Linkage method of security protection system, equipment, medium and program product

By establishing a linkage mechanism between the firewall and the vulnerability scanning tool, and using vulnerability scanning data to generate linkage information to update the firewall policy, the problem of lack of linkage between firewall and vulnerability scanning tools in the existing technology is solved, and the security protection performance of the network system is improved.

CN120223440AActive Publication Date: 2025-06-27ZIGUANG HENGYUE TECH CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510687089.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-06-27
Estimated Expiration
2045-05-27

AI Technical Summary

Technical Problem

The lack of linkage between existing firewalls and vulnerability scanning tools has led to low security protection performance of network systems.

Method used

By monitoring vulnerability scanning data in real time, linkage information is generated when vulnerabilities are discovered and sent to the associated firewall, so that the firewall updates the flow control policy based on the linkage information, thereby realizing the linkage between the firewall and the vulnerability scanning tool.

Benefits of technology

It improves the security protection performance of the network system, enables the firewall to synchronize security protection policies in a timely manner, and enhances its response capabilities to network threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223440A_ABST
    Figure CN120223440A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a linkage method of a safety protection system, equipment, a medium and a program product, and relates to the technical field of safety protection. The method comprises the steps of monitoring vulnerability scanning data of a target system in real time in a scene that the target system starts a security protection linkage function; under the condition that the vulnerability discovery event occurs, linkage information is generated and sent to a firewall associated with the target system, so that the firewall updates a local protection strategy of the firewall based on the linkage information, and safety protection operation is executed according to the updated protection strategy; and acquiring protection state information fed back by the firewall in real time, and maintaining or switching the starting state of the safety protection linkage function according to the protection state information. According to the embodiment of the invention, by monitoring the vulnerability scanning condition in real time, the corresponding linkage information is sent to the firewall when the new vulnerability is found, so that the firewall can timely synchronize the security protection strategy, and the security protection performance of a network system is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of security protection, and more particularly, to a linkage method, device, medium, and program product for a security protection system. Background Art

[0002] A firewall is a network security system mainly used to monitor and control data flow between networks, preventing unauthorized access and data leakage. It sets up an access control list and allows or denies network traffic according to preset rules to ensure that only authorized devices or users can access internal network resources.

[0003] A vulnerability scanning tool (vulnerability scanner) is a proactive security tool used to detect vulnerabilities and weaknesses in a network. It is deployed on the system or network to be detected for regular or on-demand scanning. By simulating the behavior of an attacker, it probes the network or system to discover potential security hazards.

[0004] Currently, firewalls and vulnerability scanners are deployed in different systems and work independently of each other, lacking linkage, resulting in low security protection performance of the network system. Summary of the Invention

[0005] The purpose of the embodiments of the present application is to provide a linkage method, device, medium, and program product for a security protection system to improve the security protection performance of the network system.

[0006] In a first aspect, the embodiments of the present application provide a linkage method for a security protection system, including: When the security protection linkage function of the target system is in an enabled state, real-time monitoring of the vulnerability scanning data of the target system; When it is determined based on the vulnerability scanning data that a vulnerability discovery event occurs in the target system, generating linkage information based on the vulnerability discovery event; Sending the linkage information to the firewall associated with the target system, so that the firewall obtains the current flow control policy corresponding to the vulnerability discovery event based on the linkage information, updates the local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy; Real-time obtaining of the protection status information fed back by the firewall, and maintaining or switching the enabled state of the security protection linkage function according to the protection status information.

[0007] In the embodiments of the present application, by real-time monitoring of the vulnerability scanning situation and sending corresponding linkage information to the firewall when a new vulnerability is discovered, the firewall can synchronize the security protection policy in a timely manner, thereby effectively improving the security protection performance of the network system.

[0008] In some possible embodiments, generating linkage information based on the vulnerability discovery event includes: Obtaining the current vulnerability type corresponding to the vulnerability discovery event; When it is determined that the current vulnerability type meets the preset linkage condition, generating linkage information based on the vulnerability discovery event.

[0009] In the embodiments of the present application, by adding a judgment condition and judging whether to trigger linkage with the firewall according to the type of the current vulnerability, the flexibility of the linkage security protection is further improved.

