A firewall policy optimization generation method based on big data

CN120455075BActive Publication Date: 2026-06-05HUANENG INFORMATION TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HUANENG INFORMATION TECH CO LTD
Filing Date
2025-05-07
Publication Date
2026-06-05

Smart Images

  • Figure CN120455075B_ABST
    Figure CN120455075B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of computer security, and discloses a firewall policy optimization generation method based on big data, historical attack protection data of a to-be-strategically-optimized firewall is acquired, and historical attack protection data factors are calculated; a historical attack protection data factor sequence is constructed, a historical attack protection data factor scatter diagram is determined, a historical attack protection data factor curve is obtained, and historical attack protection strategy coefficients are calculated; the maximum historical attack protection data factor and the minimum historical attack protection data factor are extracted, and a historical attack protection drop factor is calculated; the historical attack protection strategy coefficients are adjusted, target historical attack protection strategy coefficients are obtained, and it is judged whether strategy optimization is needed; the computer firewall can be accurately judged whether strategy optimization is needed; unnecessary optimization operation is avoided, load increase and resource waste are avoided, network security threats can be responded to in time, and the overall network security protection efficiency of the computer is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer security technology, and more specifically, to a method for optimizing and generating firewall policies based on big data. Background Technology

[0002] With the rapid development of internet technology, cybersecurity issues have become increasingly prominent, and cyberattack methods are constantly emerging, causing huge economic losses and security threats to individuals and businesses. As the first line of defense for computers, the rationality and effectiveness of firewall security strategies directly affect the security of the entire computer system.

[0003] In existing technologies, determining whether a computer firewall needs policy optimization primarily relies on large-scale model analysis. However, this model-based approach has significant limitations, mainly in two aspects: First, the insufficiency of model training data severely restricts the accuracy of the judgment. High-quality labeled data is the foundation for building an effective model, but due to the difficulty in obtaining real network attack data and the high cost of labeling, training datasets often suffer from insufficient samples and limited coverage, directly affecting model performance. Second, the generalization ability of existing models is significantly limited. Most current optimization methods are designed for specific network environments and specific attack types, which often results in insufficient adaptability when facing complex and ever-changing real-world network environments. This limitation makes it difficult for models to accurately identify diverse network threats and to provide reliable and effective decision-making suggestions for firewall policy optimization. These limitations not only affect the timeliness and accuracy of firewall policy optimization but also reduce the overall effectiveness of computer security protection to some extent. Summary of the Invention

[0004] This invention provides a firewall policy optimization generation method based on big data. This invention can accurately determine whether computer firewall policies need to be optimized, significantly improving the accuracy and adaptability of policy optimization. It avoids increased system load and resource waste caused by unnecessary optimization operations, while ensuring timely response to network security threats, thereby enhancing the overall network security protection effectiveness of the computer.

[0005] To achieve the above objectives, this invention provides a firewall policy optimization and generation method based on big data, comprising:

[0006] Identify the firewall to be optimized in the computer, obtain multiple historical attack protection data of the firewall to be optimized, analyze the historical attack protection data, and calculate multiple historical attack protection data factors corresponding to the firewall to be optimized.

[0007] Extract all historical attack protection data factors, construct a historical attack protection data factor sequence, and determine a historical attack protection data factor scatter plot based on the historical attack protection data factor sequence.

[0008] All historical attack protection data factors on the historical attack protection data factor scatter plot are sequentially connected to obtain the historical attack protection data factor curve, and the historical attack protection policy coefficient of the firewall to be optimized is calculated based on the historical attack protection data factor curve.

[0009] Extract the maximum and minimum historical attack protection data factors from the historical attack protection data factor sequence, and calculate the historical attack protection gap factor of the firewall to be optimized based on the maximum and minimum historical attack protection data factors.

[0010] The historical attack protection strategy coefficient is adjusted based on the historical attack protection gap factor to obtain the target historical attack protection strategy coefficient of the firewall to be optimized, and it is determined whether the firewall to be optimized needs to be optimized based on the target historical attack protection strategy coefficient.

[0011] Furthermore, when analyzing the historical attack protection data and calculating multiple historical attack protection data factors corresponding to the firewall to be optimized, the process includes:

[0012] Obtain the standard historical attack protection data corresponding to each historical attack protection data;

[0013] Calculate multiple historical attack protection data factors corresponding to the firewall to be optimized based on the historical attack protection data and the corresponding standard historical attack protection data.

