Visualization method and system of network security policy, electronic equipment and medium

By constructing a traffic-policy matching matrix and a policy conflict propagation chain, and generating highlighted patterns for visualization, this solves the problem that existing network security visualization systems struggle to display the dynamic impact of policy changes, thereby improving the efficiency of network security policy visualization and the administrator's policy analysis capabilities.

CN120956502APending Publication Date: 2025-11-14北京志凌海纳科技股份有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511192670.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-25
Publication Date
2025-11-14

AI Technical Summary

Technical Problem

Existing network security visualization systems lack the ability to display the dynamic impact of policy changes when showing network traffic, making it difficult to quickly identify key security information and intuitively understand the actual scope and potential impact of policies, thus reducing the efficiency of network security policy visualization.

Method used

By acquiring network traffic information and security policy information, a traffic-policy matching matrix is ​​constructed to identify differential traffic. Based on the differential traffic, a policy conflict propagation chain is built, the attenuation coefficient is calculated, and a highlighted pattern is generated for visualization, which intuitively reflects the security characteristics and propagation impact of differential traffic.

Benefits of technology

It enables accurate identification of different types of data streams and precise location of security policy conflicts, improves the efficiency of visualizing network security policies, and helps administrators quickly locate anomalies and conflicts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120956502A_ABST
    Figure CN120956502A_ABST
Patent Text Reader

Abstract

The invention discloses a visualization method and system of a network security policy, electronic equipment and a medium, and relates to the technical field of image processing. The method comprises the following steps: acquiring network traffic information containing source and destination addresses and traffic size, and security policy information containing firewall black and white lists; classifying the network traffic into unprotected, protected, rejected and default allowed according to a preset security state; constructing a traffic-strategy matching matrix to identify differential traffic in various data streams; constructing a network node connection relation and a strategy conflict propagation chain based on the difference traffic, and calculating a propagation chain attenuation coefficient; calculating the width of a connecting line and the arrow size according to the flow to generate a highlight pattern; and setting the transparency and color of the pattern in combination with the attenuation coefficient, and visually displaying the difference traffic in the topology view. By implementing the technical scheme provided by the invention, the visual display efficiency of the network security policy can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of image processing technology, specifically to a visualization method, system, electronic device, and medium for network security strategies. Background Technology

[0002] With the rapid development of information technology and the continuous expansion of network scale, enterprise network environments are becoming increasingly complex, and network security threats are showing a trend towards diversification and complexity. To ensure network security, enterprises typically deploy various security devices and policies, including firewalls, intrusion detection systems, and access control lists. These security policies collectively constitute the enterprise network's security protection system. Due to the increasing complexity of network security management, visualization technology is widely used in the field of network security policy management, helping administrators intuitively understand the network security status through graphical means.

[0003] Currently, existing network security visualization systems can display network traffic information and security policy information in the form of graphical interfaces. However, in practical applications, existing security policy visualization systems typically use a uniform display standard for static display when showing network traffic, generally lacking the ability to display the "dynamic impact" of policy changes. They also struggle to provide targeted visual representations based on differences in traffic characteristics and security status, making it difficult for administrators to quickly identify key security information and intuitively understand the actual scope and potential impact of policies, thus reducing the efficiency of network security policy visualization. Summary of the Invention

[0004] This application provides a method, system, electronic device, and medium for visualizing network security strategies, which can improve the efficiency of visualizing network security strategies.

[0005] Firstly, this application provides a method for visualizing network security strategies, including: Obtain network traffic information and user-set security policy information, wherein the network traffic information includes source address, destination address and traffic volume, and the security policy information includes firewall whitelist and firewall blacklist; The network traffic information is divided into multiple types of data streams according to a preset security status, including unprotected, protected, denied, and allowed by default. A traffic-policy matching matrix is ​​constructed based on the network traffic information and the security policy information, and the traffic-policy matching matrix is ​​used to identify the different traffic in each type of data stream. Based on the source and destination addresses in the differential traffic, a network node connection relationship is constructed. Taking the network node corresponding to the differential traffic as the starting node, a policy conflict propagation chain is constructed based on the network node connection relationship, and the attenuation coefficient of the policy conflict propagation chain is calculated. The width of the data stream connection and the size of the arrow triangle are calculated based on the traffic volume, and a highlight pattern for identifying the differential traffic volume is generated based on the width of the data stream connection and the size of the arrow triangle. The transparency and color of the highlighted pattern are set according to the attenuation coefficient of the policy conflict propagation chain, and the differential traffic is visualized in the global topology view and the security policy topology view.