[0010] In some possible embodiments, sending the linkage information to a firewall associated with the target system, so that the firewall obtains the current flow control policy corresponding to the vulnerability discovery event based on the linkage information, updates the local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy, includes: Sending the linkage information to a firewall associated with the target system, so that the firewall obtains the current flow control policy corresponding to the vulnerability discovery event based on the linkage information, and when it is determined that the current flow control policy meets the preset protection policy update condition, updates the local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy.

[0011] In the embodiments of the present application, by configuring a judgment condition in the firewall and judging whether to update the local protection policy when obtaining the flow control rules to be updated, the flexibility of the linkage security protection is further improved.

[0012] In some possible embodiments, generating linkage information based on the vulnerability discovery event includes: Obtaining the current vulnerability information corresponding to the vulnerability discovery event, generating the current flow control policy corresponding to the current vulnerability information, and assembling the linkage information based on the current flow control policy; Sending the linkage information to a firewall associated with the target system, so that the firewall obtains the current flow control policy corresponding to the vulnerability discovery event based on the linkage information, updates the local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy, includes: Sending the linkage information to a firewall associated with the target system, so that the firewall obtains the current flow control policy in the linkage information, updates the local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy.

[0013] In the embodiments of the present application, by generating corresponding firewall traffic control rules according to newly discovered vulnerabilities on the device where the vulnerability tool is located and directly sending the traffic control rules to the firewall for joint protection operations, the flexibility of firewall linkage is further improved.

[0014] In some possible embodiments, generating linkage information based on the vulnerability discovery event includes: Obtaining the current vulnerability information corresponding to the vulnerability discovery event and assembling the linkage information based on the current vulnerability information; Sending the linkage information to a firewall associated with the target system, so that the firewall obtains the current traffic control policy corresponding to the vulnerability discovery event based on the linkage information, updates the local protection policy of the firewall based on the current traffic control policy, and performs security protection operations according to the updated protection policy, including: Sending the linkage information to a firewall associated with the target system, so that the firewall obtains the current vulnerability information in the linkage information, generates the current traffic control policy corresponding to the current vulnerability information, updates the local protection policy of the firewall based on the current traffic control policy, and performs security protection operations according to the updated protection policy.

[0015] In the embodiments of the present application, by directly sending the original vulnerability information of the newly discovered vulnerability to the firewall, so that the firewall generates corresponding protection rules according to the original vulnerability information, the flexibility of firewall linkage is further improved.

[0016] In some possible embodiments, the linkage method of the security protection system further includes: Real-time monitoring of the vulnerability repair data of the target system; When it is determined based on the vulnerability repair data that a vulnerability repair event occurs in the target system, generating second linkage information based on the vulnerability repair event; Sending the second linkage information to a firewall associated with the target system, so that the firewall obtains the target traffic control policy corresponding to the vulnerability repair event based on the second linkage information, updates the local protection policy of the firewall by removing the target traffic control policy, and performs security protection operations according to the updated protection policy.

[0017] In the embodiments of the present application, by real-time monitoring the repair situation of the discovered vulnerabilities and sending linkage information to the firewall according to the repaired vulnerabilities, the firewall can streamline the protection policy in a timely manner, further improving the security protection performance of the network system.

[0018] In some possible embodiments, the linkage method of the security protection system further includes: Obtain the traffic interception information of the firewall feedback associated with the target system in real time; When it is determined that the target system meets the preset policy adjustment conditions based on the traffic interception information, determine the target vulnerability type that needs to be focused on currently according to the traffic interception information; Adjust the vulnerability scanning rules of the target system based on the target vulnerability type.

[0019] In the embodiment of the present application, by monitoring the traffic interception information feedback by the firewall in real time and determining the target vulnerability type that needs to be focused on according to the traffic interception information, the vulnerability scanning rules of the target vulnerability type are adjusted, so as to further improve the security protection performance of the network system.

[0020] In a second aspect, an embodiment of the present application provides a linkage device for a security protection system, including: A data monitoring module, configured to monitor the vulnerability scanning data of the target system in real time in a scenario where the security protection linkage function of the target system is in an enabled state; An information generation module, configured to generate linkage information based on the vulnerability discovery event when it is determined that the target system has a vulnerability discovery event based on the vulnerability scanning data; An information sending module, configured to send the linkage information to the firewall associated with the target system, so that the firewall obtains the current traffic control policy corresponding to the vulnerability discovery event based on the linkage information, updates the local protection policy of the firewall based on the current traffic control policy, and performs security protection operations according to the updated protection policy; A feedback adjustment module, configured to obtain the protection status information feedback by the firewall in real time, and maintain or switch the enabled state of the security protection linkage function according to the protection status information.

