Cooperative security protection method and device for network system, medium and program product

By monitoring the status data of the security protection module in the network system in real time and generating linkage information, the problem of lack of linkage among modules in the existing technology is solved, and the coordinated security protection of the network system is realized, and the overall protection performance and flexibility are improved.

CN120223447APending Publication Date: 2025-06-27ZIGUANG HENGYUE TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510703283.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-29
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

Different security protection modules in existing network systems lack a mechanism for coordinated work, which leads to the inability to adjust protection rules in time in abnormal situations, reducing the overall protection performance.

Method used

By monitoring the status data of the security protection module in the network system in real time, linkage information is generated and sent to the relevant modules, so that they can update the protection policy and achieve collaborative security protection.

Benefits of technology

It improves the overall protection performance of the network system, ensures that protection rules can be adjusted in time in abnormal situations, and enhances the flexibility and efficiency of protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223447A_ABST
    Figure CN120223447A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a collaborative security protection method and device for a network system, a medium and a program product, and relates to the technical field of network security. The method comprises the following steps: monitoring each security protection module in a target network system in real time; when it is determined that the target protection module has the abnormal event, obtaining a corresponding target collaborative protection list and determining a plurality of to-be-synchronized protection modules; linkage information corresponding to the protection modules to be synchronized is generated; and generating the linkage information to enable each to-be-synchronized protection module to update the respective protection strategy, and executing safety protection operation according to the updated protection strategy. According to the embodiment of the invention, each security protection module in the network system is monitored, and the corresponding linkage information is generated in time when an abnormal event occurs in a certain security protection module, so that one or more other security protection modules corresponding to the module update respective protection strategies according to the linkage information to realize cooperative security protection of the whole network. Therefore, the overall security protection performance of the network system is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and more specifically, to a collaborative security protection method, device, medium and program product for a network system. Background Art

[0002] There are various security protection modules in the network system, including firewalls, intrusion detection systems, intrusion prevention systems, vulnerability scanners, routers, switches, etc. These modules play different roles and perform different functions in the network system. For example, firewalls mainly work at the network layer and transport layer to monitor and control the traffic in and out of the network, and allow or block data packets according to preset security rules; routers connect different networks by analyzing the destination address of data packets, and select the optimal path to forward data based on the routing table; vulnerability scanners scan the system based on the vulnerability library, discover potential security vulnerabilities and repair them to prevent them from being exploited.

[0003] At present, different modules in the network system perform their respective functions and lack a mechanism for linkage and collaboration. If an abnormal situation occurs in a certain link in the network system, it is necessary for humans to make corresponding adjustments to other links according to needs. Not only is the operation inconvenient, but the timeliness of the adjustment of protection rules cannot be guaranteed, resulting in low overall protection performance of the network system. Summary of the invention

[0004] The purpose of the embodiments of the present application is to provide a collaborative security protection method, device, medium and program product for a network system, so as to improve the overall protection performance of the network system.

[0005] In a first aspect, an embodiment of the present application provides a collaborative security protection method for a network system, including: Real-time monitoring of security protection status data of at least one security protection module in the target network system; In the case where it is determined based on the security protection status data that an abnormal event occurs in a target protection module, a target collaborative protection list corresponding to the target protection module is obtained, and a number of protection modules to be synchronized indicated by the target collaborative protection list are determined; wherein the target protection module is any one of the at least one security protection module; Generating linkage information corresponding to each of the protection modules to be synchronized based on the abnormal event; Each linkage information is sent to a corresponding protection module to be synchronized, so that each protection module to be synchronized updates its own protection strategy based on the received linkage information, and performs security protection operations according to the updated protection strategy.

[0006] In the embodiments of the present application, by monitoring the status of different security protection modules in the network system, corresponding linkage information is generated in a timely manner when an abnormal event occurs in a certain security protection module, so that one or more other security protection modules corresponding to the module update their respective protection strategies according to the linkage information to achieve coordinated security protection of the entire network, thereby effectively improving the overall security protection performance of the network system.

