Firewall policy optimization generation method based on big data
By obtaining and analyzing the historical attack data of the firewall, building factor scatter plots and curves, and calculating policy coefficients, the problem of inaccurate firewall policy optimization is solved, and the accurate optimization of firewall policy and timely response to network security is achieved to avoid resource waste.
Patent Information
- Application Number
- CN202510584912.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2045-05-07
AI Technical Summary
The existing firewall policy optimization methods rely on large-scale analysis, and there are problems of insufficient training data and insufficient generalization capabilities, resulting in inaccurate policy optimization and waste of resources, making it difficult to deal with complex and changeable network threats.
By obtaining the historical attack protection data of the firewall to be optimized by the policy, calculating historical attack protection data factors, constructing factor scatter plots and curves, calculating policy coefficients, extracting maximum and minimum factors, adjusting policy coefficients, determining whether optimization is needed, and avoiding unnecessary optimization operations.
It has achieved accurate judgment on the needs of firewall policy optimization, avoid resource waste, ensure timely response to network security threats, and enhance the effectiveness of computer network security protection.
Smart Images

Figure CN120455075A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer security technology, and in particular to a firewall strategy optimization generation method based on big data. Background Art
[0002] With the rapid development of internet technology, network security issues are becoming increasingly prominent. New cyberattack methods are emerging one after another, causing significant economic losses and security threats to individuals and businesses. As the first line of defense for computers, the rationality and effectiveness of firewall security policies are directly related to the security of the entire computer system.
[0003] In existing technology, determining whether computer firewalls require policy optimization primarily relies on large-scale model analysis. However, this model-based approach has significant limitations, primarily in the following two areas: First, insufficient model training data severely restricts accuracy. High-quality annotated data is essential for building effective models. However, due to the difficulty in obtaining real-world network attack data and the high cost of annotation, training datasets often suffer from insufficient samples and limited coverage, which directly impacts model performance. Second, existing models exhibit significant limitations in their generalization capabilities. Most current optimization methods are designed for specific network environments and attack types, making them less adaptable to the complex and ever-changing real-world network environment. These limitations make it difficult for models to accurately identify diverse network threats and provide reliable and effective decision-making recommendations for firewall policy optimization. These limitations not only impact the timeliness and accuracy of firewall policy optimization but also reduce the overall effectiveness of computer security protection. Summary of the Invention
[0004] The embodiment of the present invention provides a firewall policy optimization generation method based on big data. The present invention can accurately determine whether it is necessary to optimize the policy of the computer firewall, significantly improving the accuracy and adaptability of the policy optimization, avoiding the increase in system load and waste of resources caused by unnecessary optimization operations, and ensuring timely response to network security threats, thereby enhancing the overall network security protection efficiency of the computer.
[0005] To achieve the above objectives, the present invention provides a firewall policy optimization generation method based on big data, comprising: Determine a firewall to be policy-optimized in the computer, obtain multiple historical attack protection data of the firewall to be policy-optimized, analyze the historical attack protection data, and calculate multiple historical attack protection data factors corresponding to the firewall to be policy-optimized; Extracting all historical attack protection data factors, constructing a historical attack protection data factor sequence, and determining a historical attack protection data factor scatter graph based on the historical attack protection data factor sequence; All historical attack protection data factors on the historical attack protection data factor scatter graph are sequentially connected to obtain a historical attack protection data factor curve, and the historical attack protection strategy coefficient of the firewall to be optimized is calculated according to the historical attack protection data factor curve; Extracting a maximum historical attack protection data factor and a minimum historical attack protection data factor from the historical attack protection data factor sequence, and calculating a historical attack protection drop factor of the firewall to be policy optimized based on the maximum historical attack protection data factor and the minimum historical attack protection data factor; The historical attack protection strategy coefficient is adjusted based on the historical attack protection gap factor to obtain the target historical attack protection strategy coefficient of the firewall to be optimized, and whether the firewall to be optimized needs to be optimized is determined according to the target historical attack protection strategy coefficient.
[0006] Furthermore, when analyzing the historical attack protection data and calculating the multiple historical attack protection data factors corresponding to the firewall to be optimized by the policy, the following steps are included: Obtaining standard historical attack protection data corresponding to each historical attack protection data; Calculating a plurality of historical attack protection data factors corresponding to the firewall to be policy optimized according to the historical attack protection data and the corresponding standard historical attack protection data; ; Among them, m is the historical attack protection data factor corresponding to the firewall to be optimized, n is the weight corresponding to the historical attack protection data factor, e is a constant, b is the historical attack protection data factor, and b1 is the standard historical attack protection data factor.
