Security constant value strategy configuration method, system and equipment based on simulation test technology and storage medium

By constructing a virtual network topology environment and performing simulation tests on execution strategies, the consistency and efficiency issues in existing security setting strategy configurations were resolved, achieving standardized and controllable strategy configuration management and improving the accuracy and traceability of configurations.

CN120956501APending Publication Date: 2025-11-14NARI INFORMATION & COMM TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511186929.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-25
Publication Date
2025-11-14

AI Technical Summary

Technical Problem

Existing security setting policy configuration methods suffer from problems such as fragmented processes, lack of standardized verification, insufficient simulation verification capabilities, inconsistent interface calls, and lack of configuration archiving. These issues result in inconsistent policy content, low operational efficiency, and difficulty in meeting the requirements of network security visualization, controllability, and auditability.

Method used

By using simulation testing technology, a virtual network topology environment is constructed, policy simulation tests are performed, and the compliance verification and optimization of standardized security setting documents are realized. Based on the device type, the interface is called to remotely configure and distribute policies, and version archiving management is carried out to form a closed-loop process.

Benefits of technology

It improves the accuracy and consistency of policy configuration, ensures the controllability and traceability of the configuration process, enhances the management level and system operating efficiency of various security policies, and strengthens the adaptability and consistency across device environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120956501A_ABST
    Figure CN120956501A_ABST
Patent Text Reader

Abstract

The invention discloses a security fixed value strategy configuration method, system and device based on a simulation test technology and a storage medium, and relates to the technical field of electric power information security, and the method comprises the steps: binding a standardized security fixed value file according with a preset specification with an appointed issuing application form through configuration application operation; performing content compliance verification on the standardized security constant value file according to the auditing rule; constructing a virtual network topology environment according to a target actual network structure, configuring virtual security node network parameters, loading a standardized security fixed value file to a target virtual security node, completing simulation link setting and executing a strategy simulation test; after simulation verification is passed, interfaces are called in a differentiated mode according to equipment types to conduct strategy remote configuration issuing, and standardized security and protection constant value files are archived according to version indexes; according to the method disclosed by the invention, standardized modeling, simulation verification and classified remote issuing of security fixed value strategy configuration are realized, and an automatic strategy management mechanism which can be traced in the whole process is constructed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power information security technology, specifically to a method, system, device, and storage medium for configuring security setting strategies based on simulation testing technology. Background Technology

[0002] Power monitoring systems are used to monitor and control the processes of power production, transmission, and dispatch. They consist of business systems, intelligent terminals, and communication and data networks. With the continuous advancement of power information technology construction, the network structure of power monitoring systems is becoming increasingly complex, and the demand for security protection is significantly increasing. To ensure the integrity, confidentiality, and controllability of network communication, security protection measures such as encryption authentication, access control, boundary isolation, and intrusion detection are widely deployed. These security strategies rely on a large number of security configuration files for implementation. Currently, security configuration files are mainly manually compiled and distributed by maintenance personnel. Management processes mostly rely on offline work orders and on-site configuration methods, resulting in opaque approval processes, numerous operational steps, low efficiency, and difficulty in ensuring the standardization and consistency of policy content.

[0003] In the early stages of configuration, the lack of a unified data structure and field specifications led to inconsistent formatting of configuration files created by different personnel. This made it difficult to verify the completeness and logical correctness of the content, resulting in issues such as rule conflicts, port redundancy, and disordered access control chains. Furthermore, the diverse types of devices and inconsistent protocols meant that configuration interfaces lacked a unified standard. The policy configuration methods for different types of security devices varied significantly, making policy files difficult to reuse across devices, and the interface adaptation process heavily reliant on manual intervention. After configuration, the lack of a pre-deployment verification mechanism meant that most policies could not be verified for path detection and logical matching in real or simulated network environments. If communication anomalies or policy conflicts occurred after policy deployment, rework and troubleshooting were frequently required, consuming significant manpower and time. Most operations lacked standardized archiving procedures, resulting in missing records of configuration version changes and difficulties in operation traceability and configuration tracking, failing to meet the requirements of critical infrastructure for network security visualization, controllability, and auditability. Summary of the Invention

[0004] In view of the above-mentioned problems, the present invention is proposed.

