Network security policy configuration method, system, device and medium

By using the capsule neural network model to identify multiple intentions and calculate conflict evaluation values ​​in the network security policy configuration, the problems of low efficiency and poor accuracy caused by policy conflicts in the prior art are solved, and efficient and accurate automated configuration is achieved.

CN120238353APending Publication Date: 2025-07-01CHINA TELECOM NETWORK SECURITY TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510413319.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

During the configuration of existing network security policies, conflicts between policies lead to low configuration efficiency and poor accuracy, and the manual configuration process is cumbersome.

Method used

By obtaining the security intention information entered by the user, using the capsule neural network model to identify multiple intentions and calculate the conflict evaluation value between intentions, determine whether to implement current or historical security policies, avoid potential conflicts, and achieve automated configuration.

Benefits of technology

It improves the configuration efficiency of network security policies, ensures the accuracy of configuration, avoids conflicts between policies, and enhances the ability to automatically select and configure security policies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238353A_ABST
    Figure CN120238353A_ABST
Patent Text Reader

Abstract

The invention discloses a network security policy configuration method, system and device and a medium, and the method comprises the steps: obtaining security intention information inputted by a user, determining a current security intention according to the security intention information, and when the current security intention conflicts with a historical security intention, determining a network security policy according to the current security intention; calculating a conflict evaluation value between the current security intention and the historical security intention, judging whether the conflict evaluation value is greater than a preset threshold, and if yes, continuing to execute a historical security policy corresponding to the historical security intention; and if not, executing the current security policy corresponding to the current security intention. Through the method, the automatic configuration of the network security policy based on the user intention is completed, the configuration efficiency of the network security policy is improved, the conflict between the network security policies can be avoided based on the conflict evaluation between the security intentions, and the accuracy of the configured network security policy is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network technologies, and in particular, to a method, system, device, and medium for configuring network security policies. Background Art

[0002] Currently, there is a wide variety of security services for network security, so various network security policies have emerged. The configuration of network security policies is implemented by a set of constraint rules. However, conflicts may occur between these network security policies, resulting in the failure of network security policies. To avoid this problem, manual configuration needs to be added, but manual configuration also makes the configuration process cumbersome and inefficient.

[0003] To improve the configuration efficiency of network security policies, currently, an intent-driven approach can be used to implement network security policy configuration. Intent-driven means determining the user's intent based on the user input information, and then configuring the corresponding network security policy according to the intent. However, the current intent-driven approach only configures for a single intent, resulting in low efficiency and accuracy in configuring network security policies. Summary of the Invention

[0004] This application provides a method, system, device, and medium for configuring network security policies, which is used for the automated configuration of network security policies based on user intents, improving the configuration efficiency of network security policies.

[0005] In a first aspect, an embodiment of this application provides a method for configuring network security policies. The method includes: Obtaining security intent information input by a user, and determining a current security intent according to the security intent information; In response to a conflict between the current security intent and a historical security intent, calculating a conflict evaluation value between the current security intent and the historical security intent; Determining whether the conflict evaluation value is greater than a preset threshold; If so, continuing to execute the historical security policy corresponding to the historical security intent; If not, executing the current security policy corresponding to the current security intent.

[0006] Through the above method, the automated configuration of network security policies based on user intents is completed, improving the configuration efficiency of network security policies. Moreover, based on the conflict evaluation between security intents, conflicts between network security policies can be avoided, ensuring the accuracy of the configured network security policies.

[0007] In an optional embodiment, the determining the current security intent according to the security intent information includes: Extract the current security intention features from the security intention information; Import the current security intention features and historical security intention features into the capsule network model to obtain multiple candidate security intentions; Based on a preset threshold, determine the current security intention among the multiple candidate security intentions.

[0008] Train the capsule neural network model by fusing security intention features and historical security intention features, which can achieve the multi-intention recognition ability of security intention information and improve the parsing ability of user intentions. In an alternative embodiment, calculating the conflict evaluation value between the current security intention and the historical security intention includes: Determine each current security execution policy corresponding to the current security intention and each historical security execution policy corresponding to the historical security intention; Determine whether each current security execution policy is consistent with each historical security execution policy; If they are consistent, determine that the current security intention and the historical security intention do not conflict; If they are not consistent, determine that the current security intention and the historical security intention conflict, and calculate the conflict evaluation value between the current security intention and the historical security intention.

