Network equipment policy distribution security management method and system

By setting the security policy distribution path of network device nodes and merging security rules, the problem of low security policy distribution efficiency in the existing technology is solved, and the optimal balance between the security and performance of network devices is achieved.

CN120639359APending Publication Date: 2025-09-12HUANENG INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510714218.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-29
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

In the prior art, when distributing security policies on network devices, attribute parameters of each network device cannot be comprehensively considered, resulting in excessive occupation of security policy performance and affecting processing efficiency.

Method used

By obtaining the transmission distance value between network device nodes, setting the security policy distribution path, and determining the leader node based on the node's attribute parameters and load capacity value, a minimum spanning tree is established, the nodes to be optimized are screened out, and security rules are merged to optimize the security policy.

Benefits of technology

It achieves efficient distribution of security policies, ensures the optimal balance between network device security and performance, and improves processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639359A_ABST
    Figure CN120639359A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network equipment security management, and discloses a network equipment policy distribution security management method and system, and the method comprises the steps: obtaining a transmission distance value between network equipment nodes, and setting a security policy distribution path according to the transmission distance value between the network equipment nodes, performing security policy distribution according to the security policy distribution path; acquiring attribute parameters of the network equipment nodes after the security policy is distributed, and determining a policy level coefficient according to the attribute parameters of the network equipment nodes after the security policy is distributed; and according to the policy level coefficient, screening out a to-be-optimized network device node, and merging the security rules of the security policy corresponding to the to-be-optimized network device node to obtain a merged security policy. The distributed security policies can be optimized according to the attribute parameters of the network devices, the processing efficiency of the security policies is improved, and the optimal balance between the security of the network devices and the network performance is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of network device security management, and more specifically, to a network device policy distribution security management method and system. Background Art

[0002] A security policy is a set of rules used to perform security-related activities within a computer. These rules can be formulated by network administrators to ensure the normal operation of applications on the computer.

[0003] In the existing technology, when distributing security policies for network devices, it is limited to the distribution of fixed security policies formulated by network administrators, and is unable to comprehensively consider the attribute parameters of each network device. When distributing security policies, the performance occupation of security policies is too high, resulting in reduced processing efficiency. Summary of the Invention

[0004] The present invention provides a network device policy distribution security management method and system to solve the problem in the prior art of the difficulty in balancing network device security and network performance when distributing security policies for network devices. The method includes: Obtaining a transmission distance value between network device nodes, setting a security policy distribution path according to the transmission distance value between network device nodes, and distributing security policies according to the security policy distribution path; Obtaining attribute parameters of the network device node after the security policy is distributed, and determining a policy level coefficient according to the attribute parameters of the network device node after the security policy is distributed; The network device nodes to be optimized are screened out according to the policy level coefficients, and the security rules of the security policies corresponding to the network device nodes to be optimized are merged to obtain a merged security policy.

[0005] Furthermore, the setting of a security policy distribution path according to the transmission distance value between network device nodes and distributing the security policy according to the security policy distribution path includes: Acquire transmission distance values ​​between network device nodes, cluster each network device node according to the transmission distance values ​​between the network device nodes, and obtain a cluster of network device nodes; Obtaining the load capacity values ​​of the network device nodes in the cluster, setting a leader node according to the load capacity values ​​of the network device nodes, and setting the remaining network device nodes in the cluster as member nodes; A security policy distribution path is determined according to the leader node and member nodes in the cluster. According to the security policy distribution path, the leader node distributes the security policy to the member nodes.

[0006] Furthermore, setting the leader node according to the load capacity value of the network device node includes: Obtain historical network security events of each network device node in the cluster, extract features of the historical network security events, and obtain historical network security event feature data; Perform correlation analysis on the historical network security event feature data of any two network device nodes to obtain the safety distance value between any two network device nodes; Counting the safety distance and value between each network device node and all other network device nodes, and screening out network device nodes whose safety distance and value are less than a first preset threshold; Obtain the load capacity values ​​of the filtered network device nodes, and set the network device node with the largest load capacity value as the leader node.