[0005] Therefore, the technical problem solved by this invention is that existing security setting strategy configuration methods suffer from problems such as fragmented processes, lack of standardized verification, insufficient simulation verification capabilities, inconsistent interface calls, and lack of configuration archiving. The invention also addresses how to achieve standardized binding, automatic verification, virtual topology verification, and classified configuration distribution of security setting files.

[0006] To address the aforementioned technical problems, this invention provides the following technical solution: a security setting policy configuration method based on simulation testing technology, comprising: binding a standardized security setting file conforming to preset specifications and a designated issuance application form through a configuration application operation; performing content compliance verification on the standardized security setting file according to review rules; constructing a virtual network topology environment based on the actual target network structure; configuring network parameters of virtual security nodes; loading the standardized security setting file to the target virtual security node; completing the simulation link setting and executing policy simulation testing; after simulation verification, remotely distributing policy configurations by calling interfaces according to device type; and archiving the standardized security setting file by version index.

[0007] As a preferred embodiment of the security setting policy configuration method based on simulation testing technology described in this invention, the content compliance verification includes checking the field integrity and policy format standardization of the standardized security setting file, and implementing policy optimization; the policy optimization includes functions that can be selected by the user before the policy is issued, including analyzing and optimizing access rule logic conflicts, port parameter redundancy and policy structure redundancy, and supporting users to select some or all optimization items for non-mandatory optimization operations.

[0008] As a preferred embodiment of the security fixed-value strategy configuration method based on simulation testing technology described in this invention, the construction of the virtual network topology environment includes: incubating the prepared virtual network topology and binding the target virtual security node; when incubation fails, returning to re-perform content compliance verification; when incubation is successful, incubating the network topology result into the virtual network topology file for backup management and parallel distribution.

[0009] As a preferred embodiment of the security fixed-value policy configuration method based on simulation testing technology described in this invention, the simulation link setting includes selecting two points in the virtual security node as link endpoints, establishing a link communication path for policy matching verification, and configuring data packet forwarding policies and link status parameters.

[0010] As a preferred embodiment of the security setting strategy configuration method based on simulation testing technology described in this invention, the strategy simulation test includes: writing a standardized security setting file into a virtual security node, and then, based on the set link start node and end node, performing a network link connectivity test in a constructed virtual network topology environment, and recording unreachable path link interruption information and node abnormal status.

[0011] As a preferred embodiment of the security setting policy configuration method based on simulation testing technology described in this invention, the step of distinguishing the calling interface according to the device type includes, when the security setting file includes encryption and monitoring policy items, calling the policy writing interface through the TCP proxy service, and executing the configuration distribution by calling the policy writing interface based on the SO dynamic library.

[0012] As a preferred embodiment of the security setting strategy configuration method based on simulation testing technology described in this invention, the method of distinguishing the calling interface according to the device type further includes, when the security setting file content includes firewall, switch and router content information, configuration is distributed based on a predefined standardized configuration interface.

[0013] Another objective of this invention is to provide a security setting policy configuration system based on simulation testing technology. This system can solve the problems of fragmented processes, lack of verification mechanisms, inconsistent policy distribution methods, and untraceable configurations in current security setting policy configuration systems by integrating configuration application binding, content compliance verification, virtual topology construction, policy simulation verification, and typed interface calls.

[0014] As a preferred embodiment of the security setting policy configuration system based on simulation testing technology described in this invention, it includes: a setting value verification and binding module, a topology simulation verification module, and a classification policy distribution and archiving module; the setting value verification and binding module is used to bind a standardized security setting file conforming to preset specifications with a specified distribution application form through a configuration application operation, and to perform compliance verification on the standardized security setting file for field integrity and policy format standardization according to the review rules; the topology simulation verification module is used to construct a virtual network topology environment based on the actual target network structure, incubate the prepared virtual network topology and configure the network parameters of virtual security nodes, and after the standardized security setting file is loaded into the target virtual security node, to set the simulation link and execute policy simulation testing; the classification policy distribution and archiving module is used to remotely configure and distribute policies according to device type after passing simulation verification, including the distribution of security device policies for vertical and monitoring through TCP proxy and SO dynamic library. When the security setting file content includes firewall, switch and router content information, configuration distribution is performed based on a predefined standardized configuration interface, and the standardized security setting file is archived and managed by version index.

[0015] A computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement a security setting strategy configuration method based on simulation testing technology.