[0007] In some possible embodiments, the obtaining of the target collaborative protection list corresponding to the target protection module includes: Determine the current abnormal level corresponding to the abnormal event; Obtain a set of collaborative protection lists corresponding to the target protection module, and obtain the target collaborative protection list corresponding to the current abnormal level from the set of collaborative protection lists.

[0008] In the embodiments of the present application, by configuring different collaborative protection lists, different collaborative protection scopes can be determined according to different abnormal levels, thereby further improving the security protection flexibility of the overall network system.

[0009] In some possible embodiments, the real-time monitoring of the security protection status data of at least one security protection module in the target network system includes: Determine at least one security protection module in the target network system whose collaborative protection function is in an enabled state, and real-time monitor the security protection status data of the at least one security protection module.

[0010] In the embodiments of the present application, by respectively configuring the collaborative protection function for different security protection modules in the network system and monitoring the status of different ranges of security protection modules according to the enabling situation of the collaborative protection function, the efficiency of status monitoring is further improved.

[0011] In some possible embodiments, the determining of several to-be-synchronized protection modules indicated by the target collaborative protection list includes: Determine at least one collaborative protection module recorded in the target collaborative protection list; Determine the collaborative protection modules whose collaborative protection functions are in an enabled state among the at least one collaborative protection module as the several to-be-synchronized protection modules indicated by the target collaborative protection list.

[0012] In the embodiments of the present application, after determining the collaborative protection modules according to the collaborative protection list, the current to-be-synchronized protection modules are further screened according to the enabling situation of these collaborative protection modules, thereby further improving the accuracy of screening the to-be-synchronized protection modules.

[0013] In some possible embodiments, generating linkage information corresponding to each of the protection modules to be synchronized based on the abnormal event includes: Obtaining the policy generation rules corresponding to each of the protection modules to be synchronized; Based on the abnormal events, respectively generating collaborative protection strategies corresponding to the protection modules to be synchronized according to the strategy generation rules; Assembling based on each of the collaborative protection strategies to obtain linkage information corresponding to each of the protection modules to be synchronized; The step of sending each linkage information to a corresponding protection module to be synchronized, so that each protection module to be synchronized updates its own protection strategy based on the received linkage information, and performs security protection operations according to the updated protection strategy, includes: Each linkage information is sent to the corresponding protection module to be synchronized, so that each protection module to be synchronized obtains the corresponding collaborative protection strategy based on the received linkage information, updates their own protection strategy based on the corresponding collaborative protection strategy, and performs security protection operations according to the updated protection strategy.

[0014] In an embodiment of the present application, different policy generation rules are configured for different security protection modules, and linkage information of each protection module to be synchronized is generated according to different policy generation rules based on the current abnormal event, thereby further improving the convenience and accuracy of generating linkage information.

[0015] In some possible embodiments, the collaborative security protection method of the network system further includes: Real-time monitoring of the processing status data of the target protection module for the abnormal event; In the case where it is determined based on the processing status data that the abnormal event is eliminated, generating de-linking information corresponding to each of the to-be-synchronized protection modules based on the abnormal event; Each of the linkage release information is sent to the corresponding protection module to be synchronized, so that each of the protection modules to be synchronized updates its own protection strategy based on the received linkage release information, and performs security protection operations according to the updated protection strategy.

[0016] In an embodiment of the present application, by monitoring the processing status of abnormal events and sending a release information to the relevant collaborative protection modules in a timely manner when the abnormal events are resolved, the security protection operation for the abnormal events can be released, thereby further improving the overall security protection flexibility of the network system.

[0017] In some possible embodiments, the collaborative security protection method of the network system further includes: When it is determined that the target network system meets the preset security level adjustment conditions based on the security protection status data, adjust the security level of the target network system; Obtain the collaborative protection configuration policy corresponding to the adjusted security level, and turn on or off the collaborative protection functions of each security protection module in the target network system according to the collaborative protection configuration policy.

[0018] In the embodiments of the present application, it is judged whether the security level needs to be adjusted according to the protection status of each security protection module, and after adjusting the security level, the status of the collaborative protection functions of each security protection module is switched according to the collaborative protection configuration policies corresponding to different levels.

