ACL automatic creation method and device, electronic equipment and storage medium

By receiving quintuple information and switch attributes, parsing configuration files and routing tables, and automatically creating ACL rules, the problem of low operation and maintenance efficiency caused by too many ACL rule entries in the existing technology is solved, and efficient ACL automatic creation is achieved.

CN120639495AActive Publication Date: 2025-09-12BEIJING ANBOTONG TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202511042203.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-28
Publication Date
2025-09-12
Estimated Expiration
2045-07-28

AI Technical Summary

Technical Problem

In the prior art, too many ACL rule entries lead to low efficiency for network operation and maintenance personnel when creating ACLs. They need to check each entry one by one, resulting in low operation and maintenance efficiency.

Method used

By receiving five-tuple information and switch attribute information, parsing configuration files and routing tables, establishing routing table models and ACL models, automatically determining the ACLs of inbound and outbound interfaces, detecting intersections in rule lists, and generating a list of ACLs to be activated, the system realizes automatic creation of ACLs.

Benefits of technology

Improves the operation and maintenance efficiency of network operation and maintenance personnel, reduces manual verification steps through automated processing, and ensures the accuracy and efficiency of ACL rules.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639495A_ABST
    Figure CN120639495A_ABST
Patent Text Reader

Abstract

The invention provides an ACL automatic creation method and device, electronic equipment and a storage medium, and the method comprises the steps: receiving quintuple information and attribute information of a switch in response to an ACL creation request; acquiring a configuration file and a routing table of the switch according to the attribute information; analyzing the configuration file and the routing table, and establishing a routing table model and an ACL model according to an analysis result; determining an incoming interface of the switch in the first network interface according to the source IP address and the subnet; determining a first target ACL of which the binding direction is an incoming direction in the plurality of ACLs according to the incoming interface; detecting whether a first target rule having an intersection with the quintuple information exists in a first target rule list matched with the first target ACL; and when it is detected that the first target rule exists and the processing action of the first target rule is refusal, putting the first target ACL and the first target rule ID into a preset forward ACL list to be opened. According to the invention, automatic creation of the ACL can be realized, and the operation and maintenance efficiency of network operation and maintenance personnel is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a method, device, electronic device, and storage medium for automatically creating an ACL. Background Art

[0002] The ACL (Access Control List) in a network switch is a rule-based traffic filtering mechanism used to control the forwarding or discarding of data packets. Its core principle is to match each traffic passing through the switch against predefined matching conditions (such as source / destination IP, MAC address, port number, protocol type, etc.) and perform permit or deny actions. In switches, ACLs can be divided into standard ACLs (which only match the source IP address) and extended ACLs (which support multi-field matching) and are usually deployed in the inbound or outbound direction of the interface. Typical applications include isolating inter-departmental communications, blocking malicious traffic, and ensuring bandwidth for critical services. ACL rules are executed in order of priority. If configured in the wrong location, it can lead to policy conflicts or service interruptions.

[0003] In the related art, there are too many ACL rule entries. Network operation and maintenance personnel need to check each entry one by one when creating the ACL, which leads to low creation efficiency and low operation and maintenance efficiency of the network operation and maintenance personnel. Summary of the Invention

[0004] In view of this, the present application provides an ACL automatic creation method, device, electronic device and storage medium, which can realize the automatic creation of ACL and improve the operation and maintenance efficiency of network operation and maintenance personnel.

[0005] A first aspect of an embodiment of the present application provides an automatic ACL creation method, comprising: responding to an ACL creation request, receiving quintuple information and attribute information of a switch, wherein the quintuple information includes a source IP address; obtaining a configuration file and a routing table of the switch based on the attribute information; parsing the configuration file and the routing table, and establishing a routing table model and an ACL model based on the parsing results, wherein the routing table model includes multiple routing tables of different models, and a first network interface and subnet matching each routing table, and the ACL model includes multiple ACLs, and a second network interface matching each ACL, a rule list, a rule ID, and a binding direction between the ACL and the second network interface; determining an inbound interface of the switch in the first network interface based on the source IP address and the subnet; determining a first target ACL with an inbound binding direction in the multiple ACLs based on the inbound interface; detecting whether there is a first target rule in a first target rule list matching the first target ACL that has an intersection with the quintuple information; and if it is detected that the first target rule exists and the processing action of the first target rule is reject, adding the first target ACL and the first target rule ID corresponding to the first target rule to a preset forward ACL list to be opened.

[0006] In one possible implementation, the first target rule list includes multiple first rules, and each of the first rules includes a corresponding first rule ID; detecting whether there is a first target rule in the first target rule list that matches the first target ACL that has an intersection with the five-tuple information includes: matching the five-tuple information with multiple first rules in the first target rule list in sequence according to the priority of the preset first rule ID; when the matching result is that the five-tuple information and the first target rule in the multiple first rules have an intersection, splitting the five-tuple information into an intersecting part and a non-intersecting part, wherein the rule ID of the first target rule is the first target rule ID; matching the non-intersecting part with the rule in the first target rule list whose priority is greater than the first target rule ID until all the first rules in the first target rule list are matched.

[0007] In a possible implementation, the five-tuple information is matched in sequence with multiple first rules in the first target rule list according to the preset priority size of the first rule ID, including: arranging the first rule ID in order from small to large priority, and matching the five-tuple information with multiple first rules in order of the priority arrangement; the method also includes: responding to the rule ID generation request, determining the comparison rule ID that is before the first target rule ID according to the priority arrangement order; calculating the difference between the first target rule ID and the comparison rule ID; when the difference is greater than 1, setting the newly generated rule ID to the average of the first target rule ID and the comparison rule ID; when the difference is equal to 1, setting the newly generated rule ID to the opposite of the first target rule ID.