[0009] By the above method, before executing the security policy, it will be determined whether there is a conflict between the current security intention containing the security policy and the historical security intention, thus avoiding potential security policy conflicts and enhancing the automated selection and configuration ability of security policies.

[0010] In an alternative embodiment, calculating the conflict evaluation value between the current security intention and the historical security intention includes: Generate a user marking value according to the permission relationship between the first user corresponding to the current security intention and the second user corresponding to the historical security intention; Generate a time marking value according to the saved time of the historical security intention; Calculate the conflict evaluation value according to the user marking value and the time marking value.

[0011] In a second aspect, an embodiment of the present application provides a network security policy configuration system, and the system includes: An acquisition module, configured to acquire security intention information input by a user and determine a current security intention according to the security intention information; A processing module, configured to calculate the conflict evaluation value between the current security intention and the historical security intention in response to a conflict between the current security intention and the historical security intention; Determine whether the conflict evaluation value is greater than a preset threshold; If so, continue to execute the historical security policy corresponding to the historical security intention; If not, execute the current security policy corresponding to the current security intention.

[0012] In an alternative embodiment, the processing module is specifically configured to extract the current security intention features in the security intention information; Import the current security intention features and the historical security intention features into a capsule network model to obtain multiple candidate security intentions; Based on a preset threshold, determine the current security intention among the multiple candidate security intentions.

[0013] In an alternative embodiment, the processing module is specifically configured to determine each current security execution policy corresponding to the current security intention and each historical security execution policy corresponding to the historical security intention; Determine whether each current security execution policy is consistent with each historical security execution policy; If they are consistent, determine that the current security intention does not conflict with the historical security intention; If they are not consistent, determine that the current security intention conflicts with the historical security intention, and calculate the conflict evaluation value between the current security intention and the historical security intention In an alternative embodiment, the processing module is specifically configured to generate a user marking value according to the permission relationship between the first user corresponding to the current security intention and the second user corresponding to the historical security intention; Generate a time marking value according to the saved time of the historical security intention; Calculate the conflict evaluation value according to the user marking value and the time marking value.

[0014] In a third aspect, an embodiment of the present application provides an electronic device, including: A memory for storing a computer program; A processor for implementing the method steps of the above-mentioned network security policy configuration method when executing the computer program stored on the memory.

[0015] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the method steps of the above-mentioned network security policy configuration method are implemented.

[0016] For the technical effects that can be achieved by each of the above-mentioned second to fourth aspects and each aspect, please refer to the technical effects that can be achieved by the above-mentioned first aspect or various possible solutions in the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 FIG. is a flowchart of a network security policy configuration method provided by an embodiment of the present application; Figure 2 FIG. is a schematic structural diagram of a network security policy configuration system provided by an embodiment of the present application; Figure 3 FIG. is a schematic structural diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0018] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings. The specific operation methods in the method embodiments can also be applied to the device embodiments or system embodiments. It should be noted that in the description of the present application, "a plurality of" is understood as "at least two". "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. The connection between A and B may represent: the direct connection between A and B and the connection between A and B through C. In addition, in the description of the present application, terms such as "first" and "second" are only used for the purpose of distinguishing descriptions, and cannot be understood as indicating or implying relative importance, nor can they be understood as indicating or implying an order.

[0019] The embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0020] Currently, there are a variety of security services for network security, so various network security policies have emerged. These network security policies need to be configured correspondingly in the system so that the configured network security policies can be executed during the operation of the system. Currently, the configuration of network security policies is implemented by a set of constraint rules. However, conflicts may occur between these network security policies, resulting in the failure of network security policies. To avoid this problem, manual configuration needs to be added, but manual configuration also makes the configuration process cumbersome and inefficient.