[0019] In a second aspect, an embodiment of the present application provides a collaborative security protection device for a network system, including: A data monitoring module, configured to monitor the security protection status data of at least one security protection module in the target network system in real time; A collaborative matching module, configured to obtain a target collaborative protection list corresponding to the target protection module and determine a plurality of to-be-synchronized protection modules indicated by the target collaborative protection list when it is determined based on the security protection status data that an abnormal event occurs in the target protection module; wherein, the target protection module is any one of the at least one security protection module; An information generation module, configured to generate linkage information corresponding to each of the to-be-synchronized protection modules based on the abnormal event; An information sending module, configured to send each piece of linkage information to the corresponding to-be-synchronized protection module respectively, so that each to-be-synchronized protection module updates its own protection policy based on the received linkage information and performs security protection operations according to the updated protection policy.

[0020] In a third aspect, an embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, the method described in any embodiment of the first aspect can be implemented.

[0021] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is run by a processor, the method described in any embodiment of the first aspect can be implemented.

[0022] In a fifth aspect, an embodiment of the present application provides a computer program product, the computer program product includes a computer program, wherein when the computer program is executed by a processor, the method described in any embodiment of the first aspect can be implemented. Description of the Drawings

[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0024] Figure 1 A flowchart of a collaborative security protection method for a network system provided in an embodiment of the present application; Figure 2 A schematic diagram of the structure of a collaborative security protection device for a network system provided in an embodiment of the present application; Figure 3 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0025] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0026] It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.

[0027] It should be noted that the network system contains a variety of security protection modules (equipment), such as firewalls, intrusion detection systems, intrusion prevention systems, vulnerability scanners, routers, switches, etc. At present, different modules in the network system perform their respective duties, and there is a lack of linkage and collaborative working mechanism between them. For example, when the intrusion detection system detects a malicious attack event, if you want to adjust the protection strategy of other security protection devices (such as firewalls) accordingly, you can only adjust it manually, which is not only inconvenient to operate, but also cannot guarantee the timeliness of the adjustment of protection rules, resulting in low overall protection performance of the network system.

[0028] In response to the problems existing in the above-mentioned prior art, an embodiment of the present application provides a collaborative security protection method for a network system, which monitors the protection status data of each security protection device (module) in real time, and initiates linkage with other one or more security protection devices (modules) as needed to achieve collaborative protection operations, thereby effectively improving the overall protection performance of the network system.

[0029] like Figure 1As shown in the figure, an embodiment of the present application provides a collaborative security protection method for a network system, which may include the following steps: S1. Real-time monitor the security protection status data of at least one security protection module in the target network system.

[0030] It should be noted that the target network system is a network system for which whole-network collaborative protection is desired. A variety of security protection modules are deployed in this network system, such as firewalls, intrusion detection systems, intrusion prevention systems, vulnerability scanners, etc. These security protection modules can be a single device or different security protection software deployed in the same device.

[0031] It can be understood that during the process of real-time monitoring of the security protection status data, for the various security protection modules in the target network system, it is usually not necessary to perform real-time monitoring on all security protection modules, but one or more of them can be selected for real-time monitoring according to requirements.

[0032] S2. In the case where it is determined based on the security protection status data that an abnormal event has occurred in the target protection module, obtain the target collaborative protection list corresponding to the target protection module, and determine several to-be-synchronized protection modules indicated by the target collaborative protection list; where the target protection module is any one of at least one security protection module.

[0033] Specifically, by monitoring the security protection status data of each security protection module, it can be determined whether these security protection modules have abnormal events. Exemplarily, when the security protection status data of a certain security protection module indicates that a malicious attack file, malicious traffic, or a vulnerability has been scanned, it is determined that an abnormal event has occurred in this security protection module.

[0034] In the case where it is determined that an abnormal event has occurred in the target protection module (one of the monitored security protection modules), the target collaborative protection list corresponding to this target protection module can be obtained according to the pre-configured rules. The target collaborative protection list is a list recording several security protection modules that need to perform information synchronization. Therefore, several to-be-synchronized protection modules that need to perform information synchronization currently can be determined according to the indication of the target collaborative protection list.