[0016] A computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the steps of a security setting strategy configuration method based on simulation testing technology are disclosed.

[0017] The beneficial effects of this invention are as follows: The security setting policy configuration method based on simulation testing technology provided by this invention can identify potential conflicts and abnormal paths before policy configuration by constructing a virtual network topology environment and executing policy simulation tests, thereby improving policy accuracy. By introducing standardized security setting files and a configuration application binding mechanism, it ensures that the policy content structure is unified and the fields are standardized, thereby improving the controllability and consistency of the configuration process. By constructing a complete policy configuration lifecycle management mechanism through policy review, remote distribution, and version archiving, it realizes a closed-loop process from policy configuration generation to execution and deployment, improves the refined management level and configuration security of multiple types of security policies, and enhances the adaptability consistency and overall system operating efficiency in cross-device environments. This invention achieves better results in terms of policy verification accuracy, configuration process standardization, and multi-device adaptation efficiency. Attached Figure Description

[0018] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 The flowchart shows the overall process of the security setting strategy configuration method based on simulation testing technology provided in Embodiment 1 of the present invention.

[0020] Figure 2 This is a flowchart of the strategy simulation test for the security setting strategy configuration method based on simulation test technology provided in Embodiment 2 of the present invention. Detailed Implementation

[0021] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.

[0022] Example 1, referring to Figure 1 - Figure 2 As an embodiment of the present invention, a security setting strategy configuration method based on simulation testing technology is provided, including:

[0023] S1: By configuring the application operation, the standardized security value file that meets the preset specifications is bound to the designated application form, and the compliance of the standardized security value file is verified according to the audit rules.

[0024] Furthermore, content compliance verification includes checking the completeness of fields and the standardization of policy format in standardized security setting files, and implementing policy optimization. Policy optimization includes functions that users can choose to execute before policy issuance, including analyzing and optimizing access rule logic conflicts, port parameter redundancy, and policy structure redundancy, and supporting users to select some or all optimization items for non-mandatory optimization operations.

[0025] It should be noted that the configuration application operation includes establishing a binding relationship between the standardized security setting file that conforms to the preset specifications and the designated application form. The system then registers the binding relationship structurally and generates a unique configuration identifier for the policy configuration operation, ensuring that the policy's lifecycle is traceable and the configuration version is trackable.

[0026] It should be noted that the analysis and optimization of access rule logic conflicts, port parameter redundancy and policy structure redundancy include the system constructing a policy chain model to perform graph structure analysis on the execution order, priority relationship and hit path between policy items, identify whether there are redundant definitions, dead rules and unreachable paths within the policy set, and the verification process is based on the policy-level logic graph, combined with the preset access path logic rules, to supplement potential logical vulnerabilities that are difficult to find in traditional static field comparison.

[0027] It should be noted that the analysis and optimization of access rule logical conflicts, port parameter redundancy, and policy structure redundancy also include, in response to the redundancy and overlap of port parameters, the system converts the port range into a set of intervals during the verification process, performs interval intersection, union, and difference operations on the port sets between different policies, identifies parameter coverage conflicts, and constructs a rule hash index table using a five-tuple matching pattern (source address, destination address, protocol, source port, destination port) to support efficient detection of rule duplication and logical nesting issues.

[0028] It should also be noted that by configuring application binding and content compliance verification, field integrity can be completed before policy issuance, ensuring that the policy structure is standardized and logically closed, providing highly consistent input for subsequent policy simulation testing and remote issuance, and improving configuration accuracy and system stability.

[0029] S2: Construct a virtual network topology environment based on the actual target network structure, configure the network parameters of the virtual security nodes, load the standardized security setting file into the target virtual security nodes, complete the simulation link setting, and execute the strategy simulation test.

[0030] Furthermore, constructing a virtual network topology environment includes incubating the prepared virtual network topology and binding it to the target virtual security node; when incubation fails, returning to re-verify the content compliance; when incubation is successful, incubating the network topology results into the virtual network topology archive for backup management and parallel distribution.

[0031] It should be noted that the simulation link settings include selecting two points in the virtual security node as link endpoints, establishing a link communication path for policy matching verification, and configuring packet forwarding policies and link status parameters.

[0032] It should be noted that the strategy simulation test includes writing the standardized security setting file into the virtual security node, and then conducting network link connectivity tests in the constructed virtual network topology environment based on the set link start and end nodes, recording unreachable path link interruption information and node abnormal status.