[0021] To improve the configuration efficiency of network security policies, currently, an intent-driven method can be used to implement network security policy configuration. Intent-driven means determining the user's intent based on the user input information, and then configuring the corresponding network security policy according to the intent. However, the current intent-driven method only configures for a single intent, resulting in low efficiency and accuracy in the configuration of network security policies.

[0022] In order to solve the problem that the efficiency and accuracy of network security policy configuration are relatively low in the prior art, the present application provides a network security policy configuration method, which includes: obtaining security intention information input by a user, and determining a current security intention according to the security intention information. When there is a conflict between the current security intention and a historical security intention, calculating a conflict evaluation value between the current security intention and the historical security intention, and determining whether the conflict evaluation value is greater than a preset threshold. If so, continuing to execute a historical security policy corresponding to the historical security intention; if not, executing a current security policy corresponding to the current security intention. Through the above method, the automatic configuration of network security policies based on user intentions is completed, the configuration efficiency of network security policies is improved, and conflicts between network security policies can be avoided based on the conflict evaluation between security intentions, ensuring the accuracy of the configured network security policies.

[0023] Refer to Figure 1 The following is a flowchart of a network security policy configuration method provided by an embodiment of the present application, which includes: S1, obtaining security intention information input by a user, and determining a current security intention according to the security intention information; After the system obtains the security intention information input by the user, where the security intention information is text information input by the user in natural language, the security intention information will be imported into a pre-trained capsule neural network model to extract the current security intention. Therefore, in the embodiment of the present application, before using the capsule neural network model, it is necessary to first train the capsule neural network model. The specific training method is as follows: First, obtain a security intention information sample, which can be obtained from a sample database or other means.

[0024] Then, import the obtained security intention information sample into a convolutional neural network model to extract the security intention features in the security intention information sample, and then further obtain historical security intention features, which are pre-stored or features extracted from historical security intentions by other neural networks.

[0025] The extracted security intention features and historical security intention features are input into the capsule neural network model together. Then, the semantic information of the security intention features and historical security intention features is extracted in the convolutional capsule layer of the capsule neural network model. Finally, the capsule neural network model outputs various security intentions based on this semantic information. It is determined whether the capsule neural network model converges according to the output security intentions and the loss function. If the capsule neural network model converges, the trained capsule neural network model is obtained; if the capsule neural network model does not converge, the capsule neural network model continues to be trained until it converges.

[0026] In the above training process, the capsule neural network model is trained by fusing security intention features and historical security intention features, which can achieve the multi-intention recognition ability of security intention information and improve the parsing ability of user intentions.

[0027] After completing the above training to obtain the trained capsule neural network model, the obtained security intention information of the user input is imported into the capsule neural network model to obtain the current security intention corresponding to the security intention information.

[0028] It should be noted here that after importing the security intention information of the user input into the capsule neural network model, the capsule neural network model will output the probability values of multiple candidate security intentions. Each of these probability values is obtained after non-normalization processing, so these probability values will exist within an interval range. The system compares the obtained probability values with a preset threshold to determine the current security intention corresponding to the security intention information of the user input.

[0029] S2. In response to a conflict between the current security intention and the historical security intention, calculate the conflict evaluation value between the current security intention and the historical security intention; After obtaining the current security intention corresponding to the security intention information of the user input, it is further determined whether there is a conflict between the current security intention and the historical security intention. The specific implementation process is as follows: First, analyze the obtained current security intention to determine the activation ability corresponding to the current security intention and the current execution policy for executing this activation ability. Then, determine the historical security intention containing this activation ability according to this activation ability. For example, if the activation ability in the current security intention is A, then determine the historical security intention containing this activation ability A among all historical security intentions.

[0030] After determining the historical security intention, further determine the historical execution policy corresponding to the activation ability in the historical security intention, and then determine whether each current security execution policy is consistent with the historical security execution policy. If they are consistent, it is determined that there is no conflict between the current security intention and the historical security intention; if they are inconsistent, it is determined that there is a conflict between the current security intention and the historical security intention. For example, if the current execution policies corresponding to activation ability A in the current security intention are A1 and A2, and if the historical execution policies in the determined historical security intention are also A1 and A2, it means that there is no conflict between the current security intention and the historical security intention; if the historical execution policies in the determined historical security intention are B1 and B2, it means that there is a conflict between the current security intention and the historical security intention.