[0014] ;

[0015] Where m is the historical attack protection data factor corresponding to the firewall to be optimized, n is the weight corresponding to the historical attack protection data factor, e is a constant, b is the historical attack protection data factor, and b1 is the standard historical attack protection data factor.

[0016] Furthermore, the process of extracting all historical attack protection data factors, constructing a historical attack protection data factor sequence, and determining a historical attack protection data factor scatter plot based on the historical attack protection data factor sequence includes:

[0017] Based on a preset length interval, all historical attack protection data factors are deployed to the blank dot graph to obtain an initial historical attack protection data factor scatter plot.

[0018] The first historical attack protection data factor is determined from the initial historical attack protection data factor scatter plot, and one is randomly selected from the remaining historical attack protection data factors as the standard historical attack protection data factor.

[0019] Determine the preceding historical attack protection data factor of the standard historical attack protection data factor;

[0020] Determine the standard length interval corresponding to the standard historical attack protection data factor, determine the previous length interval corresponding to the previous historical attack protection data factor, and calculate the standard convergence value of the standard historical attack protection data factor.

[0021] The remaining historical attack protection data factors were analyzed, and multiple standard convergence values ​​were calculated.

[0022] Obtain a preset standard convergence value, determine whether all standard convergence values ​​are less than or equal to the preset standard convergence value, and if so, use the initial historical attack protection data factor scatter plot as the historical attack protection data factor scatter plot.

[0023] If not, the preset length interval is reduced according to the preset reduction principle to obtain the second initial historical attack protection data factor scatter plot.

[0024] The second initial historical attack protection data factor scatter plot is analyzed until all the obtained standard convergence values ​​are less than or equal to the preset standard convergence value, and the historical attack protection data factor scatter plot is obtained.

[0025] Further, in determining the standard length interval corresponding to the standard historical attack protection data factor, determining the previous length interval corresponding to the previous historical attack protection data factor, and calculating the standard convergence value of the standard historical attack protection data factor, the process includes:

[0026] The standard convergence value of the standard historical attack protection data factor is calculated according to the following formula:

[0027] ;

[0028] Where v is the standard convergence value of the standard historical attack protection data factor, c1 is the standard historical attack protection data factor, z1 is the standard length interval, c2 is the previous historical attack protection data factor, z2 is the previous length interval, k is the number of remaining historical attack protection data factors besides the standard historical attack protection data factor, and g j f is the j-th remaining historical attack protection data factor besides the standard historical attack protection data factor. j The preset length interval corresponds to the j-th remaining historical attack protection data factor other than the standard historical attack protection data factor.

[0029] Furthermore, when calculating the historical attack protection policy coefficients of the firewall to be optimized based on the historical attack protection data factor curve, the following steps are included:

[0030] Determine the first historical attack protection data factor on the historical attack protection data factor curve;

[0031] Determine all curve inflection points on the historical attack protection data factor curve, and generate a first curve identifier for all historical attack protection data factors between the first historical attack protection data factor and the first curve inflection point.

[0032] Generate a second curve identifier from all historical attack protection data factors between the first curve inflection point and the second curve inflection point, and generate a third curve identifier from all historical attack protection data factors between the second curve inflection point and the third curve inflection point. Repeat the above steps to generate multiple curve identifiers based on the curve inflection points.

[0033] The historical attack protection strategy coefficient of the firewall to be optimized is calculated according to the following formula:

[0034] ;

[0035] Where d represents the historical attack protection policy coefficient of the firewall to be optimized, s represents the number of curve markers, and p a =i a / u a i a u represents the maximum historical attack protection data factor corresponding to the a-th curve identifier. a Let y1 be the minimum historical attack protection data factor corresponding to the a-th curve identifier. a For the a-th curve identifier, excluding i a The variance of all historical attack protection data factors, y2 a The a-th curve identifier is divided by u a The variance of all historical attack protection data factors, excluding those mentioned above.