[0006] By adopting the above technical solution, network traffic information and security policy information are acquired, and network traffic is classified according to preset security status, enabling accurate identification of different types of data flows. Furthermore, by constructing a traffic-policy matching matrix to identify differential traffic, and building a policy conflict propagation chain and calculating attenuation coefficients based on these differential traffic flows, the propagation path of security policy conflicts can be accurately tracked. Simultaneously, by calculating the line width and arrow size based on traffic volume to generate highlighted patterns, and combining the attenuation coefficient with transparency and color settings for visualization, the security characteristics and propagation impact of different differential traffic flows can be intuitively reflected. This helps administrators quickly locate anomalies and conflicts in network security policies, improving the efficiency of network security policy visualization.

[0007] Optionally, based on the network traffic information, the source address and destination address of each type of data flow are extracted as corresponding traffic identifiers; the policy rules in the firewall whitelist and the firewall blacklist are parsed to obtain the matching conditions and execution actions of the policy rules, wherein the matching conditions of the policy rules follow priority decision-making; each traffic identifier is compared with the matching conditions of the policy rules to construct the traffic-policy matching matrix, wherein the traffic-policy matching matrix records the policy rules and execution actions corresponding to each traffic identifier; the expected security status of each type of data flow is determined according to the execution actions in the traffic-policy matching matrix; the actual security status of each type of data flow is compared with the corresponding expected security status, and data flows with inconsistent security status are marked as differential traffic.

[0008] Optionally, allowable policy rules are extracted from the firewall whitelist, and prohibitive policy rules are extracted from the firewall blacklist; the source address and destination address in each traffic identifier are matched with the allowable policy rules and the prohibitive policy rules, respectively; when a traffic identifier matches multiple policy rules, the final applicable action is determined according to the priority of the policy rules; based on the matching results, a traffic-policy matching matrix is ​​generated, including the traffic identifier, the policy rules matched by the traffic identifier, and the corresponding action.

[0009] Optionally, the source and destination addresses in the differential traffic are used as network nodes, and the network node connection relationship is constructed according to the data flow direction; a network node with policy execution deviation is selected as the initial conflict node; starting from the initial conflict node, the propagation search is carried out in the downstream and upstream directions along the network node connection relationship to construct the policy conflict propagation chain; the attenuation coefficient of each node on the propagation path is calculated according to the propagation distance and the number of node connections of the policy conflict propagation chain.

[0010] Optionally, the propagation distance is calculated as the number of propagation steps between each node in the strategy conflict propagation chain and the initial conflict node; the number of connection edges of each node in the network node connection relationship is counted; a distance attenuation factor is set based on the propagation distance, and the distance attenuation factor is positively correlated with the propagation distance; a node influence factor is set based on the number of connection edges, and the node influence factor is positively correlated with the number of connection edges; the distance attenuation factor and the node influence factor of each node are weighted and calculated to determine the attenuation coefficient of each node.

[0011] Optionally, the baseline width of the data stream connection is corrected based on the traffic volume to obtain the data stream connection width; the size of the arrow triangle is calculated based on the data stream connection width; a highlighted rectangular pattern is generated based on the data stream connection width, and a highlighted triangle pattern is generated based on the arrow triangle size; the highlighted rectangular pattern is set on the data stream connection line, and the highlighted triangle pattern is set at the arrow position to obtain a highlighted pattern used to identify the differential traffic volume.