[0031] If there is no conflict between the current security intention and the historical security intention, directly use the security execution policy corresponding to the historical security intention.

[0032] In this way, the conflict between the current security intention and the historical security intention can be determined more accurately, and this can also effectively avoid potential conflicts between security policies caused by conflicts between security intentions, thereby enhancing the automated selection and configuration ability of security policies.

[0033] If there is a conflict between the current security intention and the historical security intention, it is also necessary to further calculate the conflict evaluation value between the current security intention and the historical security intention. The specific calculation method of this conflict evaluation value is as follows: First, obtain the user marking value, which is obtained based on the first user corresponding to the current security intention and the second user corresponding to the historical security intention. Specifically, determine the permission inclusion relationship between the first user and the second user in the system, and this permission inclusion relationship can be obtained based on the superior-subordinate relationship between the first user and the second user. For example, if the first user is the superior of the second user, the user marking value is M; if the first user is the subordinate of the second user, the user marking value is N. It should be noted here that the smaller the permission of the second user, the smaller the user marking value.

[0034] In addition to obtaining the user marking value, it is also necessary to further obtain the time marking value, which is obtained based on the saved time of the historical security intention. The longer the saved time of the historical security intention, the smaller the time marking value.

[0035] After obtaining the user marking value and the time marking value, the conflict evaluation value can be calculated through the following formula:

[0036] Indicates the conflict evaluation value. The characterized user marking value, The characterized time marking value, Are weight coefficients respectively.

[0037] In the above - mentioned way, before executing the security policy, it can be determined whether there is a conflict between the current security intention containing the security policy and the historical security intention, thus avoiding potential security policy conflicts and enhancing the automated selection and configuration ability of security policies.

[0038] S3, Determine whether the conflict evaluation value is greater than a preset threshold; After calculating the conflict evaluation value between the current security intention and the historical security intention, compare this conflict evaluation value with the preset threshold. The preset threshold is evaluated based on historical data or can also be configured according to different application scenarios.

[0039] When the conflict evaluation value is greater than the preset threshold, execute step S4; if the conflict evaluation value is less than the preset threshold, execute step S5.

[0040] S4, Continue to execute the historical security policy corresponding to the historical security intention; The conflict evaluation value being greater than the preset threshold indicates that the conflict between the current security intention and the historical security intention is small, that is to say, there will be no obvious conflict between the historical security intention and the current security intention. Therefore, the current security intention can follow the security policy in the historical security intention. Thus, the system can continue to execute the historical security policy corresponding to the historical security intention.

[0041] In the above - mentioned way, if the conflict between the current security intention and the historical security intention is small, the historical security policy corresponding to the historical security intention will be automatically followed, thus avoiding potential security policy conflicts and enhancing the automated selection and configuration ability of security policies.

[0042] S5, Execute the current security policy corresponding to the current security intention.

[0043] If the conflict evaluation value is less than the preset threshold, it indicates that the conflict between the current security intention and the historical security intention is large. Therefore, the security policy in the historical security intention cannot be directly followed, but the latest security policy needs to be executed. The latest security policy is the security policy corresponding to the current security intention. For example, the security policies corresponding to the current security intention are S1, S2, and the security policies corresponding to the historical security intention are K1, K2. When the conflict evaluation value is less than the threshold, execute the security policies S1, S2.

[0044] In this way, when there is a significant conflict between the current security intention and the historical security intention, the latest security policy will be used, which can effectively avoid potential conflicts between security policies caused by conflicts between security intentions, thereby enhancing the automated selection and configuration ability of security policies.

[0045] In an alternative embodiment, after executing the latest security policy, the system will overwrite the historical security intention with the current security intention in the conflict comparison library, thereby forming a new conflict-based comparison library that stores various conflicting security intentions. In this way, the conflict-based comparison library can be updated in a timely manner, ensuring that the security intentions in the basic conflict comparison library are those generated by the most recent conflicts, thus improving the accuracy of conflict detection for security intentions.

