filtering rules; Establish a communication path sequence B, B = (b1, b2... b i …b m ), where b i is the i-th communication path; m is the number of communication paths.

[0024] Specifically, when presetting the risk prediction model, it includes: Set b i as the target communication path in sequence according to the communication path sequence B; Establish a risk sub-model of the target communication path according to historical parameters; Generate the risk sub-models of each communication path in sequence; Establish a risk sub-model sequence C, C = (c1, c2... ci …c m )), where c i is the risk sub-model of the i-th communication path; m is the number of communication paths; Establish a risk prediction model according to the risk sub-model sequence C.

[0025] Specifically, establish multiple data sub-domains according to the database parameters and data interaction parameters in the network system, and construct multiple communication paths according to the data interaction relationships between the data sub-domains.

[0026] Specifically, optimize all historical firewall data and then construct multiple firewall policies. Each sub-firewall policy includes multiple filtering rules, and the filtering rules can be set and updated according to the protection requirements of the sub-firewall policy.

[0027] Specifically, select the corresponding sub-firewall policy according to the protection requirements of each communication path, thereby constructing the corresponding firewall, improving the filtering protection effect on data packets, and ensuring the security of data interaction.

[0028] It can be understood that in the above embodiments, by establishing the risk prediction models of each communication path, predicting the attack risks that may be suffered on the communication paths, and dynamically adjusting the corresponding firewall parameters, the filtering efficiency of risk data is improved.

[0029] In the preferred embodiments of the embodiments of the present application, when generating the expected risk parameters of each communication path, it includes: Set b in sequence according to the communication path sequence B i as the target communication path; Generate the prediction evaluation value f of the target communication path at the current prediction time node; Set the time interval between the current prediction time node and the next prediction time node according to the prediction evaluation value f; Establish the adjustment period of the target communication path at the current prediction time node; Generate the expected risk parameters of the target communication path within the adjustment period according to the risk prediction model.

[0030] Specifically, generating the prediction evaluation value f of the current prediction time node includes: f = e1 * Q1 * (β 1i * p i )] + e2 * Q2 * (β 2i * j i )]; Wherein, e1 is a preset first weight coefficient; e2 is a preset second weight coefficient; Q1 is a preset first fixed coefficient; Q2 is a preset second fixed coefficient; is the number of model evaluation indicators; β1i is the influence factor of the i-th model evaluation indicator; p i is the reference value of the i-th model evaluation indicator in the risk sub-model corresponding to the target communication path at the current prediction time node; is the number of path evaluation indicators; β 2i is the influence factor of the i-th path evaluation indicator; j i is the reference value of the i-th path evaluation indicator in the target communication path.

[0031] Specifically, the model evaluation indicators include but are not limited to parameters such as the historical prediction accuracy and confidence level of the model, and its path evaluation indicators include but are not limited to multiple parameters such as the data interaction volume, data content, and attack frequency on the communication path.

[0032] Specifically, the larger the prediction evaluation value, the higher the prediction accuracy of the attack risk occurring on the current communication path. The lower the possibility of security risks occurring on the communication path, the time interval between two prediction time nodes can be dynamically corrected according to the prediction evaluation value. The higher the prediction evaluation value, the longer the corresponding time interval, while ensuring the control accuracy of the firewall and reducing the overall load pressure of the system.

[0033] Specifically, by periodically predicting the possible attack parameters on each communication path, the firewall policy on its communication path is dynamically adjusted to improve the defense ability against attack risks.

[0034] Specifically, all parameters in the model are normalized by presetting the first fixed coefficient and the second fixed coefficient, so that each parameter is within the same value range.

[0035] It can be understood that in the above embodiments, by dynamically adjusting the adjustment cycle duration of each communication path, the management efficiency of the firewall policies for each communication path is improved. Ensure the operation efficiency of each firewall, thereby improving the security of data interaction.