[0012] Optionally, the color of the highlighted pattern is determined according to a preset pattern color template library and the type corresponding to the differential traffic; the transparency of the highlighted pattern is calculated based on the attenuation coefficient, wherein the transparency is positively correlated with the attenuation coefficient; the color and the transparency are input as parameters into the color attribute of the highlighted pattern to generate a highlighted pattern with the specified color and transparency; a global topology view containing all network nodes and data flow connections is constructed, and a security policy topology view containing network nodes and associated data flow connections in the policy conflict propagation chain is constructed; the highlighted pattern is overlaid at the position corresponding to the differential traffic in the global topology view and the security policy topology view.

[0013] A second aspect of this application provides a visualization system for network security strategies, the system comprising: The information acquisition module is used to acquire network traffic information and user-set security policy information. The network traffic information includes source address, destination address and traffic size. The security policy information includes firewall whitelist and firewall blacklist. The differential traffic determination module is used to classify the network traffic information into multiple types of data streams according to a preset security status, including unprotected, protected, denied, and default allowed; to construct a traffic-policy matching matrix based on the network traffic information and the security policy information; and to identify differential traffic in each type of data stream through the traffic-policy matching matrix. The pattern generation module is used to construct network node connection relationships based on the source address and destination address in the differential traffic, take the network node corresponding to the differential traffic as the starting node, construct a policy conflict propagation chain based on the network node connection relationship, and calculate the attenuation coefficient of the policy conflict propagation chain; calculate the data flow connection width and arrow triangle size based on the traffic size, and generate a highlighted pattern to identify the differential traffic based on the data flow connection width and the arrow triangle size. The visualization module is used to set the transparency and color of the highlighted pattern in conjunction with the attenuation coefficient of the policy conflict propagation chain, and to visualize the differential traffic in the global topology view and the security policy topology view.

[0014] A third aspect of this application provides an electronic device including a memory, a processor, and a program stored in the memory and executable on the processor, the program being able to implement a method for visualizing a network security strategy when loaded and executed by the processor.

[0015] A fourth aspect of this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, causes the processor to implement a method for visualizing a network security strategy.

[0016] In summary, one or more technical solutions provided in this application have at least the following technical effects or advantages: By adopting the above technical solution, network traffic information and security policy information are acquired, and network traffic is classified according to preset security status, enabling accurate identification of different types of data flows. Furthermore, by constructing a traffic-policy matching matrix to identify differential traffic, and building a policy conflict propagation chain and calculating attenuation coefficients based on these differential traffic flows, the propagation path of security policy conflicts can be accurately tracked. Simultaneously, by calculating the line width and arrow size based on traffic volume to generate highlighted patterns, and combining the attenuation coefficient with transparency and color settings for visualization, the security characteristics and propagation impact of different differential traffic flows can be intuitively reflected. This helps administrators quickly locate anomalies and conflicts in network security policies, improving the efficiency of network security policy visualization. Attached Figure Description

[0017] Figure 1 This is a flowchart illustrating a method for visualizing network security strategies provided in an embodiment of this application; Figure 2 This is a schematic diagram of the structure of a network security strategy visualization system provided in an embodiment of this application; Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.

[0018] Explanation of reference numerals in the attached drawings: 300, electronic device; 301, processor; 302, communication bus; 303, user interface; 304, network interface; 305, memory. Detailed Implementation

[0019] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments.

[0020] In the description of the embodiments of this application, the words "for example" or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design that is described as "for example" or "for instance" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design options. Rather, the use of the words "for example" or "for instance" is intended to present the relevant concepts in a specific manner.

[0021] In the description of the embodiments of this application, the term "multiple" means two or more. For example, multiple systems means two or more systems, and multiple screen terminals means two or more screen terminals. Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the indicated technical features. Thus, a feature defined with "first" or "second" may explicitly or implicitly include one or more of that feature. The terms "comprising," "including," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.

