Firewall policy generation method and device, equipment and medium
By monitoring resource update events in a containerized environment in real time, building a dynamic resource relationship map and conducting risk assessment, the problem that static firewall policies cannot adapt to network changes is solved, and the dynamic generation of firewall policies is realized, which improves the timeliness and accuracy of network security.
Patent Information
- Application Number
- CN202510527497.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-09-02
AI Technical Summary
In the prior art, static firewall policies are difficult to adapt to the rapid changes in the network environment, cannot identify and defend against new network threats in a timely manner, and have high maintenance costs.
By monitoring resource update events in the containerized environment in real time, building a dynamically updated resource relationship map, performing path risk assessment, calculating risk scores, and inputting firewall policies to generate trained models to achieve dynamic generation of firewall policies.
It realizes the rapid and accurate response of firewall policies to network security threats, improves the timeliness, accuracy and adaptability of network security protection, and reduces maintenance costs.
Smart Images

Figure CN120582809A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network technology, and in particular to a firewall policy generation method, device, equipment and medium. Background Art
[0002] With the rapid development of cloud computing and containerization technologies, they have been widely adopted in the healthcare and financial sectors. In the healthcare sector, containerization has been deeply integrated into the construction of key information systems such as medical image storage and transmission systems, electronic medical record systems, and telemedicine service platforms. Its efficient operation, rapid deployment, and elastic scalability have significantly improved the efficiency of medical services. In the financial sector, containerization is also widely used in key business scenarios such as core transaction systems, payment gateways, and risk control platforms, ensuring agile response and high availability for financial services. However, given the unique sensitivity of medical data, which involves patient privacy and health, and financial data, which concerns user asset security and financial stability, network security requirements are even more stringent. Currently, existing technologies generally rely on static firewall policies to ensure network security. However, these static firewall policies have certain limitations. They are often difficult to adapt to the rapid changes in the network environment and cannot promptly identify and protect against new network threats. Moreover, with the continuous expansion and increasing complexity of medical and financial systems, the maintenance cost of static firewall rules is also increasing. Therefore, how to automatically generate firewall policies dynamically has become an urgent problem. Summary of the Invention
[0003] The present invention provides a firewall policy generation method, device, computer equipment and medium to solve the problem of how to automatically realize the dynamic generation of firewall policies.
[0004] In a first aspect, a method for generating a firewall policy is provided, comprising: Real-time monitoring of resource update events in the containerized environment, obtaining updated resource data corresponding to the resource update events, the updated resource data including updated resource entities, metadata of each updated resource entity, and associations between updated resource entities; Obtaining a historical resource relationship graph constructed based on historical resource entities in the containerized environment, metadata of each historical resource entity, and associations between historical resource entities, and updating the historical resource relationship graph according to the updated resource data to obtain an updated resource relationship graph; Performing a risk assessment on all paths in the updated resource relationship graph to obtain an assessment result, determining a risk path based on the assessment result, and calculating a risk score representing the risk level of each node in any risk path; The updated resource relationship map and all risk scores are input into a model that has been trained to generate a firewall policy to obtain a firewall policy, which is used to provide security protection for network traffic in the containerized environment.
[0005] In a second aspect, a firewall policy generation device is provided, comprising: A first acquisition module is configured to monitor resource update events in a containerized environment in real time and acquire updated resource data corresponding to the resource update events, wherein the updated resource data includes updated resource entities, metadata of each updated resource entity, and associations between updated resource entities; An update module is configured to obtain a historical resource relationship map constructed based on historical resource entities in the containerized environment, metadata of each historical resource entity, and associations between historical resource entities, and to update the historical resource relationship map based on the updated resource data to obtain an updated resource relationship map; A first calculation module is configured to perform a risk assessment on all paths in the updated resource relationship graph to obtain an assessment result, determine a risk path based on the assessment result, and calculate, for any risk path, a risk score representing the risk level of each node in the risk path; A generation module is used to input the updated resource relationship map and all risk scores into a model that has been trained for firewall policy generation to obtain a firewall policy, which is used to securely protect network traffic in the containerized environment.