[0021] In a third aspect, an embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, the method described in any embodiment of the first aspect can be implemented.

[0022] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is run by a processor, the method described in any embodiment of the first aspect can be implemented.

[0023] In a fifth aspect, an embodiment of the present application provides a computer program product, the computer program product includes a computer program, wherein when the computer program is executed by a processor, the method described in any embodiment of the first aspect can be implemented. Description of the Drawings

[0024] To more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the accompanying drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show certain embodiments of the present application and should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0025] Figure 1 It is a schematic flowchart of a linkage method for a security protection system provided by an embodiment of the present application; Figure 2 It is a schematic structural diagram of a linkage device for a security protection system provided by an embodiment of the present application; Figure 3 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Specific embodiments

[0026] The following will describe the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings in the embodiments of the present application.

[0027] It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, terms such as "first" and "second" are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0028] It should be noted that the firewall and the vulnerability scanning tool are two different security protection systems. Among them, the firewall works at the network layer and the transport layer, mainly responsible for monitoring and controlling the data packets entering and leaving the network. By setting up an access control list, it allows or rejects network traffic according to pre-set rules to ensure that only authorized devices or users can access internal network resources; vulnerability scanning is an active security measure to discover potential security vulnerabilities in the system by simulating the behavior of attackers. Even if the network system has a firewall enabled, vulnerability scanning is still required to discover potential security problems and take corresponding repair measures.

[0029] Currently, the firewall and the vulnerability scanning tool play different roles in network security, and there is a lack of a linkage mechanism between them. For example, when the vulnerability scanning tool discovers a new vulnerability and needs to make corresponding adjustments to the firewall's protection strategy, it can only be manually adjusted through manual means. This not only consumes manpower but also has poor timeliness of strategy adjustment, resulting in low security protection performance of the system.

[0030] In view of the problems existing in the above-mentioned prior art, the embodiment of the present application provides a linkage method for a security protection system. By detecting vulnerability scanning data or the protection status information of a firewall, and automatically triggering the linkage protection between the vulnerability scanning tool (the device where it is located) and the firewall according to requirements, the protection performance of the security protection system is improved.

[0031] As Figure 1 shown, the embodiment of the present application provides a linkage method for a security protection system, which may include the steps: S1. In a scenario where the security protection linkage function of the target system is in an enabled state, real-time monitor the vulnerability scanning data of the target system.

[0032] It should be noted that the method of the embodiment of the present application can be executed by the linkage control system in the target system. Exemplarily, the target system can be a computer device that needs security protection, and a vulnerability scanning tool is deployed in the target system.

[0033] Exemplarily, the security protection linkage function of the target system can be set to an enabled state or a disabled state. If it is in the disabled state, the vulnerability scanning tool and the firewall operate in their respective normal working modes, and no linkage control is performed between them; if it is in the enabled state, monitoring or linkage control is performed according to their states.

[0034] Specifically, when the security protection linkage function of the target system is in an enabled state, the vulnerability scanning data of the target system is real-time monitored. According to the vulnerability scanning data, the vulnerability scanning situation of the target system can be known, including whether there are vulnerabilities and the specific vulnerability information of the discovered vulnerabilities, etc.

[0035] S2. In the case where it is determined based on the vulnerability scanning data that a vulnerability discovery event occurs in the target system, generate linkage information based on the vulnerability discovery event.

[0036] Specifically, when the vulnerability scanning data indicates that the vulnerability scanning tool scans a vulnerability, that is, it is determined that a vulnerability discovery event occurs in the target system. In this case, corresponding linkage information is generated according to the specific information of the currently detected vulnerability discovery event according to a preset rule.

[0037] Exemplarily, the preset rule can be configured to set corresponding linkage operation information according to different vulnerability types, different vulnerability locations, the severity level of the vulnerability, etc.; after obtaining the corresponding linkage operation information according to the specific information of the currently detected vulnerability discovery event according to the preset rule, assemble the currently obtained linkage operation information into linkage information.

[0038] S3. Send the linkage information to the firewall associated with the target system, so that the firewall can obtain the current traffic control policy corresponding to the vulnerability discovery event based on the linkage information, update the local protection policy of the firewall based on the current traffic control policy, and perform security protection operations according to the updated protection policy.