[0022] In actual network operations and maintenance, administrators typically need to first set up a "enabled but not yet effective" monitoring mode for security policies for testing and verification to avoid policy changes directly impacting the production environment. However, due to the complexity of the network environment, policies may have dependencies and conflicts. A policy execution deviation on one node may propagate through network connections and affect other nodes, and the scope and extent of this impact are difficult to judge intuitively. The policy conflict propagation concept proposed in this application helps administrators accurately assess the impact range of policy execution deviations, providing visual analysis support for the transition of security policies from monitoring mode to formal deployment.

[0023] This application provides a method for visualizing network security policies. In one embodiment, please refer to... Figure 1 , Figure 1 This is a flowchart illustrating a method for visualizing network security strategies provided in this application. This method can be implemented using a computer program, which can be integrated into an application or run as a standalone utility application. The method can also be implemented using a microcontroller or run on a network security strategy visualization system based on the von Neumann architecture. Specifically, the method may include the following steps: Step 101: Obtain network traffic information and user-set security policy information. Network traffic information includes source address, destination address and traffic volume. Security policy information includes firewall whitelist and firewall blacklist.

[0024] Network traffic information refers to the characteristics of data packets transmitted in the network, including three key attributes: source address, destination address, and traffic size. The source address is the IP address or network identifier of the packet sender, indicating the starting point of the traffic. The destination address is the IP address or network identifier of the packet receiver, indicating the destination of the traffic. Traffic size refers to the number of data packets or bytes transmitted within a specific time period, representing the network transmission load. Security policy information refers to the access control rules set by users to protect network security, including firewall whitelists and blacklists. A firewall whitelist represents a list of allowed IP addresses or network segments. A firewall blacklist represents a list of prohibited IP addresses or network segments.

[0025] Specifically, this process is executed during the initialization of the network security policy visualization system or when policy displays need to be updated. The system first collects real-time network traffic data through the network traffic acquisition module, obtaining the source IP address, destination IP address, and traffic volume information for each data packet. Simultaneously, the system reads user-configured firewall policy information from the security configuration database, including whitelist and blacklist rule sets. These rules contain matching conditions such as allowed or prohibited IP addresses, port numbers, and protocol types. The system preprocesses and formats the acquired network traffic and security policy information for subsequent analysis.

[0026] In some embodiments, network traffic information and security policy information can be obtained in various ways: Optionally, a passive monitoring method can be used to obtain network traffic information: First, a traffic mirroring device is deployed at a critical network node to copy the network traffic and send it to a traffic analysis server; then, the traffic analysis server uses packet capture tools such as tcpdump or Wireshark to parse the traffic packets to obtain the source and destination addresses; finally, the number of traffic packets or the total number of bytes within a specified time window is counted as the traffic size; simultaneously, whitelist and blacklist rules are parsed from the firewall device's configuration file. Optionally, an active probing method can be used to obtain network traffic information: First, probe packets are periodically sent to the target network segment; then, the round-trip path of the probe packets is recorded to obtain the source and destination addresses; next, the round-trip latency and packet loss rate of the probe packets are calculated; finally, the actual network traffic size is estimated based on the latency and packet loss rate; simultaneously, the whitelist and blacklist configurations are directly obtained through the firewall management interface API. It is understood that other methods, such as obtaining traffic information through an SDN controller or analyzing security device logs, can also be used to obtain network traffic and policy information, which are not limited here.

[0027] Step 102: Divide network traffic information into multiple data stream types according to preset security status, including unprotected, protected, denied, and allowed by default.

[0028] The default security state indicates the type of processing result of network traffic under the action of security policies. "Unprotected" means the data flow is not covered by any security policy and poses a potential security risk. "Protected" means the data flow is explicitly allowed by the firewall's whitelist policy. "Denyed" means the data flow is explicitly prohibited by the firewall's blacklist policy. "Default Allowed" means the data flow is allowed to pass based on the firewall's default policy, even though it does not match any specific policy rule. A data flow refers to a collection of traffic with the same source and destination addresses in the network. "Type" refers to the classification and identification of data flows based on their security state.