[0006] In a third aspect, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the steps of the firewall policy generation method of the first aspect are implemented.
[0007] In a fourth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the firewall policy generation method of the first aspect are implemented.
[0008] The solution implemented by the above-mentioned firewall policy generation method, device, equipment and medium monitors resource update events in a containerized environment in real time, updates the historical resource relationship map according to the updated resource entities corresponding to the resource update events, the metadata of each updated resource entity, and the association relationship between the updated resource entities, obtains an updated resource relationship map, performs risk assessment on all paths in the updated resource relationship map, obtains assessment results, determines the risk path based on the assessment results, and calculates a risk score that represents the risk level of each node in the risk path for any risk path. The updated resource relationship map and all risk scores are input into a model that has been trained for firewall policy generation to obtain a firewall policy.
[0009] Among them, by constructing a dynamically updated resource relationship map based on the updated resource data monitored in real time, and performing a quantitative assessment of path risks based on the map, the map and risk scores are input into a model that has been trained for firewall policy generation to obtain a firewall policy, thereby realizing the dynamic generation of firewall policies and automatically adjusting the firewall policies as the network environment changes, thereby being able to respond to network security threats more quickly and accurately, and improving the timeliness, accuracy and adaptability of network security protection. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments of the present invention. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0011] Figure 1 A schematic diagram of an application environment of a firewall policy generation method provided in Example 1 of the present invention; Figure 2 A flowchart of a method for generating a firewall policy according to a second embodiment of the present invention is provided; Figure 3 A flowchart of a method for generating a firewall policy according to a third embodiment of the present invention is provided; Figure 4 A flowchart of a method for generating a firewall policy according to a fourth embodiment of the present invention is provided; Figure 5 A flowchart of a method for generating a firewall policy according to a fifth embodiment of the present invention is provided; Figure 6 A schematic diagram of the structure of a firewall policy generation device provided in Example 6 of the present invention; Figure 7 A structural diagram of a computer device provided in Example 7 of the present invention. DETAILED DESCRIPTION
[0012] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0013] The firewall policy generation method provided in the first embodiment of the present invention can be applied in the following situations: Figure 1 In an application environment, a server communicates with a client, providing firewall policy generation services. The client triggers firewall policy generation tasks on the server. Clients include, but are not limited to, PDAs, desktop computers, laptops, ultra-mobile personal computers (UMPCs), netbooks, cloud computing devices, and personal digital assistants (PDAs). The server's corresponding computer device can be implemented as a standalone server or a server cluster consisting of multiple servers.
[0014] like Figure 2 FIG. 1 is a flow chart of a method for generating a firewall policy according to a second embodiment of the present invention, comprising the following steps: Step S201: monitor resource update events in the containerized environment in real time, and obtain updated resource data corresponding to the resource update events.
[0015] In this embodiment, a container may refer to an independent, portable operating environment formed by packaging an application and its dependencies, a containerized environment may refer to a container orchestration and management platform, for example, the containerized environment may be a container orchestration platform based on Kubernetes, a resource update event may refer to a change operation on a resource entity, metadata of a resource entity, and an association relationship between resource entities in a containerized environment, wherein a resource entity may refer to a basic object that can be independently managed and operated in a containerized environment, updated resource data may refer to incrementally changed resource data corresponding to a resource update event, including updated resource entities, metadata of each updated resource entity, and an association relationship between updated resource entities, wherein an updated resource entity may refer to incrementally changed resource entities corresponding to a resource update event.
[0016] For example, in the Kubernetes container orchestration platform, resource entities can include Pod, Service, Namespace, and Node. The metadata of resource entities can include communication protocols, Quality of Service (QoS) levels, encryption status, etc. The associations between resource entities can include HyperText Transfer Protocol (HTTP) / Google Remote Procedure Call (gRPC) call relationships, Persistent Volume (PV) mounting relationships, Role-Based Access Control (RBAC) permission mapping relationships, etc.; resource update events in Kubernetes can include the creation and deletion of Pod, Service, Namespace, and Node, update operations on HTTP / gRPC call relationships, PersistentVolume mounting relationships, RBAC permission mapping relationships, and update operations on the metadata of Pod, Service, Namespace, and Node.