[0008] In one possible implementation, the quintuple information also includes a destination IP address; the method also includes: determining the outgoing interface of the switch in the first network interface based on the destination IP address and the subnet; determining a second target ACL whose binding direction is the outgoing direction in multiple ACLs based on the outgoing interface; detecting whether there is a second target rule in the second target rule list that matches the second target ACL that has an intersection with the quintuple information; when it is detected that the second target rule exists and the processing action of the second target rule is reject, placing the second target ACL and the second target rule ID corresponding to the second target rule into the forward ACL list to be opened.

[0009] In one possible implementation, the quintuple information also includes protocol information and a destination port; when the protocol information is the TCP protocol, the method further includes: exchanging the source IP address with the destination IP address to obtain a new source IP address and a new destination IP address, and setting the destination port to a preset port number; determining a third target ACL whose binding direction is an inbound direction in multiple ACLs according to the outbound interface; detecting whether there is a third target rule in the third target rule list that matches the third target ACL that has an intersection with the quintuple information, wherein the port of the third target rule is the preset port number; when it is detected that the third target rule exists and the processing action of the third target rule is reject, the third target ACL and the third target rule ID corresponding to the third target rule are placed in a preset reverse ACL list to be opened.

[0010] In one possible implementation, the method further includes: determining a fourth target ACL whose binding direction is an outbound direction in multiple ACLs according to the inbound interface; detecting whether there is a fourth target rule that has an intersection with the five-tuple information in the fourth target rule list that matches the fourth target ACL, wherein the port of the fourth target rule is the preset port number; when it is detected that the fourth target rule exists and the processing action of the fourth target rule is rejection, the fourth target ACL and the fourth target rule ID corresponding to the fourth target rule are placed in the reverse ACL list to be opened.

[0011] In one possible implementation, the attribute information includes a switch manufacturer model; obtaining the configuration file and routing table of the switch based on the attribute information includes: determining the configuration command of the switch based on the switch manufacturer model; connecting to the switch through a secure shell protocol, controlling the switch to execute the configuration command, and obtaining the configuration file and the routing table.

[0012] In the second aspect, the embodiment of the present application also provides an ACL automatic creation device, including: a receiving module, an acquisition module, a parsing module, a first determination module, a second determination module, a detection module and a creation module; the receiving module is used to respond to the ACL creation request, receive five-tuple information and attribute information of the switch, wherein the five-tuple information includes a source IP address; the acquisition module is used to obtain the configuration file and routing table of the switch according to the attribute information; the parsing module is used to parse the configuration file and the routing table, and establish a routing table model and an ACL model according to the parsing results, wherein the routing table model includes multiple routing tables of different models, and a first network interface and subnet matching each of the routing tables, and the ACL model includes multiple ACLs, and a first network interface and subnet matching each of the ACLs. the second network interface, rule list, rule ID and the binding direction of the ACL and the second network interface; the first determination module is used to determine the inbound interface of the switch in the first network interface according to the source IP address and the subnet; the second determination module is used to determine the first target ACL whose binding direction is the inbound direction in multiple ACLs according to the inbound interface; the detection module is used to detect whether there is a first target rule that has an intersection with the quintuple information in the first target rule list matching the first target ACL; the creation module is used to put the first target ACL and the first target rule ID corresponding to the first target rule into a preset forward ACL list to be opened when it is detected that the first target rule exists and the processing action of the first target rule is reject.

[0013] In a third aspect, an embodiment of the present application further provides an electronic device, comprising a processor and a memory, wherein the memory is used to store instructions, and the processor is used to call the instructions in the memory so that the electronic device executes the ACL automatic creation method as described in the first aspect.

[0014] In a fourth aspect, an embodiment of the present application further provides a storage medium storing computer instructions. When the computer instructions are executed on an electronic device, the electronic device executes the ACL automatic creation method as described in the first aspect.

[0015] Compared with related technologies, the embodiments of the present application have at least the following advantages: by responding to an ACL creation request, receiving quintuple information and switch attribute information, the switch configuration file and routing table can be obtained based on the attribute information, thereby being able to parse the configuration file and routing table to obtain a routing table model and ACL model. Since the routing table model includes multiple routing tables of different models and a first network interface and subnet matching each routing table, the switch's inbound interface can be determined in the first network interface based on the source IP address and subnet, thereby being able to determine the first target ACL with an inbound binding direction in multiple ACLs based on the inbound interface. By detecting the first target rule that intersects the quintuple information and the first target rule list, since the intersection of the quintuple information and the first target rule list indicates that the user wishes the intersecting quintuple information to pass, when the first target rule is detected and the processing action of the first target rule is reject, the first target ACL and the first target rule ID corresponding to the first target rule are added to the forward ACL list to be activated, thereby achieving automatic creation of an ACL that meets user needs, thereby improving the operation and maintenance efficiency of network operation and maintenance personnel.

[0016] The technical effects obtained in the above-mentioned second, third and fourth aspects are similar to the technical effects obtained by the corresponding technical means in the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 A flowchart of the steps of the automatic ACL creation method provided in one embodiment of the present application.

[0018] Figure 2 A schematic diagram of an application scenario of the ACL creation form provided in one embodiment of the present application.

[0019] Figure 3 A schematic diagram of an application scenario of a routing table model provided in one embodiment of the present application.

[0020] Figure 4 A schematic diagram of an application scenario of the ACL model provided in one embodiment of the present application.

[0021] Figure 5 Another step flow chart of the ACL automatic creation method provided in one embodiment of the present application.

[0022] Figure 6 This is another step flow chart of the method for automatically creating an ACL provided in an embodiment of the present application.

[0023] Figure 7 This is a functional module diagram of the ACL automatic creation device provided in one embodiment of the present application.

[0024] Figure 8 A schematic diagram of the structure of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION

[0025] In order to more clearly understand the above-mentioned objectives, features and advantages of the present application, the present application is described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be noted that the embodiments of the present application and the features therein can be combined with each other in the absence of conflict.