[0036] Further, when calculating the historical attack protection gap factor of the firewall to be optimized based on the maximum historical attack protection data factor and the minimum historical attack protection data factor, the following steps are included:

[0037] The historical attack protection gap factor of the firewall to be optimized is calculated according to the following formula:

[0038] ;

[0039] Where t is the historical attack protection gap factor of the firewall to be optimized, r1 is the maximum historical attack protection data factor, and r2 is the minimum historical attack protection data factor.

[0040] Further, when adjusting the historical attack protection strategy coefficient based on the historical attack protection gap factor to obtain the target historical attack protection strategy coefficient of the firewall to be optimized, the following steps are included:

[0041] A first preset historical attack protection gap factor and a second preset historical attack protection gap factor are pre-set;

[0042] The first preset coefficient adjustment value, the second preset coefficient adjustment value, and the third preset coefficient adjustment value are preset;

[0043] When the historical attack protection drop factor is less than the first preset historical attack protection drop factor, the first product of the first preset coefficient adjustment value and the historical attack protection strategy coefficient is calculated and used as the target historical attack protection strategy coefficient of the firewall to be optimized.

[0044] When the historical attack protection drop factor is greater than or equal to the first preset historical attack protection drop factor and less than the second preset historical attack protection drop factor, the second product of the second preset coefficient adjustment value and the historical attack protection strategy coefficient is calculated and used as the target historical attack protection strategy coefficient of the firewall to be optimized.

[0045] When the historical attack protection gap factor is greater than or equal to the second preset historical attack protection gap factor, the third product of the third preset coefficient adjustment value and the historical attack protection strategy coefficient is calculated and used as the target historical attack protection strategy coefficient of the firewall to be optimized.

[0046] Furthermore, when determining whether policy optimization is needed for the firewall to be optimized based on the target historical attack protection policy coefficient, the process includes:

[0047] Based on the relationship between the target historical attack protection policy coefficient and the preset target historical attack protection policy coefficient, it is determined whether the firewall to be optimized needs to be optimized.

[0048] When the target historical attack protection policy coefficient is less than the preset target historical attack protection policy coefficient, it is determined that the firewall to be optimized needs to be optimized.

[0049] When the target historical attack protection policy coefficient is greater than or equal to the preset target historical attack protection policy coefficient, it is determined that no policy optimization is needed for the firewall to be optimized.

[0050] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0051] This invention discloses a firewall policy optimization generation method based on big data. The method involves acquiring historical attack protection data of the firewall to be optimized, calculating historical attack protection data factors, constructing a historical attack protection data factor sequence, determining a historical attack protection data factor scatter plot, obtaining a historical attack protection data factor curve, and calculating historical attack protection policy coefficients. The method also extracts the maximum and minimum historical attack protection data factors and calculates the historical attack protection drop factor. Adjusting the historical attack protection policy coefficients yields the target historical attack protection policy coefficients, allowing for a precise determination of whether policy optimization is needed. This approach avoids unnecessary optimization operations that increase load and waste resources, while ensuring timely response to network security threats and enhancing the overall network security protection effectiveness of the computer. Attached Figure Description

[0052] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:

[0053] Figure 1 The diagram illustrates a flowchart of a firewall policy optimization generation method based on big data, according to an embodiment of the present invention. Detailed Implementation

[0054] The specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings and examples. The following examples are for illustrative purposes only and are not intended to limit the scope of the invention.

[0055] In the description of this application, it should be understood that the terms "center", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this application.

[0056] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "a plurality of" means two or more.

[0057] In the description of this application, it should be noted that, unless otherwise expressly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection between two components. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances.

[0058] The following is a description of preferred embodiments of the present invention in conjunction with the accompanying drawings.

[0059] like Figure 1 As shown, an embodiment of the present invention discloses a firewall policy optimization generation method based on big data, including:

[0060] S110: Determine the firewall to be optimized in the computer, obtain multiple historical attack protection data of the firewall to be optimized, analyze the historical attack protection data, and calculate multiple historical attack protection data factors corresponding to the firewall to be optimized.

[0061] In some embodiments of this application, when analyzing the historical attack protection data and calculating multiple historical attack protection data factors corresponding to the firewall to be optimized, the following steps are included:

[0062] Obtain the standard historical attack protection data corresponding to each historical attack protection data;

[0063] Calculate multiple historical attack protection data factors corresponding to the firewall to be optimized based on the historical attack protection data and the corresponding standard historical attack protection data.

