Network equipment optimization method and device, computer equipment and storage medium

By identifying and optimizing the policy relationships in the network security policy table, the problem of low network device management efficiency is solved, and efficient and accurate network device optimization is achieved.

CN120528701AActive Publication Date: 2025-08-22ASPIRE TECH (SHENZHEN) LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511013488.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-23
Publication Date
2025-08-22
Estimated Expiration
2045-07-23

AI Technical Summary

Technical Problem

The existing network equipment optimization methods have low management efficiency and insufficient accuracy, resulting in operation and maintenance problems.

Method used

By obtaining the network security policy table, identifying policy relationships, combining policies and deleting policies, building an optimized network security policy table, and applying it to the target network device.

Benefits of technology

It improves the efficiency and accuracy of network equipment management, reduces human intervention, and optimizes the process of sorting out network security strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528701A_ABST
    Figure CN120528701A_ABST
Patent Text Reader

Abstract

The invention discloses a network equipment optimization method and device, computer equipment and a storage medium. The method comprises the following steps: acquiring a network security policy table of target network equipment; determining a network security policy group with a policy relationship in the network security policy table based on the policy action, the policy virtual wall and the communication quintuple information; performing optimization processing on the network security policy table based on the policy relationship of the network security policy group to obtain an optimized network security policy table; and performing optimization processing on the target network equipment based on the optimized network security policy table to obtain the optimized target network equipment. The target network equipment is optimized through the optimized network security policy table, so that the network security policy of the target network equipment can be effectively combed and optimized, and the management efficiency is effectively improved while the management accuracy is ensured due to the fact that no human intervention is needed in the whole process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a network equipment optimization method, device, computer equipment and storage medium. Background Art

[0002] As networks and services expand, the number of security policies configured on devices for network security explodes, easily reaching device capacity limits and leading to performance degradation, significantly impacting network and security operations. To address these issues, operations personnel rely on traditional manual methods to manage tens of thousands of policies, making it difficult to streamline and optimize them. Existing network device optimization methods suffer from low management efficiency.

[0003] Therefore, how to provide a network equipment optimization method that ensures management accuracy while taking into account management efficiency has become an urgent problem to be solved. Summary of the Invention

[0004] Based on this, it is necessary to provide a network equipment optimization method, device, computer equipment and storage medium to address the above technical problems, so as to solve the problems of low management efficiency and management accuracy of traditional methods.

[0005] A network device optimization method, the method comprising: Obtaining a network security policy table of a target network device, wherein the network security policy table includes at least one network security policy, and each network security policy includes a policy action, a policy virtual wall, and communication quintuple information; Determining, based on the policy action, the policy virtual wall, and the communication quintuple information, a network security policy group having a policy relationship in the network security policy table; Optimizing the network security policy table based on the policy relationship of the network security policy group to obtain an optimized network security policy table; The target network device is optimized based on the optimized network security policy table to obtain the optimized target network device.

[0006] Optionally, before obtaining the network security policy table of the target network device, the method further includes: Logging into the target network device through a preset protocol to obtain configuration information of the target network device; extracting at least one set of security policy information from the configuration information; Performing unified formatting on each set of security policy information to obtain a network security policy corresponding to each set of security policy information; A network security policy table of the target network device is obtained based on the network security policy.

[0007] Optionally, the constructing and obtaining the network security policy table of the target network device based on the network security policy includes: Obtaining hit count information for each of the network security policies; Based on the hit count information, determining the order in which each of the network security policies is added; The network security policies are added to a preset empty table in sequence according to the adding order to obtain the network security policy table.

[0008] Optionally, the determining, based on the policy action, the policy virtual wall, and the communication quintuple information, a network security policy group having a policy relationship in the network security policy table includes: In the network security policy table, determining at least two network security policies having the same policy actions and policy virtual walls as a network security policy group to be processed; Based on the communication quintuple information, network security policies with policy relationships are determined in the network security policy group to be processed as the network security policy group.

[0009] Optionally, the communication quintuple information includes a source address, a destination address, and protocol port information, and the determining, based on the communication quintuple information, a network security policy having a policy relationship in the network security policy group to be processed as the network security policy group includes: If the source address, destination address, and protocol port information of the first network security policy in the network security policy group to be processed all contain the source address, destination address, and protocol port information of the second network security policy in the network security policy group to be processed, then the policy relationship between the first network security policy and the second network security policy is an inclusion relationship; If any two of the source address, destination address, and protocol port information of the first network security policy in the network security policy group to be processed are the same as any two of the source address, destination address, and protocol port information of the second network security policy in the network security policy group to be processed, and the policy relationship between the first network security policy and the second network security policy is not an inclusion relationship, then the policy relationship between the first network security policy and the second network security policy is a merge relationship.