[0033] The system simulates business data flow in a virtual topology, captures the communication path of matching links, policy hit sequence and node forwarding status in real time, records policy priority configuration and logical conflict, and identifies abnormal blocking points such as path interruption, policy false rejection and port blocking. Finally, it generates a simulation test report for reference in policy adjustment and configuration verification.

[0034] It should also be noted that the incubation of the prepared virtual network topology includes verifying the connectivity of logical links between virtual security nodes, identifying loop structures, detecting node IP address conflicts, and confirming topology boundaries. When structural conflicts, address duplication, or illegal routing paths are detected in the topology, the system automatically interrupts the incubation process and returns to the content compliance verification process to re-verify the mapping relationship between the standardized security value file and the topology. When the incubation operation is successful, the system will generate a topology version identifier and store the incubated network topology result in the virtual network topology archive for subsequent testing processes. At the same time, the topology structure can be distributed to the simulation engine to start the policy injection task in parallel.

[0035] It should also be noted that the network parameters of the virtual security node include a unique IP address, MAC address, subnet mask, default gateway address, static routing table, and interface number.

[0036] It should also be noted that by constructing a virtual network topology environment consistent with the actual network structure, and executing the topology incubation, network parameter configuration, link setting, and policy simulation testing process, the standardized security setting files are effectively verified in the simulation environment. This ensures the logical closed loop of the configuration links and the accuracy of policy matching, and can detect configuration errors and potential conflicts in advance, thereby improving the verification efficiency of setting policies and the reliability of configuration distribution.

[0037] S3: After simulation verification, the system calls the interface to remotely configure and distribute policies based on the device type, and archives the standardized security setting files by version index.

[0038] Furthermore, based on the device type, the calling interface is differentiated as follows: when the security setting file includes encryption and monitoring policy items, the policy writing interface is called through the TCP proxy service, and the configuration is distributed by calling the policy writing interface based on the SO dynamic library.

[0039] It should be noted that distinguishing the calling interface based on device type also includes, when the security configuration file contains information about firewalls, switches, and routers, configuration is distributed based on a predefined standardized configuration interface.

[0040] It should also be noted that the predefined standardized configuration interface includes a unified policy parameter transmission structure for common network devices such as firewalls, routers, and switches. It supports passing access control, port forwarding, and bandwidth limiting through the standardized interface, and automatically matches and adapts templates to generate corresponding SSH configuration commands based on device type. The standardized configuration interface is bound during the device and virtual security node registration phase, and supports automatic command injection when policies are issued, enabling remote configuration and deployment of policy content.

[0041] It should also be noted that after configuration, a fixed value version index number is generated based on the unique configuration identifier, topology version identifier, and configuration timestamp, and an archive path corresponding to the current index number is constructed. The standardized security fixed value files used in the configuration process, the call interface types, the target device response logs, and the policy topology are all encapsulated and written into the standardized configuration archive directory to realize version retrieval and traceability management of security fixed value files.

[0042] It should also be noted that by differentiating the calling interfaces based on device type and combining them with a predefined standardized configuration structure, remote automated configuration and distribution of multiple security policy items are achieved, enhancing the system's adaptability to encryption, monitoring, boundary control, and data forwarding policies. By constructing a fixed-value version index using configuration identifiers, topology versions, and timestamps, and by archiving and managing the entire configuration process data, unified recording, traceability, and tracking of the configuration process are achieved, improving the standardization, consistency, and controllability of policy configuration in multi-device environments.

[0043] Example 2, an embodiment of the present invention, provides a security setting policy configuration system based on simulation testing technology, including a setting verification and binding module, a topology simulation verification module, and a classification policy distribution and archiving module.

[0044] The value verification and binding module is used to bind standardized security value files that conform to preset specifications to a specified application form through configuration application operations, and to perform compliance verification on the standardized security value files for field integrity and policy format standardization according to the review rules.

[0045] The topology simulation verification module is used to construct a virtual network topology environment based on the actual network structure of the target. It incubates the prepared virtual network topology and configures the network parameters of the virtual security nodes. After the standardized security setting file is loaded into the target virtual security node, the simulation link is set and the policy simulation test is executed.