[0036] In the preferred embodiment of the present application, the firewall parameters of each communication path are set according to all expected risk parameters, including: Set b in sequence according to the communication path sequence B i is the target communication path; Generate the association evaluation value between the target communication path and each sub-firewall policy at the current prediction time node; Establish an association evaluation value sequence D, D=(d1, d2…d i …d n ), wherein, di is the associated evaluation value between the target communication path and the i-th sub-firewall policy; n is the number of sub-firewall policies; The preset first associated evaluation value threshold D1; If d i > D1, set the i-th sub-firewall policy as the associated sub-firewall policy of the target communication path; Obtain the associated sub-firewall policy of the target communication path, and establish an associated sub-firewall policy sequence A1, A1=(a 11 , a 12 … a 1i … a 1n1 ), where a 1i is the i-th associated sub-firewall policy of the target communication path at the current prediction time node; n1 is the number of associated sub-firewall policies; Generate firewall parameters for the target communication path within the corresponding adjustment period at the current prediction time node according to the associated sub-firewall policy sequence A1.

[0037] Specifically, the first associated evaluation value threshold can be set according to historical parameters.

[0038] Specifically, the larger the associated evaluation value, the better the filtering effect of the corresponding sub-firewall policy on the risk data on the target communication path.

[0039] Specifically, generating the associated evaluation value with each sub-firewall policy includes: Preprocess the expected risk parameters of the target communication path within the corresponding adjustment period at the current prediction time node; Generate a risk characteristic data packet for the target communication path according to the preprocessing result; Set a i as the target sub-firewall policy in turn according to the sub-firewall policy sequence A; Generate the associated evaluation value d between the target sub-firewall policy and the target communication path according to the risk characteristic data packet; Generate the associated evaluation value with each sub-firewall policy in turn.

[0040] Specifically, generating the associated evaluation value d includes: d = Y * µ i *(w i - w' i ) 2 ; Wherein, is the number of risk characteristic indicators of the target sub-firewall policy; µ i is the influence factor of the i-th risk characteristic indicator of the target sub-firewall policy; w' iis the standard reference value of the i-th risk characteristic index of the target sub-firewall policy; w i is the real-time reference value of the i-th risk characteristic index of the target sub-firewall policy generated based on the risk characteristic data packet; Y is the conversion coefficient.

[0041] Specifically, the risk characteristic indexes include, but are not limited to, the category of attack data, the identification method of attack data, the characteristic parameters of attack data, etc.

[0042] Specifically, the influence factors of each risk characteristic index can be determined according to historical parameters. By analyzing the risk characteristics on the target communication path, each firewall policy can be quickly screened, thereby improving the efficiency of firewall construction on a single communication path.

[0043] Specifically, the larger the correlation evaluation value, the better the filtering effect of the corresponding sub-firewall policy on the risk data on the target communication path.

[0044] It can be understood that in the above embodiments, by establishing risk sub-models for each communication path to periodically predict the attack risks of each communication path, and dynamically correcting the firewall policies on each communication path according to the prediction results, the risk identification and filtering efficiency of each communication path can be ensured, and the security of data access can be improved.

[0045] In the preferred embodiment of the present application, generating firewall parameters within the adjustment period corresponding to the current prediction time node of the target communication path includes: Obtaining the sequence of associated sub-firewall policies A1; Correcting all the associated sub-firewall policies in the sequence of associated sub-firewall policies A1 according to the preset rule anomaly model; Generating multiple firewall plans according to the correction results; Establishing a firewall plan sequence H, H = (h1, h2... h i ... h r ), where h i is the i-th firewall plan; r is the number of firewall plans; Generating the operation evaluation values of each firewall plan; Establishing an operation evaluation value sequence G, G = (g1, g2... g i ... g r ), where g i is the operation evaluation value of the i-th firewall plan; r is the number of firewall plans; Setting the firewall plan corresponding to the maximum value g max in the operation evaluation value sequence G as the target firewall plan; Setting firewall parameters according to the target firewall plan.

[0046] Specifically, when setting the firewall parameters for a single communication path, preprocess the selected sub-firewall policies, eliminate the abnormal conflict rules therein, and at the same time ensure the filtering efficiency and accuracy for access data by dynamically adjusting the setting order of each sub-firewall policy, thereby improving the security of data access.

[0047] Specifically, according to the differences in the selected associated sub-firewall policies, different priorities of each associated sub-firewall policy, and different eliminations of abnormal conflict rules, multiple firewall plans are constructed.