[0026] In the following description, many specific details are set forth to facilitate a full understanding of the present application. The described embodiments are only part of the embodiments of the present application, rather than all of the embodiments.

[0027] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application pertains. The terms used herein in the specification of this application are only for the purpose of describing specific embodiments and are not intended to limit this application.

[0028] It should be further noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not preclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.

[0029] In this application, "at least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can mean: A alone, A and B together, and B alone, where A and B can be singular or plural. The terms "first," "second," "third," "fourth," and so on (if any) in the specification, claims, and drawings of this application are used to distinguish similar objects, not to describe a specific order or precedence.

[0030] In the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this application should not be interpreted as being more preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0031] To facilitate understanding, some illustrations of concepts related to the embodiments of the present application are given for reference.

[0032] ACL: Access Control List, used by network devices to filter and manage data packets in a refined manner. Its core functions include allowing or denying data packets based on conditions such as source / destination IP, port number, and protocol type.

[0033] Quintuple: A core concept used in network communications to uniquely identify inter-process communication connections. It consists of the following five elements: transport layer protocol, source IP address and source port, and destination IP address and destination port.

[0034] Configuration files: These include basic network parameters, protocol and state control, and advanced configuration. Basic network parameters include the interface IP address, subnet mask override parameters, and default gateway address; protocol and state control includes the protocol type and interface startup status; and advanced configuration includes specifying the target network, next hop, and outbound interface in the router configuration.

[0035] Routing table: The core basis for a router to make packet forwarding decisions. Its parameter configuration directly affects network communication efficiency. Routing table parameters include network interface, VPN instance, subnet, and next-hop address.

[0036] Secure Shell (SSH) is a protocol used for secure remote login and other secure network services over insecure networks. Developed by the IETF's Network Working Group, SSH is an application-layer security protocol.

[0037] Please refer to Figure 1 , Figure 1 This is a flowchart of the steps of an embodiment of the ACL automatic creation method of the present application. According to different requirements, the order of the steps in the flowchart can be changed, and some steps can be omitted.

[0038] It should be noted that the automatic ACL creation method of the embodiments of this application can be applied to user access scenarios, and its execution entity can be an automatic ACL creation device. For example, in user access scenarios, the automatic ACL creation device can be used to automatically create an ACL. Of course, the automatic ACL creation method can also be applied to other scenarios requiring automatic ACL creation, such as scenarios where operations personnel are maintaining a website, but this application does not specifically limit this.

[0039] The specific process of this embodiment is as follows Figure 1 As shown, the following steps are included: S101 , responding to an ACL creation request, receiving quintuple information and switch attribute information, wherein the quintuple information includes a source IP address.

[0040] In some embodiments, the five-tuple information includes a source IP address, a destination IP address, a transport layer protocol, a destination port, and a destination IP address.

[0041] In some embodiments, the attribute information includes the switch manufacturer model, the switch IP address, the switch user name, and the switch password.

[0042] For ease of understanding, the following Figure 2 A detailed description of how this application receives quintuple information and switch attribute information is provided: Please refer to Figure 2 , which is a schematic diagram of an application scenario of the ACL creation form provided in an embodiment of the present application.

[0043] The electronic device responds to the user's ACL creation request and displays Figure 2 In the ACL work form shown, the user enters relevant information on the ACL work form, that is, the electronic device receives the five-tuple information and attribute information entered by the user. After the user clicks Submit, the electronic device automatically generates an ACL list to be activated.

[0044] In some embodiments, electronic devices include but are not limited to laptop computers, tablet computers, mobile phones and other terminal devices. This embodiment does not specifically limit the type of electronic devices.

[0045] S102: Obtain the configuration file and routing table of the switch according to the attribute information.

[0046] In some embodiments, since the attribute information includes the switch manufacturer model, the switch configuration command can be determined according to the switch manufacturer model; the switch is connected through the secure shell protocol, and the switch is controlled to execute the configuration command to obtain the configuration file and routing table.

[0047] S103: Parse the configuration file and the routing table, and establish a routing table model and an ACL model according to the parsing results.

[0048] Specifically, the routing table model includes multiple routing tables of different models, as well as the first network interface and subnet matching each routing table. The ACL model includes multiple ACLs, as well as the second network interface matching each ACL, the rule list, the rule ID, and the binding direction between the ACL and the second network interface.

[0049] For ease of understanding, the following Figure 3 and Figure 4 How to generate and establish a routing table model and an ACL model in this embodiment is described in detail: Please refer to Figure 3 , which is a schematic diagram of an application scenario of the routing table model provided in an embodiment of the present application. By parsing the configuration file and routing table, the binding relationship between the first network interface and the routing table is identified, as well as the routing table forwarding items contained in each routing table. The routing tables of different device models are converted into a unified routing table model based on the routing table, subnet, next hop, and first network interface. Figure 3 In the routing table model shown, the subnet is Figure 3 The IP and mask shown are for the first network interface. Figure 3 The outgoing interface is shown.

[0050] Please refer to Figure 4 , which is a schematic diagram of an application scenario of the ACL model provided in an embodiment of the present application. By parsing the configuration file and routing table, the binding relationship between the ACL and the second network interface, the binding direction of the ACL and the second network interface, and the rule list contained in each ACL are identified. According to the ACL, the rule ID, source IP address, destination IP address, transport protocol, source port, destination port, and action in the rule list, the routing tables of different models of devices are converted into a unified ACL model. Figure 4 In the ACL model shown, the source IP address is Figure 4 The source and destination IP addresses shown are Figure 4 The destination shown is the port Figure 4 Services shown.

[0051] It's worth noting that by converting to a unified routing table and ACL model, the code can be layered. The data parsing layer is responsible for processing configuration texts from different vendors into a unified data model, allowing the business processing layer to use a single set of code. Otherwise, every time a new brand of switch is purchased, all code must be rewritten, thus improving the efficiency and reliability of the automatic ACL creation method.

