Network security management method and device, equipment, storage medium and product
By using icons and colors to display access control actions in the network security management system, and displaying source and destination information in the form of cards and directed connections, the problem of users' difficulty in managing a large number of network access isolation policies is solved, and the readability and management efficiency of the policies are improved.
Patent Information
- Application Number
- CN202510413630.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-07-18
AI Technical Summary
It is difficult for users to understand and manage a large amount of information in network access isolation policies, resulting in inefficient management.
Improve the readability and comprehensibility of information by displaying access control actions in icons and colors in the policy management page, and displaying source and destination information in the form of cards and directed connections.
It improves the readability and management efficiency of users' network access isolation policies, allowing users to understand the protection effects of policies and the relationship between the objects they act.
Smart Images

Figure CN120342670A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of network security technologies, and in particular, to a network security management method, apparatus, device, storage medium, and product. Background Art
[0002] With the development of network technologies and the promotion of digital office work, more and more users conduct business through network-side resources (such as big data processing platforms, distributed storage systems, etc.). To ensure the security during business execution and the reasonable allocation of network resources, network security protection is carried out for the access and use of network-side resources. Among them, users can configure network security protection methods adapted to their business by setting network access isolation policies. In this way, each user corresponds to thousands of network access isolation policies, and each policy corresponds to various information such as a policy name, network access source and destination ends, network access control actions, whether the policy is in effect, the policy modification date, and corresponding operations. When a user manages the network access isolation policies they have set, a large amount of information is laid out flat, making it difficult for the user to understand the protection effect of the policies and to clarify the relationship between each policy and various network-side resources, resulting in low management efficiency of network access isolation policies. Summary of the Invention
[0003] To solve the above technical problems, embodiments of the present disclosure provide a network security management method, apparatus, device, storage medium, and product.
[0004] In a first aspect, embodiments of the present disclosure provide a network security management method, which includes:
[0005] Responding to an interactive operation of viewing a policy, determining an action display style of an access control action in a network access isolation policy; wherein, the action display style includes an icon and / or color adapted to the access control action;
[0006] In a policy management page, displaying the access control action in the network access isolation policy in the action display style, and respectively displaying source end information and destination end information in the network access isolation policy in a first card form and a second card form, and displaying a data flow relationship between the source end information and the destination end information with a directed connection line.
[0007] In a second aspect, embodiments of the present disclosure further provide a network security management apparatus, which includes:
[0008] An action display style determination module, configured to respond to an interactive operation of viewing a policy, and determine an action display style of an access control action in a network access isolation policy; wherein, the action display style includes an icon and / or color adapted to the access control action;
[0009] A policy display module, configured to display, in a policy management page, access control actions in the network access isolation policy in the action display style, and display source - end information and destination - end information in the network access isolation policy in a first card form and a second card form respectively, and display the data flow relationship between the source - end information and the destination - end information with a directed connection line.
[0010] Thirdly, an embodiment of the present disclosure further provides an electronic device, which includes:
[0011] A processor;
[0012] A memory for storing executable instructions;
[0013] Wherein, the processor is configured to read the executable instructions from the memory and execute the executable instructions to implement the network security management method described in any embodiment of the present disclosure.
[0014] Fourthly, an embodiment of the present disclosure further provides a computer - readable storage medium, which stores a computer program. When the computer program is executed by a processor, the processor is caused to implement the network security management method described in any embodiment of the present disclosure.
[0015] Fifthly, an embodiment of the present disclosure further provides a computer program product, which is used to execute the network security management method described in any embodiment of the present disclosure.
[0016] The network security management method, device, equipment, storage medium and product of the embodiments of the present disclosure can, in response to an interactive operation of viewing a policy, determine an action display style of an access control action in a network access isolation policy; the action display style includes an icon and / or color adapted to the access control action; in the policy management page, display the access control action in the network access isolation policy in the action display style, and display source - end information and destination - end information in the network access isolation policy in a first card form and a second card form respectively, and display the data flow relationship between the source - end information and the destination - end information with a directed connection line; in this way, through the access control action visually displayed in the action display style, users can more concisely and effectively understand the protection effect of each network access control action; and, by highlighting the source - end information and destination - end information in the network access isolation policy in a first card form and a second card form, the information of the objects of the policy is more concentrated and intuitive, without the user having to laboriously search for the required information among various information of the policy, improving the efficiency of the user's understanding of the relationship between the policy and its objects, thereby improving the readability and comprehensibility of the network access isolation policy, and further improving the efficiency of the user's management of each network access isolation policy.
[0017] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the embodiments of the present disclosure are all information and data that have been authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions, and corresponding operation entrances are provided for users to choose to authorize or reject. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In combination with the accompanying drawings and with reference to the following specific embodiments, the above and other features, advantages, and aspects of the embodiments of the present disclosure will become more apparent. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the elements and elements are not necessarily drawn to scale.
[0019] Figure 1 It is a schematic diagram showing the display of a network security management page in the related art;
[0020] Figure 2 It is a schematic flowchart of a network security management method provided by an embodiment of the present disclosure;
[0021] Figure 3 It is a schematic diagram showing the display of each network access isolation policy in a list style provided by an embodiment of the present disclosure;
[0022] Figure 4 It is a schematic diagram showing the display of each network access isolation policy in a topology relationship map style centered on a cluster provided by an embodiment of the present disclosure;
[0023] Figure 5 It is a schematic diagram showing the display of each network access isolation policy in the form of an isolation policy group provided by an embodiment of the present disclosure;
[0024] Figure 6 It is a schematic diagram showing the display of each network access isolation policy within an isolation policy group provided by an embodiment of the present disclosure;
[0025] Figure 7 It is a schematic diagram showing the display of a policy creation page provided by an embodiment of the present disclosure;
[0026] Figure 8 It is a schematic diagram showing the display of a group change configuration page provided by an embodiment of the present disclosure;
[0027] Figure 9 It is a schematic diagram showing the structure of a network security management device provided by an embodiment of the present disclosure;
[0028] Figure 10 It is a schematic diagram showing the structure of an electronic device provided by an embodiment of the present disclosure. Detailed implementation manners
[0029] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Instead, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.
[0030] It should be understood that the various steps recited in the method embodiments of the present disclosure can be executed in different orders and / or executed in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this regard.
[0031] The term "including" and its variations used herein are open-ended, that is, "including but not limited to". The term "based on" is "based at least in part on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.
[0032] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order of the functions performed by these devices, modules or units or the interdependent relationship therebetween.
[0033] It should be noted that the modifications of "one" and "plural" mentioned in the present disclosure are illustrative rather than restrictive. Those skilled in the art should understand that, unless otherwise clearly specified in the context, it should be understood as "one or more".
[0034] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.
[0035] See Figure 1, multiple network access isolation policies in the policy management page are basically displayed in a tiled list of information. Each network access isolation policy will display various detailed policy information such as the policy name, network access source, protocol / port of network access, destination of network access, network access control action (also known as policy action), policy status indicating whether the policy is in effect, operations that can be performed on the policy, and the policy modification date. Then, when the user has hundreds or thousands of network access isolation policies, a large amount of information will be presented on the policy management page. In this way, it is not easy for the user to figure out which network access isolation policies are deployed in the network-side resources / cloud resources / resources based on cloud services / resources based on public clouds (such as containers, clusters, hosts, etc.) they manage, and it is also difficult to quickly understand the protection effect of each policy, resulting in a weak perception of each network access isolation policy by the user, and thus unable to efficiently manage each network access isolation policy.
[0036] Based on the above situation, the embodiments of the present disclosure provide a network security management solution to visually display the access control actions, source information, destination information, etc. of each network access isolation policy in the policy management page, so as to improve the readability of policy information, enable the user to more quickly understand the protection effects of each policy, and more intuitively focus on information such as the objects of action of the policy, thereby enhancing the user's perception of each network access isolation policy, and further enhancing the management efficiency of each network access isolation policy.