[0035] Exemplarily, when it is monitored that the abnormal event has occurred in the security protection module A (the target protection module), obtain the target collaborative protection list corresponding to the security protection module A. This target collaborative protection list records the security protection modules B and C. Then, it can be determined that the to-be-synchronized protection modules currently are the security protection modules B and C.

[0036] S3. Based on the abnormal event, generate linkage information corresponding to each to-be-synchronized protection module.

[0037] Based on the specific information of the currently occurring exception event, linkage information corresponding to each protection module to be synchronized can be generated respectively.

[0038] Specifically, in addition to pre-configuring the target collaborative protection list corresponding to the target protection module, rules for generating policies corresponding to the target protection module and each protection module to be synchronized can also be configured. Based on these policy generation rules, linkage protection policies corresponding to each protection module to be synchronized can be generated respectively according to the currently occurring exception event, and these linkage protection policies can be assembled into linkage information corresponding to each protection module to be synchronized respectively.

[0039] Exemplarily, when the target protection module (such as a vulnerability scanner) scans and detects the existence of a target vulnerability (an exception event occurs), according to information such as the vulnerability type and location of the target vulnerability, linkage information of other protection modules to be synchronized is generated. For example, for a firewall device, a linkage protection policy for this firewall device can be generated according to the current vulnerability information in accordance with the preset policy generation rules. This linkage protection policy can be used to represent the types of traffic that other protection modules (firewalls) need to intercept when a specific vulnerability (the current vulnerability) occurs in a certain device (the target protection module) in the network system.

[0040] S4. Send each piece of linkage information to the corresponding protection module to be synchronized respectively, so that each protection module to be synchronized updates its own protection policy based on the received linkage information and performs security protection operations according to the updated protection policy.

[0041] Specifically, after each protection module to be synchronized receives the linkage information sent by the target protection module, it respectively obtains the corresponding linkage protection policy therein according to the received linkage information, and on the basis of its own original protection policy, updates the original protection policy by adding or replacing the linkage protection policy, so as to perform security protection operations according to the updated protection policy.

[0042] In this way, when an exception event is detected by a certain security protection module in the entire network system, linkage information of other different security protection modules can be generated according to this exception event, so that other security protection modules can synchronously update their own protection policies, thereby realizing the collaborative protection operation of multiple security protection modules.

[0043] It should be noted that after each protection module to be synchronized receives its own linkage protection policy, it can compare the linkage protection policy with its own original protection policy to determine whether there is a duplicate or conflict situation between the linkage protection policy and the original protection policy. If so, the protection policy is not updated; otherwise, the protection policy is updated and security protection operations are performed according to the updated protection policy.

[0044] Based on this, by configuring collaborative protection functions for different security protection modules in the network system, corresponding linkage information is generated in a timely manner when an abnormal event of a certain module is detected, so that one or more other security protection modules corresponding to the module synchronously update the protection policy and perform collaborative security protection on the network system, thereby effectively improving the overall security protection performance of the network system.

[0045] In some possible embodiments, in step S2, obtaining the target collaborative protection list corresponding to the target protection module may include: S201. Determine the current abnormal level corresponding to the abnormal event; S202. Obtain the set of collaborative protection lists corresponding to the target protection module, and obtain the target collaborative protection list corresponding to the current abnormal level from the set of collaborative protection lists.

[0046] Specifically, each security protection module in the target network system can be configured with multiple collaborative protection lists according to requirements, and each collaborative protection list corresponds to a different abnormal level. It can be understood that the higher the abnormal level of the abnormal event, the lower the security, which means a larger protection scope is required. Therefore, the more protection modules to be synchronized are indicated in the collaborative protection list.

[0047] When an abnormal event occurs in the target protection module is detected, first determine the abnormal level of the currently occurring abnormal event, then obtain the set of collaborative protection lists corresponding to the target protection module (including multiple collaborative protection lists), and according to the corresponding relationship between the abnormal level and the collaborative protection list, obtain the target collaborative protection list corresponding to the current abnormal level from the set of collaborative protection lists as the target collaborative protection list corresponding to the target protection module.

[0048] Based on this, by configuring multiple collaborative protection lists for the same security protection module, different collaborative protection scopes can be determined according to different current abnormal levels, thereby further improving the flexibility of the overall security protection of the network system.