[0010] Optionally, the policy relationship is an inclusion relationship or a merge relationship, and the network security policy further includes security domain information and a policy name. The network security policy table is optimized based on the policy relationship of the network security policy group to obtain an optimized network security policy table, including: In the network security policy table, determining a network security policy group whose policy relationship is an inclusion relationship, determining a network security policy with a smaller policy coverage in the network security policy group, and adding a deletion mark to the network security policy with the smaller policy coverage in the network security policy table to obtain a network security policy table to be merged; In the network security policy table to be merged, a network security policy group whose policy relationship is a merge relationship is determined, and the network security policies in the network security policy group are merged in the network security policy table to be merged to obtain the optimized network security policy table. The merging process includes merging and deduplicating the policy actions, policy virtual walls, communication quintuple information and security domain information, and retaining the policy names with higher rankings.

[0011] Optionally, the method further includes: Obtaining hit count information for each of the network security policies; In the optimized network security policy table, adding a zero hit mark for the network security policy whose hit count information is zero; If within a preset time, the hit count information corresponding to the network security policy with a zero hit mark is not zero, then the zero hit mark is removed from the optimized network security policy table; If, after the preset time expires, the hit count information corresponding to the network security policy mark with the zero hit mark is still zero, a deletion mark is added to the network security policy with the zero hit mark in the optimized network security policy table.

[0012] A network equipment optimization device, comprising: A first acquisition module is configured to acquire a network security policy table of a target network device, wherein the network security policy table includes at least one network security policy, and each network security policy includes a policy action, a policy virtual wall, and communication quintuple information; A first determining module is configured to determine, based on the policy action, the policy virtual wall, and the communication quintuple information, a network security policy group having a policy relationship in the network security policy table; A first optimization module, configured to optimize the network security policy table based on the policy relationship of the network security policy group to obtain an optimized network security policy table; The second optimization module is configured to optimize the target network device based on the optimized network security policy table to obtain the optimized target network device.

[0013] A computer device includes a memory, a processor, and computer-readable instructions stored in the memory and executable on the processor. When the processor executes the computer-readable instructions, the network device optimization method is implemented.

[0014] A readable storage medium stores computer-readable instructions, which implement the above-mentioned network device optimization method when executed by a processor.

[0015] The above-mentioned network device optimization method, device, computer device and storage medium include: obtaining a network security policy table of a target network device, wherein the network security policy table includes at least one network security policy, each of the network security policies including a policy action, a policy virtual wall and communication five-tuple information; determining a network security policy group with a policy relationship in the network security policy table based on the policy relationship of the network security policy group to obtain an optimized network security policy table; optimizing the target network device based on the optimized network security policy table to obtain an optimized target network device. Through the policy action, the policy virtual wall and the communication five-tuple information, the network security policy group with a policy relationship can be accurately determined in the network security policy table, and then the network security policy table can be optimized according to the policy relationship to obtain an optimized network security policy table. Then, the target network device is optimized using the optimized network security policy table, which can effectively sort out and optimize the network security policy of the target network device. Since no human intervention is required throughout the process, management accuracy is ensured while management efficiency is effectively improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments of the present invention. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0017] Figure 1 This is a flow chart of a network device optimization method provided by an embodiment of the present invention; Figure 2 1 is a flow chart of a second network device optimization method provided by an embodiment of the present invention; Figure 3 1 is a flow chart of a third network device optimization method provided by an embodiment of the present invention; Figure 4 This is a schematic diagram of the structure of a network equipment optimization device provided by an embodiment of the present invention; Figure 5 It is a schematic diagram of a computer device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0018] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0019] In one embodiment, if Figure 1 As shown, a network device optimization method is provided, comprising the following steps: 101. Obtain the network security policy table of the target network device.

[0020] In embodiments of the present invention, the aforementioned network device optimization method can be applied to a network device optimization platform. The network device optimization platform can be constructed from a server or server cluster. The server or server cluster can be any electronic device capable of data processing, data analysis, data transmission, or data storage. The network device optimization platform can communicate with any network device through the aforementioned data transmission capabilities, thereby implementing the aforementioned network device optimization method to optimize the network device.

[0021] The target network device can be any network device that can communicate with the network device optimization platform. Specifically, it can refer to a device with network data flow control, protection, detection, and auditing capabilities, used to implement secure management and policy enforcement of network communication behavior. Typical network devices include, but are not limited to, firewalls, intrusion detection and prevention systems (IDS / IPS), unified threat management devices (UTM), next-generation firewalls (NGFW), security gateways, security proxy devices, virtual firewalls, and smart switches or security routers with access control capabilities. By configuring security policies, network devices can accurately identify and control different sources, targets, and communication behaviors, preventing unauthorized access, data leakage, and network attacks, and ensuring the secure and stable operation of the network environment.

[0022] The above-mentioned network security policy table includes at least one network security policy. Each network security policy includes a policy action, a policy virtual wall, and communication five-tuple information. In addition, it can also include a policy name and security domain information. The order of the above-mentioned policy names can be set according to the number of hits of the above-mentioned network security policy. The more hits, the higher the order, and vice versa. The above-mentioned security domain information can include the source security domain and the destination security domain. The above-mentioned policy action can refer to the processing behavior performed by the network security policy after matching specific communication conditions (such as communication five-tuple information). Common policy actions include allow, deny, record, redirect, etc., which are used to control the processing method of data packets in network devices. The policy virtual wall can refer to a policy scope or policy container used to logically classify and isolate network security policies. It usually represents different security domains, security zone pairs or policy configuration sets in network devices, which facilitates the establishment of structured management relationships between different policy instances and realizes refined control and matching analysis of policy rules.