[0037] The network security management method provided by the embodiments of the present disclosure can be applied to scenarios where each network access isolation policy is managed (such as viewed, added, deleted, changed, etc.) in traditional network security or cloud security related services. Here, the network access isolation policy is set for network-side resources / cloud resources / resources based on cloud services / resources based on public clouds. This method can be executed by a network security management device, which can be implemented in software and / or hardware, and the device can be integrated in an electronic device with a display function. The electronic device may include, but is not limited to, smartphones, personal digital assistants (PDAs), tablet personal computers (Tablet PCs), laptop computers, mobile workstations, desktop computers, etc.
[0038] Figure 2 shows a schematic flowchart of a network security management method provided by an embodiment of the present disclosure. As Figure 2 shown, the network security management method may include the following steps:
[0039] S210. In response to an interactive operation of viewing a policy, determine the action display style of the access control action in the network access isolation policy.
[0040] Among them, the network access isolation policy is a network security mechanism designed to ensure that only devices that meet security standards can access network resources. Its main goal is to prevent insecure or non-compliant devices from accessing the network, thereby reducing security risks. The access control action is a real-time response behavior set in the network access isolation policy for the access requests of users or devices. The access control actions can include an allow action that allows a user or device to access network-side resources, a deny action that prohibits a user or device from accessing network-side resources, a monitor action that does not directly prevent a user or device from accessing network-side resources but monitors and records it in real time, a warning action that allows a user or device to access network-side resources but issues a warning to the administrator, an isolation action that restricts the access request of a user or device to an isolated environment, and so on.
[0041] The action display style is a display style for visually displaying the access control actions. In the embodiments of the present disclosure, the action display style includes icons and / or colors adapted to the access control actions. To enhance the user's perception and understanding of the access control actions in the policy, visual icons and / or colors that match the semantics of the access control actions can be preset for each access control action. The colors here can be text colors and / or icon colors. For example, the action display style of the allow action can be a checkmark icon representing passage / through and / or green; the action display style of the deny action can be a cross (or X) icon representing block and / or red; the action display style of the monitor action can be an exclamation mark icon representing warning / alarm and / or orange, etc.
[0042] Specifically, the user can start an application / web page / miniapp, etc. with policy management capabilities, and the electronic device can respond to this function startup operation and trigger the management process of the network access isolation policy. The user can also trigger a switch to the relevant page for viewing / managing each network access isolation policy in the relevant page of the already started application / web page / miniapp, etc., and the electronic device can respond to the page switching operation and trigger the management process of the network access isolation policy, etc. In the management process, the electronic device can obtain the detailed policy information of multiple network access isolation policies under the jurisdiction of this user. Then, the electronic device can, according to the access control actions in each network access isolation policy, screen out from the multiple preset action display styles the action display style that is adapted to the access control action and has a higher degree of visualization. This can avoid presenting the access control actions of the network access isolation policy only in text form, thereby enhancing the user's perception and understanding of the protection effect of the network access isolation policy.
[0043] S120. On the policy management page, display the access control actions in the network access isolation policy in an action display style, and display the source information and destination information in the network access isolation policy in the first card form and the second card form respectively, and display the data flow relationship between the source information and the destination information with a directed connection line.
[0044] Among them, the policy management page is an interactive page for providing management functions for viewing, adding, deleting, changing, etc. of network access isolation policies. The first card form and the second card form are two pre-set forms of visual cards for displaying source information and destination information respectively, which may include card styles, information types and amounts of information that the cards can carry, etc. The first card form and the second card form may be the same or different, and can be specifically set according to business requirements. Source information refers to the relevant information of the starting point (i.e., the source) of the network access request. The source can be, for example, the user who issues the request, the device, the network address, the network area, etc. Destination information refers to the relevant information of the target / destination (i.e., the destination) of the network request. The destination can be, for example, the network address, device, service, network area, etc. that the request wants to access.
[0045] Specifically, since there is a lot of policy information for each network access isolation policy, such as Figure 1 shown, the simple text form is difficult to highlight the important information that users care about. Therefore, in the embodiments of the present disclosure, the first card form and the second card form can be set in advance according to the source information and the destination information, so as to use the card form to aggregate the important content in the source information and the destination information.
[0046] The electronic device can display the policy management page, and on the policy management page, perform the same display processing for each network access isolation policy: display the access control actions in the network access isolation policy in the determined action display style, display the source information in the network access isolation policy in the first card form, display the destination information in the network access isolation policy in the second card form, and display a directed connection line (such as a line with a directed arrow) between the first card form and the second card form, and this directed connection line points from the source information to the destination information to represent that the traffic flow of the access request is from the source to the destination. In this way, by displaying the source information in the first card form and the destination information in the second card form, the key information of the source and the key information of the destination can be highlighted, and the information is made more concentrated and intuitive. Users do not need to search for the required source information in a large amount of text or a complex interface, thus facilitating users to quickly browse and identify, improving the readability and operability of the source information and the destination information, and further enabling users to more efficiently understand the relationship between the network access isolation policy and its acting object, laying a foundation for users to efficiently manage each network access isolation policy.
[0047] It should be noted that a single network access isolation policy can be visually displayed according to the above description. For multiple network access isolation policies, in order to further improve their visualization level, comprehensibility, and the management efficiency of users, the electronic device can adopt a list style, a topological relationship graph style, a tree structure graph style, a matrix view style, etc. to display them. Among them, an entry in the list style corresponds to a network access isolation policy and adopts the above visualization method; in the topological relationship graph, source end information and / or destination end information can be displayed in the above card form on the nodes, and the corresponding policy and traffic flow relationship, etc. are expressed by directed lines between the nodes to clearly display the relationship between each end and its policy; the tree structure graph can be constructed according to the policy hierarchical relationship (such as first classifying by cluster and then subdividing into namespaces, workloads, etc.) to clearly show the hierarchical logic of the policy and facilitate viewing specific part of the policy and its associated policies; the matrix view can use the source end and the destination end as the horizontal and vertical axes, and the access rules are marked in the cross cells to more concisely present the policies between each end, facilitating comparison and analysis, etc.
[0048] The network security management method provided by the above embodiments of the present disclosure can, in response to an interactive operation of viewing a policy, determine the action display style of the access control action in the network access isolation policy; the action display style includes an icon and / or color adapted to the access control action; in the policy management page, the access control action in the network access isolation policy is displayed in the action display style, and the source end information and destination end information in the network access isolation policy are respectively displayed in a first card form and a second card form, and the data flow relationship between the source end information and the destination end information is displayed by a directed line; in this way, through the access control action visually displayed in the action display style, users can more concisely and effectively understand the protection effect of each network access control action; and, by highlighting the source end information and destination end information in the network access isolation policy in the first card form and the second card form, the information of the object of the policy is more concentrated and intuitive, without the need for users to laboriously search for the required information among various information of the policy, improving the efficiency of users to understand the relationship between the policy and its object, thereby improving the readability and comprehensibility of the network access isolation policy, and further improving the efficiency of users to manage each network access isolation policy.
[0049] In some embodiments, the policy management page also displays a list view control. Here, the list view control is an interactive control used to trigger the display of each network access isolation policy in a list style. See Figure 3 , the electronic device displays a list view control 310 in the policy management page 300.
[0050] Based on the above embodiments, S120 includes: in response to a triggering operation on the list view control, in the policy management page, displaying each network access isolation policy in a list style; sequentially displaying a priority adjustment control, an access control action presented in an action display style, source end information presented in a first card form, a directed connection line, and destination end information presented in a second card form in the display area corresponding to each list entry.
[0051] Specifically, in order to improve compatibility with the policy management solutions in related technologies, the embodiments of the present disclosure can also provide a list style, but can improve the text display style of the entries in the list style, that is, display the network access isolation policies of each list entry in the list in a visual manner such as the above action display style, first card form, second card form, and directed connection line. Based on this, the embodiments of the present disclosure can provide a list view control to provide the function of switching from other view styles to the list style.