[0049] In some possible embodiments, step S1, real-time monitoring of the security protection status data of at least one security protection module in the target network system may include: S101. Determine at least one security protection module in the target network system whose collaborative protection function is in the enabled state, and real-time monitor the security protection status data of at least one security protection module.

[0050] It should be noted that for each security protection module in the target network system, the switch state of the collaborative protection function can be set separately, and the management user can switch the collaborative protection function of each security protection module to the on state or the off state according to the needs. It can be understood that during the process of real-time monitoring of the security protection status data, one or more security protection modules with the current collaborative protection function in the on state can be targeted.

[0051] It should be noted that in step S101, the security protection modules that need to be monitored in real time are selectively determined according to the switch state of the collaborative protection function. After an abnormal event occurs in these monitored security protection modules, linkage information can be sent to other security protection modules with the collaborative protection function in the off state according to their respective collaborative protection lists, and the security protection module can be made to perform collaborative protection operations.

[0052] Based on this, by flexibly setting the switch states of different security protection modules in the network system and monitoring the status of different ranges of security protection modules according to the opening situation of the collaborative protection function, the flexibility of the protection status monitoring can be further improved.

[0053] In some possible embodiments, in step S2, determining a number of to-be-synchronized protection modules indicated by the target collaborative protection list may include: S211. Determine at least one collaborative protection module recorded in the target collaborative protection list; S212. Determine the collaborative protection modules with the collaborative protection function in the on state among the at least one collaborative protection module as the number of to-be-synchronized protection modules indicated by the target collaborative protection list.

[0054] Specifically, one or more collaborative protection modules recorded in the list can be determined according to the target collaborative protection list, which are the original collaborative protection modules indicated by the target collaborative protection list; then, from these original one or more collaborative protection modules, according to the switch situation of the collaborative protection function of each security protection module (collaborative protection module), the collaborative protection modules with the collaborative protection function in the on state are selected as the number of to-be-synchronized protection modules that need to perform collaborative protection currently.

[0055] It should be noted that if all the collaborative protection modules originally recorded in the target collaborative protection list are currently in the off state, the number of current to-be-synchronized protection modules is zero, so the subsequent steps are no longer executed.

[0056] Based on this, by further screening the current to-be-synchronized protection modules according to the switch situation of these collaborative protection modules after determining the collaborative protection modules according to the collaborative protection list, the flexibility of collaborative security protection can be effectively improved.

[0057] In some possible embodiments, step S3, generating linkage information corresponding to each protection module to be synchronized based on the abnormal event, may include: S301. Obtain the policy generation rules corresponding to each protection module to be synchronized; S302. Generate collaborative protection policies corresponding to each protection module to be synchronized respectively according to each policy generation rule based on the abnormal event; S303. Assemble based on each collaborative protection policy respectively to obtain the linkage information corresponding to each protection module to be synchronized; Specifically, for each target protection module, the policy generation rules corresponding to the protection module and the respective protection modules to be synchronized can be configured. Then, according to the same abnormal event occurring currently, the collaborative protection policies (linkage protection policies) corresponding to each protection module to be synchronized can be generated respectively based on different policy generation rules, and the linkage information corresponding to the protection module to be synchronized can be assembled based on the collaborative protection policies corresponding to each protection module to be synchronized.

[0058] Step S4, sending each piece of linkage information to the corresponding protection module to be synchronized respectively, so that each protection module to be synchronized updates its own protection policy based on the received linkage information and performs security protection operations according to the updated protection policy, may include: S401. Send each piece of linkage information to the corresponding protection module to be synchronized respectively, so that each protection module to be synchronized obtains the corresponding collaborative protection policy based on the received linkage information, updates its own protection policy based on the corresponding collaborative protection policy, and performs security protection operations according to the updated protection policy.

[0059] Specifically, after sending each piece of linkage information to the corresponding protection module to be synchronized respectively, each protection module to be synchronized can obtain the corresponding collaborative protection policy from the linkage information received by itself, update its original protection policy according to the collaborative protection policy obtained by itself, and finally perform security protection operations according to the updated protection policy.