[0039] Specifically, after generating the linkage information corresponding to the current vulnerability discovery event, the linkage information can be sent to the firewall associated with the target system. When the firewall receives the linkage information, it can obtain the current traffic control policy corresponding to the vulnerability discovery event according to the current linkage information. For example, it can obtain the current traffic control policy according to the linkage operation information included in the linkage information.

[0040] It should be noted that the current traffic control policy is the traffic control rule for the currently detected vulnerability discovery event. Therefore, the firewall can update the protection policy based on the current traffic control policy by adding or replacing it on the basis of the original local protection policy of itself, and then perform security protection operations according to the updated protection policy.

[0041] S4. Real-time obtain the protection status information feedback by the firewall, and maintain or switch the on state of the security protection linkage function according to the protection status information.

[0042] It should be noted that the firewall can feedback its own protection status information to the linkage control system in the target system in real time, and the linkage control system can judge whether to adjust the on / off state of the security protection linkage function according to these protection status information in real time.

[0043] Exemplarily, the protection status information may include the situation information of the firewall for traffic interception, such as the interception volume, the interception rate (the proportion of the interception volume in the total traffic), etc.

[0044] It should be noted that by comparing the real-time protection status information with the preset status threshold, the on / off state of the security protection linkage function of the target system can be switched according to the comparison result. It can be understood that when the security protection linkage function of the target system is in the on state, the security protection effect on the target system is relatively strong. On the contrary, when the security protection linkage function of the target system is in the off state, the security protection effect on the target system is relatively weak.

[0045] Exemplarily, when the security protection linkage function of the target system is in the on state, if it is judged that the interception volume in the past period of time is lower than the preset interception volume threshold, or the interception rate in the past period of time is lower than the preset interception rate threshold, it means that the target system is currently in a relatively safe data traffic environment, then the security protection linkage function of the target system can be switched to the off state to save the resource consumption of security protection; otherwise, maintain the security protection linkage function in the on state.

[0046] Exemplarily, when the security protection linkage function of the target system is in the off state, if it is determined that the interception volume in the past period is higher than the preset interception volume threshold, or the interception rate in the past period is higher than the preset interception rate threshold, indicating that the target system is currently in a relatively dangerous data traffic environment, the security protection linkage function of the target system can be switched to the on state to improve the performance of security protection; otherwise, the security protection linkage function is maintained in the on state.

[0047] It should be noted that, in some embodiments, the switch state of the security protection linkage function can also be switched according to a preset period. Exemplarily, when the security protection linkage function is in the off state and the duration exceeds the preset first period, the security protection linkage function is switched from the off state to the on state; when the security protection linkage function is in the on state and the duration exceeds the preset second period, the security protection linkage function is switched from the on state to the off state.

[0048] In the embodiments of the present application, by real-time monitoring the vulnerability scanning situation, when an event of newly scanned vulnerabilities is detected, linkage information is sent to the associated firewall, so that the firewall can timely synchronize and update the security protection policy according to the current vulnerability discovery situation, thereby effectively improving the security protection performance of the network system.

[0049] In some possible embodiments, in step S2, generating linkage information based on the vulnerability discovery event may include: S201. Obtain the current vulnerability type corresponding to the vulnerability discovery event; S202. When it is determined that the current vulnerability type meets the preset linkage condition, generate linkage information based on the vulnerability discovery event.

[0050] It should be noted that after the vulnerability discovery event occurs and before generating the linkage information, it can first be determined whether the vulnerability type corresponding to the current vulnerability discovery event meets the condition for triggering linkage protection.

[0051] Specifically, according to the detailed vulnerability information of the vulnerability discovery event, the type of the scanned vulnerability (current vulnerability type) can be determined; then, it is determined whether the current vulnerability type meets the preset linkage condition, for example, it is determined whether the current vulnerability type is a preset vulnerability type that needs to trigger linkage protection; if so, linkage information is generated based on the vulnerability discovery event; if not, the subsequent steps are omitted.

[0052] Based on this, by adding a judgment condition before generating the linkage information, it is determined whether to trigger the linkage protection operation with the firewall according to the type of the current vulnerability, thereby further improving the flexibility of the linkage security protection.