[0007] Furthermore, determining the security policy distribution path according to the leader node and member nodes in the cluster includes: The transmission distance between the leader node and the member nodes in the cluster is used as the weight, and the minimum spanning tree of the cluster is established based on the minimum spanning tree algorithm; Obtain historical network security event feature data of each leader node, perform correlation analysis on the historical network security event feature data of leader nodes in different clusters, and obtain the safety distance values ​​of leader nodes in different clusters; The leader nodes whose safety distance values ​​are smaller than the second preset threshold are connected, and a minimum spanning tree that completes the connection is set as a security policy distribution path.

[0008] Furthermore, the determining of the policy level coefficient according to the attribute parameters of the network device node after the security policy is distributed includes: Obtaining the number of attacks successfully blocked by the network device node within a preset period after the security policy is distributed, and determining effective parameters of the security policy based on the number of attacks successfully blocked by the network device node; Obtaining processing efficiency change data of network device nodes in a preset period after the security policy is distributed, and determining security policy performance impact parameters based on the processing efficiency change data of the network device nodes; The policy level coefficient after security policy distribution is determined based on the security policy effective parameters and security policy performance impact parameters of the network device nodes.

[0009] Furthermore, the determining of the policy level coefficient after security policy distribution based on the security policy effective parameters and security policy performance impact parameters of the network device node includes: The security policy effective parameters and security policy performance impact parameters of the network device node are calculated according to the policy level coefficient calculation formula to obtain the policy level coefficient. The policy level coefficient calculation formula is specifically as follows: , in, is the strategy level coefficient, is the effective parameter weight, The number of attacks successfully blocked by the network device node after the security policy is distributed. The number of attacks that the network device node has successfully blocked in history. is the weight of the performance-affecting parameters, is the processing efficiency weight, with a value range of [0-1], is the historical processing efficiency of network device nodes, It is the change in processing efficiency of network device nodes after security policy distribution.

[0010] Furthermore, the step of selecting the network device nodes to be optimized according to the policy level coefficients includes: Obtaining a preset level coefficient standard value, calculating a difference between the policy level coefficient of the network device node and the preset level coefficient standard value, and determining whether the difference between the policy level coefficient of the network device node and the preset level coefficient standard value is less than a third preset threshold; If the difference between the policy level coefficient of the network device node and the preset level coefficient standard value is less than a third preset threshold, then optimizing the security policy of the corresponding network device node; If the difference between the policy level coefficient of the network device node and the preset level coefficient standard value is greater than or equal to the third preset threshold, security policy optimization is not performed on the corresponding network device node.

[0011] Furthermore, the security rules of the security policies corresponding to the network device nodes to be optimized are merged to obtain a merged security policy, including: Obtaining security rules corresponding to the security policy of the network device node to be optimized, obtaining attribute characteristics of the security rules, establishing a dictionary index table, and generating a feature vector of the attribute characteristics of the security rules based on the dictionary index table; Calculating effective parameters of each security rule in the security policy, and screening out security rules whose effective parameters are greater than a fourth preset threshold; The security rules are merged according to the feature vectors of the filtered security rules and the feature vectors of the remaining security rules in the security policy to obtain a merged security policy.

[0012] Furthermore, the security rule merging is performed based on the feature vector of the screened security rule and the feature vectors of the remaining security rules in the security policy, including: The cosine similarity between the feature vectors of the remaining security rules and the feature vectors of the screened security rules is calculated, and the remaining security rules whose cosine similarity is less than a fifth preset threshold are merged into the corresponding screened security rules.

[0013] In order to achieve the above object, the present invention also provides a network device policy distribution security management system, comprising: A distribution module is used to obtain the transmission distance value between network device nodes, set a security policy distribution path according to the transmission distance value between network device nodes, and distribute security policies according to the security policy distribution path; A level module is used to obtain attribute parameters of network device nodes after security policy distribution, and determine a policy level coefficient based on the attribute parameters of network device nodes after security policy distribution; The optimization module is used to screen out the network device nodes to be optimized according to the policy level coefficient, merge the security rules of the security policy corresponding to the network device nodes to be optimized, and obtain the merged security policy.