[0052] S104: Determine the inbound interface of the switch in the first network interface according to the source IP address and the subnet.

[0053] It is understandable that Figure 3 The subnet shown includes the IP address corresponding to each router. The intersection of the input source IP address and the IP addresses corresponding to all routers is taken. If there is an intersection, the first network interface in the routing table model, that is, the input interface of the switch, is obtained.

[0054] In some embodiments, if there are multiple inbound interfaces, they are stored in a list, namely, the inbound interface list.

[0055] In some embodiments, when saving the inbound interface, the binding relationship between each inbound interface and the router also needs to be included for use in subsequent search for the outbound interface.

[0056] S105 : Determine, according to the inbound interface, a first target ACL from among the multiple ACLs, the binding direction of which is the inbound direction.

[0057] In some embodiments, the inbound interface list is traversed to obtain a first target ACL whose binding direction is the inbound direction.

[0058] S106, detecting whether there is a first target rule that intersects with the five-tuple information in the first target rule list that matches the first target ACL; when it is detected that there is a first target rule and the processing action of the first target rule is reject, the first target ACL and the first target rule ID corresponding to the first target rule are put into the preset forward ACL list to be opened.

[0059] In some embodiments, the first target rule list includes multiple first rules, and each first rule includes a corresponding first rule ID; detecting whether there is a first target rule in the first target rule list that matches the first target ACL that has an intersection with the quintuple information includes: matching the quintuple information with the multiple first rules in the first target rule list in sequence according to the priority of the preset first rule ID; when the matching result is that the quintuple information and the first target rule in the multiple first rules have an intersection, splitting the quintuple information into an intersecting part and a non-intersecting part, wherein the rule ID of the first target rule is the first target rule ID; matching the non-intersecting part with the rule in the first target rule list whose priority is greater than the first target rule ID until all the first rules in the first target rule list are matched.

[0060] In some embodiments, according to the priority size of the preset first rule ID, the quintuple information is matched in sequence with multiple first rules in the first target rule list, including: arranging the first rule ID in order of priority from small to large, and matching the quintuple information with multiple first rules in order of priority.

[0061] In some embodiments, the method further includes: responding to the rule ID generation request, determining a comparison rule ID preceding the first target rule ID based on the priority order; calculating the difference between the first target rule ID and the comparison rule ID; if the difference is greater than 1, setting the newly generated rule ID to the average of the first target rule ID and the comparison rule ID; and if the difference is equal to 1, setting the newly generated rule ID to the opposite of the first target rule ID. This method enables automatic creation of ACL rule IDs, avoiding the prior art issue of "manual rule ID assignment prone to sorting errors, resulting in policy execution order inconsistent with expectations," and further improving the reliability of the automatic ACL creation method.

[0062] To facilitate understanding, the following describes in detail how to create a forward ACL for an inbound interface in this embodiment: 1. Define variables: the ACL list to be enabled.

[0063] 2. Traverse the inbound interface list and obtain the first target ACL. The binding direction of the first target ACL is inbound.

[0064] 3. In ascending order of priority of the first rule ID, use the quintuple information to intersect with the first rule in the first target rule list. It is understandable that the first rule is configured with an IP address and a port number, so the quintuple information and the first rule are not in a complete include or be included relationship.

[0065] 4. When the quintuple information intersects with the first target rule, the current quintuple information is split into the intersecting and non-intersecting parts. Depending on whether the first target rule's action is allow or deny, the intersecting part is stored in the data stream or the deny data stream. It is understood that if the first target rule's action is allow, the intersecting part is stored in the data stream; if the first target rule's action is deny, the intersecting part is stored in the deny data stream. The ID of the first rule with an intersection and a deny action is also recorded and defined as the conflicting rule ID, which is also the first target rule ID in this embodiment.

[0066] 5. Use the disjoint parts to continue matching the first rules backward in the order of priority of the first rule IDs until all first rules in the first target rule list are matched.

[0067] 6. Check the denied data flow. If it's not empty, add the first target ACL and the first target rule ID to the forward ACL list to be enabled. It's important to note that if a denied data flow exists, it means a first rule already exists to deny the user's input data flow; the user wants to allow the input data flow. Therefore, if a deny rule has already been set, a new allow rule (with a higher priority) must be set above it to meet the user's needs. The method for generating the rule ID for the new rule is described in detail in the previous steps and will not be repeated here.

[0068] Compared with related technologies, the embodiments of the present application have at least the following advantages: by responding to an ACL creation request, receiving quintuple information and switch attribute information, the switch configuration file and routing table can be obtained based on the attribute information, thereby being able to parse the configuration file and routing table to obtain a routing table model and ACL model. Since the routing table model includes multiple routing tables of different models and a first network interface and subnet matching each routing table, the switch's inbound interface can be determined in the first network interface based on the source IP address and subnet, thereby being able to determine the first target ACL with an inbound binding direction in multiple ACLs based on the inbound interface. By detecting the first target rule that intersects the quintuple information and the first target rule list, since the intersection of the quintuple information and the first target rule list indicates that the user wishes the intersecting quintuple information to pass, when the first target rule is detected and the processing action of the first target rule is reject, the first target ACL and the first target rule ID corresponding to the first target rule are added to the forward ACL list to be activated, thereby achieving automatic creation of an ACL that meets user needs, thereby improving the operation and maintenance efficiency of network operation and maintenance personnel.

[0069] Please refer to Figure 5 , Figure 5This is a flowchart of the steps of an embodiment of the automatic ACL creation method of the present application. Depending on different requirements, the order of the steps in this flowchart can be changed, and some steps can be omitted. This automatic ACL creation method can be applied to the aforementioned automatic ACL creation device, but is not limited thereto, and this embodiment of the present application is not limited thereto.