[0023] The communication quintuple information includes a source address, a destination address, and protocol port information. The protocol port information may include a communication protocol and port information. The port information may include a source port and a destination port.

[0024] The above-mentioned target network device can be any network device that requires network security policy optimization, and the brand of the above-mentioned target network device can be any brand. Specifically, the above-mentioned target network device can be logged in through a preset protocol to obtain the configuration information of the above-mentioned target network device, and then multiple network security policies can be parsed from the configuration information, and the above-mentioned network security policy table can be constructed based on multiple network security policies.

[0025] 102. Based on the policy action, the policy virtual wall, and the communication quintuple information, determine a network security policy group having a policy relationship in the network security policy table.

[0026] In embodiments of the present invention, the policy relationships described above can be inclusion relationships or merging relationships. The merging relationship can be simply understood as the network security policies intersecting but not identical. The inclusion relationship can be understood as one policy containing all the information of the other network security policies. A network security policy group with a policy relationship includes at least two network security policies with a policy relationship.

[0027] Specifically, the policy inclusion relationship can be defined as: under the premise that the "policy virtual wall" and "policy action" values ​​are exactly the same, if the source address, destination address, and service range of policy A completely cover the source address, destination address, and service range of another policy B, then policy A includes policy B.

[0028] Accordingly, the policy merge relationship can be defined as follows: under the premise that the "Policy Virtual Wall" and "Policy Action" values ​​are exactly the same, if two of the source address, destination address, and service scope of policy A completely cover two of the source address, destination address, and service scope of another policy B, then policies A and B are in a merge relationship.

[0029] It should be noted that the scope of the above service can be understood as the above protocol port information. The same service scope means that the protocol port information between the two policies is the same.

[0030] 103. Optimize the network security policy table based on the policy relationship of the network security policy group to obtain an optimized network security policy table.

[0031] In an embodiment of the present invention, the above-mentioned policy relationship is a merging relationship or an inclusion relationship. When the policy relationship of the network security policy group is an inclusion relationship, the policies with a larger scope in the network security policy group are retained, and the policies with a smaller scope are marked for deletion; for the policies that have been marked for deletion, all subsequent comparisons will no longer be performed.

[0032] If the network security policy group policy relationship is a merge relationship, this means that two of the source address, destination address, and service scope are identical. Therefore, the remaining different one is merged. Simultaneously, the "Source Security Domain" and "Destination Security Domain" information of the network security policies in the network security policy group are merged and deduplicated to obtain the merged policy. Finally, the positions of the two network security policies in the network security policy group in the policy table are compared. The policy with the higher priority is modified to the merged policy, and the other policy is marked for deletion. Accordingly, the two policies that cannot be merged are retained as is.

[0033] By traversing the policy relationships of the network security policy groups in the network security policy table and performing corresponding optimization processing such as tag deletion and modification through the policy relationships, the optimized network security policy table can be obtained after all network security policy groups with policy relationships have completed the optimization processing.

[0034] In another embodiment, for each network security policy, the source address and the destination address may be merged separately within the policy; that is, in an address set, if multiple address elements belong to the same network segment and are continuous, the addresses are merged.

[0035] 104. Optimize the target network device based on the optimized network security policy table to obtain the optimized target network device.

[0036] In an embodiment of the present invention, after obtaining the optimized network security policy table, the target network device can be logged in. Specifically, the configuration information in the target network device can be modified first based on the modification and tag deletion processing corresponding to the network security policy groups with a merge policy relationship in the optimized network security policy table. Then, the configuration information in the target network device can be modified secondly based on the tag deletion processing corresponding to the network security policy groups with an inclusion policy relationship. After all policy relationships are completed, the optimized target network device can be obtained.

[0037] In an embodiment of the present invention, a network security policy table of a target network device is obtained, wherein the network security policy table includes at least one network security policy, and each network security policy includes a policy action, a policy virtual wall, and communication five-tuple information; based on the policy action, the policy virtual wall, and the communication five-tuple information, a network security policy group with a policy relationship in the network security policy table is determined; based on the policy relationship of the network security policy group, the network security policy table is optimized to obtain an optimized network security policy table; based on the optimized network security policy table, the target network device is optimized to obtain an optimized target network device. Through the policy action, the policy virtual wall, and the communication five-tuple information, the network security policy group with a policy relationship in the network security policy table can be accurately determined, and then the network security policy table can be optimized according to the policy relationship to obtain an optimized network security policy table, and then the target network device is optimized through the optimized network security policy table, which can effectively sort out and optimize the network security policy of the target network device, and since no human intervention is required throughout the process, while ensuring management accuracy, management efficiency is effectively improved.