[0017] Specifically, based on the event monitoring mechanism in the containerized environment, resource update events can be monitored in real time, and the updated resource entities corresponding to the incremental changes of the resource update events, the metadata of each updated resource entity, and the association relationship between the updated resources can be obtained.
[0018] Step S202: Obtain a historical resource relationship map constructed based on historical resource entities in a containerized environment, metadata of each historical resource entity, and the relationship between historical resource entities. Update the historical resource relationship map based on updated resource data to obtain an updated resource relationship map.
[0019] In this embodiment, the historical resource entity may refer to the resource entity in the containerized environment before the resource update event is detected, the historical resource relationship graph may refer to the knowledge graph constructed based on the historical resource entity, the metadata of each historical resource entity, and the association relationship between historical resource entities, and the updated resource relationship graph may refer to the knowledge graph after the historical resource relationship graph is updated according to the updated resource data.
[0020] Specifically, before a resource update event is detected, a historical resource relationship graph is constructed for each historical resource entity, using the historical resource entity as a node, the metadata of the historical resource entity as a node attribute, and the relationships between the historical resource entity and other historical resource entities as edges. When a resource update event is detected, the historical resource relationship graph is reconstructed based on the updated resource entity, the metadata of each updated resource entity, and the relationships between the updated resource entities to obtain an updated resource relationship graph.
[0021] Step S203: Perform risk assessment on all paths in the updated resource relationship graph to obtain assessment results. Based on the assessment results, determine the risk path. For any risk path, calculate a risk score that represents the risk level of each node in the risk path.
[0022] In this embodiment, the assessment result may refer to the result of a risk assessment of the paths in the updated resource relationship graph. A risk path may refer to an access path that violates security policies or architectural design expectations. For example, in a Kubernetes environment, a non-risk path may be accessing a high-security database pod from a high-security namespace through a gateway. The corresponding risk path may be direct access to a high-security database pod from a low-security namespace. Because this risk path bypasses necessary security boundaries (such as gateways and intermediate services), it may lead to the exposure of sensitive data or trigger security risks such as lateral penetration. The risk score may refer to a score that characterizes the risk level of each node in the risk path.
[0023] Specifically, a risk assessment is performed on each path in the update resource relationship graph to determine the risk path, and for any risk path, a risk score of each node in the risk path is calculated.
[0024] Step S204: The updated resource relationship graph and all risk scores are input into the model that has been trained for firewall policy generation to obtain the firewall policy.
[0025] In this embodiment, the firewall policy is used to protect the network traffic in the containerized environment. For example, in a Kubernetes environment in the financial sector, a firewall policy might be implemented to restrict access to core transaction services in a payment system through Network Policy to only pods from the production environment Namespace (such as ns-prod) and labeled with role=api-gateway, denying all other access to ensure the isolation and security of payment traffic. In a Kubernetes environment in the healthcare sector, a firewall policy might be implemented to restrict access to the patient database Namespace (such as ns-ehr) through Network Policy to only pods labeled with hipaa-compliant=true, denying all requests from the test environment to ensure compliance with medical data privacy regulations.
[0026] Specifically, the updated resource relationship graph and all risk scores are input into the model that has been trained for firewall policy generation to obtain the firewall policy.
[0027] In this embodiment, a dynamically updated resource relationship graph is constructed based on updated resource data monitored in real time, and a path risk quantitative assessment is performed based on the graph. The graph and risk score are input into a model that has been trained for firewall policy generation to obtain a firewall policy. This realizes the dynamic generation of firewall policies, and enables the firewall policies to be automatically adjusted as the network environment changes, thereby being able to respond to network security threats more quickly and accurately, thereby improving the timeliness, accuracy, and adaptability of network security protection.