[0070] This embodiment further improves upon the previous one, primarily by identifying a second target ACL with outbound binding direction from among multiple ACLs based on the outbound interface. The second target rule ID corresponding to the second target ACL and the second target rule is added to the forward ACL list to be activated. This approach enables automatic creation of forward ACLs for outbound interfaces, further improving the efficiency of network operators.

[0071] The specific process of this embodiment is as follows Figure 5 As shown, the following steps are included: S501 , responding to an ACL creation request, receiving quintuple information and switch attribute information, wherein the quintuple information includes a source IP address.

[0072] S502: Obtain the configuration file and routing table of the switch according to the attribute information.

[0073] S503: Parse the configuration file and the routing table, and establish a routing table model and an ACL model according to the parsing results.

[0074] S504: Determine the inbound interface of the switch in the first network interface according to the source IP address and the subnet.

[0075] S505 : Determine, according to the inbound interface, a first target ACL from among the multiple ACLs, the binding direction of which is the inbound direction.

[0076] S506, detect whether there is a first target rule that intersects with the five-tuple information in the first target rule list that matches the first target ACL; when it is detected that there is a first target rule and the processing action of the first target rule is reject, put the first target ACL and the first target rule ID corresponding to the first target rule into the preset forward ACL list to be opened.

[0077] S501 to S506 of this embodiment are similar to S101 to S106 of the aforementioned embodiment, and are not described again here to avoid repetition.

[0078] S507: Determine the outgoing interface of the switch in the first network interface according to the destination IP address and the subnet.

[0079] S508: Determine, according to the outbound interface, a second target ACL with an outbound binding direction from among the multiple ACLs.

[0080] S509, detect whether there is a second target rule that intersects with the five-tuple information in the second target rule list that matches the second target ACL; when it is detected that there is a second target rule and the processing action of the second target rule is reject, put the second target rule ID corresponding to the second target ACL and the second target rule into the forward ACL list to be opened.

[0081] To facilitate understanding, the following describes in detail how to create a forward ACL for an outbound interface in this embodiment: 1. Traverse the outbound interface list and obtain the second target ACL. The second target ACL is bound in the outbound direction.

[0082] 2. In ascending order of priority of the second rule ID, use the five-tuple information to intersect the second rule in the second target rule list. It can be understood that the second rule ID is the ID of the second rule.

[0083] 3. If the quintuple information intersects with the second target rule, the quintuple information is split into the intersecting and non-intersecting parts. Depending on the second target rule's action of permit or deny, the intersecting part is either stored in the data stream or denied. The ID of the first second rule with an intersecting part and a deny action is also recorded and defined as the conflicting rule ID, which is also the second target rule ID in this embodiment.

[0084] 4. Use the disjoint parts to continue matching the second rules backward in the order of priority of the second rule IDs until all second rules in the second target rule list are matched.

[0085] 5. Check the denied data flow. If it is not empty, put the second target ACL and the second target rule ID into the forward ACL list to be opened.

[0086] Compared with related technologies, the embodiments of the present application have at least the following advantages: by responding to an ACL creation request, receiving quintuple information and switch attribute information, the switch configuration file and routing table can be obtained based on the attribute information, thereby being able to parse the configuration file and routing table to obtain a routing table model and ACL model. Since the routing table model includes multiple routing tables of different models and a first network interface and subnet matching each routing table, the switch's inbound interface can be determined in the first network interface based on the source IP address and subnet, thereby being able to determine the first target ACL with an inbound binding direction in multiple ACLs based on the inbound interface. By detecting the first target rule that intersects the quintuple information and the first target rule list, since the intersection of the quintuple information and the first target rule list indicates that the user wishes the intersecting quintuple information to pass, when the first target rule is detected and the processing action of the first target rule is reject, the first target ACL and the first target rule ID corresponding to the first target rule are added to the forward ACL list to be activated, thereby achieving automatic creation of an ACL that meets user needs, thereby improving the operation and maintenance efficiency of network operation and maintenance personnel.

[0087] Please refer to Figure 6 , Figure 6 This is a flowchart of the steps of an embodiment of the automatic ACL creation method of the present application. Depending on different requirements, the order of the steps in this flowchart can be changed, and some steps can be omitted. This automatic ACL creation method can be applied to the aforementioned automatic ACL creation device, but is not limited thereto, and this embodiment of the present application is not limited thereto.

[0088] This embodiment further improves upon the previous embodiment. The main improvement is that, when the protocol in the quintuple information is TCP, reverse data flow matching is performed to create reverse ACLs for both the inbound and outbound interfaces. This approach enables automatic creation of reverse ACLs for both inbound and outbound interfaces, making the automatic ACL creation method applicable to a wider range of scenarios and further improving its reliability.

[0089] The specific process of this embodiment is as follows Figure 6 As shown, the following steps are included: S601 , responding to an ACL creation request, receiving quintuple information and switch attribute information, wherein the quintuple information includes a source IP address, a destination IP address, protocol information, and a destination port.

[0090] S602: Obtain the configuration file and routing table of the switch according to the attribute information.

[0091] S603: Parse the configuration file and the routing table, and establish a routing table model and an ACL model according to the parsing results.

[0092] S604: Determine the inbound interface of the switch in the first network interface according to the source IP address and the subnet.

[0093] S605: Determine the outgoing interface of the switch in the first network interface according to the destination IP address and the subnet.

[0094] S606: Exchange the source IP address and the destination IP address to obtain a new source IP address and a new destination IP address, and set the destination port to a preset port number.

[0095] In some embodiments, the preset port number is any (0-65536). Since the source port is randomly generated when a TCP session is established and cannot be controlled by the user, after reversing, the source port becomes the destination port. The algorithm cannot know the specific port and can only assume that all ports are possible.

[0096] S607: Determine, according to the outbound interface, a third target ACL from among the multiple ACLs, the binding direction of which is the inbound direction.