[0060] Based on this, by configuring different policy generation rules for different security protection modules and generating the linkage information of each protection module to be synchronized respectively according to different policy generation rules based on the current abnormal event, the step of generating policies in the protection module to be synchronized is omitted, thereby further improving the convenience and accuracy of generating linkage information.

[0061] In some possible embodiments, the collaborative security protection method of the network system may further include the steps: S501. Monitor the processing status data of the target protection module for the abnormal event in real time; S502. When it is determined based on the processing status data that the abnormal event has been eliminated, generate de-linkage information corresponding to each protection module to be synchronized respectively based on the abnormal event; S503. Send each piece of de-linkage information to the corresponding protection module to be synchronized respectively, so that each protection module to be synchronized updates its own protection policy based on the received de-linkage information and performs security protection operations according to the updated protection policy.

[0062] It should be noted that during the process of each security protection module performing collaborative protection operations for the abnormal event, by monitoring the processing status of the abnormal event in real time, when the abnormal event is processed (eliminated), the collaborative protection operations for the abnormal event can be terminated for each security protection module.

[0063] Specifically, since the current abnormal event is detected in the target protection module, the processing of the abnormal event is usually carried out by the target protection module. For example, if the target protection module is a vulnerability scanner and the abnormal event is the detection of a certain vulnerability, the vulnerability scanner needs to repair the detected vulnerability after detecting it.

[0064] By monitoring the processing status data of the target protection module for the abnormal event in real time, it can be determined whether the abnormal event has been processed and eliminated. When it is determined that the abnormal event has been eliminated, de-linkage information can be generated respectively for each protection module to be synchronized (the security protection modules currently participating in the collaborative protection operations for the abnormal event) according to the abnormal event.

[0065] It should be noted that the de-linkage information may include marking information corresponding to the abnormal event, or collaborative protection policies corresponding to the abnormal event (the collaborative protection policies of different protection modules to be synchronized for the same abnormal event are usually different); then, after each protection module to be synchronized receives the corresponding de-linkage information, it can obtain the corresponding marking information or collaborative protection policy therefrom, so as to remove the collaborative protection policy in the current protection policy that matches the marking information, or remove the corresponding collaborative protection policy in the current protection policy according to the collaborative protection policy obtained from the de-linkage information. Finally, perform security protection operations according to the updated protection policy.

[0066] Based on this, by monitoring the processing status of the abnormal event and sending de-linkage information to the relevant protection modules in time after the abnormal event is eliminated to terminate the collaborative protection operations of each protection module for the abnormal event, the overall security protection flexibility of the network system can be further improved.

[0067] In some possible embodiments, the collaborative security protection method of the network system may further include the steps: S601. When it is determined that the target network system meets the preset security level adjustment conditions based on the security protection status data, adjust the security level of the target network system; S602. Obtain the collaborative protection configuration policy corresponding to the adjusted security level, and turn on or off the collaborative protection functions of each security protection module in the target network system according to the collaborative protection configuration policy.

[0068] It should be noted that based on the security protection status data of each security protection module in the target network system, the security situation of the network environment where the target network system is located can be judged, so as to judge whether the target network system meets the preset security level adjustment conditions: when the security situation is relatively severe, the security level needs to be improved; when the security situation is relatively optimistic, the security level can be appropriately reduced.

[0069] Exemplarily, if the security protection status data of a certain security protection module indicates that a certain value exceeds the preset threshold (for example, the number of malicious file interceptions in a unit time period exceeds the threshold), it means that the security situation of the network environment where the target network system is located has become more severe, and it is judged that the target network system meets the preset security level adjustment conditions. At this time, the security level of the target network system needs to be adjusted (increase the security level).

[0070] It should be noted that the target network system can store a comparison table of different security levels and collaborative protection configuration policies configured in advance. According to the currently adjusted security level, the corresponding collaborative protection configuration policy can be adopted.

[0071] Among them, different collaborative protection configuration policies can include different indication information, which is used to represent the on / off state of the collaborative protection functions of each security protection module in the target network system. It can be understood that for the collaborative protection configuration policy with a higher security level, the more security protection modules whose collaborative protection functions need to be turned on are represented.