[0052] Continuing to refer to Figure 3 , the user can perform a triggering operation on the list view control 310, and the electronic device can respond to this triggering operation, display the list view control 310 in a selected style (such as black) in the policy management page 300, and switch the display style of each network access isolation policy to the list style. For each list entry (that is, each network access isolation policy), a priority adjustment control 320, an access control action 330 presented in an action display style, source end information 340 presented in a first card form, a directed connection line 350, and destination end information 360 presented in a second card form can be sequentially displayed in the corresponding display area.
[0053] The above priority adjustment control 320 is an interactive control with the function of adjusting the policy priority / policy execution order. The user can use this control to adjust the policy priority (also known as the policy execution order).
[0054] The above first card form can determine the specific information to be aggregated and highlighted according to different source end types, so that users can efficiently obtain the key information that may be concerned under different source end types.
[0055] In one example, if the source end information corresponds to the cluster type, the first card form includes a source end identifier, a cluster icon, a cluster identifier, and cluster key information.
[0056] Among them, the source end identifier is the identifying information of the source end, for example, it can be text or coding symbols representing the source end. Such as Figure 3As shown, the source - end identifier can be the text "source". The cluster icon is a visual symbol representing the cluster type. The cluster identifier is the unique identifier of the cluster, which is used to distinguish different clusters. The cluster key information is information that has a key relationship with the configuration of the network access isolation policy in the cluster. Exemplarily, the cluster key information includes at least one of the cluster space identifier, cluster service information, and cluster subdivision type. The cluster space identifier is the identifying information that divides the cluster resources into multiple virtual clusters. For example, it can be the identifier of the namespace. The cluster service information is the identifier of the services or applications running in the cluster. For example, it can be the workload. The cluster space and the cluster service are the direct objects of the network access isolation policy. Therefore, revealing the cluster space identifier and the cluster service information in the first - card form can help users understand the applicable scope of the policy at a finer granularity. The cluster subdivision type is the refined classification or use of the cluster. For example, it can be a database cluster, a cloud - computing cluster, etc., which is used to help users understand the use of the cluster, thereby assisting users in understanding the actual protection effect of the policy.
[0057] Specifically, continue to refer to Figure 3 , for the source - end information 341 of the cluster type, the first - card form can include the source - end identifier (such as the text "source"), the cluster icon (such as a Rubik's Cube - like icon), the cluster identifier (such as the cluster name "Cluster000"), and the cluster key information (such as the specific namespace name and workload name, etc.). In this way, the important information of the cluster source - end can be revealed through the card, enabling users to quickly focus on this information, improving the readability and acquisition efficiency of the source - end information, and thus enhancing users' understanding of the policy.
[0058] In another example, if the source - end information corresponds to the Internet - working protocol type, the first - card form includes the source - end identifier, the Internet - working protocol icon, and the Internet - protocol address information.
[0059] Among them, the Internet - working protocol icon is a visual symbol identifying the Internet - Protocol (IP) type. The Internet - protocol address information is the relevant information identifying the Internet - protocol address. For example, it can be a specific Internet - protocol address, or an access entry to a group of Internet - protocol addresses, a group name, etc.
[0060] Specifically, continue to refer to Figure 3, for the source - end information 342 of the IP type, in its first card form, it can include a source - end identifier (such as the text "source"), an internetworking protocol icon (such as an icon containing the text "IP"), and internet protocol address information (such as a specific IP address). In this way, the important information of the IP source - end can be revealed through the card, enabling users to quickly focus on this information, improving the readability and acquisition efficiency of the source - end information, and thus enhancing the user's understanding of the policy.
[0061] Similarly, the above - mentioned second card form can determine the specific information to be highlighted according to different destination - end types, so that users can efficiently obtain the key information that may be concerned under different destination - end types.
[0062] In an example, if the destination - end information corresponds to the cluster type, the second card form includes a destination - end identifier, a cluster icon, a cluster identifier, and cluster key information.
[0063] Among them, the destination - end identifier is the identifying information of the destination - end, which can be, for example, text or encoded symbols representing the destination - end. As Figure 3 shown, the destination - end identifier can be the text "destination".
[0064] Specifically, continue to refer to Figure 3 , for the destination - end information 361 of the cluster type, in its second card form, it can include a destination - end identifier (such as the text "destination"), a cluster icon (such as a Rubik's Cube - like icon), a cluster identifier (such as the cluster name "Cluster000"), and cluster key information (such as specific namespace names and workload names, etc.). In this way, the important information of the cluster destination - end can be revealed through the card, enabling users to quickly focus on this information, improving the readability and acquisition efficiency of the destination - end information, and thus enhancing the user's understanding of the policy.
[0065] In another example, if the destination - end information corresponds to the internetworking protocol type, the second card form includes a destination - end identifier, an internetworking protocol icon, and internet protocol address information.
[0066] Specifically, continue to refer to Figure 3 , for the destination - end information 362 of the IP type, in its second card form, it can include a destination - end identifier (such as the text "destination"), an internetworking protocol icon (such as an icon containing the text "IP"), and internet protocol address information (such as the group name of a specific IP address group). In this way, the important information of the IP destination - end can be revealed through the card, enabling users to quickly focus on this information, improving the readability and acquisition efficiency of the destination - end information, and thus enhancing the user's understanding of the policy.
[0067] In some embodiments, when displaying each network access isolation policy in a list style, the method further includes: in response to a first dragging operation on the priority adjustment control, determining the effective order of the network access isolation policy corresponding to the priority adjustment control based on the first end position.
[0068] Specifically, continue to refer to Figure 3 , the user can change the position of the policy entry corresponding to the triggered priority adjustment control in the list by pressing and dragging the priority adjustment control 320 (i.e., the first dragging operation). When the first dragging operation of the user ends, the electronic device can determine the final position of the dragged policy entry in the list (i.e., the first end position), and determine the arrangement priority of the dragged policy entry according to this first end position.
[0069] In some embodiments, the policy management page further displays a relationship graph control. The relationship graph control is an interactive control for triggering the display of each network access isolation policy in a topological relationship graph style. Continue to refer to Figure 3 , the electronic device displays a relationship graph control 370 in the policy management page 300.
[0070] Based on the above embodiments, S120 includes: in response to a triggering operation on the relationship graph control, in the policy management page, displaying each network access isolation policy in a topological relationship graph style; in the display area of each topological node, displaying the source end information in the corresponding network access isolation policy in the form of a first card, or displaying the destination end information in the corresponding network access isolation policy in the form of a second card; based on the source end information and destination end information in each network access isolation policy, displaying directed connections between each topological node, and in the first peripheral area of the directed connection, displaying the access control action in the corresponding network access isolation policy in an action display style.
[0071] Specifically, continue to refer to Figure 3, the user can perform a triggering operation on the relationship graph control 370. In response to the triggering operation, the electronic device displays each network access isolation policy in the form of a topological relationship graph. The topological relationship graph is composed of multiple nodes and directed connection lines between the nodes. One node corresponds to an affected object in a network access isolation policy, such as a source end or a destination end. In this way, the corresponding information can be displayed in the form of a card at the node position. For example, if a certain node corresponds to the source end in the network access isolation policy, the corresponding source end information is displayed in the form of a first card at the position of this node; for another example, if a certain node corresponds to the destination end in the network access isolation policy, the corresponding destination end information is displayed in the form of a second card at the position of this node. Considering that there are various complex relationships such as intersection, overlap, and inclusion among the affected objects of each network access isolation policy, a node may be the source end in one network access isolation policy and may also be the destination end in another network access isolation policy. The first card form and the second card form in this embodiment may not distinguish between the source end and the destination end, but only aggregate and display the main information of the cluster type or IP type.
[0072] In addition, the direction of the connection line between nodes can be determined according to the source end information and the destination end information in the network access isolation policy including the two nodes. And the access control action in the network access isolation policy can be displayed in the action display style in the peripheral area (i.e., the first peripheral area) of the directed connection line. In this way, on the basis of highlighting the information of each end involved in the policy and the policy protection effect, the relationships between each network access isolation policy can be sorted out through the topological relationship graph, further improving the user's understanding of each network access isolation policy they manage, and thus further improving the efficiency of the user in managing each network access isolation policy.