[0064] ;

[0065] Where m is the historical attack protection data factor corresponding to the firewall to be optimized, n is the weight corresponding to the historical attack protection data factor, e is a constant, b is the historical attack protection data factor, and b1 is the standard historical attack protection data factor.

[0066] In this embodiment, historical attack protection data refers to the historical response data generated by the firewall to be optimized when it is subjected to a network attack, such as historical protection time, historical protection level, and historical performance impact. Among them, historical protection time refers to the time point when the attack starts and ends, such as 5 minutes; historical protection level refers to the effectiveness evaluation of the protection measures, such as 80%; and historical performance impact refers to the degree of impact of the network attack on the computer's performance, such as 5%. This is illustrated as an example.

[0067] In this embodiment, the standard historical attack protection data is set in a one-to-one correspondence with the historical attack protection data. For example, the standard historical attack protection data corresponding to the historical protection time is 3 minutes, and the standard historical attack protection data corresponding to the historical protection level is 95%. This is just an example, and the specific settings can be combined with the actual situation.

[0068] The beneficial effects of the above technical solution are as follows: This invention calculates multiple historical attack protection data factors corresponding to the firewall to be optimized based on historical attack protection data and corresponding standard historical attack protection data. The historical attack protection data factors can reflect the degree of deviation between historical attack protection data and standard historical attack protection data. At the same time, by calculating the historical attack protection data factors, different historical attack protection data can be uniformly processed, which is convenient for subsequent analysis.

[0069] S120: Extract all historical attack protection data factors, construct a historical attack protection data factor sequence, and determine a historical attack protection data factor scatter plot based on the historical attack protection data factor sequence.

[0070] In some embodiments of this application, the process of extracting all historical attack protection data factors, constructing a historical attack protection data factor sequence, and determining a historical attack protection data factor scatter plot based on the historical attack protection data factor sequence includes:

[0071] Based on a preset length interval, all historical attack protection data factors are deployed to the blank dot graph to obtain an initial historical attack protection data factor scatter plot.

[0072] The first historical attack protection data factor is determined from the initial historical attack protection data factor scatter plot, and one is randomly selected from the remaining historical attack protection data factors as the standard historical attack protection data factor.

[0073] Determine the preceding historical attack protection data factor of the standard historical attack protection data factor;

[0074] Determine the standard length interval corresponding to the standard historical attack protection data factor, determine the previous length interval corresponding to the previous historical attack protection data factor, and calculate the standard convergence value of the standard historical attack protection data factor.

[0075] The remaining historical attack protection data factors were analyzed, and multiple standard convergence values ​​were calculated.

[0076] Obtain a preset standard convergence value, determine whether all standard convergence values ​​are less than or equal to the preset standard convergence value, and if so, use the initial historical attack protection data factor scatter plot as the historical attack protection data factor scatter plot.

[0077] If not, the preset length interval is reduced according to the preset reduction principle to obtain the second initial historical attack protection data factor scatter plot.

[0078] The second initial historical attack protection data factor scatter plot is analyzed until all the obtained standard convergence values ​​are less than or equal to the preset standard convergence value, and the historical attack protection data factor scatter plot is obtained.

[0079] In this embodiment, the preset length interval is pre-set, preferably 2, 5, 8, 11, 14, 17, 20, etc., with a specific pattern of 3Δn-1, where Δn is the number of historical attack protection data factors.

[0080] In this embodiment, an initial historical attack protection data factor scatter plot can be obtained by using a preset length interval as the horizontal axis and historical attack protection data factors as the vertical axis.

[0081] In this embodiment, the first historical attack protection data factor is the historical attack protection data factor corresponding to the horizontal axis 2 mentioned above.

[0082] In this embodiment, if the randomly selected historical attack protection data factor is the historical attack protection data factor corresponding to the horizontal coordinate 11, then the previous historical attack protection data factor is the historical attack protection data factor corresponding to the horizontal coordinate 8. In order to facilitate the distinction, the length interval corresponding to the standard historical attack protection data factor is taken as the standard length interval, which is 11, and the length interval corresponding to the previous historical attack protection data factor is taken as the previous length interval, which is 8.