[0038] It can be understood that in the specific implementation of this application, it involves network security policy tables, policy names, policy actions, policy virtual walls, communication five-tuple information, security domain information, configuration information, security policy information, hit count information and other related data. When the embodiments in this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of relevant data and related processing such as protocol use, login, optimization, etc. of network equipment need to comply with relevant laws, regulations and standards of relevant countries and regions.

[0039] Optionally, before the step of obtaining the network security policy table of the target network device, you can also log in to the target network device through a preset protocol to obtain the configuration information of the target network device; extract at least one set of security policy information from the configuration information; uniformly format each set of security policy information to obtain the network security policy corresponding to each set of security policy information; and construct the network security policy table of the target network device based on the network security policy.

[0040] In an embodiment of the present invention, the preset protocol may be the SSH protocol. Specifically, the target network device may be logged in via the SSH protocol to obtain complete configuration information, typically saved in a txt file format. Security policy information may be extracted from the configuration information, specifically including address groups, address objects, port groups, port object information, security policies, ACL information, and the like.

[0041] Furthermore, the address groups, address objects, port groups, and port objects contained in security policies and ACLs can be parsed into IP addresses or ports, and the key data contained in the policies can be formatted so that the different data of multiple brands can be formed into a unified data format.

[0042] For example, a certain brand of firewall is partially configured as follows: Virtual Wall: switch vsys GDYDXWJ Address object configuration: ip address-set zxfw_dmz_184 type object address 0 range 172.17.20.65 172.17.20.67 address 1 172.17.20.36 0 Port object configuration: ip service-set tcp_d_eq_20011 type object service 0 protocol tcp destination-port 20011 Security policy configuration: rule name 1749_563 description dmz_to_untrust dmz_untrust_outbound source-zone dmz destination-zone untrust source-address address-set zxfw_dmz_184 destination-address 117.159.206.246 mask 255.255.255.255 service tcp_d_eq_20011 action permit After parsing the above information, we get a set of security policy information: rule name 1749_563 description dmz_to_untrust dmz_untrust_outbound source-zone dmz destination-zone untrust source-address range 172.17.20.65 172.17.20.67 source-address 172.17.20.36 mask 255.255.255.255 destination-address 117.159.206.246 mask 255.255.255.255 service protocol tcp destination-port 20011 action permit By formatting each set of security policy information in a unified format, the network security policy corresponding to each set of security policy information can be obtained. Specifically, the key data can be formatted to form a unified data format for different brands of network devices.

[0043] The unified data format can be exemplified by the unified format network security policy provided in Table 1 below: Table 1

[0044] Among them, "1749_563" represents the name of the network security policy, "dmz" represents the source security zone of the network security policy, "untrust" represents the destination security zone of the network security policy, "172.17.20.65-64 172.17.20.36" represents the source address of the network security policy, "117.159.206.246" represents the destination address of the network security policy, "tcp:20011" represents the service scope of the network security policy, that is, the protocol port information mentioned above, "permit" represents the policy action of the network security policy, and "GDYDXWJ" represents the policy virtual wall of the network security policy. Specifically, by combining multiple network security policies, the network security policy table can be constructed.

[0045] It is understandable that the unified data format enables the network device optimization method provided by the present invention to be applicable to network devices of different types and brands.

[0046] Optionally, in the step of constructing a network security policy table for the target network device based on the network security policy, the hit count information of each network security policy can also be obtained; based on the hit count information, the order of adding each network security policy is determined; and the network security policies are added to the preset empty table in sequence according to the order of addition to obtain the network security policy table.

[0047] In embodiments of the present invention, the aforementioned hit count information can be understood as the statistical results of network device matches against each network security policy during operation, reflecting the number of times the policy was triggered or hit in actual communication traffic. This hit count information can, to a certain extent, characterize the activity or frequency of use of the policy, thereby providing data support for subsequent policy sorting and optimization. By acquiring and analyzing this hit count information, the order in which network security policies are added to the policy table can be determined, prioritizing frequently hit policies, improving policy matching efficiency, and preventing invalid policies from impacting system performance.

[0048] Optionally, in the step of determining a network security policy group with a policy relationship in the network security policy table based on policy actions, policy virtual walls, and communication quintuple information, at least two network security policies with the same policy actions and policy virtual walls can be determined in the network security policy table as the network security policy group to be processed; and based on the communication quintuple information, network security policies with a policy relationship can be determined in the network security policy group to be processed as the network security policy group.

[0049] In an embodiment of the present invention, a policy relationship is used to describe the logical association between two network security policies in the communication control scope, which may specifically include an inclusion relationship or a merge relationship. When the policy actions of at least two network security policies are the same as the policy virtual wall, at least two network security policies are determined as a network security policy group to be processed, and the communication five-tuple information (including source address, destination address, source port, destination port and communication protocol) corresponding to the network security policy group to be processed is compared and analyzed. If the communication five-tuple information of one policy completely contains the communication five-tuple information of the other policy, then the two are in an inclusion relationship; if there is partial overlap between the two policies and they can be merged by range to form a broader but non-conflicting control boundary, then the two are in a merge relationship. The identification of this policy relationship provides a basis for subsequent optimization operations such as policy deduplication and rule merging, which helps to improve the overall efficiency and manageability of the network security policy table.