[0073] In some embodiments, the above-mentioned display of each network access isolation policy in the form of a topological relationship graph in the policy management page can be specifically implemented as the following steps A to D to realize a topological relationship graph centered on a cluster to more clearly display each network access isolation policy applicable to the cluster. On the one hand, it can reduce the difficulty of understanding the relationship graph with too many nodes, further improve the understanding efficiency of each network access isolation policy, and further enhance the understanding of the protection effect of the cluster; on the other hand, the topological relationship graph centered on the cluster is convenient for checking whether there are errors in each network access isolation policy, and is also convenient for adding or deleting network access isolation policies for the cluster, so as to further improve the management efficiency of network access isolation policies.
[0074] Step A: In the policy management page, display the cluster information of the target cluster in the form of a third card.
[0075] Among them, the third card form is another presentation form of the pre-set information aggregation card, which is used to visually display the cluster information of the cluster located at the center (i.e., the target cluster). The cluster information may include at least one of a cluster icon, a cluster identifier, and cluster key information. The target cluster may be the cluster that is default selected when the page is switched (such as the largest cluster or the cluster with the highest access popularity, etc.), or a cluster selected by the user customarily.
[0076] Specifically, referring to Figure 4 , in response to a trigger operation on the relationship graph control, the electronic device displays a topology relationship graph of multiple network access isolation policies centered on the target cluster (such as the cluster name Cluster001) on the policy management page 400. In this topology relationship graph, the electronic device displays the cluster name and cluster key information of the target cluster in the third card form. As Figure 4 shown in, the third card form includes a card carrier 410 in the form of a three-dimensional cuboid, cluster information including the cluster name Cluster001, the namespace name, the workload name, etc., as well as a cluster traffic inlet icon 420 and a cluster traffic outlet icon 430.
[0077] Exemplarily, the determination method of the target cluster may be: in response to a trigger operation on the cluster selection control displayed on the policy management page, the selected cluster is determined as the target cluster. Continuing to refer to Figure 4 , a cluster selection control 440 and its function prompt information are displayed on the policy management page 400. The user can select the cluster that he wants to view / manage by triggering the cluster selection control 440. In response to this trigger operation of the user, the electronic device can determine the cluster selected by the user as the target cluster. In this way, the function of viewing / managing the network access isolation policy from the asset dimension can be provided, and the policy management efficiency can be further improved.
[0078] Step B: Based on the cluster information, the source information and the destination information in each network access isolation policy, determine the target network isolation policy that has a network access control relationship with the target cluster.
[0079] Specifically, the electronic device searches the source information and the destination information in each network access isolation policy by using the cluster information of the target cluster, so as to screen out the network access isolation policies that have a network access control relationship (such as being the source or destination of the access) with the target cluster from all the network access isolation policies corresponding to the user, and use them as the target network isolation policies.
[0080] Step C: If the source information corresponding to the target cluster is included in the target network isolation policy, in the second peripheral area in the first direction of the cluster information, display the source information in the target network isolation policy in the form of a first card, and fuse the access control actions in the target network isolation policy in the action display style with the first card form, and display the data flow relationship between the target cluster and the source information in the target network isolation policy with a directed connection.
[0081] Among them, the card color and / or card outline of the first card form are determined based on the action display style, and the line color and / or line type of the directed connection are determined based on the action display style. In this embodiment, for the unity of the display effect, the corresponding relationship between the action display style of the access control action, the card color of the first card form, the card outline of the first card form, the line color of the directed connection, and the line type of the directed connection can be pre-constructed.
[0082] Specifically, if there is a target network isolation policy with the target cluster as the destination, the source information in the target network isolation policy can be displayed in the form of a first card on one side of the card area where the target cluster is located. And superimpose the access control actions displayed in the action display style in the first card form. At the same time, a directed connection pointing to the target cluster can be displayed according to the line color and / or line type of the directed connection adapted to the action display style.
[0083] Continue to refer to Figure 4 , the electronic device can display the source information in 3 target network isolation policies in the form of a first card (such as a rectangular card carrier with a right angle) in the peripheral display area (such as the second peripheral area 450) in the first direction (such as the left side) of the card carrier 410 of the third card form. On the left side of each source information, the corresponding access control actions are merged and displayed according to the action display style (the example is filled colors and icons with different grayscales). At the same time, according to the card outline and line type adapted to the action display style, the outer outline of the card carrier of the first card form and the directed connection (such as a dotted line, a solid line, and a dash-dot line from top to bottom) are respectively displayed. The arrows of the 3 directed connections all point to the cluster traffic entry icon 420.
[0084] Step D: If the destination information corresponding to the target cluster is included in the target network isolation policy, in the third peripheral area in the second direction of the cluster information, display the destination information in the target network isolation policy in the form of a second card, and fuse the access control actions in the target network isolation policy in the action display style with the second card form, and display the data flow relationship between the target cluster and the destination information in the target network isolation policy with a directed connection.
[0085] Among them, the card color and / or the card outline of the second card form are determined based on the action display style. The first direction and the second direction belong to opposite directions.
[0086] Specifically, if there is a target network isolation policy with a target cluster as the source end, then the destination end information in the target network isolation policy can be displayed in the form of a second card on the other side of the card area where the target cluster is located. And, the access control actions displayed in the action display style are superimposed on the second card form. At the same time, the directed connection lines emitted from the target cluster can be displayed according to the line color and / or line type of the directed connection line adapted to the action display style.
[0087] Continue to refer to Figure 4 , the electronic device can display the destination end information in 4 target network isolation policies in the form of a second card (such as a card carrier with rounded corners) in the peripheral display area (such as the third peripheral area 460) in the second direction (such as the right side) of the card carrier 410 in the third card form. On the left side of each destination end information, the corresponding access control actions are merged and displayed according to the action display style (the example is filling colors and icons with different grayscales). At the same time, according to the card outline and line type adapted to the action display style, the outer outline and the directed connection lines of the card carrier in the second card form are respectively displayed (such as dotted line, solid line, solid line, dotted-dashed line from top to bottom). These 4 directed connection lines all emit from the cluster traffic exit icon 430 and point to the destination end in the target network isolation policy.
[0088] In some embodiments, when displaying each network access isolation policy in the form of a topological relationship map centered on the target cluster, the method further includes: in response to a second drag operation on the source end information in the target network isolation policy displayed in the first card form, determining the effective order of the target network isolation policy based on the second end position.
[0089] Among them, the included angle between the straight line where the drag direction of the second drag operation is located and the straight line where the first direction is located is greater than a preset angle. The preset angle is a preset angle value, which can be determined according to the range of the response hot zone of the drag operation. For example, it can be set as an angle value not exceeding 45°.
[0090] Specifically, continue to refer to Figure 4, when the straight line in the first direction is the horizontal direction from left to right, the user can perform a second dragging operation on the card where the source - end information in any target network isolation policy on the left side of the target cluster is located along its vertical direction or an approximately vertical direction. The electronic device can respond to this second dragging operation and determine the effective order of the target network isolation policy corresponding to the card where the dragged source - end information is located according to the second end position of the card where the dragged source - end information is located at the end of the dragging. For example, when the user drags the card where the source - end information of the IP type is located on the left side to the first - ranked position, the effective order of the corresponding target network isolation policy will also change to the first, and the effective orders of the remaining two target network isolation policies will be shifted backward by one position in sequence.
[0091] In some other embodiments, in the case of displaying each network access isolation policy in the form of a topology relationship map centered on the target cluster, the method further includes: responding to a third dragging operation on the destination - end information in the target network isolation policy displayed in the form of a second card, and determining the effective order of the target network isolation policy based on the third end position.
[0092] Among them, the included angle between the straight line in the dragging direction of the third dragging operation and the straight line in the first direction is greater than a preset angle.