[0028] like Figure 3 FIG. 2 is a flow chart of a method for generating a firewall policy according to a third embodiment of the present invention. In step S203, risk assessment is performed on all paths in the updated resource relationship graph to obtain assessment results. Based on the assessment results, determining risk paths may include the following steps: Step S301: Use the preset risk matching rules to perform path matching in the updated resource relationship graph to obtain a matching result.
[0029] Step S302: According to the matching result, a path that successfully matches any preset risk matching rule is determined as a risk path.
[0030] In this embodiment, the preset risk matching rules may refer to pre-set rules for identifying path patterns that violate security policies or architectural design expectations, and the matching results may refer to the results of path matching in the updated resource relationship map using the preset risk matching rules.
[0031] Specifically, a graph query language can be used to describe path patterns that violate security policies or architectural design expectations, form preset risk matching rules, and use each preset risk matching rule to perform path matching in the updated resource relationship graph. Based on the matching results, the path in the updated resource relationship graph that successfully matches any preset risk matching rule is determined to be a risk path.
[0032] In this embodiment, by performing path matching in the updated resource relationship map based on preset risk matching rules to determine the risk path, it is possible to accurately identify path patterns that violate security policies or architectural design expectations, thereby effectively discovering potential security risks and providing a data basis for the dynamic generation of subsequent firewall policies, thereby improving the timeliness, accuracy and adaptability of network security protection.
[0033] like Figure 4 FIG. 2 is a flow chart of a method for generating a firewall policy according to a fourth embodiment of the present invention. In step S203, for any risk path, the risk score representing the risk level of each node in the risk path is calculated, which may include the following steps: Step S401: For any node in the risk path, the traffic entropy of the node and the vulnerability weight value representing the risk level of known vulnerabilities on the node are obtained.
[0034] Step S402: Obtain the risk score of the node according to the traffic entropy and the vulnerability weight value.
[0035] In this embodiment, the vulnerability weight value may refer to a score that represents the risk level of a known vulnerability on a node.
[0036] Specifically, for any node in the risk path, the severity of each known vulnerability on the node can be quantitatively evaluated based on the Common Vulnerability Scoring System (CVSS). According to the severity of all known vulnerabilities on the node, the vulnerability weight value of the node is obtained, and the traffic entropy of the node is obtained. The vulnerability weight value and traffic entropy are multiplied to obtain the risk score of the node.
[0037] Among them, high vulnerability weight values and high traffic entropy can indicate that the node not only has known high-risk vulnerabilities, but is also exposed to a large number of random requests. The overall risk is high and it is necessary to prioritize fixing vulnerabilities or restricting access, thereby obtaining a higher risk score; low vulnerability weight values and low traffic entropy can indicate that the node has a lower risk, thus obtaining a lower risk score.
[0038] For example, for any node in the risk path, if there are two known vulnerabilities on the node, with CVSS scores of 7.5 and 8.2 respectively, the weight values of the two known vulnerabilities can be assigned to 0.75 and 0.82 respectively, so that the vulnerability weight value of the node can be determined to be 0.75+0.82=1.57. If the node has random requests from 100 different IP (Internet Protocol) addresses, it can be determined that the node has high traffic entropy, with a traffic entropy of 3.2. Based on the traffic entropy and vulnerability weight value of the node, the risk score of the node can be determined to be 1.57×3.2=5.024.
[0039] In this embodiment, the vulnerability weight value is obtained by quantitatively evaluating the severity of known vulnerabilities on the node based on the vulnerability scoring system, and the risk score is calculated in combination with the node traffic entropy. The risk of the vulnerability itself and the network traffic environment faced by the node are comprehensively considered, which improves the accuracy of the calculated risk score, helps to accurately identify high-risk nodes, and provides a data basis for the dynamic generation of subsequent firewall policies, thereby improving the timeliness, accuracy and adaptability of network security protection.