[0083] In this embodiment, based on the above analysis and calculation methods, the remaining historical attack protection data factors are analyzed, and multiple standard convergence values ​​can be calculated. It should be noted that the first historical attack protection data factor is not analyzed.

[0084] In this embodiment, the preset standard convergence value is a preset value, preferably 0.6, but it can be adjusted according to the actual situation.

[0085] In this embodiment, the preset reduction principle is to reduce the length interval by one each time. For example, the above 2, 5, 8, 11, 14, 17, 20 are reduced to 1, 4, 7, 10, 13, 16, 19. All standard convergence values ​​are recalculated until the obtained standard convergence values ​​are all less than or equal to the preset standard convergence value.

[0086] The beneficial effects of the above technical solution are: the present invention determines the standard length interval corresponding to the standard historical attack protection data factor, determines the previous length interval corresponding to the previous historical attack protection data factor, and calculates the standard convergence value of the standard historical attack protection data factor. By calculating the standard convergence value, reliable data basis can be provided for determining the historical attack protection data factor scatter plot. The historical attack protection data factor scatter plot can facilitate subsequent calculations and lay the foundation for firewall policy optimization.

[0087] In some embodiments of this application, determining the standard length interval corresponding to the standard historical attack protection data factor, determining the previous length interval corresponding to the previous historical attack protection data factor, and calculating the standard convergence value of the standard historical attack protection data factor includes:

[0088] The standard convergence value of the standard historical attack protection data factor is calculated according to the following formula:

[0089] ;

[0090] Where v is the standard convergence value of the standard historical attack protection data factor, c1 is the standard historical attack protection data factor, z1 is the standard length interval, c2 is the previous historical attack protection data factor, z2 is the previous length interval, k is the number of remaining historical attack protection data factors besides the standard historical attack protection data factor, and g j f is the j-th remaining historical attack protection data factor besides the standard historical attack protection data factor. j The preset length interval corresponds to the j-th remaining historical attack protection data factor other than the standard historical attack protection data factor.

[0091] S130: Connect all historical attack protection data factors on the historical attack protection data factor scatter plot in sequence to obtain the historical attack protection data factor curve, and calculate the historical attack protection policy coefficient of the firewall to be optimized based on the historical attack protection data factor curve.

[0092] In some embodiments of this application, calculating the historical attack protection policy coefficients of the firewall to be optimized based on the historical attack protection data factor curve includes:

[0093] Determine the first historical attack protection data factor on the historical attack protection data factor curve;

[0094] Determine all curve inflection points on the historical attack protection data factor curve, and generate a first curve identifier for all historical attack protection data factors between the first historical attack protection data factor and the first curve inflection point.

[0095] Generate a second curve identifier from all historical attack protection data factors between the first curve inflection point and the second curve inflection point, and generate a third curve identifier from all historical attack protection data factors between the second curve inflection point and the third curve inflection point. Repeat the above steps to generate multiple curve identifiers based on the curve inflection points.

[0096] The historical attack protection strategy coefficient of the firewall to be optimized is calculated according to the following formula:

[0097] ;

[0098] Where d represents the historical attack protection policy coefficient of the firewall to be optimized, s represents the number of curve markers, and p a =i a / u a i a u represents the maximum historical attack protection data factor corresponding to the a-th curve identifier. a Let y1 be the minimum historical attack protection data factor corresponding to the a-th curve identifier. a For the a-th curve identifier, excluding i a The variance of all historical attack protection data factors, y2 a The a-th curve identifier is divided by u a The variance of all historical attack protection data factors, excluding those mentioned above.

[0099] In this embodiment, when generating curve identifiers, historical attack protection data factors located at the boundary are not generated with curve identifiers. For example, all historical attack protection data factors between the first historical attack protection data factor and the first curve inflection point are generated with first curve identifiers. Here, the first historical attack protection data factor and the historical attack protection data factor corresponding to the first curve inflection point are not generated with first curve identifiers.

[0100] The beneficial effects of the above technical solution are: by calculating the historical attack protection strategy coefficient of the firewall to be optimized, the present invention not only ensures the calculation accuracy and efficiency of the historical attack protection strategy coefficient, but also reflects the response capability of the firewall to be optimized in the face of network attacks through the historical attack protection strategy coefficient, realizing a comprehensive analysis of the firewall to be optimized and avoiding the problem of inaccurate strategy optimization caused by overly one-sided analysis.