[0046] The classification policy distribution and archiving module is used to remotely configure and distribute policies based on device type after simulation verification. This includes distributing security policies for surveillance and monitoring devices via TCP proxy and SO dynamic library. When the security setting file contains information about firewalls, switches, and routers, the configuration is distributed based on a predefined standardized configuration interface. At the same time, the standardized security setting file is archived and managed by version index.

Claims

1. A security setting strategy configuration method based on simulation testing technology, characterized in that, include: By configuring the application process, the standardized security value file that conforms to the preset specifications is bound to the designated application form, and the compliance of the standardized security value file is verified according to the review rules. Based on the actual network structure of the target, a virtual network topology environment is constructed, the network parameters of the virtual security nodes are configured, the standardized security setting file is loaded into the target virtual security nodes, the simulation link is set up, and the strategy simulation test is executed. After simulation verification, the policy is remotely configured and distributed by calling the interface according to the device type, and the standardized security setting files are archived by version index.

2. The security setting strategy configuration method based on simulation testing technology as described in claim 1, characterized in that: The content compliance verification includes, Check the completeness of fields and the standardization of policy format in the standardized security setting files, and optimize the policies accordingly; The strategy optimization includes functions that users can choose to execute before the strategy is issued, including analyzing and optimizing access rule logic conflicts, port parameter redundancy, and strategy structure redundancy, and supporting users to select some or all optimization items for non-mandatory optimization operations.

3. The security setting strategy configuration method based on simulation testing technology as described in claim 1 or 2, characterized in that: The construction of the virtual network topology environment includes The prepared virtual network topology is incubated and bound to the target virtual security node; If incubation fails, return to perform content compliance verification again; When incubation is successful, the incubated network topology results are included in the virtual network topology archive for backup management and distributed in parallel.

4. The security setting strategy configuration method based on simulation testing technology as described in claim 3, characterized in that: The simulation link settings include, Two points in the virtual security node are selected as link endpoints to establish a link communication path for policy matching verification, and packet forwarding policies and link status parameters are configured.

5. The security setting strategy configuration method based on simulation testing technology as described in any one of claims 1, 2, or 4, characterized in that: The strategy simulation test includes, After writing the standardized security setting file into the virtual security node, network link connectivity test is performed in the constructed virtual network topology environment based on the set link start and end nodes, and information on unreachable path link interruption and node abnormal status is recorded.

6. The security setting strategy configuration method based on simulation testing technology as described in claim 5, characterized in that: The distinction between calling interfaces based on device type includes... When the security configuration file includes encryption and monitoring policy items, the policy writing interface is called through the TCP proxy service, and the configuration is distributed by calling the policy writing interface based on the SO dynamic library.

7. The security setting strategy configuration method based on simulation testing technology as described in any one of claims 1, 2, 4, or 6, characterized in that: The method of distinguishing the calling interface based on device type also includes When the security configuration file includes information about firewalls, switches, and routers, the configuration is distributed based on a predefined, standardized configuration interface.

8. A security setting strategy configuration system based on simulation testing technology, employing the security setting strategy configuration method based on simulation testing technology as described in any one of claims 1 to 7, characterized in that: This includes a fixed value verification and binding module, a topology simulation verification module, and a classification strategy distribution and archiving module; The value verification and binding module is used to bind a standardized security value file that conforms to the preset specifications to a specified application form through the configuration application operation, and to perform compliance verification on the standardized security value file for field integrity and policy format standardization according to the review rules. The topology simulation verification module is used to construct a virtual network topology environment based on the actual target network structure, incubate the prepared virtual network topology and configure the network parameters of the virtual security nodes. After the standardized security value file is loaded into the target virtual security node, the simulation link is set and the policy simulation test is executed. The module analyzes and optimizes access rule logic conflicts, port parameter redundancy and policy structure redundancy, and supports users to select some or all optimization items for non-mandatory optimization operations. The classification strategy distribution and archiving module is used to remotely configure and distribute policies based on the device type after simulation verification. This includes distributing security device policies for in-depth monitoring and surveillance through TCP proxy and SO dynamic library. When the security setting file contains information about firewalls, switches, and routers, the configuration is distributed based on a predefined standardized configuration interface. At the same time, the standardized security setting file is archived and managed by version index.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the security setting strategy configuration method based on simulation testing technology as described in any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the security setting strategy configuration method based on simulation testing technology as described in any one of claims 1 to 7.