[0046] In addition, in addition to updating the conflict-based comparison library, the system will also output feedback information, which is used to prompt the user to update or reconfigure the security policy of the security intention, thereby avoiding conflicts during the execution of the security policy of the current security intention.

[0047] Based on the same inventive concept, an embodiment of the present application also provides a network security policy configuration system. Referring to Figure 2 FIG. is a schematic structural diagram of a network security policy configuration system provided by an embodiment of the present application. The system includes: An acquisition module 201, configured to acquire security intention information input by a user and determine a current security intention according to the security intention information; A processing module 202, configured to calculate a conflict evaluation value between the current security intention and the historical security intention in response to a conflict between the current security intention and the historical security intention; Determine whether the conflict evaluation value is greater than a preset threshold; If so, continue to execute the historical security policy corresponding to the historical security intention; If not, execute the current security policy corresponding to the current security intention.

[0048] In an alternative embodiment, the processing module 202 is specifically configured to extract the current security intention features in the security intention information; Import the current security intention features and historical security intention features into a capsule network model to obtain multiple candidate security intentions; Based on a preset threshold, determine the current security intention among the multiple candidate security intentions.

[0049] In an alternative embodiment, the processing module 202 is specifically configured to determine each current security execution policy corresponding to the current security intention, and each historical security execution policy corresponding to the historical security intention; Determine whether each of the current security execution policies is consistent with each of the historical security execution policies; If they are consistent, determine that the current security intention does not conflict with the historical security intention; If they are inconsistent, determine that the current security intention conflicts with the historical security intention, and calculate a conflict evaluation value between the current security intention and the historical security intention.

[0050] In an alternative embodiment, the processing module 202 is specifically configured to generate a user marking value according to the permission relationship between a first user corresponding to the current security intention and a second user corresponding to the historical security intention; Generate a time marking value according to the saved time of the historical security intention; Calculate the conflict evaluation value according to the user marking value and the time marking value.

[0051] Based on the same inventive concept, an electronic device is further provided in an embodiment of the present application. The electronic device can implement the functions of the foregoing network security policy configuration system. Refer to Figure 3 , the electronic device includes: At least one processor 301, and a memory 302 connected to at least one processor 301. In the embodiment of the present application, the specific connection medium between the processor 301 and the memory 302 is not limited. Figure 3 It is taken as an example that the processor 301 and the memory 302 are connected through a bus 300. The bus 300 is Figure 3 shown by a thick line in Figure 3 . The connection manners between other components are only for illustrative purposes and are not to be taken as a limitation. The bus 300 can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation,

[0052] In the embodiment of the present application, the memory 302 stores instructions executable by at least one processor 301. By executing the instructions stored in the memory 302, at least one processor 301 can execute a network security policy configuration method described above. The processor 301 can implement Figure 2 the functions of each module in the system shown.

[0053] Among them, the processor 301 is the control center of the device. It can connect various parts of the entire control device through various interfaces and circuits. By running or executing the instructions stored in the memory 302 and invoking the data stored in the memory 302, various functions of the device and process data, thereby monitoring the device as a whole.

[0054] In a possible design, the processor 301 may include one or more processing units. The processor 301 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor may not be integrated into the processor 301 either. In some embodiments, the processor 301 and the memory 302 may be implemented on the same chip. In some embodiments, they may also be separately implemented on independent chips.

[0055] The processor 301 may be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application-specific integrated circuit, a field-programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of a network security policy configuration method disclosed in combination with the embodiments of the present application may be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.

[0056] The memory 302, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 302 can include at least one type of storage medium. For example, it can include flash memory, hard disks, multimedia cards, card-type memories, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memories, magnetic disks, optical disks, and so on. The memory 302 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 302 in the embodiments of the present application can also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.

[0057] By designing and programming the processor 301, the code corresponding to the network security policy configuration method introduced in the foregoing embodiments can be solidified into the chip, so that the chip can execute Figure 3 the steps of the network security policy configuration method of the embodiment shown. How to design and program the processor 301 is a well-known technology to those skilled in the art and will not be elaborated here.