[0053] In some possible embodiments, step S3 of sending the linkage information to the firewall associated with the target system, so that the firewall obtains the current traffic control policy corresponding to the vulnerability discovery event based on the linkage information, updates the local protection policy of the firewall based on the current traffic control policy, and performs security protection operations according to the updated protection policy, may include: S301. Send the linkage information to the firewall associated with the target system, so that the firewall obtains the current traffic control policy corresponding to the vulnerability discovery event based on the linkage information. When it is determined that the current traffic control policy meets the preset protection policy update conditions, update the local protection policy of the firewall based on the current traffic control policy, and perform security protection operations according to the updated protection policy.

[0054] It should be noted that after receiving the linkage information and obtaining the current traffic control policy, the firewall can first determine whether the current traffic control policy meets the preset protection policy update conditions. If so, update the local protection policy of the firewall based on the current traffic control policy, and perform security protection operations according to the updated protection policy.

[0055] Exemplarily, determining whether the current traffic control policy meets the preset protection policy update conditions may include at least the following methods: 1. Determine whether the current traffic control policy duplicates the traffic control rules of the original protection policy. If so, it does not meet the preset protection policy update conditions; otherwise, it meets the preset protection policy update conditions. 2. Determine whether the current traffic control policy conflicts with the traffic control rules of the original protection policy. If so, it does not meet the preset protection policy update conditions; otherwise, it meets the preset protection policy update conditions.

[0056] Based on this, by configuring judgment conditions in the firewall and first determining whether the current traffic control policy meets the conditions before updating the local protection policy, the reliability and flexibility of the linkage security protection are further improved.

[0057] In some possible embodiments, in step S2, generating linkage information based on the vulnerability discovery event may include: S211. Obtain the current vulnerability information corresponding to the vulnerability discovery event, generate the current traffic control policy corresponding to the current vulnerability information, and assemble the linkage information based on the current traffic control policy; Step S3 of sending the linkage information to the firewall associated with the target system, so that the firewall obtains the current traffic control policy corresponding to the vulnerability discovery event based on the linkage information, updates the local protection policy of the firewall based on the current traffic control policy, and performs security protection operations according to the updated protection policy, may include: S311. Send the linkage information to the firewall associated with the target system, so that the firewall can obtain the current flow control policy in the linkage information, update the local protection policy of the firewall based on the current flow control policy, and perform security protection operations according to the updated protection policy.

[0058] It should be noted that when a vulnerability discovery event occurs in the target system, the specific information (current vulnerability information) of the vulnerability discovery event can be obtained according to the vulnerability scanning data. Then, on the target system side, the current flow control policy corresponding to the current vulnerability information can be generated directly according to the preset policy generation rules based on the current vulnerability information, and the linkage information can be assembled based on the current flow control policy.

[0059] In this way, when the firewall receives the linkage information, it can directly obtain the current flow control policy generated on the target system side from the linkage information, thus saving the computing resources of the firewall device and further improving the flexibility of firewall linkage.

[0060] In some possible embodiments, in step S2, generating the linkage information based on the vulnerability discovery event may include: S221. Obtain the current vulnerability information corresponding to the vulnerability discovery event, and assemble the linkage information based on the current vulnerability information; Step S3, sending the linkage information to the firewall associated with the target system, so that the firewall can obtain the current flow control policy corresponding to the vulnerability discovery event based on the linkage information, update the local protection policy of the firewall based on the current flow control policy, and perform security protection operations according to the updated protection policy, may include: S321. Send the linkage information to the firewall associated with the target system, so that the firewall can obtain the current vulnerability information in the linkage information, generate the current flow control policy corresponding to the current vulnerability information, update the local protection policy of the firewall based on the current flow control policy, and perform security protection operations according to the updated protection policy.

[0061] It should be noted that in addition to generating the current flow control policy corresponding to the current vulnerability information on the target system side, the current flow control policy corresponding to the current vulnerability information can also be generated on the firewall device side.

[0062] Specifically, the policy generation rules can be configured on the firewall device side. When a vulnerability discovery event occurs in the target system, the original vulnerability information (current vulnerability information) of the vulnerability discovery event can be directly assembled into the linkage information; when the firewall receives the current vulnerability information included in the linkage information, it can generate the current flow control policy corresponding to the current vulnerability information according to the policy generation rules configured locally on the firewall.

[0063] In this way, by configuring the policy generation rules on one side of the firewall device, the policy generation rules can be adaptively set and adjusted according to the characteristics of the firewall device, improving the reliability and flexibility of generating the current traffic control policy.