[0101] S140: Extract the maximum historical attack protection data factor and the minimum historical attack protection data factor from the historical attack protection data factor sequence, and calculate the historical attack protection gap factor of the firewall to be optimized based on the maximum historical attack protection data factor and the minimum historical attack protection data factor.

[0102] In some embodiments of this application, calculating the historical attack protection gap factor of the firewall to be optimized based on the maximum historical attack protection data factor and the minimum historical attack protection data factor includes:

[0103] The historical attack protection gap factor of the firewall to be optimized is calculated according to the following formula:

[0104] ;

[0105] Where t is the historical attack protection gap factor of the firewall to be optimized, r1 is the maximum historical attack protection data factor, and r2 is the minimum historical attack protection data factor.

[0106] The beneficial effects of the above technical solution are: the present invention calculates the historical attack protection drop factor of the firewall to be optimized based on the maximum historical attack protection data factor and the minimum historical attack protection data factor, thus ensuring the calculation accuracy of the historical attack protection drop factor.

[0107] S150: Adjust the historical attack protection strategy coefficient based on the historical attack protection gap factor to obtain the target historical attack protection strategy coefficient of the firewall to be optimized, and determine whether the firewall to be optimized needs to be optimized based on the target historical attack protection strategy coefficient.

[0108] In some embodiments of this application, when adjusting the historical attack protection strategy coefficient based on the historical attack protection gap factor to obtain the target historical attack protection strategy coefficient of the firewall to be optimized, the following steps are included:

[0109] A first preset historical attack protection gap factor and a second preset historical attack protection gap factor are pre-set;

[0110] The first preset coefficient adjustment value, the second preset coefficient adjustment value, and the third preset coefficient adjustment value are preset;

[0111] When the historical attack protection drop factor is less than the first preset historical attack protection drop factor, the first product of the first preset coefficient adjustment value and the historical attack protection strategy coefficient is calculated and used as the target historical attack protection strategy coefficient of the firewall to be optimized.

[0112] When the historical attack protection drop factor is greater than or equal to the first preset historical attack protection drop factor and less than the second preset historical attack protection drop factor, the second product of the second preset coefficient adjustment value and the historical attack protection strategy coefficient is calculated and used as the target historical attack protection strategy coefficient of the firewall to be optimized.

[0113] When the historical attack protection gap factor is greater than or equal to the second preset historical attack protection gap factor, the third product of the third preset coefficient adjustment value and the historical attack protection strategy coefficient is calculated and used as the target historical attack protection strategy coefficient of the firewall to be optimized.

[0114] In this embodiment, the first preset historical attack protection gap factor is smaller than the second preset historical attack protection gap factor. The first preset historical attack protection gap factor is preferably 3, and the second preset historical attack protection gap factor is preferably 7. The specific factors can be adjusted according to the actual situation.

[0115] In this embodiment, the first preset coefficient adjustment value is less than the second preset coefficient adjustment value and less than the third preset coefficient adjustment value. The first preset coefficient adjustment value is preferably 0.9, the second preset coefficient adjustment value is preferably 1.1, and the third preset coefficient adjustment value is preferably 1.2. The specific values ​​can be adjusted according to the actual situation.

[0116] The beneficial effects of the above technical solution are as follows: Based on the historical attack protection drop factor, the first preset historical attack protection drop factor and the second preset historical attack protection drop factor, the present invention selects the corresponding preset coefficient adjustment value, thereby realizing the dynamic adjustment of the historical attack protection strategy coefficient. By comprehensively considering the historical attack protection drop factor, the policy optimization accuracy of the firewall to be optimized is further guaranteed, and errors are avoided.

[0117] In some embodiments of this application, when determining whether policy optimization is needed for the firewall to be optimized based on the target historical attack protection policy coefficient, the following steps are included:

[0118] Based on the relationship between the target historical attack protection policy coefficient and the preset target historical attack protection policy coefficient, it is determined whether the firewall to be optimized needs to be optimized.

[0119] When the target historical attack protection policy coefficient is less than the preset target historical attack protection policy coefficient, it is determined that the firewall to be optimized needs to be optimized.

[0120] When the target historical attack protection policy coefficient is greater than or equal to the preset target historical attack protection policy coefficient, it is determined that no policy optimization is needed for the firewall to be optimized.