[0007] Furthermore, when extracting all historical attack protection data factors, constructing a historical attack protection data factor sequence, and determining a historical attack protection data factor scatter graph according to the historical attack protection data factor sequence, the process includes: Deploy all historical attack protection data factors into a blank point graph based on a preset length interval to obtain an initial historical attack protection data factor scatter graph; Determining a first historical attack protection data factor from the initial historical attack protection data factor scatter graph, and randomly selecting one from the remaining historical attack protection data factors as a standard historical attack protection data factor; Determining a previous historical attack protection data factor of the standard historical attack protection data factor; Determining a standard length interval corresponding to the standard historical attack protection data factor, determining a previous length interval corresponding to a previous historical attack protection data factor, and calculating a standard convergence value of the standard historical attack protection data factor; Analyze the remaining historical attack protection data factors and calculate multiple standard convergence values; Obtaining a preset standard convergence value, determining whether all standard convergence values are less than or equal to the preset standard convergence value, and if so, using the initial historical attack protection data factor scatter graph as the historical attack protection data factor scatter graph; If not, the preset length interval is shortened according to a preset shortening principle to obtain a second initial historical attack protection data factor scatter graph; The second initial historical attack protection data factor scatter graph is analyzed until the obtained standard convergence values are all less than or equal to the preset standard convergence value, and a historical attack protection data factor scatter graph is obtained.
[0008] Furthermore, when determining the standard length interval corresponding to the standard historical attack protection data factor, determining the previous length interval corresponding to the previous historical attack protection data factor, and calculating the standard convergence value of the standard historical attack protection data factor, the method includes: The standard convergence value of the standard historical attack protection data factor is calculated according to the following formula: ; Where v is the standard convergence value of the standard historical attack protection data factor, c1 is the standard historical attack protection data factor, z1 is the standard length interval, c2 is the previous historical attack protection data factor, z2 is the previous length interval, k is the number of remaining historical attack protection data factors in addition to the standard historical attack protection data factor, g j is the jth remaining historical attack protection data factor in addition to the standard historical attack protection data factor, f j It is the preset length interval corresponding to the jth remaining historical attack protection data factor except the standard historical attack protection data factor.
[0009] Furthermore, when calculating the historical attack protection strategy coefficient of the firewall to be optimized according to the historical attack protection data factor curve, it includes: Determining a first historical attack protection data factor on the historical attack protection data factor curve; Determine all curve inflection points on the historical attack protection data factor curve, and generate a first curve identifier for all historical attack protection data factors between the first historical attack protection data factor and the first curve inflection point; Generate a second curve identifier using all historical attack protection data factors between the first curve inflection point and the second curve inflection point, generate a third curve identifier using all historical attack protection data factors between the second curve inflection point and the third curve inflection point, repeat the above steps to generate multiple curve identifiers based on the curve inflection points; The historical attack protection strategy coefficient of the firewall to be optimized is calculated according to the following formula: ; Among them, d is the historical attack protection strategy coefficient of the firewall to be optimized, s is the number of curve markers, and p a =i a / u a ,i a The maximum historical attack protection data factor corresponding to the a-th curve identifier, u a The minimum historical attack protection data factor corresponding to the a-th curve, y1 a Divide i by the a-th curve identifier a The variance of all historical attack protection data factors except a Identify the ath curve by dividing u a The variance of all historical attack protection data factors except .
[0010] Furthermore, when calculating the historical attack protection gap factor of the firewall to be policy optimized according to the maximum historical attack protection data factor and the minimum historical attack protection data factor, the method includes: The historical attack protection gap factor of the firewall to be optimized is calculated according to the following formula: ; Among them, t is the historical attack protection gap factor of the firewall to be optimized, r1 is the maximum historical attack protection data factor, and r2 is the minimum historical attack protection data factor.