[0064] In some possible embodiments, the linkage method of the security protection system may further include the steps of: S501. Monitor the vulnerability repair data of the target system in real time; S502. When it is determined based on the vulnerability repair data that a vulnerability repair event has occurred in the target system, generate second linkage information based on the vulnerability repair event; S503. Send the second linkage information to the firewall associated with the target system, so that the firewall obtains the target traffic control policy corresponding to the vulnerability repair event based on the second linkage information, updates the local protection policy of the firewall by removing the target traffic control policy, and performs security protection operations according to the updated protection policy.

[0065] It should be noted that in addition to monitoring the vulnerability scanning situation (the situation of discovering new vulnerabilities) of the target system in real time, the vulnerability repair situation of the target system can also be monitored in real time, and the linkage protection policy for the firewall can be streamlined in a timely manner according to the vulnerability repair situation.

[0066] Specifically, monitor the vulnerability repair data of the target system in real time. From the vulnerability repair data, information such as the vulnerability identifier / name being repaired in the target system and the repair progress can be obtained. Determining that a vulnerability repair event has occurred in the target system based on the vulnerability repair data means judging that an event of successfully repairing one or more vulnerabilities has occurred in the target system according to the vulnerability repair data.

[0067] When it is determined that a vulnerability repair event has occurred in the target system, second linkage information can be generated based on the currently occurring vulnerability repair event.

[0068] Exemplarily, similar to generating linkage information based on a vulnerability discovery event, when generating the second linkage information, the current vulnerability information corresponding to the vulnerability repair event (the currently repaired vulnerability) can also be obtained, and according to the same policy generation rules, a target traffic control policy corresponding to the vulnerability repair event (which can also be the current traffic control policy corresponding to the current vulnerability information) can be generated; the difference is that when generating linkage information based on a vulnerability discovery event, the purpose is to enable the firewall to add / replace the current traffic control policy to the original protection policy according to the linkage information, while when generating the second linkage information based on a vulnerability repair event, the purpose is to enable the firewall to remove the target traffic control policy from the original protection policy according to the second linkage information. It can be understood that the above two processes are inverse processes of each other.

[0069] In this way, by monitoring the repair status of the discovered vulnerabilities in real time and sending the second linkage information to the firewall according to the repaired vulnerability information, the firewall can streamline the target protection policy corresponding to the repaired vulnerabilities in a timely manner, thereby further improving the flexibility of security protection.

[0070] In some possible embodiments, the linkage method of the security protection system may further include the steps of: S601. Obtain in real time the traffic interception information fed back by the firewall associated with the target system; S602. When it is determined that the target system meets the preset policy adjustment conditions based on the traffic interception information, determine the target vulnerability type that needs to be focused on currently according to the traffic interception information; S603. Adjust the vulnerability scanning rules of the target system based on the target vulnerability type.

[0071] It should be noted that, similar to the protection status information, the traffic interception information is also used to characterize the traffic interception situation of the firewall, for example, including the interception volume (for a period of time), the interception rate (the proportion of the interception volume in the total traffic), etc.

[0072] Specifically, by obtaining the traffic interception information fed back by the firewall in real time, it can be determined whether the target system meets the preset policy adjustment conditions. Exemplarily, if it is determined that the interception volume in the past period of time is higher than the preset interception volume threshold, or the interception rate in the past period of time is higher than the preset interception rate threshold, it indicates that the target system is currently in a relatively dangerous network environment and is determined to meet the preset policy adjustment conditions.

[0073] When it is determined that the target system meets the preset policy adjustment conditions, the target vulnerability type that needs to be focused on currently is determined according to the traffic interception information. Exemplarily, according to the traffic interception information, information such as the traffic type and protocol type of the currently intercepted traffic can be obtained, and the target vulnerability type (the vulnerability type that needs to be focused on currently) corresponding to the traffic type / protocol type of the currently intercepted traffic can be determined according to the preset type comparison table.

[0074] According to the target vulnerability type, the vulnerability scanning rules of the target system can be adjusted accordingly. Exemplarily, the scanning frequency of the vulnerability scanning rules of the target vulnerability type can be increased, for example, from once a day to twice a day; Exemplarily, the scanning range of the vulnerability scanning rules of the target vulnerability type can also be increased, for example, from the scanning range only for key areas / key files / key data objects to the vulnerability scanning for all areas / files / data objects in the target system.