[0072] Exemplarily, for the collaborative protection configuration policy with a security level of one, it is used to indicate that the collaborative protection functions of two security protection modules, namely A and B, in the target network system are set to the on state, and the other security protection modules are set to the off state; for the collaborative protection configuration policy with a security level of two, it is used to indicate that the collaborative protection functions of three security protection modules, namely A, B, and C, in the target network system are set to the on state, and the other security protection modules are set to the off state, and so on.

[0073] Based on this, by monitoring the protection status of each security protection module and adjusting the security level of the target network system according to needs, the collaborative protection function of each security protection module is switched according to the collaborative protection configuration strategies corresponding to different levels, thereby further improving the overall security protection flexibility of the network system.

[0074] Please refer to Figure 2 , Figure 2 The block diagram of the network system collaborative security protection device provided by some embodiments of the present application is shown. It should be understood that the network system collaborative security protection device is similar to the above Figure 1 Corresponding to the method embodiment, it is able to execute each step involved in the above method embodiment. The specific functions of the collaborative security protection device of the network system can be found in the description above. To avoid repetition, the detailed description is appropriately omitted here.

[0075] Figure 2 The collaborative security protection device of the network system includes at least one software function module that can be stored in a memory in the form of software or firmware or solidified in the collaborative security protection device of the network system, and the collaborative security protection device of the network system includes: The data monitoring module 210 is used to monitor the security protection status data of at least one security protection module in the target network system in real time; The collaborative matching module 220 is used to obtain a target collaborative protection list corresponding to the target protection module and determine a number of protection modules to be synchronized indicated by the target collaborative protection list when it is determined that an abnormal event occurs in the target protection module based on the security protection status data; wherein the target protection module is any one of the at least one security protection module; An information generation module 230, used to generate linkage information corresponding to each protection module to be synchronized based on the abnormal event; The information sending module 240 is used to send each linkage information to the corresponding protection module to be synchronized, so that each protection module to be synchronized updates its own protection strategy based on the received linkage information and performs security protection operations according to the updated protection strategy.

[0076] It can be understood that the above-mentioned device item embodiments correspond to the method item embodiments of the present invention. A collaborative security protection device for a network system provided by an embodiment of the present invention can implement the collaborative security protection method for a network system provided by any method item embodiment of the present invention.

[0077] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the device described above can refer to the corresponding process in the aforementioned method, and will not be described in detail here.

[0078] like Figure 3As shown, some embodiments of the present application provide an electronic device 300, which includes: a memory 310, a processor 320, and a computer program stored on the memory 310 and executable on the processor 320. When the processor 320 reads the program from the memory 310 through a bus 330 and executes the program, it can implement the method of any embodiment included in the collaborative security protection method of the above network system.

[0079] The processor 320 can process digital signals and can include various computing architectures. For example, a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements a combination of multiple instruction sets. In some examples, the processor 320 can be a microprocessor.

[0080] The memory 310 can be used to store instructions executed by the processor 320 or data related to the execution of the instructions. These instructions and / or data can include code for implementing some or all of the functions of one or more modules described in the embodiments of the present application. The processor 320 of the present disclosure embodiment can be used to execute the instructions in the memory 310 to implement the method shown above. The memory 310 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memories well known to those skilled in the art.

[0081] Some embodiments of the present application also provide a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it executes the method described in the method embodiment.

[0082] Some embodiments of the present application also provide a computer program product. When the computer program product runs on a computer, it causes the computer to execute the method described in the method embodiment.

[0083] It should be noted that the embodiments in this specification are all described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For device embodiments, since they are basically similar to the method embodiments, the description is relatively simple. The relevant parts can refer to the partial description of the method embodiments.

[0084] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0085] In addition, each functional module in various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.

[0086] If the described functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs, etc., which can store program codes.

[0087] The above are only embodiments of the present application and are not intended to limit the protection scope of the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application. It should be noted that similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0088] As described above, these are only the specific implementation manners of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, and all of them should be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.

[0089] It should be noted that in this text, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.