[0011] Furthermore, when the historical attack protection strategy coefficient is adjusted based on the historical attack protection gap factor to obtain the target historical attack protection strategy coefficient of the firewall to be optimized, the process includes: Presetting a first preset historical attack protection gap factor and a second preset historical attack protection gap factor; Presetting a first preset coefficient adjustment value, a second preset coefficient adjustment value, and a third preset coefficient adjustment value; When the historical attack protection gap factor is less than the first preset historical attack protection gap factor, a first product value of the first preset coefficient adjustment value and the historical attack protection policy coefficient is calculated as the target historical attack protection policy coefficient of the firewall to be policy optimized; When the historical attack protection gap factor is greater than or equal to the first preset historical attack protection gap factor and less than the second preset historical attack protection gap factor, a second product value of the second preset coefficient adjustment value and the historical attack protection policy coefficient is calculated as the target historical attack protection policy coefficient of the firewall to be policy optimized; When the historical attack protection gap factor is greater than or equal to the second preset historical attack protection gap factor, a third product value of the third preset coefficient adjustment value and the historical attack protection strategy coefficient is calculated as the target historical attack protection strategy coefficient of the firewall to be policy optimized.
[0012] Furthermore, when determining whether it is necessary to perform policy optimization on the firewall to be optimized according to the target historical attack protection policy coefficient, the method includes: Determining whether it is necessary to perform policy optimization on the firewall to be policy optimized based on the relationship between the target historical attack protection policy coefficient and the preset target historical attack protection policy coefficient; When the target historical attack protection strategy coefficient is less than the preset target historical attack protection strategy coefficient, it is determined that the firewall to be optimized needs to be optimized; When the target historical attack protection strategy coefficient is greater than or equal to the preset target historical attack protection strategy coefficient, it is determined that there is no need to perform strategy optimization on the firewall to be optimized.
[0013] Compared with the prior art, the present invention has the following beneficial effects: The present invention discloses a firewall policy optimization generation method based on big data. The method comprises the following steps: obtaining historical attack protection data of a firewall to be policy-optimized, calculating a historical attack protection data factor; constructing a historical attack protection data factor sequence, determining a historical attack protection data factor scatter plot, obtaining a historical attack protection data factor curve, and calculating a historical attack protection policy coefficient; extracting a maximum historical attack protection data factor and a minimum historical attack protection data factor, and calculating a historical attack protection gap factor; adjusting the historical attack protection policy coefficient, obtaining a target historical attack protection policy coefficient, and judging whether policy optimization is required. The method can accurately judge whether policy optimization is required for a computer firewall, thereby avoiding load increase and resource waste caused by unnecessary optimization operations, ensuring timely response to network security threats, and enhancing the overall network security protection efficiency of the computer. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the present invention. The same reference symbols are used throughout the drawings to represent the same components. In the drawings: Figure 1 A flowchart of a method for optimizing and generating firewall policies based on big data in an embodiment of the present invention is shown. DETAILED DESCRIPTION
[0015] The following embodiments of the present invention are described in further detail with reference to the accompanying drawings and examples. The following embodiments are used to illustrate the present invention but are not intended to limit the scope of the present invention.
[0016] In the description of this application, it should be understood that the terms "center", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", etc., indicating the orientation or position relationship, are based on the orientation or position relationship shown in the accompanying drawings, and are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation on this application.
[0017] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature specified as "first" or "second" may explicitly or implicitly include one or more of such features. Throughout this application, unless otherwise specified, "plurality" means two or more.
[0018] In the description of this application, it should be noted that, unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be understood in a broad sense. For example, they can refer to fixed, detachable, or integral connections; mechanical or electrical connections; direct or indirect connections through an intermediate medium; and internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in this application based on the specific circumstances.
[0019] The following is a description of preferred embodiments of the present invention with reference to the accompanying drawings.
[0020] like Figure 1 As shown, an embodiment of the present invention discloses a firewall policy optimization generation method based on big data, comprising: S110: Determine a firewall to be optimized in the computer, obtain multiple historical attack protection data of the firewall to be optimized, analyze the historical attack protection data, and calculate multiple historical attack protection data factors corresponding to the firewall to be optimized; In some embodiments of the present application, when analyzing the historical attack protection data and calculating multiple historical attack protection data factors corresponding to the firewall to be policy optimized, the process includes: Obtaining standard historical attack protection data corresponding to each historical attack protection data; Calculating a plurality of historical attack protection data factors corresponding to the firewall to be policy optimized according to the historical attack protection data and the corresponding standard historical attack protection data; ; Among them, m is the historical attack protection data factor corresponding to the firewall to be optimized, n is the weight corresponding to the historical attack protection data factor, e is a constant, b is the historical attack protection data factor, and b1 is the standard historical attack protection data factor.