[0014] The beneficial effects of the present invention are: By applying the above technical solution, the present invention obtains the transmission distance value between network device nodes, sets the security policy distribution path based on the transmission distance value between the network device nodes, and distributes the security policy according to the security policy distribution path; obtains the attribute parameters of the network device nodes after the security policy is distributed, and determines the policy level coefficient based on the attribute parameters of the network device nodes after the security policy is distributed; selects the network device nodes to be optimized based on the policy level coefficient, merges the security rules of the security policies corresponding to the network device nodes to be optimized, and obtains the merged security policy. The present invention can optimize the distributed security policy based on the attribute parameters of each network device, improve the processing efficiency of the security policy, and ensure the optimal balance between network device security and network performance. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.

[0016] Figure 1 The following is an overall flow chart of a network device policy distribution security management method proposed in an embodiment of the present invention; Figure 2 A schematic structural diagram of a network device policy distribution security management system proposed in an embodiment of the present invention is shown. DETAILED DESCRIPTION

[0017] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0018] The present application embodiment provides a network device policy distribution security management method, such as Figure 1 Shown, including: S101, obtaining a transmission distance value between network device nodes, setting a security policy distribution path according to the transmission distance value between the network device nodes, and distributing the security policy according to the security policy distribution path; In some embodiments of the present application, the security policy distribution path is set according to the transmission distance value between network device nodes, and the security policy is distributed according to the security policy distribution path, including: obtaining the transmission distance value between network device nodes, clustering each network device node according to the transmission distance value between network device nodes, and obtaining a cluster cluster of network device nodes; obtaining the load capacity value of the network device nodes in the cluster cluster, setting the leader node according to the load capacity value of the network device node, and setting the remaining network device nodes in the cluster cluster as member nodes; determining the security policy distribution path according to the leader node and member nodes in the cluster cluster, and according to the security policy distribution path, the leader node distributes the security policy to the member nodes according to the security policy distribution path.

[0019] In this embodiment, the transmission distance value of the target network device node is obtained by calculating the sum of the transmission distances between the target network device node and all other network device nodes, and the network device nodes are clustered according to the transmission distance value of each network device node based on the k-means clustering algorithm, so that the leader node and member nodes in each cluster are set according to the load capacity value, and the security policy is distributed to each member node according to the security policy distribution path through the leader node.

[0020] In some embodiments of the present application, the setting of the leader node according to the load capacity value of the network device node includes: obtaining historical network security events of each network device node in the cluster, performing feature extraction on the historical network security events, and obtaining historical network security event feature data; performing correlation analysis on the historical network security event feature data of any two network device nodes, and obtaining the safety distance value of any two network device nodes; counting the safety distance and value of each network device node with all other network device nodes, and screening out network device nodes whose safety distance and value are less than a first preset threshold; obtaining the load capacity values ​​of the screened network device nodes, and setting the network device node with the largest load capacity value as the leader node.

[0021] In this embodiment, after clustering all network device nodes, the traffic characteristics of the network device nodes in the historical network security event feature data are extracted, and the traffic characteristics of any two network device nodes are subjected to correlation analysis to obtain the safety distance value of any two network device nodes. The correlation coefficient of the traffic characteristics of the network device nodes is used as the safety distance value, and the network device nodes with low correlation with the remaining network device nodes are obtained by screening the network device nodes whose safety distance sum value is less than the first preset threshold. The network device node with the largest load capacity value is set as the leader node, thereby effectively reducing the impact of network security events on the leader node.

[0022] In some embodiments of the present application, the security policy distribution path is determined based on the leader node and member nodes in the cluster, including: using the transmission distance value between the leader node and member nodes in the cluster as the weight, and establishing the minimum spanning tree of the cluster based on the minimum spanning tree algorithm; obtaining the historical network security event feature data of each leader node, performing correlation analysis on the historical network security event feature data of the leader nodes in different clusters, and obtaining the safety distance values ​​of the leader nodes in different clusters; connecting the leader nodes whose safety distance values ​​are less than a second preset threshold, and setting the minimum spanning tree that completes the connection as the security policy distribution path.