Claims

1. A collaborative security protection method for a network system, characterized in that, include: Real-time monitoring of security protection status data of at least one security protection module in the target network system; In the case where it is determined based on the security protection status data that an abnormal event occurs in a target protection module, a target collaborative protection list corresponding to the target protection module is obtained, and a number of protection modules to be synchronized indicated by the target collaborative protection list are determined; wherein the target protection module is any one of the at least one security protection module; Generating linkage information corresponding to each of the protection modules to be synchronized based on the abnormal event; Each linkage information is sent to a corresponding protection module to be synchronized, so that each protection module to be synchronized updates its own protection strategy based on the received linkage information, and performs security protection operations according to the updated protection strategy.

2. The collaborative security protection method for the network system according to claim 1, characterized in that The acquiring the target collaborative protection list corresponding to the target protection module includes: Determine a current abnormality level corresponding to the abnormal event; A collaborative protection list set corresponding to the target protection module is obtained, and a target collaborative protection list corresponding to the current abnormal level is obtained from the collaborative protection list set.

3. The collaborative security protection method of the network system according to claim 1, characterized in that The real-time monitoring of the security protection status data of at least one security protection module in the target network system includes: At least one security protection module in the target network system whose collaborative protection function is in an enabled state is determined, and security protection status data of the at least one security protection module is monitored in real time.

4. The collaborative security protection method for the network system according to claim 1, wherein The determining of the plurality of protection modules to be synchronized indicated by the target coordinated protection list includes: Determine at least one collaborative protection module recorded in the target collaborative protection list; The collaborative protection modules in which the collaborative protection function is turned on in the at least one collaborative protection module are determined as the several protection modules to be synchronized indicated by the target collaborative protection list.

5. The collaborative security protection method for the network system according to claim 1, characterized in that The generating linkage information corresponding to each of the protection modules to be synchronized based on the abnormal event includes: Obtaining the policy generation rules corresponding to each of the protection modules to be synchronized; Based on the abnormal events, generating collaborative protection strategies corresponding to the protection modules to be synchronized according to the strategy generation rules; Assembling based on each of the collaborative protection strategies to obtain linkage information corresponding to each of the protection modules to be synchronized; The step of sending each linkage information to a corresponding protection module to be synchronized, so that each protection module to be synchronized updates its own protection strategy based on the received linkage information, and performs security protection operations according to the updated protection strategy, includes: Each linkage information is sent to the corresponding protection module to be synchronized, so that each protection module to be synchronized obtains the corresponding collaborative protection strategy based on the received linkage information, updates their own protection strategy based on the corresponding collaborative protection strategy, and performs security protection operations according to the updated protection strategy.

6. The collaborative security protection method for the network system according to claim 1, wherein Also includes: Real-time monitoring of the processing status data of the target protection module for the abnormal event; In the case where it is determined based on the processing status data that the abnormal event is eliminated, generating de-linking information corresponding to each of the to-be-synchronized protection modules based on the abnormal event; Send each of the de-linkage information to the corresponding protection module to be synchronized, so that each protection module to be synchronized updates its own protection policy based on the received de-linkage information and performs security protection operations according to the updated protection policy.

7. The collaborative security protection method of the network system according to claim 1, characterized in that It further includes: When it is determined based on the security protection status data that the target network system meets the preset security level adjustment conditions, adjust the security level of the target network system; Obtain the collaborative protection configuration policy corresponding to the adjusted security level, and turn on or off the collaborative protection functions of each security protection module in the target network system according to the collaborative protection configuration policy.

8. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the collaborative security protection method of the network system according to any one of claims 1-7 can be implemented.

9. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is run by the processor, it executes the collaborative security protection method of the network system according to any one of claims 1-7.

10. A computer program product, characterized in that, The computer program product includes a computer program, and when the computer program is executed by the processor, it implements the collaborative security protection method of the network system according to any one of claims 1-7.

Citation Information

Patent Citations

  • Terminal security protection method, device and system and storage medium

    CN112003862A

  • Power network dynamic defense system based on intelligent decision

    CN117319019A

  • Computer security protection management system

    CN119312322A

  • Systems and methods to protect against a vulnerability event

    US9313211B1