[0021] In this embodiment, historical attack protection data refers to the historical response data generated by the firewall to be policy optimized when it is attacked by a network attack, such as historical protection time, historical protection level, historical performance impact, etc., wherein the historical protection time refers to the time points when the attack starts and ends, such as 5 minutes, the historical protection level refers to the effectiveness evaluation of the protection measures, such as 80%, and the historical performance impact refers to the performance impact of the network attack on the computer, such as 5%, which is shown here as an example.
[0022] In this embodiment, the standard historical attack protection data and the historical attack protection data are set in a one-to-one correspondence. For example, the standard historical attack protection data corresponding to the historical protection time is 3 minutes, and the standard historical attack protection data corresponding to the historical protection degree is 95%. This is shown here as an example, and the specific setting can be based on the actual situation.
[0023] The beneficial effect of the above technical solution is: the present invention calculates multiple historical attack protection data factors corresponding to the firewall to be policy-optimized based on the historical attack protection data and the corresponding standard historical attack protection data. The historical attack protection data factors can reflect the degree of deviation between the historical attack protection data and the standard historical attack protection data. At the same time, by calculating the historical attack protection data factors, different historical attack protection data can be unified for processing, which is convenient for subsequent analysis.
[0024] S120: extracting all historical attack protection data factors, constructing a historical attack protection data factor sequence, and determining a historical attack protection data factor scatter graph according to the historical attack protection data factor sequence; In some embodiments of the present application, when extracting all historical attack protection data factors, constructing a historical attack protection data factor sequence, and determining a historical attack protection data factor scatter graph based on the historical attack protection data factor sequence, the process includes: Deploy all historical attack protection data factors into a blank point graph based on a preset length interval to obtain an initial historical attack protection data factor scatter graph; Determining a first historical attack protection data factor from the initial historical attack protection data factor scatter graph, and randomly selecting one from the remaining historical attack protection data factors as a standard historical attack protection data factor; Determining a previous historical attack protection data factor of the standard historical attack protection data factor; Determining a standard length interval corresponding to the standard historical attack protection data factor, determining a previous length interval corresponding to a previous historical attack protection data factor, and calculating a standard convergence value of the standard historical attack protection data factor; Analyze the remaining historical attack protection data factors and calculate multiple standard convergence values; Obtaining a preset standard convergence value, determining whether all standard convergence values are less than or equal to the preset standard convergence value, and if so, using the initial historical attack protection data factor scatter graph as the historical attack protection data factor scatter graph; If not, the preset length interval is shortened according to a preset shortening principle to obtain a second initial historical attack protection data factor scatter graph; The second initial historical attack protection data factor scatter graph is analyzed until the obtained standard convergence values are all less than or equal to the preset standard convergence value, and a historical attack protection data factor scatter graph is obtained.
[0025] In this embodiment, the preset length interval is pre-set, and preferably 2, 5, 8, 11, 14, 17, 20, etc., and the specific rule is 3Δn-1, where Δn is the number of historical attack protection data factors.
[0026] In this embodiment, the initial historical attack protection data factor scatter plot can be obtained by taking the preset length interval as the horizontal axis and the historical attack protection data factor as the vertical axis.
[0027] In this embodiment, the first historical attack protection data factor is the historical attack protection data factor corresponding to the horizontal coordinate 2.
[0028] In this embodiment, if the randomly selected historical attack protection data factor is the historical attack protection data factor corresponding to the horizontal coordinate 11, then the previous historical attack protection data factor is the historical attack protection data factor corresponding to the horizontal coordinate 8. In order to facilitate distinction, the length interval corresponding to the standard historical attack protection data factor is used as the standard length interval, that is, 11, and the length interval corresponding to the previous historical attack protection data factor is used as the previous length interval, that is, 8.
[0029] In this embodiment, based on the above analysis and calculation method, the remaining historical attack protection data factors are analyzed to calculate multiple standard convergence values. It should be noted that the first historical attack protection data factor is not analyzed.
[0030] In this embodiment, the preset standard convergence value is a preset value, preferably 0.6 here, and can be adjusted according to actual conditions.