[0040] like Figure 5 FIG. 2 is a flow chart of a method for generating a firewall policy according to a fifth embodiment of the present invention. In step S204, the updated resource relationship graph and all risk scores are input into the model that has been trained for firewall policy generation. After obtaining the firewall policy, the method may further include the following steps: Step S501: for any firewall policy, perform conflict detection on each firewall policy except the firewall policy.
[0041] Step S502: If a firewall policy that conflicts with the firewall policy is detected, a historical firewall policy corresponding to the firewall policy is obtained, and the historical firewall policy is used to perform security protection on the network traffic in the containerized environment.
[0042] Specifically, for any firewall policy, a conflict detection is performed between the firewall policy and each firewall policy except the firewall policy. If a firewall policy that conflicts with the firewall policy is detected, for example, in a Kubernetes environment, it is detected that the firewall policy and another firewall policy both allow and deny access to the same Namespace, then it is determined that a conflict occurs in the firewall policy. The conflict-free historical firewall policy corresponding to the firewall policy is then obtained, and the historical firewall policy is used to provide security protection for network traffic in the containerized environment.
[0043] If no firewall policy that conflicts with the firewall policy is detected, the compliance of the firewall policy is verified based on the preset compliance summary. If the verification passes, the firewall policy is used to securely protect the network traffic in the containerized environment. If the verification fails, the historical firewall policy corresponding to the firewall policy is obtained, and the historical firewall policy is used to securely protect the network traffic in the containerized environment.
[0044] In this embodiment, by performing conflict detection on each generated firewall policy, conflicts between policies can be discovered and handled in a timely manner, avoiding security loopholes or network access anomalies caused by policy conflicts. For conflicting policies, their corresponding historical conflict-free policies are used for security protection, thereby ensuring the security of network traffic. For policies where no conflicts are detected, further compliance verification is performed to ensure that the policies meet security specifications. After verification, they are used for security protection. If they fail, the historical policies are also used, which effectively improves the reliability and security of the firewall policies and ensures the stability and security of network traffic in the containerized environment.
[0045] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0046] like Figure 6 As shown, a firewall policy generation device is provided in the sixth embodiment of the present invention, and the firewall policy generation device corresponds to the firewall policy generation method in the above embodiment. Figure 6 As shown, the firewall policy generation device includes a first acquisition module 61, an update module 62, a first calculation module 63 and a generation module 64. The functional modules are described in detail as follows: A first acquisition module 61 is configured to monitor resource update events in a containerized environment in real time and acquire updated resource data corresponding to the resource update events. The updated resource data includes updated resource entities, metadata of each updated resource entity, and associations between updated resource entities. An updating module 62 is configured to obtain a historical resource relationship graph constructed based on the historical resource entities in the containerized environment, metadata of each historical resource entity, and relationships between the historical resource entities, and to update the historical resource relationship graph based on the updated resource data to obtain an updated resource relationship graph; A first calculation module 63 is configured to perform a risk assessment on all paths in the updated resource relationship graph to obtain an assessment result, determine a risk path based on the assessment result, and calculate, for any risk path, a risk score representing the risk level of each node in the risk path; The generation module 64 is used to input the updated resource relationship map and all risk scores into the model that has been trained for firewall policy generation to obtain a firewall policy, which is used to securely protect network traffic in the containerized environment.
[0047] Optionally, the first calculation module 63 includes: A matching unit, configured to perform path matching in the updated resource relationship graph using a preset risk matching rule to obtain a matching result; A determination unit is configured to determine, based on the matching result, a path that successfully matches any preset risk matching rule as the risk path.
[0048] Optionally, the first calculation module 63 includes: A second acquisition unit is configured to acquire, for any node in the risk path, the traffic entropy of the node and a vulnerability weight value representing the risk level of a known vulnerability on the node; The second calculation unit is used to obtain the risk score of the node according to the traffic entropy and the vulnerability weight value.
[0049] Optionally, the firewall policy generating device further includes: a conflict detection module, configured to perform conflict detection on any firewall policy based on each firewall policy other than the firewall policy; The first rollback module is used to obtain a historical firewall policy corresponding to the firewall policy if a firewall policy that conflicts with the firewall policy is detected, and use the historical firewall policy to perform security protection on network traffic in the containerized environment.