[0029] This step is executed after network traffic information is obtained and is used to classify the traffic into security states. Specifically, the system first reads the firewall's default policy configuration to determine the default action when a specific rule is not matched. Then, it iterates through each network traffic record, extracts its source and destination addresses, and queries the firewall's whitelist and blacklist rules. If the traffic matches a whitelist rule, it is marked as "protected"; if it matches a blacklist rule, it is marked as "denied"; if it does not match any specific rule and the firewall's default policy is allow, it is marked as "allowed by default"; if it does not match any rule and the default policy is deny, it is marked as "unprotected". Finally, traffic with the same source address, destination address, and security state type is aggregated into a single data stream record.

[0030] In some embodiments, network traffic security status classification can be implemented in several ways: Optionally, classification can be performed using rule priority: First, firewall whitelist and blacklist rules are sorted from highest to lowest priority; then, each piece of traffic is matched against the sorted rules in turn. Once a match is successful, its security status type is determined, and subsequent rules are not matched; finally, the type of traffic that does not match any rules is determined according to the default policy. Optionally, classification can be performed using parallel matching: First, traffic is matched against both whitelist and blacklist rules in parallel; then, the number of whitelist rules and the number of blacklist rules matched for each piece of traffic are counted; finally, the security status is determined based on the matching results, with the more restrictive blacklist determination result being prioritized when both whitelist and blacklist rules are matched simultaneously. It is understood that other methods, such as machine learning-based classification methods or classification methods based on historical policy matching records, can also be used to implement network traffic security status classification, which is not limited here.

[0031] Step 103: Construct a traffic-policy matching matrix based on network traffic information and security policy information, and identify the differences in traffic among different types of data streams through the traffic-policy matching matrix.

[0032] The traffic-policy matching matrix is ​​a two-dimensional data structure used to record the matching relationship between network traffic and security policy rules. Its rows represent different traffic identifiers, and its columns represent different policy rules. Discrepancy traffic represents data flows whose actual security state differs from the expected security state. A traffic identifier is a data flow uniquely identified by its source and destination addresses. A policy rule refers to the access control conditions defined in a firewall whitelist or blacklist. The matching relationship refers to the result of judging whether a traffic identifier meets the conditions of a policy rule. The expected security state refers to the security processing result that should be executed according to the policy rule. The actual security state refers to the security processing result actually observed in the current network.

[0033] This step is executed after traffic classification to identify policy execution deviations. Specifically, the system first constructs a two-dimensional matrix, where the number of rows equals the number of different traffic identifiers and the number of columns equals the number of policy rules. Then, it iterates through each traffic identifier, matching it against all policy rules and recording the matching result at the corresponding position in the matrix (1 indicates a match, 0 indicates a mismatch). For each traffic identifier, based on the matched policy rule and its priority, the expected security action, i.e., the expected security state, is determined. The expected security state is compared with the actual security state identified in step 102; if they do not match, the data stream is marked as a differential traffic flow. Finally, a list of all differential traffic flows is output, including traffic identifier, actual state, and expected state information.

[0034] In some embodiments, traffic-policy matching analysis can be implemented in several ways: Optionally, a rule decomposition approach can be used for matching: First, complex policy rules are decomposed into multiple basic matching conditions, such as decomposing IP address ranges into specific addresses; then, traffic identifiers are precisely matched against these basic conditions one by one; finally, based on the matching results of the basic conditions and the logical relationship of the rules, a comprehensive judgment is made as to whether the traffic meets the original rules. Optionally, a hash index approach can be used for matching: First, a hash index table is built for the matching conditions in the policy rules, and similar conditions are clustered and stored; then, the feature hash value of the traffic identifier is calculated to quickly locate the possible matching rule subset; finally, detailed matching is performed on the candidate rule subset to improve matching efficiency. It is understood that other methods, such as parallel matching engines and rule decision trees, can also be used to implement traffic-policy rule matching analysis, which is not limited here.