[0031] In this embodiment, the preset reduction principle is to reduce one length interval each time, such as 2, 5, 8, 11, 14, 17, 20 mentioned above, to 1, 4, 7, 10, 13, 16, 19, and recalculate all standard convergence values until the obtained standard convergence values are less than or equal to the preset standard convergence value.
[0032] The beneficial effects of the above technical solution are: the present invention determines the standard length interval corresponding to the standard historical attack protection data factor, determines the previous length interval corresponding to the previous historical attack protection data factor, and calculates the standard convergence value of the standard historical attack protection data factor. By calculating the standard convergence value, a reliable data basis can be provided for determining the scatter graph of the historical attack protection data factor. The scatter graph of the historical attack protection data factor can facilitate subsequent calculations and lay the foundation for firewall policy optimization.
[0033] In some embodiments of the present application, determining the standard length interval corresponding to the standard historical attack protection data factor, determining the previous length interval corresponding to the previous historical attack protection data factor, and calculating the standard convergence value of the standard historical attack protection data factor includes: The standard convergence value of the standard historical attack protection data factor is calculated according to the following formula: ; Where v is the standard convergence value of the standard historical attack protection data factor, c1 is the standard historical attack protection data factor, z1 is the standard length interval, c2 is the previous historical attack protection data factor, z2 is the previous length interval, k is the number of remaining historical attack protection data factors in addition to the standard historical attack protection data factor, g jis the jth remaining historical attack protection data factor in addition to the standard historical attack protection data factor, f j It is the preset length interval corresponding to the jth remaining historical attack protection data factor except the standard historical attack protection data factor.
[0034] S130: sequentially connecting all historical attack protection data factors on the historical attack protection data factor scatter graph to obtain a historical attack protection data factor curve, and calculating the historical attack protection policy coefficient of the firewall to be policy-optimized based on the historical attack protection data factor curve; In some embodiments of the present application, when calculating the historical attack protection policy coefficient of the firewall to be policy-optimized based on the historical attack protection data factor curve, the process includes: Determining a first historical attack protection data factor on the historical attack protection data factor curve; Determine all curve inflection points on the historical attack protection data factor curve, and generate a first curve identifier for all historical attack protection data factors between the first historical attack protection data factor and the first curve inflection point; Generate a second curve identifier using all historical attack protection data factors between the first curve inflection point and the second curve inflection point, generate a third curve identifier using all historical attack protection data factors between the second curve inflection point and the third curve inflection point, repeat the above steps to generate multiple curve identifiers based on the curve inflection points; The historical attack protection strategy coefficient of the firewall to be optimized is calculated according to the following formula: ; Among them, d is the historical attack protection strategy coefficient of the firewall to be optimized, s is the number of curve markers, and p a =i a / u a ,i a The maximum historical attack protection data factor corresponding to the a-th curve identifier, u a The minimum historical attack protection data factor corresponding to the a-th curve, y1 a Divide i by the a-th curve identifier a The variance of all historical attack protection data factors except a Identify the ath curve by dividing u a The variance of all historical attack protection data factors except .
[0035] In this embodiment, when generating curve identifiers, historical attack protection data factors located at the boundary do not generate curve identifiers. For example, all historical attack protection data factors between the first historical attack protection data factor and the first curve inflection point are used to generate the first curve identifier. Here, the first historical attack protection data factor and the historical attack protection data factors corresponding to the first curve inflection point do not generate the first curve identifier.
[0036] The beneficial effect of the above technical solution is: the present invention ensures the calculation accuracy and efficiency of the historical attack protection strategy coefficient by calculating the historical attack protection strategy coefficient of the firewall to be optimized. At the same time, the historical attack protection strategy coefficient can reflect the response capability of the firewall to be optimized when facing network attacks, thereby realizing a comprehensive analysis of the firewall to be optimized and avoiding the problem of inaccurate policy optimization caused by overly one-sided analysis.
[0037] S140: Extracting a maximum historical attack protection data factor and a minimum historical attack protection data factor from the historical attack protection data factor sequence, and calculating a historical attack protection gap factor of the firewall to be policy optimized based on the maximum historical attack protection data factor and the minimum historical attack protection data factor; In some embodiments of the present application, when calculating the historical attack protection gap factor of the firewall to be policy optimized based on the maximum historical attack protection data factor and the minimum historical attack protection data factor, the process includes: The historical attack protection gap factor of the firewall to be optimized is calculated according to the following formula: ; Among them, t is the historical attack protection gap factor of the firewall to be optimized, r1 is the maximum historical attack protection data factor, and r2 is the minimum historical attack protection data factor.