[0097] S608, detect whether there is a third target rule that intersects with the quintuple information in the third target rule list that matches the third target ACL; when it is detected that there is a third target rule and the processing action of the third target rule is rejection, put the third target ACL and the third target rule ID corresponding to the third target rule into the preset reverse ACL list to be opened.

[0098] Specifically, the port of the third target rule is a preset port number.

[0099] S609: Determine, according to the inbound interface, a fourth target ACL with an outbound direction from among the multiple ACLs.

[0100] S610, detect whether there is a fourth target rule that intersects with the five-tuple information in the fourth target rule list that matches the fourth target ACL; when it is detected that there is a fourth target rule and the processing action of the fourth target rule is reject, put the fourth target ACL and the fourth target rule ID corresponding to the fourth target rule into the reverse ACL list to be opened.

[0101] Specifically, the port of the fourth target rule is a preset port number.

[0102] To facilitate understanding, the following describes in detail how to create a reverse ACL for the inbound and outbound interfaces in this embodiment. 1. Define variables: reverse ACL list to be opened.

[0103] 2. Traverse the outbound interface list and obtain the third target ACL. The binding direction of the third target ACL is in the inbound direction.

[0104] 3. Read the model data corresponding to the third target ACL and obtain the third target rule list corresponding to the third target ACL.

[0105] 4. In ascending order of third rule ID priority, use the quintuple information to intersect the third rules in the third target rule list. However, skip any third rules whose port number is not any (0-65536). The third rule ID is the ID of the third rule.

[0106] 5. If the quintuple information intersects with the third target rule, the quintuple information is split into the intersecting and non-intersecting parts. Depending on whether the third target rule's action is to allow or deny, the intersecting part is either stored in the data stream or denied. The ID of the first third rule with an intersecting part and a deny action is recorded and defined as the conflicting rule ID, which is also the third target rule ID in this embodiment.

[0107] 6. Use the disjoint parts to continue matching the third rules backward in the order of priority of the third rule IDs until all third rules in the third target rule list are matched.

[0108] 7. Check the denied data flow. If it is not empty, add the third target ACL and the third target rule ID to the reverse ACL list to be opened.

[0109] 8. Traverse the inbound interface list to obtain the fourth target ACL. The binding direction of the fourth target ACL is inbound.

[0110] 9. In ascending order of priority of the fourth rule ID, use the quintuple information to intersect the fourth rule in the fourth target rule list. However, skip any fourth rule whose port number is not any (0-65536). It should be understood that the fourth rule ID is the ID of the fourth rule.

[0111] 10. If the quintuple information intersects with the fourth target rule, the quintuple information is split into the intersecting and non-intersecting parts. Depending on whether the fourth target rule's action is to allow or deny, the intersecting part is either stored in the data stream or denied. The ID of the first fourth rule with an intersecting part and a deny action is recorded and defined as the conflicting rule ID, which is also the fourth target rule ID in this embodiment.

[0112] 11. Use the disjoint parts to continue matching the fourth rules backward in the order of priority of the fourth rule IDs until all fourth rules in the fourth target rule list are matched.

[0113] 12. Check the denied data flow. If it is not empty, put the fourth target ACL and the fourth target rule ID into the reverse ACL list to be opened.

[0114] Compared with related technologies, the embodiments of the present application have at least the following advantages: by responding to an ACL creation request, receiving quintuple information and switch attribute information, the switch configuration file and routing table can be obtained based on the attribute information, thereby being able to parse the configuration file and routing table to obtain a routing table model and ACL model. Since the routing table model includes multiple routing tables of different models and a first network interface and subnet matching each routing table, the switch's inbound interface can be determined in the first network interface based on the source IP address and subnet, thereby being able to determine the first target ACL with an inbound binding direction in multiple ACLs based on the inbound interface. By detecting the first target rule that intersects the quintuple information and the first target rule list, since the intersection of the quintuple information and the first target rule list indicates that the user wishes the intersecting quintuple information to pass, when the first target rule is detected and the processing action of the first target rule is reject, the first target ACL and the first target rule ID corresponding to the first target rule are added to the forward ACL list to be activated, thereby achieving automatic creation of an ACL that meets user needs, thereby improving the operation and maintenance efficiency of network operation and maintenance personnel.

[0115] Based on the same concept as the automatic ACL creation method in the above-mentioned embodiment, the present application also provides an automatic ACL creation device, which can be used to execute the above-mentioned automatic ACL creation method. For ease of explanation, the structural diagram of the embodiment of the automatic ACL creation device only shows the parts relevant to the embodiment of the present application. Those skilled in the art will understand that the illustrated structure does not constitute a limitation of the device, and the device may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0116] like Figure 7 As shown, the automatic ACL creation device 70 includes a receiving module 701, an acquisition module 702, a parsing module 703, a first determination module 704, a second determination module 705, a detection module 706, and a creation module 707. In some embodiments, the above modules may be programmable software instructions stored in a memory and executable by a processor. It is understood that in other embodiments, the above modules may also be program instructions or firmware embedded in the processor.

[0117] The receiving module 701 is configured to respond to an ACL creation request and receive five-tuple information and switch attribute information, wherein the five-tuple information includes a source IP address; An acquisition module 702 is configured to acquire a configuration file and a routing table of the switch according to the attribute information; A parsing module 703 is configured to parse the configuration file and the routing table, and establish a routing table model and an ACL model based on the parsing results, wherein the routing table model includes multiple routing tables of different models, and a first network interface and subnet matching each routing table; and the ACL model includes multiple ACLs, and a second network interface matching each ACL, a rule list, a rule ID, and a binding direction between the ACL and the second network interface. A first determining module 704 is configured to determine an inbound interface of the switch in the first network interface according to the source IP address and the subnet; A second determining module 705 is configured to determine, according to the inbound interface, a first target ACL whose binding direction is an inbound direction from among the multiple ACLs; A detection module 706 is configured to detect whether there is a first target rule in the first target rule list matching the first target ACL that has an intersection with the five-tuple information; The creation module 707 is configured to add the first target ACL and the first target rule ID corresponding to the first target rule into a preset forward ACL list to be activated when detecting that the first target rule exists and the processing action of the first target rule is reject.