[0050] It should be noted that when the communication quintuple information of a network security policy completely includes the communication quintuple information of multiple other policies, then an inclusion relationship is formed between the policy and the multiple policies. At this time, the above-mentioned policy set can be defined as a network security policy group with an inclusion relationship, and the number of its members depends on the number of policy entries that satisfy the inclusion relationship. When there is only one policy that completely includes another policy, the network security policy group with the inclusion relationship contains two policies. Similarly, for a network security policy group with a merge relationship, if there are two or more policies that meet the merge conditions, they can be grouped together, and the number of members of the policy group also depends on the number of policies that meet the merge conditions. Therefore, the number of policies in the inclusion relationship group and the merge relationship group are both determined by the number of policy entries that actually meet the corresponding policy relationship.

[0051] Optionally, in the step of determining the network security policies with policy relationships in the network security policy group to be processed based on the communication quintuple information, as the network security policy group, if the source address, destination address and protocol port information of the first network security policy in the network security policy group to be processed all contain the source address, destination address and protocol port information of the second network security policy in the network security policy group to be processed, then the policy relationship between the first network security policy and the second network security policy is an inclusion relationship; if any two of the source address, destination address and protocol port information of the first network security policy in the network security policy group to be processed are the same as any two of the source address, destination address and protocol port information of the second network security policy in the network security policy group to be processed, and the policy relationship between the first network security policy and the second network security policy is not an inclusion relationship, then the policy relationship between the first network security policy and the second network security policy is a merge relationship.

[0052] In the embodiment of the present invention, the communication quintuple information includes at least a source address, a destination address, and protocol port information (ie, the scope of the following service, or understood as service).

[0053] The inclusion relationship among source address, destination address, and service is defined as follows: for address or service sets a and b, if any element in set a can be included in any element in set b, then address set a is included in b (or b includes a).

[0054] The inclusion relationship of address elements is defined as: if the addresses represented by address element c can all be included in the address range represented by address element d, then c is included by d (or d contains c).

[0055] The inclusion relationship of service elements is defined as follows: if the combination of the protocol, source port, and destination port of service element e is also included in the combination of the protocol, source port, and destination port of service element f, then e is included by f (or f includes e). In other words, the inclusion relationship of services can be understood as the inclusion relationship of protocol and port information.

[0056] The format of the service element (that is, the format of the protocol port information) can be specifically the format of protocol: source port~destination port, that is, e can be written as: tcp:1-65535~22; f can be written as: tcp:1-65535~22,2222; and usually, if the port is 1-65535, it can be omitted, that is, e can be written as: tcp:22; f can be written as: tcp:22,2222; if the source and destination ports are both 1-65535, only the protocol can be written, such as: tcp:1-65535~1-65535, which can be written as: tcp.

[0057] The inclusion relationship of the protocol is defined as: the IP protocol includes the ICMP protocol, all ports of the TCP protocol, and all ports of the UDP protocol, just like any.

[0058] For all the inclusion relationships defined above, when comparing two network security policies X and Y, if X=Y, then we can say that X includes Y, and we can also say that Y includes X.

[0059] Correspondingly, the merge relationship of source address, destination address, and service is defined as: for address or service sets a and b, if any two elements of the source address, destination address, and service of set a are the same as any two elements of the source address, destination address, and service of set b, then a and b are in a merge relationship.

[0060] Furthermore, the above inclusion relationship can be further illustrated by the following inclusion relationship example: Assume that the network security policy group to be processed contains the three network security policies provided in Table 2 below: Table 2

[0061] The policy Cloud_840812000 contains two other policies.

[0062] The inclusion relationship among source address, destination address, and service (i.e., protocol port information) is defined as follows: for address or service sets a and b, if any element in set a can be included in any element in set b, then address set a is included in b (or b includes a).

[0063] like: Address set a: 10.250.10.122 / 32; 10.250.10.123 / 32; Address set b: 10.250.10.0 / 24; In this case, a is contained by b; The inclusion relationship of address elements is defined as follows: if the addresses represented by address element c are all included in the address range represented by address element d, then c is included by d (or d contains c); like: Address element c: 10.250.10.122 / 32; Address element d: 10.250.10.0 / 24; In this example, the address range represented by address element d is 256 addresses from 10.250.10.0 to 10.250.10.255, including 10.250.10.122 / 32. Therefore, c is included in d. The inclusion relationship of a service element is defined as follows: if the combination of the protocol, source port, and destination port of a service element e can be included in the combination of the protocol, source port, and destination port of a service element f, then e is included by f (or f includes e). like: Service element e: protocol tcp, source port 1-655535, destination port 22; Service element f: protocol tcp, source port 1-655535, destination port 22, 2222; In this example, service element e is contained by service element f; It should be noted that the service element can be written in the format of: protocol: source port~destination port, that is, e can be written as: tcp:1-65535~22; f can be written as: tcp:1-65535~22, 2222; and usually, if the port is 1-65535, it can be omitted, that is, e can be written as: tcp:22; f can be written as: tcp:22, 2222; if the source and destination ports are both 1-65535, only the protocol can be written, such as: tcp:1-65535~1-65535, which can be written as: tcp.