[0038] The beneficial effect of the above technical solution is that the present invention calculates the historical attack protection gap factor of the firewall to be policy optimized based on the maximum historical attack protection data factor and the minimum historical attack protection data factor, thereby ensuring the calculation accuracy of the historical attack protection gap factor.
[0039] S150: Adjust the historical attack protection policy coefficient based on the historical attack protection gap factor to obtain the target historical attack protection policy coefficient of the firewall to be policy optimized, and determine whether policy optimization of the firewall to be policy optimized needs to be performed based on the target historical attack protection policy coefficient.
[0040] In some embodiments of the present application, when adjusting the historical attack protection policy coefficient based on the historical attack protection gap factor to obtain the target historical attack protection policy coefficient of the firewall to be policy optimized, the process includes: Presetting a first preset historical attack protection gap factor and a second preset historical attack protection gap factor; Presetting a first preset coefficient adjustment value, a second preset coefficient adjustment value, and a third preset coefficient adjustment value; When the historical attack protection gap factor is less than the first preset historical attack protection gap factor, a first product value of the first preset coefficient adjustment value and the historical attack protection policy coefficient is calculated as the target historical attack protection policy coefficient of the firewall to be policy optimized; When the historical attack protection gap factor is greater than or equal to the first preset historical attack protection gap factor and less than the second preset historical attack protection gap factor, a second product value of the second preset coefficient adjustment value and the historical attack protection policy coefficient is calculated as the target historical attack protection policy coefficient of the firewall to be policy optimized; When the historical attack protection gap factor is greater than or equal to the second preset historical attack protection gap factor, a third product value of the third preset coefficient adjustment value and the historical attack protection strategy coefficient is calculated as the target historical attack protection strategy coefficient of the firewall to be policy optimized.
[0041] In this embodiment, the first preset historical attack protection gap factor is smaller than the second preset historical attack protection gap factor. The first preset historical attack protection gap factor is preferably 3, and the second preset historical attack protection gap factor is preferably 7. The specific factor can be adjusted according to actual conditions.
[0042] In this embodiment, the first preset coefficient adjustment value is smaller than the second preset coefficient adjustment value, which is smaller than the third preset coefficient adjustment value. The first preset coefficient adjustment value is preferably 0.9, the second preset coefficient adjustment value is preferably 1.1, and the third preset coefficient adjustment value is preferably 1.2. The specific value can also be adjusted according to actual conditions.
[0043] The beneficial effect of the above technical solution is: the present invention selects the corresponding preset coefficient adjustment value according to the historical attack protection gap factor, the first preset historical attack protection gap factor and the second preset historical attack protection gap factor, thereby realizing dynamic adjustment of the historical attack protection strategy coefficient. By comprehensively considering the historical attack protection gap factor, the policy optimization accuracy of the firewall to be policy optimized is further guaranteed, and errors are avoided.
[0044] In some embodiments of the present application, when determining whether it is necessary to perform policy optimization on the firewall to be policy optimized according to the target historical attack protection policy coefficient, the method includes: Determining whether it is necessary to perform policy optimization on the firewall to be policy optimized based on the relationship between the target historical attack protection policy coefficient and the preset target historical attack protection policy coefficient; When the target historical attack protection strategy coefficient is less than the preset target historical attack protection strategy coefficient, it is determined that the firewall to be optimized needs to be optimized; When the target historical attack protection strategy coefficient is greater than or equal to the preset target historical attack protection strategy coefficient, it is determined that there is no need to perform strategy optimization on the firewall to be optimized.
[0045] In this embodiment, the preset target historical attack protection strategy coefficient is preferably 6, which can be adjusted according to actual conditions. The preset target historical attack protection strategy coefficient is used to determine whether policy optimization is required for the firewall to be optimized.
[0046] The beneficial effect of the above technical solution is that the present invention can accurately determine whether it is necessary to optimize the computer firewall policy, which not only avoids the load increase and resource waste caused by unnecessary optimization operations, but also ensures timely response to network security threats and enhances the overall network security protection effectiveness of the computer.
[0047] In the description of the above embodiments, specific features, structures, materials or characteristics may be combined in an appropriate manner in any one or more embodiments or examples.