[0118] The automatic ACL creation device 70 provided in the above embodiment can implement the technical solution described in the above embodiment of the automatic ACL creation method. The specific implementation principles of the above modules or units can be found in the corresponding content of the above embodiment of the automatic ACL creation method, which will not be repeated here.

[0119] Please refer to 8, Figure 8 This is a schematic diagram of an embodiment of an electronic device of the present application.

[0120] In some embodiments, the processor 801 may be a central processing unit (CPU), a microprocessor, or other data processing chip, configured to execute program codes stored in the memory 802 or process data, such as the ACL automatic creation method of the present invention.

[0121] In some embodiments, processor 801 may be a single server or a server group. The server group may be centralized or distributed. In some embodiments, processor 801 may be local or remote. In some embodiments, processor 801 may be implemented on a cloud platform. In one embodiment, the cloud platform may include a private cloud, a public cloud, a hybrid cloud, a community cloud, a distributed cloud, an on-premises cloud, a multi-cloud, or any combination thereof.

[0122] In some embodiments, the memory 802 may be an internal storage unit of the electronic device 800, such as a hard disk or memory of the electronic device 800. In other embodiments, the memory 802 may also be an external storage device of the electronic device 800, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the electronic device 800.

[0123] Furthermore, the memory 802 may include both an internal storage unit of the electronic device 800 and an external storage device. The memory 802 is used to store application software installed in the electronic device 800 and various data.

[0124] In some embodiments, display 803 can be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, or an OLED (Organic Light-Emitting Diode) touchscreen. Display 803 is used to display information on electronic device 800 and to display a visual user interface. Components 801-803 of electronic device 800 communicate with each other via a system bus.

[0125] In one embodiment, when the processor 801 executes the ACL automatic creation program in the memory 802, the following steps may be implemented: In response to the ACL creation request, receiving five-tuple information and attribute information of the switch, wherein the five-tuple information includes a source IP address; Acquire a configuration file and a routing table of the switch according to the attribute information; Parsing the configuration file and the routing table, and establishing a routing table model and an ACL model based on the parsing results, wherein the routing table model includes multiple routing tables of different models, and a first network interface and subnet matching each routing table; and the ACL model includes multiple ACLs, and a second network interface matching each ACL, a rule list, a rule ID, and a binding direction between the ACL and the second network interface; Determine the inbound interface of the switch in the first network interface according to the source IP address and the subnet; Determine, according to the inbound interface, a first target ACL in the plurality of ACLs, wherein the binding direction is an inbound direction; Detect whether there is a first target rule in the first target rule list matching the first target ACL that has an intersection with the five-tuple information; When it is detected that the first target rule exists and the processing action of the first target rule is reject, the first target ACL and the first target rule ID corresponding to the first target rule are added to a preset forward ACL list to be opened.

[0126] It should be understood that, when the processor 801 executes the ACL automatic creation program in the memory 802 , in addition to the above functions, it can also implement other functions. For details, please refer to the description of the corresponding method embodiment above.

[0127] Furthermore, the embodiment of the present invention does not specifically limit the type of the electronic device 800 mentioned. The electronic device 800 may be a portable electronic device such as a mobile phone, a tablet computer, a personal digital assistant (PDA), a wearable device, a laptop computer, or the like. Exemplary embodiments of portable electronic devices include, but are not limited to, portable electronic devices equipped with IOS, Android, Microsoft, or other operating systems. The above-mentioned portable electronic devices may also be other portable electronic devices, such as a laptop computer with a touch-sensitive surface (e.g., a touch panel). It should also be understood that in some other embodiments of the present invention, the electronic device 800 may not be a portable electronic device, but a desktop computer with a touch-sensitive surface (e.g., a touch panel).

[0128] Accordingly, an embodiment of the present application further provides a storage medium for storing a computer-readable program or instruction. When the program or instruction is executed by a processor, the steps or functions of the ACL automatic creation method provided in the above-mentioned method embodiments can be implemented.

[0129] Those skilled in the art will appreciate that all or part of the process flow of the above-described method embodiment can be implemented by instructing related hardware (such as a processor, controller, etc.) through a computer program, and the computer program can be stored in a computer-readable storage medium. The computer-readable storage medium may be a magnetic disk, an optical disk, a read-only memory, or a random access memory.

[0130] The above describes in detail the automatic ACL creation method, apparatus, electronic device, and storage medium provided by this application. Specific examples are used herein to illustrate the principles and implementation methods of this application. The description of the above embodiments is intended only to facilitate understanding of the method and core concepts of this application. Furthermore, those skilled in the art will appreciate that variations in the specific implementation methods and scope of application may occur based on the concepts of this application. Therefore, this specification should not be construed as limiting this application.

Claims

1. A method for automatically creating an ACL, characterized in that: include: In response to the ACL creation request, receiving five-tuple information and attribute information of the switch, wherein the five-tuple information includes a source IP address; Acquire a configuration file and a routing table of the switch according to the attribute information; Parsing the configuration file and the routing table, and establishing a routing table model and an ACL model based on the parsing results, wherein the routing table model includes multiple routing tables of different models, and a first network interface and subnet matching each routing table; and the ACL model includes multiple ACLs, and a second network interface matching each ACL, a rule list, a rule ID, and a binding direction between the ACL and the second network interface; Determine the inbound interface of the switch in the first network interface according to the source IP address and the subnet; Determine, according to the inbound interface, a first target ACL in the plurality of ACLs, wherein the binding direction is an inbound direction; Detect whether there is a first target rule in the first target rule list matching the first target ACL that has an intersection with the five-tuple information; When it is detected that the first target rule exists and the processing action of the first target rule is reject, the first target ACL and the first target rule ID corresponding to the first target rule are added to a preset forward ACL list to be opened.