[0048] Specifically, when correcting the selected sub-firewall policies, if eliminating a group of filtering rules with abnormal conflicts, it is necessary to comprehensively consider each elimination method, and after comprehensive evaluation, select the optimal elimination method. The elimination means reducing the priority level of the specified filtering rule to the lowest, so that it does not play a role between the current prediction time node and the next prediction time node.

[0049] Specifically, establish an operation evaluation value sequence G, including: Set h in sequence according to the firewall plan sequence H i as the target firewall plan; Generate the operation evaluation value g of the target firewall plan; g = e3 * Q3 * s i * k i + e4 * Q4 * U; Wherein, e3 is a preset third weight coefficient; e4 is a preset fourth weight coefficient; Q3 is a preset third fixed coefficient; Q4 is a preset fourth fixed coefficient; is the number of operation evaluation indicators; s i is the influence factor of the i-th operation evaluation indicator; k i is the reference value of the i-th operation evaluation indicator in the target firewall plan; U is the risk fluctuation evaluation value.

[0050] Specifically, the larger the operation evaluation value, the more reasonable the adaptation degree and priority setting of each associated sub-firewall policy selected by the current firewall plan, and the better the data filtering efficiency and the stronger the attack and defense capabilities for the corresponding target communication path.

[0051] Specifically, normalize all the parameters in the model through the preset third fixed coefficient and fourth fixed coefficient, so that each parameter is in the same value range.

[0052] According to the first concept of the present application, the attack risk of each communication path is periodically predicted by establishing a risk sub-model for each communication path, and the firewall policy on each communication path is dynamically modified according to the budget result, thereby ensuring the risk identification and filtering efficiency of each communication path and improving the security of data access.

[0053] According to the second concept of the present application, when setting the firewall parameters of a single communication path, the selected sub-firewall policy is preprocessed to eliminate abnormal conflicting rules. At the same time, by dynamically adjusting the setting order of each sub-firewall policy, the filtering efficiency and filtering accuracy of access data are guaranteed, thereby improving the security of data access.

[0054] The above is only a preferred implementation of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and substitutions can be made without departing from the technical principles of the present application. These improvements and substitutions should also be regarded as the scope of protection of the present application.

Claims

1. A firewall policy management method based on risk prediction, characterized in that: include: Establishing multiple data subdomains, and establishing multiple communication paths based on all the data subdomains; Generate expected risk parameters for each communication path according to a preset risk prediction model; Set firewall parameters for each communication path based on all expected risk parameters; Among them, it also includes: Establish a sub-firewall policy array A, A=(a1,a2…a i …a n ), where a i is the i-th sub-firewall policy; n is the number of sub-firewall policies; A single sub-firewall policy includes multiple filtering rules; Establish a communication path sequence B, B=(b1, b2…b i …b m ), where b i is the i-th communication path; m is the number of communication paths.

2. The risk prediction-based firewall policy management method according to claim 1, characterized in that: When presetting the risk prediction model, it includes: According to the communication path sequence B, set bi as the target communication path in sequence; Establish a risk sub-model for the target communication path based on historical parameters; Generate risk sub-models for each communication path in turn; Establish the risk sub-model series C, C=(c1, c2…c i …c m ), where c i is the risk sub-model of the ith communication path; m is the number of communication paths; A risk prediction model is established based on the risk sub-model sequence C.

3. The risk prediction-based firewall policy management method according to claim 2, characterized in that: When generating expected risk parameters for each communication path, include: According to the communication path sequence B, set bi as the target communication path in sequence; Generate a predicted evaluation value f of the target communication path at the current predicted time node; According to the prediction evaluation value f, the time interval between the current prediction time node and the next prediction time node is set; Establishing the adjustment period of the target communication path at the current prediction time node; The expected risk parameters of the target communication path within the adjustment period are generated according to the risk prediction model.