[0048] While the present invention has been described above with reference to exemplary embodiments, various modifications may be made and equivalent components may be substituted without departing from the scope of the present invention. In particular, the various features of the disclosed embodiments may be combined with one another in any manner, provided no structural conflicts exist. These combinations are not fully described in this specification for reasons of space and resource conservation.
[0049] Those skilled in the art will understand that the above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art will still be able to modify the technical solutions described in the aforementioned embodiments or replace some of the technical features therein with equivalents. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A firewall policy optimization generation method based on big data, characterized in that: include: Determine a firewall to be policy-optimized in the computer, obtain multiple historical attack protection data of the firewall to be policy-optimized, analyze the historical attack protection data, and calculate multiple historical attack protection data factors corresponding to the firewall to be policy-optimized; Extracting all historical attack protection data factors, constructing a historical attack protection data factor sequence, and determining a historical attack protection data factor scatter graph based on the historical attack protection data factor sequence; All historical attack protection data factors on the historical attack protection data factor scatter graph are sequentially connected to obtain a historical attack protection data factor curve, and the historical attack protection strategy coefficient of the firewall to be optimized is calculated according to the historical attack protection data factor curve; Extracting a maximum historical attack protection data factor and a minimum historical attack protection data factor from the historical attack protection data factor sequence, and calculating a historical attack protection drop factor of the firewall to be policy optimized based on the maximum historical attack protection data factor and the minimum historical attack protection data factor; The historical attack protection strategy coefficient is adjusted based on the historical attack protection gap factor to obtain the target historical attack protection strategy coefficient of the firewall to be optimized, and whether the firewall to be optimized needs to be optimized is determined according to the target historical attack protection strategy coefficient.
2. The method for optimizing and generating firewall policies based on big data according to claim 1, characterized in that: When analyzing the historical attack protection data and calculating multiple historical attack protection data factors corresponding to the firewall to be optimized, the method includes: Obtaining standard historical attack protection data corresponding to each historical attack protection data; Calculating a plurality of historical attack protection data factors corresponding to the firewall to be policy optimized according to the historical attack protection data and the corresponding standard historical attack protection data; ; Among them, m is the historical attack protection data factor corresponding to the firewall to be optimized, n is the weight corresponding to the historical attack protection data factor, e is a constant, b is the historical attack protection data factor, and b1 is the standard historical attack protection data factor.
3. The method for optimizing and generating firewall policies based on big data according to claim 1, characterized in that: When extracting all historical attack protection data factors, constructing a historical attack protection data factor sequence, and determining a historical attack protection data factor scatter graph according to the historical attack protection data factor sequence, the process includes: Deploy all historical attack protection data factors into a blank point graph based on a preset length interval to obtain an initial historical attack protection data factor scatter graph; Determining a first historical attack protection data factor from the initial historical attack protection data factor scatter graph, and randomly selecting one from the remaining historical attack protection data factors as a standard historical attack protection data factor; Determining a previous historical attack protection data factor of the standard historical attack protection data factor; Determining a standard length interval corresponding to the standard historical attack protection data factor, determining a previous length interval corresponding to a previous historical attack protection data factor, and calculating a standard convergence value of the standard historical attack protection data factor; Analyze the remaining historical attack protection data factors and calculate multiple standard convergence values; Obtaining a preset standard convergence value, determining whether all standard convergence values are less than or equal to the preset standard convergence value, and if so, using the initial historical attack protection data factor scatter graph as the historical attack protection data factor scatter graph; If not, the preset length interval is shortened according to a preset shortening principle to obtain a second initial historical attack protection data factor scatter graph; The second initial historical attack protection data factor scatter graph is analyzed until the obtained standard convergence values are all less than or equal to the preset standard convergence value, and a historical attack protection data factor scatter graph is obtained.
4. The method for optimizing and generating firewall policies based on big data according to claim 3, characterized in that: When determining a standard length interval corresponding to the standard historical attack protection data factor, determining a previous length interval corresponding to a previous historical attack protection data factor, and calculating a standard convergence value of the standard historical attack protection data factor, the method includes: The standard convergence value of the standard historical attack protection data factor is calculated according to the following formula: ; Where v is the standard convergence value of the standard historical attack protection data factor, c1 is the standard historical attack protection data factor, z1 is the standard length interval, c2 is the previous historical attack protection data factor, z2 is the previous length interval, k is the number of remaining historical attack protection data factors in addition to the standard historical attack protection data factor, g j is the jth remaining historical attack protection data factor in addition to the standard historical attack protection data factor, f j It is the preset length interval corresponding to the jth remaining historical attack protection data factor except the standard historical attack protection data factor.