[0023] In this embodiment, each member node in each cluster is connected to the leader node through a minimum spanning tree algorithm, thereby obtaining a security policy distribution path.

[0024] S102, obtaining attribute parameters of the network device node after the security policy is distributed, and determining a policy level coefficient according to the attribute parameters of the network device node after the security policy is distributed; In some embodiments of the present application, the method of determining the policy level coefficient based on the attribute parameters of the network device node after the security policy is distributed includes: obtaining the number of attacks successfully blocked by the network device node in a preset time period after the security policy is distributed, and determining the effective parameters of the security policy based on the number of attacks successfully blocked by the network device node; obtaining the processing efficiency change data of the network device node in a preset time period after the security policy is distributed, and determining the security policy performance impact parameters based on the processing efficiency change data of the network device node; and determining the policy level coefficient after the security policy is distributed based on the security policy effective parameters and the security policy performance impact parameters of the network device node.

[0025] In some embodiments of the present application, determining the policy level coefficient after security policy distribution based on the security policy effective parameters and security policy performance impact parameters of the network device node includes: calculating the security policy effective parameters and security policy performance impact parameters of the network device node according to the policy level coefficient calculation formula to obtain the policy level coefficient, wherein the policy level coefficient calculation formula is specifically: , in, is the strategy level coefficient, is the effective parameter weight, The number of attacks successfully blocked by the network device node after the security policy is distributed. The number of attacks that the network device node has successfully blocked in history. is the weight of the performance-affecting parameters, is the processing efficiency weight, with a value range of [0-1], is the historical processing efficiency of network device nodes, It is the change in processing efficiency of network device nodes after security policy distribution.

[0026] In this embodiment, the security policy is evaluated by calculating the security policy effective parameters and the security policy performance impact parameters, so as to facilitate the subsequent screening of network device nodes to be optimized.

[0027] S103 , selecting network device nodes to be optimized according to the policy level coefficients, merging security rules of security policies corresponding to the network device nodes to be optimized, and obtaining a merged security policy.

[0028] In some embodiments of the present application, the method of screening out network device nodes to be optimized based on the policy level coefficient includes: obtaining a preset level coefficient standard value, calculating the difference between the policy level coefficient of the network device node and the preset level coefficient standard value, and judging whether the difference between the policy level coefficient of the network device node and the preset level coefficient standard value is less than a third preset threshold; if the difference between the policy level coefficient of the network device node and the preset level coefficient standard value is less than the third preset threshold, performing security policy optimization on the corresponding network device node; if the difference between the policy level coefficient of the network device node and the preset level coefficient standard value is greater than or equal to the third preset threshold, not performing security policy optimization on the corresponding network device node.

[0029] In this embodiment, the network device nodes are screened by the difference between the policy level coefficient of the network device node and the preset level coefficient standard value, so that the network device nodes to be optimized can be accurately screened.

[0030] In some embodiments of the present application, the security rules of the security policy corresponding to the network device node to be optimized are merged to obtain a merged security policy, including: obtaining the security rules of the security policy corresponding to the network device node to be optimized, obtaining the attribute characteristics of the security rules, establishing a dictionary index table, and generating a feature vector of the attribute characteristics of the security rules according to the dictionary index table; calculating the effective parameters of each security rule in the security policy, and screening out security rules whose effective parameters are greater than a fourth preset threshold; merging the security rules according to the feature vectors of the screened security rules and the feature vectors of the remaining security rules in the security policy to obtain a merged security policy.

[0031] In some embodiments of the present application, the security rule merging is performed based on the feature vectors of the filtered security rules and the feature vectors of the remaining security rules in the security policy, including: calculating the cosine similarity between the feature vectors of each remaining security rule and the feature vector of the filtered security rule, and merging the remaining security rules whose cosine similarity is less than the fifth preset threshold into the corresponding filtered security rules.

[0032] In this embodiment, the effective parameters of the security rules are obtained by calculating the ratio of the number of attacks successfully blocked by the network device nodes with the target security rules after the security policy is distributed to the corresponding preset allowed number of attacks, so as to screen the security rules and then merge the security rules, reduce the unnecessary security rule occupation, and improve the efficiency of the network device nodes.