[0121] In this embodiment, the preset target historical attack protection policy coefficient is preferably 6, but it can be adjusted according to the actual situation. The preset target historical attack protection policy coefficient is used to determine whether the firewall to be optimized needs to be optimized.

[0122] The beneficial effects of the above technical solution are: the present invention can accurately determine whether it is necessary to optimize the computer firewall policy, which avoids the increase in load and waste of resources caused by unnecessary optimization operations, and ensures timely response to network security threats, thereby enhancing the overall network security protection effectiveness of the computer.

[0123] In the description of the above embodiments, specific features, structures, materials, or characteristics may be combined in any suitable manner in one or more embodiments or examples.

[0124] Although the invention has been described above with reference to embodiments, various modifications can be made and components can be replaced with equivalents without departing from the scope of the invention. In particular, as long as there is no structural conflict, the features in the embodiments disclosed in this invention can be combined with each other in any way. The fact that not all of these combinations are described in this specification is merely for the sake of brevity and resource conservation.

[0125] It will be understood by those skilled in the art that the above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for optimizing and generating firewall policies based on big data, characterized in that, include: Identify the firewall to be optimized in the computer, obtain multiple historical attack protection data of the firewall to be optimized, analyze the historical attack protection data, and calculate multiple historical attack protection data factors corresponding to the firewall to be optimized. Extract all historical attack protection data factors, construct a historical attack protection data factor sequence, and determine a historical attack protection data factor scatter plot based on the historical attack protection data factor sequence. All historical attack protection data factors on the historical attack protection data factor scatter plot are sequentially connected to obtain the historical attack protection data factor curve, and the historical attack protection policy coefficient of the firewall to be optimized is calculated based on the historical attack protection data factor curve. Extract the maximum and minimum historical attack protection data factors from the historical attack protection data factor sequence, and calculate the historical attack protection gap factor of the firewall to be optimized based on the maximum and minimum historical attack protection data factors. The historical attack protection strategy coefficient is adjusted based on the historical attack protection gap factor to obtain the target historical attack protection strategy coefficient of the firewall to be optimized, and it is determined whether the firewall to be optimized needs to be optimized based on the target historical attack protection strategy coefficient. When calculating the historical attack protection policy coefficients of the firewall to be optimized based on the historical attack protection data factor curve, the following steps are included: Determine the first historical attack protection data factor on the historical attack protection data factor curve; Determine all curve inflection points on the historical attack protection data factor curve, and generate a first curve identifier for all historical attack protection data factors between the first historical attack protection data factor and the first curve inflection point. Generate a second curve identifier from all historical attack protection data factors between the first curve inflection point and the second curve inflection point, and generate a third curve identifier from all historical attack protection data factors between the second curve inflection point and the third curve inflection point. Repeat the above steps to generate multiple curve identifiers based on the curve inflection points. The historical attack protection strategy coefficient of the firewall to be optimized is calculated according to the following formula: ; Where d represents the historical attack protection policy coefficient of the firewall to be optimized, s represents the number of curve markers, and p a =i a / u a i a u represents the maximum historical attack protection data factor corresponding to the a-th curve identifier. a Let y1 be the minimum historical attack protection data factor corresponding to the a-th curve identifier. a For the a-th curve identifier, excluding i a The variance of all historical attack protection data factors, y2 a The a-th curve identifier is divided by u a The variance of all historical attack protection data factors other than those; When calculating the historical attack protection gap factor of the firewall to be optimized based on the maximum historical attack protection data factor and the minimum historical attack protection data factor, the following steps are included: The historical attack protection gap factor of the firewall to be optimized is calculated according to the following formula: ; Where t is the historical attack protection gap factor of the firewall to be optimized, r1 is the maximum historical attack protection data factor, and r2 is the minimum historical attack protection data factor.

2. The firewall policy optimization and generation method based on big data according to claim 1, characterized in that, When analyzing the historical attack protection data and calculating multiple historical attack protection data factors corresponding to the firewall to be optimized, the following steps are included: Obtain the standard historical attack protection data corresponding to each historical attack protection data; Based on the historical attack protection data and the corresponding standard historical attack protection data, calculate multiple historical attack protection data factors corresponding to the firewall to be optimized.