[0093] Specifically, continue to refer to Figure 4 , the user can also perform a third dragging operation on the card where the destination - end information in any target network isolation policy on the right side of the target cluster is located to change the effective order of the corresponding target network isolation policy.
[0094] In some embodiments, S110 includes: responding to an interactive operation of viewing the policy, displaying at least one policy - group identifier and a policy - group details control corresponding to the policy - group identifier on the policy management page; responding to a triggering operation on the policy - group details control, displaying each network access isolation policy in the isolation policy group in the fourth peripheral area corresponding to the policy - group identifier of the triggered policy - group details control, and determining the action display style of the access control action in the network access isolation policy.
[0095] Among them, the policy - group identifier is the identifying information of the isolation policy group. For example, it can be a name, abbreviation, icon, or number, etc. The isolation policy group corresponding to the policy - group identifier contains at least one network access isolation policy applicable to the target business scenario. That is, the isolation policy group is divided according to the target business scenario. The policy - group details control is an interactive control used to trigger the display of each network access isolation policy in the isolation policy group.
[0096] Specifically, Figure 1The displayed network access isolation policy (which can be simply referred to as a policy) display method will lay out a large number of policies together, making it difficult for users to quickly select the policies they want to view and perform management operations such as adjusting their priorities. Therefore, in this embodiment, an isolation policy group can be set up to divide a large number of policies into different policy groups, implementing a management solution of first managing the policy groups and then managing the policies within the groups, thereby further improving the policy management efficiency. Therefore, referring to Figure 5 , in response to an interactive operation of viewing a policy, the electronic device displays a policy management page 500, and displays the policy group identifiers (such as policy group icons 510 and policy group names 520) of at least one isolation policy group, as well as the policy group details control 530 corresponding to the isolation policy group, on the policy management page 500. After the user triggers the policy group details control 530, the electronic device can determine the peripheral area (i.e., the fourth peripheral area) corresponding to the policy group identifier of the triggered policy group details control. For example, referring to Figure 6 , the electronic device can move down each isolation policy group arranged after the policy group identifier to obtain a blank area as the fourth peripheral area 610. Another example is that the electronic device can create a floating layer or a pop-up window around the policy group identifier as the fourth peripheral area. Then, the electronic device can display each network access isolation policy within the corresponding isolation policy group in the fourth peripheral area. The display methods of these network access isolation policies can refer to the relevant descriptions in the above embodiments. As Figure 6 shown, the electronic device can display each network access isolation policy within the group in the style and function as Figure 3 or Figure 4 shown.
[0097] In some embodiments, continuing to refer to Figure 5 , the policy group status icon 540 corresponding to the policy group identifier and the policy information within the group are also displayed on the policy management page 500. The policy information within the group includes the number of policies and the policy status of whether the policies are effective for each network access isolation policy included in the isolation policy group. For example, the total number of policies included in the group, the number of enabled (i.e., effective) policies, and the number of disabled (i.e., ineffective) policies. The policy group status icon 540 is determined based on the policy status. For example, when there is at least one enabled policy within the isolation policy group, the policy group status icon 540 is a concentric circle filled with black; when all the policies within the isolation policy group are in the disabled state, the policy group status icon 540 is a concentric circle filled with gray.
[0098] Based on the above embodiments, an effective order identifier 550 between each policy group status icon is also displayed on the policy management page. The effective order identifier is used to visually represent the effective priority / execution priority between each isolation policy group. Figure 5The order of effectiveness identification is exemplified as a line segment with an arrow. In this way, through the status icons 540 of each policy group strung together by the order of effectiveness identification 550, in the form of process visualization, it can assist users to more efficiently understand the order of effectiveness / priority among each isolation policy group.
[0099] In some embodiments, when displaying each network access isolation policy by isolation policy group, the method further includes: in response to a fourth drag operation on the policy group identifier, determining the order of effectiveness of the isolation policy group corresponding to the dragged policy group identifier based on the fourth end position.
[0100] Specifically, each isolation policy group also provides the function of dragging to adjust the priority. Then, the electronic device can, in response to the user's fourth drag operation on a certain isolation policy group, change the arrangement position of the dragged isolation policy group until the drag ends and determine the fourth end position. At this time, the electronic device can determine the order of effectiveness of the dragged isolation policy group according to the fourth end position. For example, if the user drags the isolation policy group with the policy group name "isolation policy group corresponding to business scenario 6" to the second arrangement position, then the order of effectiveness of the "isolation policy group corresponding to business scenario 6" can be determined to be the second, and the order of effectiveness of the "isolation policy group corresponding to business scenarios 2 / 3 / 4 / 5" will be shifted back one by one in sequence, changing to the third to the sixth.
[0101] It should be noted that continue to refer to Figure 5 , the electronic device can display a policy group creation control 560 on the policy management page 500. The user can trigger this policy group creation control to create a new policy group.
[0102] In some embodiments, continue to refer to Figure 6 , the electronic device can also display a policy creation control 620 in the fourth peripheral area 610. The policy creation control is an interactive control for triggering the creation of a new network access isolation policy.
[0103] Based on the above embodiments, the method further includes: in response to a trigger operation on the policy creation control, displaying a policy creation page and displaying a policy group identifier and a policy configuration control on the policy creation page; in response to a trigger operation on the policy configuration control, creating a new network isolation policy based on the policy configuration information; and inserting the new network isolation policy into the fourth peripheral area for display based on the first configuration priority of the new network isolation policy.
[0104] Among them, the policy creation page is an interactive page for guiding users to create new network access isolation policies. The policy configuration control is an interactive control for configuring relevant information in the new network access isolation policy. Exemplarily, the policy configuration control includes at least one of a priority configuration control, a source information configuration control, a destination information configuration control, a protocol and port configuration control, and a control action configuration control presented in an action display style. The priority configuration control includes a priority icon and icon description information. The priority icon is a visual graphical symbol related to the policy execution order. The icon description information is text for explaining the policy execution order represented by the priority icon. The policy configuration information is the configuration content of relevant dimensions of the newly created policy input through the policy configuration control. The first configured priority is the execution order of the policy custom-configured through the priority configuration control during the policy creation process.
[0105] Specifically, when the user performs a triggering operation on Figure 6 the policy creation control 620 shown, the electronic device can display the policy creation page 700 as shown in Figure 7 . Referring to Figure 7 , the electronic device can display the policy group identifier 710, the priority configuration control 720, the source information configuration control 730, the destination information configuration control 740, the protocol and port configuration control 750, and the control action configuration control 760 presented in an action display style corresponding to the triggered policy creation control 620 on the policy creation page 700.
[0106] The above-mentioned priority configuration control 720 includes a highest priority configuration item 721, a lowest priority configuration item 722, and intermediate priority configuration items 723, and each configuration item contains a priority icon and icon description information. In this way, the visualization of priorities can be realized during the process of creating a new policy, enabling users to better understand the concepts of various priorities, thereby improving the accuracy of policy priority configuration and further enhancing the policy management efficiency.
[0107] The above-mentioned source information configuration control 730, destination information configuration control 740, and protocol and port configuration control 750 are set to adapt to the policy display method of presenting important information in the policy in the form of a visual card in the above embodiments, so that users can correspond the content in the policy creation process and the policy display process, further reducing the difficulty of understanding the policy for users, and thus further enhancing the management efficiency of users for the policy.
[0108] The control action configuration control 760 presented in the above action display style may include configuration items corresponding to various access control actions (such as an allow action configuration item 761, a monitoring action configuration item 762, and a deny action configuration item 763), and each configuration item is visually presented in the corresponding action display style determined in the above embodiments. In this way, the prevention and control effect of the policy can be visualized during the policy creation process, enabling the user to better understand the protection effect of various access control actions, thereby improving the configuration accuracy of the access control actions in the policy and further enhancing the policy management efficiency.