[0064] The inclusion relationship of the protocol is defined as: the IP protocol includes the ICMP protocol, all TCP protocol ports, and all UDP protocol ports, just like any; like: Service element g: ip (or any); Service element h: tcp:100-10000;udp; In this example, service element h is contained by service element g; For all the inclusion relations defined above, when comparing two elements X and Y, if X=Y, then we can say that X contains Y, and we can also say that Y contains X; like: X:10.187.7.128 / 26; Y:10.187.7.128 / 26; In this example, X contains Y, or we can say that Y contains X.

[0065] Optionally, in the step of optimizing the network security policy table based on the policy relationship of the network security policy group to obtain the optimized network security policy table, it is also possible to determine in the network security policy table a network security policy group whose policy relationship is an inclusion relationship, determine in the network security policy group a network security policy with a smaller policy coverage, and add a deletion mark to the network security policy with a smaller policy coverage in the network security policy table to obtain a network security policy table to be merged; in the network security policy table to be merged, determine a network security policy group whose policy relationship is a merge relationship, and merge the network security policies in the network security policy group in the network security policy table to be merged to obtain an optimized network security policy table, and the merging process includes merging and deduplicating policy actions, policy virtual walls, communication five-tuple information, and security domain information, and retaining the top-ranked policy names.

[0066] In an embodiment of the present invention, the policy relationship is an inclusion relationship or a merge relationship, and the network security policy also includes security domain information and a policy name. In the process of optimizing the network security policy table based on the policy relationship of the network security policy group, it is preferred to perform different processing methods according to the type of policy relationship. First, for a network security policy group whose policy relationship is an inclusion relationship, it can be considered that the communication control range of one of the policies (i.e., the address range, port range, and protocol type represented by its communication quintuple information) is completely covered by another policy. At this time, in order to reduce redundancy and avoid repeated matching, network security policies with smaller policy coverage can be determined, and deletion marks can be added to them in the policy table. Such policies will be filtered or cleared by the system during the subsequent release or deployment of the policy table, thereby avoiding the waste of execution performance due to overlapping rules.

[0067] Then, in the obtained network security policy table to be merged, the network security policy group whose policy relationship is a merge relationship is further identified. A merge relationship usually indicates that two policies have partial intersections or can be merged in fields such as source address, destination address or port range, and their policy actions are the same as the policy virtual wall, and have the feasibility of being merged into a broader policy. During the merging process, the policy actions, policy virtual walls, communication five-tuple information and the security domain information can be merged and deduplicated, and the policy names with higher rankings are retained, so that the two policies are merged into a new policy to replace the original policy pair. Specifically, the network security policy that ranks higher in the network security policy table in the network security policy group can be replaced, and the network security policy that ranks lower can be deleted.

[0068] Through the refined processing corresponding to the above-mentioned inclusion relationship and merging relationship, it is possible to effectively eliminate redundant policy entries, compress the policy table volume, reduce policy conflicts and matching paths, improve the efficiency and maintainability of network devices when executing policies, and ensure the accuracy of policy optimization and business continuity.

[0069] It's important to note that policy coverage refers to the range of communication traffic that can be identified and controlled by a network security policy, determined by the communication quintuple (source address, destination address, source port, destination port, and communication protocol). A larger coverage range applies to a wider variety of network data flows; a smaller coverage range means a more targeted control target.

[0070] Furthermore, the above merging process can be further illustrated by the following example: Assume that the network security policy group to be processed contains the two network security policies provided in Table 3 below: Table 3

[0071] The two policies in this example can be merged (i.e., the policy relationship is a merge relationship). After merging, a new policy is obtained as shown in Table 4: Table 4

[0072] After the new policy is obtained, it can replace the network security policy that ranks higher in the network security policy table in the network security policy group.

[0073] In another embodiment, for each network security policy, the source address and destination address can be merged separately within the policy; that is, within an address set, if multiple address elements belong to the same network segment and are continuous, the addresses are merged. This can be understood as a policy-wide merge within a single policy. The policy-wide merge can be further illustrated by the following example: Assume that the network security policy table contains the network security policies provided in Table 5 below: Table 5

[0074] In the source address set of the above network security policy, if multiple address elements belong to the same network segment and are continuous, the addresses are merged to obtain the optimized network security policy table provided in Table 6 below: Table 6

[0075] It can be seen that the address set of source addresses in the optimized network security policy table has been merged.

[0076] Optionally, the network device optimization method can also obtain the hit count information of each network security policy; in the optimized network security policy table, add a zero hit mark for the network security policy with a hit count information of zero; if within a preset time, the hit count information corresponding to the network security policy with a zero hit mark is not zero, then in the optimized network security policy table, remove the zero hit mark; if after the preset time, the hit count information corresponding to the network security policy with a zero hit mark is still zero, then add a deletion mark to the network security policy with a zero hit mark in the optimized network security policy table.