3. The firewall policy optimization and generation method based on big data according to claim 1, characterized in that, The process of extracting all historical attack protection data factors, constructing a historical attack protection data factor sequence, and determining a historical attack protection data factor scatter plot based on the historical attack protection data factor sequence includes: Based on a preset length interval, all historical attack protection data factors are deployed to the blank dot graph to obtain an initial historical attack protection data factor scatter plot. The first historical attack protection data factor is determined from the initial historical attack protection data factor scatter plot, and one is randomly selected from the remaining historical attack protection data factors as the standard historical attack protection data factor. Determine the preceding historical attack protection data factor of the standard historical attack protection data factor; Determine the standard length interval corresponding to the standard historical attack protection data factor, determine the previous length interval corresponding to the previous historical attack protection data factor, and calculate the standard convergence value of the standard historical attack protection data factor. The remaining historical attack protection data factors were analyzed, and multiple standard convergence values ​​were calculated. Obtain a preset standard convergence value, determine whether all standard convergence values ​​are less than or equal to the preset standard convergence value, and if so, use the initial historical attack protection data factor scatter plot as the historical attack protection data factor scatter plot. If not, the preset length interval is reduced according to the preset reduction principle to obtain the second initial historical attack protection data factor scatter plot. The second initial historical attack protection data factor scatter plot is analyzed until all the obtained standard convergence values ​​are less than or equal to the preset standard convergence value, and the historical attack protection data factor scatter plot is obtained.

4. The firewall policy optimization and generation method based on big data according to claim 3, characterized in that, When determining the standard length interval corresponding to the standard historical attack protection data factor, determining the previous length interval corresponding to the previous historical attack protection data factor, and calculating the standard convergence value of the standard historical attack protection data factor, the process includes: The standard convergence value of the standard historical attack protection data factor is calculated according to the following formula: ; Where v is the standard convergence value of the standard historical attack protection data factor, c1 is the standard historical attack protection data factor, z1 is the standard length interval, c2 is the previous historical attack protection data factor, z2 is the previous length interval, k is the number of remaining historical attack protection data factors besides the standard historical attack protection data factor, and g j f is the j-th remaining historical attack protection data factor besides the standard historical attack protection data factor. j The preset length interval corresponds to the j-th remaining historical attack protection data factor other than the standard historical attack protection data factor.

5. The firewall policy optimization and generation method based on big data according to claim 1, characterized in that, When adjusting the historical attack protection strategy coefficient based on the historical attack protection gap factor to obtain the target historical attack protection strategy coefficient of the firewall to be optimized, the following steps are included: A first preset historical attack protection gap factor and a second preset historical attack protection gap factor are pre-set; The first preset coefficient adjustment value, the second preset coefficient adjustment value, and the third preset coefficient adjustment value are preset; When the historical attack protection drop factor is less than the first preset historical attack protection drop factor, the first product of the first preset coefficient adjustment value and the historical attack protection strategy coefficient is calculated and used as the target historical attack protection strategy coefficient of the firewall to be optimized. When the historical attack protection drop factor is greater than or equal to the first preset historical attack protection drop factor and less than the second preset historical attack protection drop factor, the second product of the second preset coefficient adjustment value and the historical attack protection strategy coefficient is calculated and used as the target historical attack protection strategy coefficient of the firewall to be optimized. When the historical attack protection gap factor is greater than or equal to the second preset historical attack protection gap factor, the third product of the third preset coefficient adjustment value and the historical attack protection strategy coefficient is calculated and used as the target historical attack protection strategy coefficient of the firewall to be optimized.

6. The firewall policy optimization and generation method based on big data according to claim 1, characterized in that, When determining whether policy optimization is needed for the firewall to be optimized based on the target historical attack protection policy coefficient, the following steps are included: Based on the relationship between the target historical attack protection policy coefficient and the preset target historical attack protection policy coefficient, it is determined whether the firewall to be optimized needs to be optimized. When the target historical attack protection policy coefficient is less than the preset target historical attack protection policy coefficient, it is determined that the firewall to be optimized needs to be optimized. When the target historical attack protection policy coefficient is greater than or equal to the preset target historical attack protection policy coefficient, it is determined that no policy optimization is needed for the firewall to be optimized.