[0109] Then, the user can perform a triggering operation on any of the above policy configuration controls, and the electronic device can obtain the policy configuration information of the corresponding configuration item through this triggering operation. Then, the electronic device can create a new network access isolation policy based on the obtained policy configuration information. After that, the electronic device can determine the effective order of the newly created policy in the corresponding isolation policy group according to the first configuration priority and insert it into the corresponding arrangement position in the fourth peripheral area, completing the creation and display of the new policy.
[0110] In some embodiments, continuing to refer to Figure 6 , the electronic device can display a policy group change control 630 at relevant positions of each network access isolation policy in the fourth peripheral area 610 of the policy management page. The policy group change control 630 is used to trigger the group change function of the corresponding network access isolation policy. Alternatively, the electronic device can display a separate policy group change control in the fourth peripheral area 610 for triggering the group change function of one or more selected policies.
[0111] Based on the above embodiments, the method further includes: in response to a triggering operation on the policy group change control, displaying a group change configuration page and displaying the policy identifier to be group-changed, the policy group identifier before group change, the policy group selection control after group change, and the priority configuration control in the group change configuration page; in response to a triggering operation on the policy group selection control, determining the policy group identifier after group change; in response to a triggering operation on the priority configuration control, determining the second configuration priority corresponding to the policy identifier to be group-changed; and based on the policy group identifier after group change and the second configuration priority, performing the group change process of the network access isolation policy corresponding to the policy identifier to be group-changed.
[0112] Among them, the group change configuration page is an interactive page for guiding the user to change the group of the network access isolation policy. The policy identifier to be group-changed is the policy identifier of the network access isolation policy to be subjected to the group change operation. The second configuration priority is the effective order of the policy custom-configured through the priority configuration control during the policy group change process.
[0113] Specifically, if the user performs a triggering operation on the policy group change control 630 displayed in the fourth peripheral area 610, the electronic device may display a group change configuration page 800 as shown in Figure 8 See Figure 8 . The electronic device may display a policy to be group-changed identifier 810, a policy group identifier before group change, a policy group selection control 830 after group change, and a priority configuration control 840 on the group change configuration page 800. The policy group identifier before group change may be determined by the isolation policy group where the fourth peripheral area 610 is located. The policy group selection control 830 may use each policy group identifier other than the policy group identifier before group change among all the policy group identifiers corresponding to the user as candidate items.
[0114] When the user performs a triggering operation on the policy group selection control 830 and selects a certain policy group identifier, the electronic device may determine the policy group identifier after group change as the selected policy group identifier. When the user performs a triggering operation on a certain priority configuration item in the priority configuration control 840, the electronic device may accordingly determine the second configuration priority of the policy to be group-changed in the isolation policy group after group change. If the user performs a triggering operation on the middle priority configuration item, the electronic device may additionally display a policy selection control 850 on the group change configuration page. The user may, through the triggering operation on the policy selection control 850, determine that the second configuration priority is after the selected policy. Then, the electronic device may, according to the determined policy group identifier after group change, migrate the policy to be group-changed from the isolation policy group where the fourth peripheral area 610 is located to the isolation policy group corresponding to the policy group identifier after group change, and may correctly display the policy to be group-changed in the isolation policy group after group change according to the second configuration priority, thus completing the group change process. This can perform the policy group change process more efficiently and further improve the user's policy management efficiency.
[0115] It should be noted that for the existing policies before dividing each policy into groups, they may all be divided into the default policy group. Then, the user may, through the group change operation, divide these existing policies into appropriate isolation policy groups to improve the compatibility of the policy management solution by group.
[0116] The following is an embodiment of a network security management device provided by an embodiment of the present invention. This device and the network security management method of the above embodiments belong to the same inventive concept. For the details not described in detail in the embodiment of the network security management device, reference may be made to the embodiment of the above network security management method.
[0117] Figure 9 shows a schematic structural diagram of a network security management device provided by an embodiment of the present disclosure. As shown in Figure 9 , the network security management device 900 may include:
[0118] An action display style determination module 910 is configured to determine an action display style of an access control action in a network access isolation policy in response to an interaction operation for viewing a policy; wherein, the action display style includes an icon and / or a color adapted to the access control action;
[0119] A policy display module 920 is configured to display the access control action in the network access isolation policy in the action display style, and display the source end information and the destination end information in the network access isolation policy in a first card form and a second card form respectively in a policy management page, and display a data flow relationship between the source end information and the destination end information with a directed connection line.
[0120] The network security management device provided by the embodiments of the present disclosure can determine an action display style of an access control action in a network access isolation policy in response to an interaction operation for viewing a policy; the action display style includes an icon and / or a color adapted to the access control action; in a policy management page, display the access control action in the network access isolation policy in the action display style, and display the source end information and the destination end information in the network access isolation policy in a first card form and a second card form respectively, and display a data flow relationship between the source end information and the destination end information with a directed connection line; in this way, through the access control action visually displayed in the action display style, a user can more concisely and effectively understand the protection effect of each network access control action; and, by highlighting the source end information and the destination end information in the network access isolation policy in a first card form and a second card form, the information of the action object of the policy is more concentrated and intuitive, without the user having to laboriously search for the required information among various information of the policy, improving the efficiency of the user understanding the relationship between the policy and its action object, thereby improving the readability and understandability of the network access isolation policy, and further improving the efficiency of the user managing each network access isolation policy.
[0121] In some embodiments, a list view control is further displayed on the policy management page;
[0122] Correspondingly, the policy display module 920 is specifically configured to:
[0123] In response to a trigger operation on the list view control, display each network access isolation policy in a list style in the policy management page;
[0124] In a display area corresponding to each list entry, sequentially display a priority adjustment control, an access control action presented in the action display style, source end information presented in a first card form, a directed connection line, and destination end information presented in a second card form;
[0125] Wherein, if the source end information corresponds to a cluster type, the first card form includes a source end identifier, a cluster icon, a cluster identifier, and cluster key information;
[0126] If the destination information corresponds to the cluster type, the second card form includes a destination identifier, a cluster icon, a cluster identifier, and cluster key information;
[0127] If the source information corresponds to the Internetworking Protocol type, the first card form includes a source identifier, an Internetworking Protocol icon, and Internet Protocol address information;
[0128] If the destination information corresponds to the Internetworking Protocol type, the second card form includes a destination identifier, an Internetworking Protocol icon, and Internet Protocol address information.
[0129] Further, the network security management device 900 further includes a priority adjustment module for:
[0130] In response to a first drag operation on the priority adjustment control, determine the effective order of the network access isolation policy corresponding to the priority adjustment control based on the first end position.
[0131] In some embodiments, the policy management page further displays a relationship graph control;
[0132] Correspondingly, the policy display module 920 is specifically configured to:
[0133] In response to a trigger operation on the relationship graph control, in the policy management page, display each network access isolation policy in the style of a topological relationship graph;
[0134] In the display area of each topological node, display the source information in the corresponding network access isolation policy in the first card form, or display the destination information in the corresponding network access isolation policy in the second card form;
[0135] Based on the source information and destination information in each network access isolation policy, display the directed connection lines between each topological node, and in the first peripheral area of the directed connection line, display the access control actions in the corresponding network access isolation policy in the action display style.
[0136] Further, the policy display module 920 is specifically configured to:
[0137] In the policy management page, display the cluster information of the target cluster in the third card form; wherein, the cluster information includes at least one of a cluster icon, a cluster identifier, and cluster key information;
[0138] Based on the cluster information, the source information and destination information in each network access isolation policy, determine the target network isolation policy having a network access control relationship with the target cluster;
[0139] If the source - end information corresponding to the target cluster is included in the target network isolation policy, in the second peripheral area in the first direction of the cluster information, the source - end information in the target network isolation policy is displayed in the form of a first card, and the access control action in the target network isolation policy is integrally displayed in the action display style in the first - card form, and the data - flow relationship between the target cluster and the source - end information in the target network isolation policy is displayed by a directed connection line; wherein, the card color and / or the card outline of the first - card form are determined based on the action display style, and the line color and / or the line type of the directed connection line are determined based on the action display style;
[0140] If the destination - end information corresponding to the target cluster is included in the target network isolation policy, in the third peripheral area in the second direction of the cluster information, the destination - end information in the target network isolation policy is displayed in the form of a second card, and the access control action in the target network isolation policy is integrally displayed in the action display style in the second - card form, and the data - flow relationship between the target cluster and the destination - end information in the target network isolation policy is displayed by a directed connection line; wherein, the card color and / or the card outline of the second - card form are determined based on the action display style; the first direction and the second direction are in opposite directions.