[0075] Based on this, by real-time monitoring of the traffic interception information fed back by the firewall, and determining the target vulnerability types that need to be focused on based on the traffic interception information, the leakage scanning rules of the target vulnerability types can be adjusted, thereby further improving the security protection performance of the network system.

[0076] Please refer to Figure 2 , Figure 2 FIG. 1 shows a block diagram of the linkage device of the safety protection system provided in some embodiments of the present application. It should be understood that the linkage device of the safety protection system is similar to the above-mentioned Figure 1 Corresponding to the method embodiment, each step involved in the above method embodiment can be executed. The specific functions of the linkage device of the safety protection system can be found in the description above. To avoid repetition, the detailed description is appropriately omitted here.

[0077] Figure 2 The linkage device of the safety protection system includes at least one software function module that can be stored in a memory in the form of software or firmware or solidified in the linkage device of the safety protection system, and the linkage device of the safety protection system includes: The data monitoring module 210 is used to monitor the vulnerability scanning data of the target system in real time when the security protection linkage function of the target system is turned on; The information generation module 220 is used to generate linkage information based on the vulnerability discovery event when it is determined based on the vulnerability scanning data that a vulnerability discovery event occurs in the target system; The information sending module 230 is used to send the linkage information to the firewall associated with the target system, so that the firewall obtains the current flow control policy corresponding to the vulnerability discovery event based on the linkage information, updates the local protection policy of the firewall based on the current flow control policy, and performs security protection operations according to the updated protection policy; The feedback adjustment module 240 is used to obtain the protection status information fed back by the firewall in real time, and maintain or switch the enabling state of the security protection linkage function according to the protection status information.

[0078] It can be understood that the above-mentioned device item embodiments correspond to the method item embodiments of the present invention. A linkage device of a security protection system provided by an embodiment of the present invention can implement a linkage method of a security protection system provided by any method item embodiment of the present invention.

[0079] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the device described above can refer to the corresponding process in the aforementioned method, and will not be described in detail here.

[0080] like Figure 3As shown, some embodiments of the present application provide an electronic device 300, which includes: a memory 310, a processor 320, and a computer program stored on the memory 310 and executable on the processor 320. When the processor 320 reads the program from the memory 310 through a bus 330 and executes the program, it can implement the methods of any of the embodiments included in the above-mentioned linkage method of the security protection system.

[0081] The processor 320 can process digital signals and can include various computing architectures. For example, a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements a combination of multiple instruction sets. In some examples, the processor 320 can be a microprocessor.

[0082] The memory 310 can be used to store instructions executed by the processor 320 or data related to the execution of the instructions. These instructions and / or data can include code for implementing some or all of the functions of one or more modules described in the embodiments of the present application. The processor 320 of the present disclosure embodiment can be used to execute the instructions in the memory 310 to implement the method shown above. The memory 310 includes a dynamic random access memory, a static random access memory, a flash memory, an optical memory, or other memories well-known to those skilled in the art.

[0083] Some embodiments of the present application also provide a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it executes the method described in the method embodiment.

[0084] Some embodiments of the present application also provide a computer program product. When the computer program product runs on a computer, it causes the computer to execute the method described in the method embodiment.

[0085] It should be noted that the embodiments in this specification are all described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, please refer to the partial description of the method embodiments.

[0086] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0087] In addition, in each embodiment of the present application, the various functional modules may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.

[0088] If the described functions are implemented in the form of software functional modules and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0089] The above are only embodiments of the present application and are not intended to limit the protection scope of the present application. For those skilled in the art, various modifications and changes can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application. It should be noted that similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0090] As mentioned above, the above are only specific implementation manners of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, and all should be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.

[0091] It should be noted that in this text, relative terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article or device including the said element.

Claims

1. A linkage method for a security protection system, characterized in that, Including: When the security protection linkage function of the target system is in the enabled state, the vulnerability scanning data of the target system is monitored in real time; When it is determined that a vulnerability discovery event occurs in the target system based on the vulnerability scanning data, linkage information is generated based on the vulnerability discovery event; The linkage information is sent to the firewall associated with the target system, so that the firewall obtains the current traffic control policy corresponding to the vulnerability discovery event based on the linkage information, updates the local protection policy of the firewall based on the current traffic control policy, and performs security protection operations according to the updated protection policy; The protection status information fed back by the firewall is obtained in real time, and the enabled state of the security protection linkage function is maintained or switched according to the protection status information.