[0035] Based on the above embodiments, as an optional embodiment, step 103: constructing a traffic-policy matching matrix based on network traffic information and security policy information, and identifying the differential traffic in each type of data stream through the traffic-policy matching matrix, may further include the following steps: Step 201: Based on network traffic information, extract the source address and destination address of each type of data stream as the corresponding traffic identifier.

[0036] Network traffic information represents the set of characteristics of data packets transmitted in the network. Data flow types include four states: unprotected, protected, denied, and allowed by default. The source and destination addresses represent the network location identifiers of the sender and receiver of the data packet, respectively. The traffic identifier is an address pair of information used to uniquely identify a specific data flow.

[0037] Specifically, this step analyzes the categorized network traffic information to extract address information from each type of data flow. In practice, network traffic is first grouped according to security status type, and each group of data flows is processed. The source IP address and destination IP address of each data flow are extracted and combined into an identifier pair in the form of "source address-destination address". For example, a data flow from IP address 192.168.1.1 to 10.0.0.1 is represented as "192.168.1.1-10.0.0.1". For IPv6 addresses, the complete 128-bit address is used as the identifier. The security status type of this traffic identifier is also recorded for subsequent policy matching analysis. Finally, a list containing all traffic identifiers and their type information is generated.

[0038] Step 202: Parse the policy rules in the firewall whitelist and firewall blacklist, obtain the matching conditions and execution actions of the policy rules, and the matching conditions of the policy rules follow the priority decision.

[0039] The firewall whitelist contains a set of allowed access rules, while the firewall blacklist contains a set of prohibited access rules. Policy rules consist of two parts: matching conditions and execution actions. Matching conditions define the network traffic characteristics to which the rule applies, and execution actions define how to process the matched traffic.

[0040] Specifically, this step involves parsing the firewall configuration to extract specific policy rule information. First, the firewall configuration file is read, or whitelist and blacklist rules are obtained through the management interface. Each rule is then parsed in a structured manner to extract matching conditions, including source IP address / network segment, destination IP address / network segment, port number, protocol type, etc. The execution action defined by the rule, such as "allow access" or "deny access," is also obtained. The parsing results are saved as a unified data structure for subsequent matching with traffic identifiers. For example, the rule "Allow 192.168.1.0 / 24 to access port 80 of 10.0.0.0 / 24" is parsed to obtain the matching conditions {source network segment: 192.168.1.0 / 24, destination network segment: 10.0.0.0 / 24, port: 80} and the execution action "allow."

[0041] Step 203: Compare each traffic identifier with the matching conditions of the policy rules to construct a traffic-policy matching matrix. The traffic-policy matching matrix records the policy rules and execution actions corresponding to each traffic identifier.

[0042] Here, the traffic identifier is the address pair information of the data flow. The matching conditions of the policy rule define the scope of application of the rule. The traffic-policy matching matrix is ​​a two-dimensional data structure that records the matching relationship between traffic and rules. The execution action is the processing method determined according to the policy rule.

[0043] Specifically, this step constructs a matching matrix by comparing traffic identifiers and policy rules. First, a two-dimensional matrix is ​​created with the number of rows equal to the number of traffic identifiers and the number of columns equal to the number of policy rules. For each traffic identifier, its source and destination addresses are compared with the matching conditions of each policy rule. If the traffic's source address is within the rule's source network segment range and its destination address is within the rule's target network segment range, then the traffic matches this rule, and a 1 is recorded in the corresponding position in the matrix; otherwise, a 0 is recorded. The execution action defined by the matching rule is also recorded. When a traffic identifier matches multiple rules, the final execution action is determined based on the rule priority. Finally, a complete traffic-policy matching matrix is ​​generated, containing all matching relationships between traffic identifiers and policy rules.

[0044] Based on the above embodiments, as an optional embodiment, step 203, which compares each traffic identifier with the matching conditions of the policy rules to construct a traffic-policy matching matrix, may further include the following steps: Step 213: Extract the allowed policy rules from the firewall whitelist and extract the prohibited policy rules from the firewall blacklist.