[0141] In some embodiments, the policy display module 920 is further configured to:
[0142] Before displaying the cluster information of the target cluster in the form of a third card on the policy management page, in response to a trigger operation on the cluster selection control displayed on the policy management page, the selected cluster is determined as the target cluster.
[0143] In some embodiments, the priority adjustment module is further configured to:
[0144] In response to a second drag operation on the source - end information in the target network isolation policy displayed in the form of a first card, the effective order of the target network isolation policy is determined based on the second end position; wherein, the included angle between the straight line where the drag - direction of the second drag operation is located and the straight line where the first direction is located is greater than a preset angle;
[0145] And / or, in response to a third drag operation on the destination - end information in the target network isolation policy displayed in the form of a second card, the effective order of the target network isolation policy is determined based on the third end position; wherein, the included angle between the straight line where the drag - direction of the third drag operation is located and the straight line where the first direction is located is greater than a preset angle.
[0146] In some embodiments, the action display style determination module 910 is specifically configured to:
[0147] In response to an interactive operation for viewing a policy, at least one policy group identifier and a policy group details control corresponding to the policy group identifier are displayed on a policy management page; wherein, the isolation policy group corresponding to the policy group identifier includes at least one network access isolation policy applicable to a target business scenario.
[0148] In response to a triggering operation on the policy group details control, each network access isolation policy in the isolation policy group is displayed in a fourth peripheral area corresponding to the policy group identifier of the triggered policy group details control, and an action display style of an access control action in the network access isolation policy is determined.
[0149] Wherein, a policy group status icon and intra-group policy information corresponding to the policy group identifier are also displayed on the policy management page, and an effective order identifier between each policy group status icon is displayed; wherein, the effective order identifier is used to visually represent the execution priority of each isolation policy group; the intra-group policy information includes the number of policies and the policy status of each network access isolation policy; the policy group status icon is determined based on the policy status.
[0150] In some embodiments, the priority adjustment module is further configured to:
[0151] In response to a fourth dragging operation on the policy group identifier, determine the effective order of the isolation policy group corresponding to the dragged policy group identifier based on the fourth end position.
[0152] In some embodiments, a policy creation control is also displayed in the fourth peripheral area.
[0153] Correspondingly, the network security management device 900 further includes a policy creation module, configured to:
[0154] In response to a triggering operation on the policy creation control, display a policy creation page, and display a policy group identifier and a policy configuration control on the policy creation page; wherein, the policy configuration control includes at least one of a priority configuration control, a source information configuration control, a destination information configuration control, a protocol and port configuration control, and a control action configuration control presented in an action display style; the priority configuration control includes a priority icon and icon description information.
[0155] In response to a triggering operation on the policy configuration control, create a new network isolation policy based on the policy configuration information.
[0156] Based on a first configuration priority of the new network isolation policy, insert the new network isolation policy into the fourth peripheral area for display.
[0157] In some embodiments, a policy group change control is also displayed in the fourth peripheral area.
[0158] Correspondingly, the network security management device 900 further includes a policy group change module, configured to:
[0159] In response to a triggering operation on the policy group change control, display a group change configuration page, and display the policy identifier to be grouped, the policy group identifier before grouping, the policy group selection control after grouping, and the priority configuration control on the group change configuration page;
[0160] In response to a triggering operation on the policy group selection control, determine the policy group identifier after grouping;
[0161] In response to a triggering operation on the priority configuration control, determine the second configuration priority corresponding to the policy identifier to be grouped;
[0162] Based on the policy group identifier after grouping and the second configuration priority, perform the grouping process of the network access isolation policy corresponding to the policy identifier to be grouped.
[0163] The network security management device provided by the embodiments of the present invention can execute the network security management method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.
[0164] It should be noted that in the embodiments of the above-mentioned network security management device, the included units and modules are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of the functional units are only for the convenience of mutual distinction and do not limit the protection scope of the present disclosure.
[0165] The embodiments of the present disclosure also provide an electronic device, which may include a processor and a memory, and the memory may be used to store executable instructions. Among them, the processor may be used to read the executable instructions from the memory and execute the executable instructions to implement the network security management method in the above embodiments.
[0166] Figure 10 Shows a schematic structural diagram of an electronic device provided by the embodiments of the present disclosure.
[0167] Such as Figure 10As shown, the electronic device 1000 may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1008 into a random access memory (RAM) 1003. In the RAM 1003, various programs and data required for the operation of the electronic device 1000 are also stored. The processing device 1001, the ROM 1002, and the RAM 1003 are connected to each other through a bus 1004. An input / output interface (I / O interface) 1005 is also connected to the bus 1004.
[0168] Generally, the following devices may be connected to the I / O interface 1005: an input device 1006 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 1007 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 1008 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 may allow the electronic device 1000 to communicate with other devices wirelessly or wiredly to exchange data.
[0169] It should be noted that Figure 10 the illustrated electronic device 1000 is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure. That is, although Figure 10 the illustrated electronic device 1000 has various devices, it should be understood that it is not required to implement or include all the illustrated devices. Instead, more or fewer devices may be implemented or included.
[0170] Specifically, according to the embodiments of the present disclosure, the processes described above with reference to the flowcharts may be implemented as computer software programs. For example, the embodiments of the present disclosure include a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program may be downloaded and installed from a network through the communication device 1009, or installed from the storage device 1008, or installed from the ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the network security management method of any embodiment of the present disclosure are executed.
[0171] The embodiments of the present disclosure also provide a computer-readable storage medium, which stores a computer program, and when the computer program is executed by a processor, the processor is caused to implement the network security management method in any embodiment of the present disclosure.
[0172] It should be noted that the computer-readable medium described above in this disclosure can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this disclosure, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. And in this disclosure, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, and this computer-readable signal medium can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wires, optical cables, radio frequency (RF), etc., or any suitable combination of the above.
[0173] In some embodiments, the client and the server can communicate using any currently known or future-developed network protocol such as the Hypertext Transfer Protocol (HTTP), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), the Internet (e.g., the Internet), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.
[0174] The above computer-readable medium may be included in the above electronic device; or may exist separately without being assembled into the electronic device.
[0175] The above computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to execute the network security management method described in any embodiment of the present disclosure.
[0176] In embodiments of the present disclosure, computer program code for performing the operations of the present disclosure may be written in one or more programming languages or combinations thereof. The above programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, C++; and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., by connecting through the Internet using an Internet service provider).
[0177] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of devices, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a portion of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0178] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that can be used include: Field Programmable Gate Array (FPGA), Application Specific Integrated Circuit (ASIC), Application Specific Standard Parts (ASSP), System on Chip (SOC), Complex Programmable Logic Device (CPLD), and so on.
[0179] The above description is only a preferred embodiment of the present disclosure and an illustration of the applied technical principles. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the present disclosure.
[0180] In addition, although the operations are depicted in a particular order, this should not be construed as requiring that the operations be performed in the particular order shown or in sequential order. In certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of the present disclosure. Certain features described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, the various features described in the context of a single embodiment may also be implemented separately or in any suitable sub-combination in multiple embodiments.
[0181] Although the subject matter has been described in language specific to structural features and / or methodological logical acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. On the contrary, the specific features and acts described above are merely example forms for implementing the claims.
Claims
1. A network security management method, characterized in that, Including: In response to an interactive operation for viewing a policy, determining an action display style of an access control action in a network access isolation policy; wherein, the action display style includes an icon and / or color adapted to the access control action; On a policy management page, displaying the access control action in the network access isolation policy in the action display style, and respectively displaying source end information and destination end information in the network access isolation policy in a first card form and a second card form, and displaying a data flow relationship between the source end information and the destination end information with a directed connection line.