[0058] Based on the same inventive concept, the embodiments of the present application also provide a storage medium storing computer instructions, which, when running on a computer, cause the computer to execute a network security policy configuration method described above.

[0059] In some possible implementation manners, each aspect of the network security policy configuration method provided in the present application can also be implemented in the form of a program product, which includes program code. When the program product runs on a device, the program code is used to cause the control device to execute the steps in the network security policy configuration method according to various exemplary embodiments of the present application described above in this specification.

[0060] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0061] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or combinations of blocks.

[0062] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or combinations of blocks.

[0063] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or combinations of blocks.

[0064] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.

Claims

1. A network security policy configuration method, characterized in that: The method comprises: Obtaining security intention information input by the user, and determining the current security intention based on the security intention information; In response to a conflict between the current safety intention and the historical safety intention, calculating a conflict evaluation value between the current safety intention and the historical safety intention; Determining whether the conflict evaluation value is greater than a preset threshold; If yes, continue to execute the historical security policy corresponding to the historical security intention; If not, the current security policy corresponding to the current security intention is executed.

2. The method according to claim 1, characterized in that The determining the current security intention according to the security intention information includes: Extracting the current security intention feature from the security intention information; Importing the current security intention features and historical security intention features into the capsule network model to obtain multiple security intentions to be selected; Based on a preset threshold, the current security intention is determined from the multiple security intentions to be selected.

3. The method according to claim 1, characterized in that Calculating a conflict evaluation value between the current safety intention and the historical safety intention includes: Determine each current security execution policy corresponding to the current security intention, and each historical security execution policy corresponding to the historical security intention; Determining whether each of the current security execution policies is consistent with each of the historical security execution policies; If they are consistent, it is determined that the current security intention does not conflict with the historical security intention; If they are inconsistent, it is determined that the current safety intention conflicts with the historical safety intention, and a conflict evaluation value between the current safety intention and the historical safety intention is calculated.

4. The method according to claim 1, characterized in that The calculating the conflict evaluation value between the current safety intention and the historical safety intention includes: generating a user tag value according to a permission relationship between a first user corresponding to the current security intention and a second user corresponding to the historical security intention; Generating a time stamp value according to the saved time of the historical security intention; The conflict assessment value is calculated according to the user mark value and the time mark value.

5. A network security policy configuration system, characterized in that: The system comprises: An acquisition module is used to acquire security intention information input by a user and determine the current security intention based on the security intention information; a processing module, configured to calculate a conflict evaluation value between the current security intention and the historical security intention in response to a conflict between the current security intention and the historical security intention; Determining whether the conflict evaluation value is greater than a preset threshold; If yes, continue to execute the historical security policy corresponding to the historical security intention; If not, the current security policy corresponding to the current security intention is executed.

6. The system according to claim 5, characterized in that The processing module is specifically used to extract the current security intention features in the security intention information; Importing the current security intention features and historical security intention features into the capsule network model to obtain multiple security intentions to be selected; Based on a preset threshold, the current security intention is determined from the multiple security intentions to be selected.

7. The system according to claim 5, characterized in that The processing module is specifically used to determine each current security execution policy corresponding to the current security intention, and each historical security execution policy corresponding to the historical security intention; Determining whether each of the current security execution policies is consistent with each of the historical security execution policies; If they are consistent, it is determined that the current security intention does not conflict with the historical security intention; If they are inconsistent, it is determined that the current safety intention conflicts with the historical safety intention, and a conflict evaluation value between the current safety intention and the historical safety intention is calculated.

8. The system according to claim 5, characterized in that The processing module is specifically configured to generate a user tag value according to a permission relationship between a first user corresponding to the current security intention and a second user corresponding to the historical security intention; Generating a time stamp value according to the saved time of the historical security intention; The conflict assessment value is calculated according to the user mark value and the time mark value.

9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to implement the method steps of any one of claims 1 to 4 when executing the computer program stored in the memory.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps described in any one of claims 1 to 4 are implemented.

Citation Information

Cited By

  • Plann reuse method, device and equipment for row-level security policy, medium and product

    CN121681590A