[0050] Optionally, the firewall policy generating device further includes: a verification module, configured to verify the compliance of the firewall policy if no firewall policy that conflicts with the firewall policy is detected, and to use the firewall policy to securely protect network traffic in the containerized environment if the verification passes; The second rollback module is used to obtain a historical firewall policy corresponding to the firewall policy if the verification fails, and use the historical firewall policy to perform security protection on the network traffic in the containerized environment.
[0051] Optionally, the firewall policy generating device further includes: A construction module is used to construct the historical resource relationship map for any historical resource entity, with the historical resource entity as a node, the metadata of the historical resource entity as the attribute of the node, and the relationship between the historical resource entity and other historical resource entities as an edge.
[0052] The specific definition of the firewall policy generation device can be found in the definition of the firewall policy generation method above and will not be repeated here. Each module in the aforementioned firewall policy generation device can be implemented in whole or in part via software, hardware, or a combination thereof. Each of the aforementioned modules can be embedded in or independent of a processor in a computer device in hardware form, or can be stored in a memory in the computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0053] like Figure 7 FIG. 1 is a schematic diagram of a computer device according to a seventh embodiment of the present invention. The computer device according to this embodiment includes: at least one processor ( Figure 7 Only one is shown in the figure), a memory, and a computer program stored in the memory and executable on at least one processor, wherein when the processor executes the computer program, the steps of any of the above-mentioned embodiments of the method for generating a firewall policy are implemented.
[0054] The computer device may include, but is not limited to, a processor and a memory. It will be understood by those skilled in the art that Figure 7 The above is merely an example of a computer device and does not constitute a limitation on the computer device. The computer device may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, it may also include a network interface, a display screen, and an input device.
[0055] The processor may be a CPU, other general-purpose processors, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0056] Memory includes readable storage media, internal memory, and the like. Internal memory can be the internal memory of a computer device, providing an environment for the operation of the operating system and computer-readable instructions stored in the readable storage medium. The readable storage medium can be the computer device's hard drive. In other embodiments, it can also be an external storage device, such as a plug-in hard drive, a Smart Media Card (SMC), a Secure Digital (SD) card, or a flash memory card. Furthermore, memory can include both the computer device's internal storage unit and external storage devices. Memory is used to store the operating system, application programs, boot loaders, data, and other programs, such as the program code of computer programs. Memory can also be used to temporarily store data that has been output or is about to be output.
[0057] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned device can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here. If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the process steps in the above-described method embodiments by instructing the relevant hardware through a computer program. The computer program may be stored in a computer-readable storage medium. When executed by a processor, the computer program implements the steps of the above-described method embodiments. The computer program includes computer program code, which may be in source code form, object code form, executable file, or some intermediate form. Computer-readable media may include at least: any entity or device capable of carrying computer program code, recording media, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunications signals, and software distribution media. Examples include USB flash drives, removable hard drives, magnetic disks, or optical disks. In some jurisdictions, based on legislation and patent practice, computer-readable media cannot be electrical carrier signals or telecommunications signals.
[0058] The present application implements all or part of the processes in the above-mentioned embodiment method, and can also be completed through a computer program product. When the computer program product runs on a computer device, the computer device can implement the steps in the above-mentioned method embodiment when executing it.
[0059] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.
[0060] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0061] In the embodiments provided in this application, it should be understood that the disclosed apparatus / computer equipment and methods can be implemented in other ways. For example, the apparatus / computer equipment embodiments described above are merely schematic. For example, the division of modules or units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of the apparatus or unit, which can be electrical, mechanical or other forms.
[0062] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0063] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the scope of protection of the present application. The non-company software tools or components that appear in the embodiments of the present application are merely examples and do not represent actual use.