2. The method according to claim 1, wherein The policy management page also displays a list view control; The step of, on the policy management page, displaying the access control action in the network access isolation policy in the action display style, and respectively displaying source end information and destination end information in the network access isolation policy in a first card form and a second card form, and displaying a data flow relationship between the source end information and the destination end information with a directed connection line, includes: In response to a trigger operation on the list view control, displaying each network access isolation policy in a list style on the policy management page; Sequentially displaying a priority adjustment control, the access control action presented in the action display style, the source end information presented in the first card form, the directed connection line, and the destination end information presented in the second card form in a display area corresponding to each list entry; Wherein, if the source end information corresponds to a cluster type, the first card form includes a source end identifier, a cluster icon, a cluster identifier, and cluster key information; If the destination end information corresponds to the cluster type, the second card form includes a destination end identifier, the cluster icon, the cluster identifier, and the cluster key information; If the source end information corresponds to an Internet protocol type, the first card form includes the source end identifier, an Internet protocol icon, and Internet protocol address information; If the destination end information corresponds to the Internet protocol type, the second card form includes the destination end identifier, the Internet protocol icon, and the Internet protocol address information.
3. The method according to claim 2, wherein The method further includes: In response to a first drag operation on the priority adjustment control, determining an effective order of the network access isolation policy corresponding to the priority adjustment control based on a first end position.
4. The method according to claim 1, wherein The policy management page also displays a relationship graph control; The step of, on the policy management page, displaying the access control action in the network access isolation policy in the action display style, and respectively displaying source end information and destination end information in the network access isolation policy in a first card form and a second card form, and displaying a data flow relationship between the source end information and the destination end information with a directed connection line, includes: In response to a trigger operation on the relationship graph control, displaying each network access isolation policy in a topological relationship graph style on the policy management page; In the display area of each topology node, the source - end information in the corresponding network access isolation policy is displayed in the form of the first card, or the destination - end information in the corresponding network access isolation policy is displayed in the form of the second card; Based on the source - end information and the destination - end information in each of the network access isolation policies, a directed connection between each of the topology nodes is displayed, and in the first peripheral area of the directed connection, the access control action in the corresponding network access isolation policy is displayed in the action display style.
5. The method according to claim 4, characterized in that, The method of displaying each of the network access isolation policies in the form of a topology relationship map in the policy management page includes: In the policy management page, the cluster information of the target cluster is displayed in the form of a third card; wherein, the cluster information includes at least one of a cluster icon, a cluster identifier, and cluster key information; Based on the cluster information, the source - end information and the destination - end information in each of the network access isolation policies, a target network isolation policy having a network access control relationship with the target cluster is determined; If the source - end information corresponding to the target cluster is included in the target network isolation policy, in the second peripheral area in the first direction of the cluster information, the source - end information in the target network isolation policy is displayed in the form of the first card, and the access control action in the target network isolation policy is integrally displayed in the action display style in the first - card form, and a data flow relationship between the target cluster and the source - end information in the target network isolation policy is displayed by a directed connection; wherein, the card color and / or card contour line of the first - card form are determined based on the action display style, and the line color and / or line type of the directed connection are determined based on the action display style; If the destination - end information corresponding to the target cluster is included in the target network isolation policy, in the third peripheral area in the second direction of the cluster information, the destination - end information in the target network isolation policy is displayed in the form of the second card, and the access control action in the target network isolation policy is integrally displayed in the action display style in the second - card form, and a data flow relationship between the target cluster and the destination - end information in the target network isolation policy is displayed by a directed connection; wherein, the card color and / or card contour line of the second - card form are determined based on the action display style; the first direction and the second direction are in opposite directions.
6. The method according to claim 5, wherein Before the cluster information of the target cluster is displayed in the form of a third card in the policy management page, the method further includes: In response to a trigger operation on a cluster selection control displayed in the policy management page, the selected cluster is determined as the target cluster.
7. The method according to claim 5, wherein The method further includes: In response to a second dragging operation on the source - end information in the target network isolation policy displayed in the form of the first card, the effective order of the target network isolation policy is determined based on the second end position; wherein, the included angle between the straight line in the dragging direction of the second dragging operation and the straight line in the first direction is greater than a preset angle; And / or, in response to a third drag operation on the destination information in the target network isolation policy of the second card form display, determine the effective order of the target network isolation policy based on the third end position; wherein, the included angle between the straight line where the drag direction of the third drag operation is located and the straight line where the first direction is located is greater than the preset angle.
8. The method according to any one of claims 1 to 7, characterized in that, The determining the action display style of the access control action in the network access isolation policy in response to the interactive operation of viewing the policy includes: In response to the interactive operation of viewing the policy, display at least one policy group identifier and a policy group details control corresponding to the policy group identifier on the policy management page; wherein, the isolation policy group corresponding to the policy group identifier includes at least one of the network access isolation policies applicable to the target business scenario. In response to a trigger operation on the policy group details control, display each of the network access isolation policies in the isolation policy group in a fourth peripheral area corresponding to the policy group identifier of the triggered policy group details control, and determine the action display style of the access control action in the network access isolation policy.
9. The method according to claim 8, wherein On the policy management page, also display a policy group status icon corresponding to the policy group identifier and intra-group policy information, and display an effective order identifier between the policy group status icons; wherein, the effective order identifier is used to visually represent the execution priority of each isolation policy group; the intra-group policy information includes the policy quantity and policy status of each network access isolation policy; the policy group status icon is determined based on the policy status.
10. The method according to claim 8, characterized in that, The method further includes: In response to a fourth drag operation on the policy group identifier, determine the effective order of the isolation policy group corresponding to the dragged policy group identifier based on the fourth end position.
11. The method according to claim 8, wherein Also display a policy creation control in the fourth peripheral area. The method further includes: In response to a trigger operation on the policy creation control, display a policy creation page, and display the policy group identifier and a policy configuration control on the policy creation page; wherein, the policy configuration control includes at least one of a priority configuration control, a source information configuration control, a destination information configuration control, a protocol and port configuration control, and a control action configuration control presented in the action display style; the priority configuration control includes a priority icon and icon description information. In response to a trigger operation on the policy configuration control, create a new network isolation policy based on the policy configuration information. Based on the first configuration priority of the new network isolation policy, insert the new network isolation policy into the fourth peripheral area for display.
12. The method according to claim 8, characterized in that, Also display a policy group change control in the fourth peripheral area. The method further includes: In response to a trigger operation on the policy group change control, display a group change configuration page, and display a policy identifier to be changed group, a policy group identifier before group change, a policy group selection control after group change, and a priority configuration control on the group change configuration page. In response to a trigger operation on the policy group selection control, determine the policy group identifier after group change. In response to a triggering operation on the priority configuration control, determine a second configuration priority corresponding to the policy identifier to be switched; Based on the policy group identifier after the group switch and the second configuration priority, perform a group switch process on the network access isolation policy corresponding to the policy identifier to be switched.
13. A network security management device, characterized in that, Comprising: An action display style determination module, configured to determine an action display style of an access control action in a network access isolation policy in response to an interactive operation of viewing a policy; wherein, the action display style includes an icon and / or a color adapted to the access control action; A policy display module, configured to display the access control action in the network access isolation policy in the action display style on a policy management page, and display source end information and destination end information in the network access isolation policy in a first card form and a second card form respectively, and display a data flow relationship between the source end information and the destination end information with a directed connection.
14. An electronic device, characterized in that, Comprising: A processor; A memory for storing executable instructions; Wherein, the processor is configured to read the executable instructions from the memory and execute the executable instructions to implement the network security management method according to any one of claims 1-12 above.
15. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, and when the computer program is executed by a processor, the processor is caused to implement the network security management method according to any one of claims 1-12 above.
16. A computer program product, characterized in that, The computer program product is used to implement the network security management method according to any one of claims 1-12 above.