[0077] In an embodiment of the present invention, the network device optimization method can also obtain hit count information for each network security policy and, based on this information, evaluate and dynamically manage policy usage. This hit count information can be obtained by logging into the target network device via a web interface or using the SSH protocol. The device typically records the number of times each configured network security policy is triggered (i.e., matched) within a certain time window. This hit count information can be extracted through commands or interface calls and integrated into the data structure of each network security policy, forming a statistical field that can be used for subsequent judgment.

[0078] Furthermore, in the optimized network security policy table, if the hit count of a policy is zero, it will be marked as "zero hit" and enter the observation period (for example, the preset time is one week). During the observation period, the system continuously monitors the changes in the hit count of the policy: If the hit count becomes non-zero during the observation period, it means that the strategy has actually been used, and its "zero hit" mark can be automatically removed; If the hit count is still zero after the observation period, it means that the policy has not been called in the current business scenario. In this case, you can add a "deletion mark" for it to streamline the policy table.

[0079] This processing mechanism enables the network security policy table to self-clean, effectively reducing the number of redundant policies that exist but are not actually matched. This optimizes the policy matching path and improves the resource utilization and responsiveness of network devices during operation. It also avoids the potential service interruption risks caused by blindly deleting missed policies, ensuring that the optimization process is rollable and provides an observation period buffer.

[0080] In one embodiment, if Figure 2 As shown, a second network device optimization method is provided, comprising the following steps: The first step is to extract the network security policy from the configuration information of the network device through the policy extraction and parsing module, and construct a network security policy table; The second step is to sort out and optimize the duplicate policies of the network security policy groups that have inclusion relationships in the network security policy table; The third step is to perform policy merging optimization on the network security policy groups that have a merge relationship in the network security policy table; The fourth step is to extract the hit count information of each network security policy through the hit count extraction module, and sort out and optimize the hit count strategy of the network security policy table based on the hit count information; After completing steps 2 to 4 above, you can get the optimized network security policy table; The fifth step is to optimize the network devices by using the optimized network security policy table to obtain optimized network devices.

[0081] In one embodiment, if Figure 3 As shown, a third network device optimization method is provided, comprising the following steps: The first step is to obtain the device configuration, that is, the configuration information of the network device; The second step involves extracting and parsing network security policies for multi-brand devices. This involves extracting at least one set of security policy information from the configuration information. Each set of security policy information is formatted uniformly to obtain the network security policy corresponding to each set of security policy information. Based on the network security policy, a network security policy table for the target network device is constructed. This table, which is applicable to network devices of different brands and types, is formatted uniformly. The third step is to sort out and optimize the network security policy table based on the policy relationships of the network security policy groups to obtain an optimized network security policy table. The fourth step is to log in to the network device and optimize the network device through the optimized network security policy table to obtain the optimized network device.

[0082] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0083] In one embodiment, a network device optimization device is provided, which corresponds to the network device optimization method in the above embodiment. Figure 4 As shown, the network equipment optimization device includes a first acquisition module 401, a first determination module 402, a first optimization module 403, and a second optimization module 404. The functional modules are described in detail as follows: A first acquisition module 401 is configured to acquire a network security policy table of a target network device, wherein the network security policy table includes at least one network security policy, each of which includes a policy action, a policy virtual wall, and communication quintuple information; A first determining module 402 is configured to determine, based on the policy action, the policy virtual wall, and the communication quintuple information, a network security policy group having a policy relationship in the network security policy table; A first optimization module 403 is configured to optimize the network security policy table based on the policy relationship of the network security policy group to obtain an optimized network security policy table; The second optimization module 404 is configured to optimize the target network device based on the optimized network security policy table to obtain an optimized target network device.

[0084] The specific definition of the network device optimization device can be found in the definition of the network device optimization method above and will not be repeated here. Each module in the above-mentioned network device optimization device can be implemented in whole or in part through software, hardware, or a combination thereof. Each of the above-mentioned modules can be embedded in or independent of the processor in the computer device in hardware form, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each of the above modules.

[0085] In one embodiment, a computer device is provided. The computer device may be a terminal device, and its internal structure diagram may be as follows: Figure 5 As shown. The computer device includes a processor, a memory, and a network interface connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a readable storage medium. The readable storage medium stores computer-readable instructions. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer-readable instructions are executed by the processor, a network device optimization method is implemented. The readable storage medium provided in this embodiment includes a non-volatile readable storage medium and a volatile readable storage medium.

[0086] In an embodiment of the present application, a computer device is provided, including a memory, a processor, and computer-readable instructions stored in the memory and executable on the processor. When the processor executes the computer-readable instructions, the steps of the above-mentioned network device optimization method are implemented.

[0087] In an embodiment of the application, a readable storage medium is provided, which stores computer-readable instructions. When the computer-readable instructions are executed by a processor, the steps of the above-mentioned network device optimization method are implemented.

[0088] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing related hardware through computer-readable instructions. The computer-readable instructions can be stored in a non-volatile readable storage medium or a volatile readable storage medium. When the computer-readable instructions are executed, they can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0089] Those skilled in the art will clearly understand that for the sake of convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0090] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the scope of protection of the present application.