Claims
1. A method for generating a firewall policy, characterized in that: include: Real-time monitoring of resource update events in the containerized environment, obtaining updated resource data corresponding to the resource update events, the updated resource data including updated resource entities, metadata of each updated resource entity, and associations between updated resource entities; Obtaining a historical resource relationship graph constructed based on historical resource entities in the containerized environment, metadata of each historical resource entity, and associations between historical resource entities, and updating the historical resource relationship graph according to the updated resource data to obtain an updated resource relationship graph; Performing a risk assessment on all paths in the updated resource relationship graph to obtain an assessment result, determining a risk path based on the assessment result, and calculating a risk score representing the risk level of each node in any risk path; The updated resource relationship map and all risk scores are input into a model that has been trained for firewall policy generation to obtain a firewall policy, which is used to provide security protection for network traffic in the containerized environment.
2. The method for generating a firewall policy according to claim 1, wherein: The step of performing risk assessment on all paths in the update resource relationship graph to obtain assessment results, and determining risk paths based on the assessment results, includes: Using preset risk matching rules, path matching is performed on the updated resource relationship graph to obtain a matching result; According to the matching result, a path that successfully matches any preset risk matching rule is determined as the risk path.
3. The method for generating a firewall policy according to claim 1, wherein: The step of calculating, for any risk path, a risk score representing the risk level of each node in the risk path includes: For any node in the risk path, obtain the traffic entropy of the node and a vulnerability weight value representing the risk level of a known vulnerability on the node; A risk score of the node is obtained according to the traffic entropy and the vulnerability weight value.
4. The method for generating a firewall policy according to claim 1, wherein: After inputting the updated resource relationship graph and all risk scores into a model that has been trained for firewall policy generation to obtain a firewall policy, the method further includes: For any firewall policy, performing conflict detection on the firewall policy according to each firewall policy other than the firewall policy; If a firewall policy that conflicts with the firewall policy is detected, a historical firewall policy corresponding to the firewall policy is obtained, and the historical firewall policy is used to perform security protection on the network traffic in the containerized environment.
5. The method for generating a firewall policy according to claim 4, wherein: After performing conflict detection on the firewall policy according to each firewall policy other than the firewall policy, the method further includes: If no firewall policy that conflicts with the firewall policy is detected, the firewall policy is verified for compliance, and if the verification passes, the firewall policy is used to securely protect network traffic in the containerized environment; If the verification fails, a historical firewall policy corresponding to the firewall policy is obtained, and the historical firewall policy is used to perform security protection on the network traffic in the containerized environment.
6. The method for generating a firewall policy according to claim 1, wherein: The firewall policy generation method further includes: For any historical resource entity, the historical resource relationship graph is constructed by taking the historical resource entity as a node, the metadata of the historical resource entity as the attribute of the node, and the association relationship between the historical resource entity and other historical resource entities as an edge.
7. A firewall policy generation device, characterized in that: include: A first acquisition module is configured to monitor resource update events in a containerized environment in real time and acquire updated resource data corresponding to the resource update events, wherein the updated resource data includes updated resource entities, metadata of each updated resource entity, and associations between updated resource entities; An update module is configured to obtain a historical resource relationship map constructed based on historical resource entities in the containerized environment, metadata of each historical resource entity, and associations between historical resource entities, and to update the historical resource relationship map based on the updated resource data to obtain an updated resource relationship map; A first calculation module is configured to perform a risk assessment on all paths in the updated resource relationship graph to obtain an assessment result, determine a risk path based on the assessment result, and calculate, for any risk path, a risk score representing the risk level of each node in the risk path; A generation module is used to input the updated resource relationship map and all risk scores into a model that has been trained for firewall policy generation to obtain a firewall policy, which is used to securely protect network traffic in the containerized environment.
8. The firewall policy generating device according to claim 7, wherein: The first calculation module includes: A matching unit, configured to perform path matching in the updated resource relationship graph using a preset risk matching rule to obtain a matching result; A determination unit is configured to determine, based on the matching result, a path that successfully matches any preset risk matching rule as the risk path.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the firewall policy generation method according to any one of claims 1 to 6 are implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the firewall policy generation method according to any one of claims 1 to 6 are implemented.