2. The ACL automatic creation method according to claim 1, characterized in that: The first target rule list includes a plurality of first rules, each of the first rules includes a corresponding first rule ID; The detecting whether there is a first target rule in the first target rule list matching the first target ACL that has an intersection with the five-tuple information includes: Matching the five-tuple information with the plurality of first rules in the first target rule list in sequence according to the preset priority of the first rule ID; If the matching result is that the quintuple information and the first target rule in the plurality of first rules have an intersection, splitting the quintuple information into an intersecting part and a non-intersecting part, wherein the rule ID of the first target rule is the first target rule ID; The disjoint portion is matched with the rules in the first target rule list whose priority is greater than the first target rule ID, until all the first rules in the first target rule list are matched.

3. The ACL automatic creation method according to claim 2, characterized in that: The matching of the five-tuple information with the plurality of first rules in the first target rule list in sequence according to the preset priority of the first rule ID includes: Arrange the first rule IDs in ascending order of priority, and match the quintuple information with the plurality of first rules in sequence according to the order of priority; The method further comprises: In response to the rule ID generation request, determining a comparison rule ID that precedes the first target rule ID according to the priority order; Calculating the difference between the first target rule ID and the comparison rule ID; If the difference is greater than 1, the newly generated rule ID is set to the average of the first target rule ID and the comparison rule ID; When the difference is equal to 1, the newly generated rule ID is set to the opposite number of the first target rule ID.

4. The ACL automatic creation method according to claim 1, characterized in that: The five-tuple information also includes a destination IP address; and the method further includes: Determine the outgoing interface of the switch in the first network interface according to the destination IP address and the subnet; Determine, according to the outbound interface, a second target ACL in the plurality of ACLs, wherein the binding direction is an outbound direction; Detect whether there is a second target rule in the second target rule list matching the second target ACL that has an intersection with the five-tuple information; When it is detected that the second target rule exists and the processing action of the second target rule is reject, the second target ACL and the second target rule ID corresponding to the second target rule are added to the forward ACL list to be opened.

5. The ACL automatic creation method according to claim 4, characterized in that: The five-tuple information also includes protocol information and destination port; In the case where the protocol information is the TCP protocol, the method further includes: Swapping the source IP address with the destination IP address to obtain a new source IP address and a new destination IP address, and setting the destination port to a preset port number; Determine, according to the outbound interface, a third target ACL from the plurality of ACLs, the binding direction of which is an inbound direction; Detecting whether there is a third target rule in the third target rule list that matches the third target ACL that has an intersection with the quintuple information, wherein the port of the third target rule is the preset port number; When it is detected that the third target rule exists and the processing action of the third target rule is reject, the third target ACL and the third target rule ID corresponding to the third target rule are put into a preset reverse ACL list to be opened.

6. The ACL automatic creation method according to claim 5, characterized in that: The method further comprises: Determine, according to the inbound interface, a fourth target ACL from the plurality of ACLs, the binding direction of which is an outbound direction; Detecting whether there is a fourth target rule in a fourth target rule list that matches the fourth target ACL that has an intersection with the quintuple information, wherein the port of the fourth target rule is the preset port number; When it is detected that the fourth target rule exists and the processing action of the fourth target rule is reject, the fourth target ACL and the fourth target rule ID corresponding to the fourth target rule are added to the reverse ACL list to be opened.

7. The method for automatically creating an ACL according to any one of claims 1 to 6, characterized in that: The attribute information includes the switch manufacturer model; The acquiring the configuration file and routing table of the switch according to the attribute information includes: Determining a configuration command for the switch according to the switch manufacturer and model; The switch is connected via a secure shell protocol, and the switch is controlled to execute the configuration command to obtain the configuration file and the routing table.

8. An ACL automatic creation device, characterized in that: include: A receiving module, an acquiring module, a parsing module, a first determining module, a second determining module, a detecting module, and a creating module; The receiving module is used to respond to the ACL creation request and receive quintuple information and attribute information of the switch, wherein the quintuple information includes a source IP address; The acquisition module is used to acquire the configuration file and routing table of the switch according to the attribute information; The parsing module is used to parse the configuration file and the routing table, and establish a routing table model and an ACL model based on the parsing results, wherein the routing table model includes multiple routing tables of different models, and a first network interface and subnet matching each routing table; the ACL model includes multiple ACLs, and a second network interface matching each ACL, a rule list, a rule ID, and a binding direction between the ACL and the second network interface; The first determining module is configured to determine the inbound interface of the switch in the first network interface according to the source IP address and the subnet; The second determining module is configured to determine, according to the inbound interface, a first target ACL whose binding direction is an inbound direction from among the multiple ACLs; The detection module is used to detect whether there is a first target rule in the first target rule list that matches the first target ACL that has an intersection with the five-tuple information; The creation module is configured to, when detecting that the first target rule exists and the processing action of the first target rule is reject, add the first target ACL and the first target rule ID corresponding to the first target rule to a preset forward ACL list to be opened.

9. An electronic device comprising a processor and a memory, characterized in that: The memory is used to store instructions, and the processor is used to call the instructions in the memory, so that the electronic device executes the ACL automatic creation method according to any one of claims 1 to 7.

10. A storage medium, characterized in that: The storage medium stores computer instructions, and when the computer instructions are executed on an electronic device, the electronic device executes the ACL automatic creation method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Intelligent question answering method based on network security equipment question, electronic equipment and medium

    CN116737901A

  • Centralized Management and Distributed Enforcement of Policies for Network Segmentation

    US20210352013A1

  • Data transmission method and related device

    WO2024113776A1