[0033] Based on the same technical concept, such as Figure 2 As shown, the present invention also provides a network device policy distribution security management system, including: The distribution module is used to obtain the transmission distance value between network device nodes, set the security policy distribution path according to the transmission distance value between network device nodes, and distribute the security policy according to the security policy distribution path; the level module is used to obtain the attribute parameters of the network device nodes after the security policy is distributed, and determine the policy level coefficient according to the attribute parameters of the network device nodes after the security policy is distributed; the optimization module is used to screen out the network device nodes to be optimized according to the policy level coefficient, merge the security rules of the security policy corresponding to the network device nodes to be optimized, and obtain the merged security policy.

[0034] By applying the above technical solution, the present invention obtains the transmission distance value between network device nodes, sets the security policy distribution path based on the transmission distance value between the network device nodes, and distributes the security policy according to the security policy distribution path; obtains the attribute parameters of the network device nodes after the security policy is distributed, and determines the policy level coefficient based on the attribute parameters of the network device nodes after the security policy is distributed; selects the network device nodes to be optimized based on the policy level coefficient, merges the security rules of the security policies corresponding to the network device nodes to be optimized, and obtains the merged security policy. The present invention can optimize the distributed security policy based on the attribute parameters of each network device, improve the processing efficiency of the security policy, and ensure the optimal balance between network device security and network performance.

[0035] Through the above description of the embodiments, those skilled in the art will clearly understand that the present invention can be implemented via hardware or via software combined with a necessary general-purpose hardware platform. Based on this understanding, the technical solution of the present invention can be embodied in the form of a software product. This software product can be stored on a non-volatile storage medium (such as a CD-ROM, USB flash drive, or external hard drive) and includes instructions for enabling a computer device (such as a personal computer, server, or network device) to execute the methods described in various implementation scenarios of the present invention.

[0036] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A network device policy distribution security management method, characterized in that: The method comprises: Obtaining a transmission distance value between network device nodes, setting a security policy distribution path according to the transmission distance value between network device nodes, and distributing security policies according to the security policy distribution path; Obtaining attribute parameters of the network device node after the security policy is distributed, and determining a policy level coefficient according to the attribute parameters of the network device node after the security policy is distributed; The network device nodes to be optimized are screened out according to the policy level coefficients, and the security rules of the security policies corresponding to the network device nodes to be optimized are merged to obtain a merged security policy.

2. The network device policy distribution security management method according to claim 1, characterized in that: The method of setting a security policy distribution path according to the transmission distance between network device nodes and distributing the security policy according to the security policy distribution path includes: Acquire transmission distance values ​​between network device nodes, cluster each network device node according to the transmission distance values ​​between the network device nodes, and obtain a cluster of network device nodes; Obtaining the load capacity values ​​of the network device nodes in the cluster, setting a leader node according to the load capacity values ​​of the network device nodes, and setting the remaining network device nodes in the cluster as member nodes; A security policy distribution path is determined according to the leader node and member nodes in the cluster. According to the security policy distribution path, the leader node distributes the security policy to the member nodes.

3. The network device policy distribution security management method according to claim 2, characterized in that: The step of setting a leader node according to the load capacity value of the network device node includes: Obtain historical network security events of each network device node in the cluster, extract features of the historical network security events, and obtain historical network security event feature data; Perform correlation analysis on the historical network security event feature data of any two network device nodes to obtain the safety distance value between any two network device nodes; Counting the safety distance and value between each network device node and all other network device nodes, and screening out network device nodes whose safety distance and value are less than a first preset threshold; Obtain the load capacity values ​​of the filtered network device nodes, and set the network device node with the largest load capacity value as the leader node.