4. The risk prediction-based firewall policy management method according to claim 3, characterized in that: Generate the prediction evaluation value f of the current prediction time node, including: f=e1*Q1* (β 1i *p i )]+e2*Q2* (β 2i *j i )]; Among them, e1 is the preset first weight coefficient; e2 is the preset second weight coefficient; Q1 is the preset first fixed coefficient; Q2 is the preset second fixed coefficient; is the number of model evaluation indicators; β1i is the influencing factor of the i-th model evaluation indicator; p i is the reference value of the i-th model evaluation index in the risk sub-model corresponding to the target communication path at the current prediction time node; is the number of path evaluation indicators; β 2i is the influencing factor of the i-th path evaluation index; j i is the reference value of the evaluation index of the i-th path in the target communication path.

5. The risk prediction-based firewall policy management method according to claim 3, characterized in that: Set firewall parameters for each communication path based on all expected risk parameters, including: Set b in sequence according to the communication path sequence B i is the target communication path; Generate the associated evaluation value of the target communication path at the current prediction time node and each sub-firewall strategy; Establish the correlation evaluation value series D, D = (d1, d2…d i …d n ), where d i is the association evaluation value between the target communication path and the i-th sub-firewall policy; n is the number of sub-firewall policies; Preset the first association evaluation value threshold D1; If d i >D1, set the i-th sub-firewall policy as the associated sub-firewall policy of the target communication path; Get the associated sub-firewall policy of the target communication path and establish the associated sub-firewall policy array A1, A1=(a 11 ,a 12 …a 1i …a 1n1 ), where a 1i is the i-th associated sub-firewall policy of the target communication path at the current prediction time node; n1 is the number of associated sub-firewall policies; The firewall parameters of the target communication path within the adjustment period corresponding to the current prediction time node are generated according to the associated sub-firewall strategy sequence A1.

6. The risk prediction-based firewall policy management method according to claim 5, characterized in that: Generates evaluation values ​​associated with each sub-firewall policy, including: Preprocessing the expected risk parameters of the target communication path within the adjustment period corresponding to the current prediction time node; Generate a risk feature data packet of the target communication path according to the preprocessing result; Set a in sequence according to the sub-firewall policy sequence A i The target sub-firewall policy; Generate an associated evaluation value d between the target sub-firewall policy and the target communication path according to the risk feature data packet; Generate the associated evaluation value with each sub-firewall policy in turn.

7. The risk prediction-based firewall policy management method according to claim 6, characterized in that: Generate an associated evaluation value d, including: d=Y* µ i *(w i -w' i ) 2 ]; in, is the number of risk characteristic indicators of the target sub-firewall policy; µ i is the influencing factor of the i-th risk characteristic index of the target sub-firewall strategy; w' i is the standard reference value of the i-th risk characteristic indicator of the target sub-firewall policy; w i is the real-time reference value of the i-th risk characteristic indicator of the target sub-firewall policy generated based on the risk characteristic data packet; Y is the conversion coefficient.

8. The risk prediction-based firewall policy management method according to claim 6, characterized in that: Generate firewall parameters for the target communication path within the adjustment period corresponding to the current prediction time node, including: Get the associated sub-firewall policy array A1; Modify all associated sub-firewall policies of associated sub-firewall policy sequence A1 according to the preset rule exception model; Generate multiple firewall plans based on the correction results; Establish a firewall plan sequence H, H = (h1, h2…h i …h r ), where h i is the i-th firewall plan; r is the number of firewall plans; Generate operational evaluation values ​​for each firewall plan; Establish the running evaluation value sequence G, G=(g1, g2…g i …g r ), where g i is the operational evaluation value of the ith firewall plan; r is the number of firewall plans; Set the maximum value g in the running evaluation value sequence G max The corresponding firewall plan is the target firewall plan; Set firewall parameters according to the target firewall plan.

9. The risk prediction-based firewall policy management method according to claim 8, characterized in that: Establish the running evaluation value sequence G, including: Set h in sequence according to the firewall plan sequence H i Plan for target firewalls; Generate an operation evaluation value g of the target firewall plan; g=e3*Q3*[ s i *k i ]+e4*Q4*U; Among them, e3 is the preset third weight coefficient; e4 is the preset fourth weight coefficient; Q3 is the preset third fixed coefficient; Q4 is the preset fourth fixed coefficient; is the number of operation evaluation indicators; s i is the influencing factor of the i-th operation evaluation index; k i is the reference value of the i-th operation evaluation index in the target firewall plan; U is the risk fluctuation evaluation value.