Claims

1. A network device optimization method, characterized in that: The method comprises: Obtaining a network security policy table of a target network device, wherein the network security policy table includes at least one network security policy, and each network security policy includes a policy action, a policy virtual wall, and communication quintuple information; Determining, based on the policy action, the policy virtual wall, and the communication quintuple information, a network security policy group having a policy relationship in the network security policy table; Optimizing the network security policy table based on the policy relationship of the network security policy group to obtain an optimized network security policy table; The target network device is optimized based on the optimized network security policy table to obtain the optimized target network device.

2. The network device optimization method according to claim 1, wherein: Before obtaining the network security policy table of the target network device, the method further includes: Logging into the target network device through a preset protocol to obtain configuration information of the target network device; extracting at least one set of security policy information from the configuration information; Performing unified formatting on each set of security policy information to obtain a network security policy corresponding to each set of security policy information; A network security policy table of the target network device is obtained based on the network security policy.

3. The network device optimization method according to claim 2, wherein: The constructing a network security policy table of the target network device based on the network security policy includes: Obtaining hit count information for each of the network security policies; Based on the hit count information, determining the order in which each of the network security policies is added; The network security policies are added to a preset empty table in sequence according to the adding order to obtain the network security policy table.

4. The network device optimization method according to claim 1, wherein: The determining, based on the policy action, the policy virtual wall, and the communication quintuple information, of a network security policy group having a policy relationship in the network security policy table includes: In the network security policy table, determining at least two network security policies having the same policy actions and policy virtual walls as a network security policy group to be processed; Based on the communication quintuple information, network security policies with policy relationships are determined in the network security policy group to be processed as the network security policy group.

5. The network device optimization method according to claim 4, wherein: The communication quintuple information includes a source address, a destination address, and protocol port information. Based on the communication quintuple information, determining a network security policy having a policy relationship in the network security policy group to be processed as the network security policy group includes: If the source address, destination address, and protocol port information of the first network security policy in the network security policy group to be processed all contain the source address, destination address, and protocol port information of the second network security policy in the network security policy group to be processed, then the policy relationship between the first network security policy and the second network security policy is an inclusion relationship; If any two of the source address, destination address, and protocol port information of the first network security policy in the network security policy group to be processed are the same as any two of the source address, destination address, and protocol port information of the second network security policy in the network security policy group to be processed, and the policy relationship between the first network security policy and the second network security policy is not an inclusion relationship, then the policy relationship between the first network security policy and the second network security policy is a merge relationship.

6. The network device optimization method according to claim 1, wherein: The policy relationship is an inclusion relationship or a merger relationship, the network security policy also includes security domain information and a policy name, and the network security policy table is optimized based on the policy relationship of the network security policy group to obtain an optimized network security policy table, including: In the network security policy table, determining a network security policy group whose policy relationship is an inclusion relationship, determining a network security policy with a smaller policy coverage in the network security policy group, and adding a deletion mark to the network security policy with the smaller policy coverage in the network security policy table to obtain a network security policy table to be merged; In the network security policy table to be merged, a network security policy group whose policy relationship is a merge relationship is determined, and the network security policies in the network security policy group are merged in the network security policy table to be merged to obtain the optimized network security policy table. The merging process includes merging and deduplicating the policy actions, policy virtual walls, communication quintuple information and security domain information, and retaining the policy names with higher rankings.

7. The network device optimization method according to claim 1, wherein: The method further comprises: Obtaining hit count information for each of the network security policies; In the optimized network security policy table, adding a zero hit mark for the network security policy whose hit count information is zero; If within a preset time, the hit count information corresponding to the network security policy with a zero hit mark is not zero, then the zero hit mark is removed from the optimized network security policy table; If, after the preset time expires, the hit count information corresponding to the network security policy mark with the zero hit mark is still zero, a deletion mark is added to the network security policy with the zero hit mark in the optimized network security policy table.

8. A network equipment optimization device, characterized in that: The device comprises: A first acquisition module is configured to acquire a network security policy table of a target network device, wherein the network security policy table includes at least one network security policy, and each network security policy includes a policy action, a policy virtual wall, and communication quintuple information; A first determining module is configured to determine, based on the policy action, the policy virtual wall, and the communication quintuple information, a network security policy group having a policy relationship in the network security policy table; A first optimization module, configured to optimize the network security policy table based on the policy relationship of the network security policy group to obtain an optimized network security policy table; The second optimization module is configured to optimize the target network device based on the optimized network security policy table to obtain the optimized target network device.

9. A computer device comprising a memory, a processor, and computer-readable instructions stored in the memory and executed on the processor, wherein: When the processor executes the computer-readable instructions, the network device optimization method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium having computer-readable instructions stored thereon, characterized in that: When the computer-readable instructions are executed by a processor, the network device optimization method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Access gateway distribution method and device

    CN105376309A

  • Network security policy management system

    CN111600912A

  • Strategy identification method and device

    CN112788059A

  • Security policy optimization method and device, electronic equipment and storage medium

    CN115065538A

  • Security protection control method and apparatus, and device

    WO2024140277A1