2. The linkage method of the safety protection system according to claim 1, characterized in that, The generating of the linkage information based on the vulnerability discovery event includes: Obtaining the current vulnerability type corresponding to the vulnerability discovery event; When it is determined that the current vulnerability type meets the preset linkage conditions, linkage information is generated based on the vulnerability discovery event.

3. The linkage method of the safety protection system according to claim 1, characterized in that, The sending of the linkage information to the firewall associated with the target system, so that the firewall obtains the current traffic control policy corresponding to the vulnerability discovery event based on the linkage information, updates the local protection policy of the firewall based on the current traffic control policy, and performs security protection operations according to the updated protection policy, includes: The linkage information is sent to the firewall associated with the target system, so that the firewall obtains the current traffic control policy corresponding to the vulnerability discovery event based on the linkage information. When it is determined that the current traffic control policy meets the preset protection policy update conditions, the local protection policy of the firewall is updated based on the current traffic control policy, and security protection operations are performed according to the updated protection policy.

4. The linkage method of the safety protection system according to claim 1, characterized in that, The generating of the linkage information based on the vulnerability discovery event includes: Obtaining the current vulnerability information corresponding to the vulnerability discovery event, generating the current traffic control policy corresponding to the current vulnerability information, and assembling the linkage information based on the current traffic control policy; The sending of the linkage information to the firewall associated with the target system, so that the firewall obtains the current traffic control policy in the linkage information, updates the local protection policy of the firewall based on the current traffic control policy, and performs security protection operations according to the updated protection policy, includes: The linkage information is sent to the firewall associated with the target system, so that the firewall obtains the current traffic control policy in the linkage information, updates the local protection policy of the firewall based on the current traffic control policy, and performs security protection operations according to the updated protection policy.

5. The linkage method of the safety protection system according to claim 1, characterized in that, The generating of the linkage information based on the vulnerability discovery event includes: Obtaining the current vulnerability information corresponding to the vulnerability discovery event, and assembling the linkage information based on the current vulnerability information; Sending the linkage information to a firewall associated with the target system, so that the firewall obtains a current traffic control policy corresponding to the vulnerability discovery event based on the linkage information, updates the protection policy on the local firewall based on the current traffic control policy, and performs security protection operations according to the updated protection policy, including: Sending the linkage information to a firewall associated with the target system, so that the firewall obtains the current vulnerability information in the linkage information, generates a current traffic control policy corresponding to the current vulnerability information, updates the protection policy on the local firewall based on the current traffic control policy, and performs security protection operations according to the updated protection policy.

6. The linkage method of the safety protection system according to claim 1, characterized in that, Further comprising: Real-time monitoring of the vulnerability repair data of the target system; When it is determined based on the vulnerability repair data that a vulnerability repair event has occurred in the target system, generating second linkage information based on the vulnerability repair event; Sending the second linkage information to a firewall associated with the target system, so that the firewall obtains a target traffic control policy corresponding to the vulnerability repair event based on the second linkage information, updates the protection policy on the local firewall by removing the target traffic control policy, and performs security protection operations according to the updated protection policy.

7. The linkage method of the safety protection system according to claim 1, characterized in that, Further comprising: Real-time obtaining of traffic interception information fed back by a firewall associated with the target system; When it is determined based on the traffic interception information that the target system meets a preset policy adjustment condition, determining a target vulnerability type that needs to be focused on currently according to the traffic interception information; Adjusting the vulnerability scanning rules of the target system based on the target vulnerability type.

8. An electronic device, characterized in that, Comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, the linkage method of the security protection system according to any one of claims 1-7 can be implemented.

9. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is run by a processor, it executes the linkage method of the security protection system according to any one of claims 1-7.

10. A computer program product, characterized in that, The computer program product includes a computer program, and when the computer program is executed by a processor, it implements the linkage method of the security protection system according to any one of claims 1-7.

Citation Information

Patent Citations

  • Network safety protection method, equipment and system thereof

    CN102523218A

  • Web protection method based on asset type recognition and loophole self-discovery

    CN109361692A

  • Vulnerability protection method and device and electronic equipment

    CN111027075A

  • Linkage scanning method for loopholes

    CN112738020A

  • Protection method and device based on cloud firewall, equipment and storage medium

    CN117914574A