4. The network device policy distribution security management method according to claim 3, characterized in that: The step of determining a security policy distribution path based on the leader node and member nodes in the cluster includes: The transmission distance between the leader node and the member nodes in the cluster is used as the weight, and the minimum spanning tree of the cluster is established based on the minimum spanning tree algorithm; Obtain historical network security event feature data of each leader node, perform correlation analysis on the historical network security event feature data of leader nodes in different clusters, and obtain the safety distance values ​​of leader nodes in different clusters; The leader nodes whose safety distance values ​​are smaller than the second preset threshold are connected, and a minimum spanning tree that completes the connection is set as a security policy distribution path.

5. The network device policy distribution security management method according to claim 1, characterized in that: The determining of the policy level coefficient according to the attribute parameters of the network device node after the security policy is distributed includes: Obtaining the number of attacks successfully blocked by the network device node within a preset period after the security policy is distributed, and determining effective parameters of the security policy based on the number of attacks successfully blocked by the network device node; Obtaining processing efficiency change data of network device nodes in a preset period after the security policy is distributed, and determining security policy performance impact parameters based on the processing efficiency change data of the network device nodes; The policy level coefficient after security policy distribution is determined based on the security policy effective parameters and security policy performance impact parameters of the network device nodes.

6. The network device policy distribution security management method according to claim 5, characterized in that: The method of determining the policy level coefficient after security policy distribution based on the security policy effective parameters and security policy performance impact parameters of the network device node includes: The security policy effective parameters and security policy performance impact parameters of the network device node are calculated according to the policy level coefficient calculation formula to obtain the policy level coefficient. The policy level coefficient calculation formula is specifically as follows: , in, is the strategy level coefficient, is the effective parameter weight, The number of attacks successfully blocked by the network device node after the security policy is distributed. The number of attacks that the network device node has successfully blocked in history. is the weight of the performance-affecting parameters, is the processing efficiency weight, with a value range of [0-1], is the historical processing efficiency of network device nodes, It is the change in processing efficiency of network device nodes after security policy distribution.

7. The network device policy distribution security management method according to claim 6, characterized in that: The step of screening out the network device nodes to be optimized according to the policy level coefficient includes: Obtaining a preset level coefficient standard value, calculating a difference between the policy level coefficient of the network device node and the preset level coefficient standard value, and determining whether the difference between the policy level coefficient of the network device node and the preset level coefficient standard value is less than a third preset threshold; If the difference between the policy level coefficient of the network device node and the preset level coefficient standard value is less than a third preset threshold, then optimizing the security policy of the corresponding network device node; If the difference between the policy level coefficient of the network device node and the preset level coefficient standard value is greater than or equal to the third preset threshold, security policy optimization is not performed on the corresponding network device node.

8. The network device policy distribution security management method according to claim 7, characterized in that: The step of merging the security rules of the security policies corresponding to the network device nodes to be optimized to obtain a merged security policy includes: Obtain security rules of the security policy corresponding to the network device node to be optimized, obtain attribute characteristics of the security rules, establish a dictionary index table, and generate a feature vector of the attribute characteristics of the security rules based on the dictionary index table; Calculating effective parameters of each security rule in the security policy, and screening out security rules whose effective parameters are greater than a fourth preset threshold; The security rules are merged according to the feature vectors of the filtered security rules and the feature vectors of the remaining security rules in the security policy to obtain a merged security policy.

9. The network device policy distribution security management method according to claim 8, characterized in that: The security rule merging according to the feature vector of the screened security rule and the feature vectors of the remaining security rules in the security policy includes: The cosine similarity between the feature vectors of the remaining security rules and the feature vectors of the screened security rules is calculated, and the remaining security rules whose cosine similarity is less than a fifth preset threshold are merged into the corresponding screened security rules.

10. A network device policy distribution security management system, characterized in that: include: A distribution module is used to obtain the transmission distance value between network device nodes, set a security policy distribution path according to the transmission distance value between network device nodes, and distribute security policies according to the security policy distribution path; A level module is used to obtain attribute parameters of network device nodes after security policy distribution, and determine a policy level coefficient based on the attribute parameters of network device nodes after security policy distribution; The optimization module is used to screen out the network device nodes to be optimized according to the policy level coefficient, merge the security rules of the security policy corresponding to the network device nodes to be optimized, and obtain the merged security policy.