5. The method for optimizing and generating firewall policies based on big data according to claim 1, characterized in that: When calculating the historical attack protection policy coefficient of the firewall to be optimized according to the historical attack protection data factor curve, it includes: Determining a first historical attack protection data factor on the historical attack protection data factor curve; Determine all curve inflection points on the historical attack protection data factor curve, and generate a first curve identifier for all historical attack protection data factors between the first historical attack protection data factor and the first curve inflection point; Generate a second curve identifier using all historical attack protection data factors between the first curve inflection point and the second curve inflection point, generate a third curve identifier using all historical attack protection data factors between the second curve inflection point and the third curve inflection point, repeat the above steps to generate multiple curve identifiers based on the curve inflection points; The historical attack protection strategy coefficient of the firewall to be optimized is calculated according to the following formula: ; Among them, d is the historical attack protection strategy coefficient of the firewall to be optimized, s is the number of curve markers, and p a =i a / u a ,i a The maximum historical attack protection data factor corresponding to the a-th curve identifier, u a The minimum historical attack protection data factor corresponding to the a-th curve, y1 a Divide i by the a-th curve identifier a The variance of all historical attack protection data factors except a Identify the ath curve by dividing u a The variance of all historical attack protection data factors except .
6. The method for optimizing and generating firewall policies based on big data according to claim 1, characterized in that: When calculating the historical attack protection gap factor of the firewall to be policy optimized according to the maximum historical attack protection data factor and the minimum historical attack protection data factor, the method includes: The historical attack protection gap factor of the firewall to be optimized is calculated according to the following formula: ; Among them, t is the historical attack protection gap factor of the firewall to be optimized, r1 is the maximum historical attack protection data factor, and r2 is the minimum historical attack protection data factor.
7. The method for optimizing and generating firewall policies based on big data according to claim 1, characterized in that: When the historical attack protection policy coefficient is adjusted based on the historical attack protection gap factor to obtain the target historical attack protection policy coefficient of the firewall to be policy optimized, the method includes: Presetting a first preset historical attack protection gap factor and a second preset historical attack protection gap factor; Presetting a first preset coefficient adjustment value, a second preset coefficient adjustment value, and a third preset coefficient adjustment value; When the historical attack protection gap factor is less than the first preset historical attack protection gap factor, a first product value of the first preset coefficient adjustment value and the historical attack protection policy coefficient is calculated as the target historical attack protection policy coefficient of the firewall to be policy optimized; When the historical attack protection gap factor is greater than or equal to the first preset historical attack protection gap factor and less than the second preset historical attack protection gap factor, a second product value of the second preset coefficient adjustment value and the historical attack protection policy coefficient is calculated as the target historical attack protection policy coefficient of the firewall to be policy optimized; When the historical attack protection gap factor is greater than or equal to the second preset historical attack protection gap factor, a third product value of the third preset coefficient adjustment value and the historical attack protection strategy coefficient is calculated as the target historical attack protection strategy coefficient of the firewall to be policy optimized.
8. The method for optimizing and generating firewall policies based on big data according to claim 1, characterized in that: When determining whether it is necessary to perform policy optimization on the firewall to be optimized according to the target historical attack protection policy coefficient, the method includes: Determining whether it is necessary to perform policy optimization on the firewall to be policy optimized based on the relationship between the target historical attack protection policy coefficient and the preset target historical attack protection policy coefficient; When the target historical attack protection strategy coefficient is less than the preset target historical attack protection strategy coefficient, it is determined that the firewall to be optimized needs to be optimized; When the target historical attack protection strategy coefficient is greater than or equal to the preset target historical attack protection strategy coefficient, it is determined that there is no need to perform strategy optimization on the firewall to be optimized.
Citation Information
Patent Citations
Firewall policy management method, system and device and readable storage medium
CN113452715A
Method and device for determining invalid firewall policy, equipment and storage medium
CN116319078A
DDoS attack protection strategy template generation method and device
CN116668170A
Network security protection method based on edge computing
CN119051933A
Network security protection system based on firewall technology
CN119094173A