[0045] A firewall whitelist is a set of rules configured on a firewall that allow network access. A firewall blacklist is a set of rules configured on a firewall that block network access. Allowing rules define the characteristics of traffic that can pass through the firewall. Blocking rules define the characteristics of traffic that must be blocked. A policy rule contains two basic elements: a matching condition and an action to be taken.

[0046] Specifically, this step extracts allow and deny rules from the firewall configuration. First, it accesses the firewall configuration database or configuration file to read the complete set of policy rules. It analyzes the action attributes of each rule, grouping rules with actions such as "allow" or "accept" into an "allow" rule group, and rules with actions such as "deny" or "block" into a "deny" rule group. It then parses the matching conditions contained in each rule, such as source address / network segment, destination address / network segment, port number, and protocol type. Simultaneously, it extracts the rule priority information for subsequent rule conflict handling. Finally, it forms two independent rule lists, each containing complete rule information for allowing and denying access, respectively.

[0047] Step 223: Match the source address and destination address in each traffic identifier with the policy rules for allowing passage and the policy rules for denying passage, respectively.

[0048] In this context, traffic identification uniquely identifies a data stream using source and destination addresses. The source address represents the sender's network location, and the destination address represents the receiver's network location. Policy rule matching is the process of determining whether traffic characteristics meet the defined rule conditions.

[0049] Specifically, this step matches each traffic identifier against two types of policy rules. For each traffic identifier, it first checks whether its source address is within the source address range of the allowed rule and whether its destination address is within the destination address range of the allowed rule. For example, if the source address 192.168.1.1 matches the rule source network segment 192.168.1.0 / 24, bitwise operations are used to determine whether the address belongs to the network segment range. When both the source address and destination address meet the rule conditions, the traffic identifier is recorded as matching the allowed rule. Then, the same matching process is performed on the denied rule to determine whether the traffic identifier meets the address conditions of the denied rule. All matching results are recorded, including the list of allowed rules and the list of denied rules matched by the traffic identifier.

[0050] Step 233: When a traffic identifier matches multiple policy rules, determine the final applicable action based on the priority of the policy rules.

[0051] In this context, the policy rule priority indicates the processing order and effectiveness level of the rules. The execution action defines the specific processing method for the matching traffic. The final applicable execution action is the processing decision selected from multiple matching rules based on their priority.

[0052] Specifically, this step handles cases where traffic matches multiple rules. When a traffic identifier is detected to match multiple policy rules simultaneously, the priority information of these rules is first obtained. Priority can be represented numerically (e.g., 1-100, with lower numbers indicating higher priority) or by keywords (e.g., high, medium, low). The matching rules are sorted from highest to lowest priority. The rule with the highest priority is selected as the final applicable rule. If the highest priority rule is a prohibition rule, the final action is "deny"; if it is an allowance rule, the final action is "allow". In cases of equal priority, prohibition rules take precedence over allowance rules.

[0053] Step 243: Based on the matching results, generate a traffic-policy matching matrix that includes traffic identifiers, policy rules matched to the traffic identifiers, and corresponding execution actions.

[0054] The traffic-policy matching matrix is ​​a two-dimensional data structure that records the relationship between traffic and rules. The matching result includes the correspondence between traffic identifiers and rules. The action is the decision to process the matched traffic.

[0055] Specifically, this step constructs a complete traffic-policy matching matrix. First, a matrix structure is created, where rows represent different traffic identifiers and columns represent different policy rules. For each traffic identifier, the matched policy rule number is recorded in the matrix, with unmatched positions filled with 0 or empty values. The final action determined by rule priority is also recorded. For example, if a traffic identifier matches rule 1 (allow) and rule 2 (deny), and rule 2 has a higher priority, then the matrix records that the traffic identifier matches both rules, and the final action is "deny". The final generated matrix contains the policy matching status and processing decisions for all traffic identifiers.

[0056] Step 204: Determine the expected security status of each type of data flow based on the execution actions in the traffic-policy matching matrix; compare the actual security status of each type of data flow with the corresponding expected security status, and mark the data flows with inconsistent security status as differential traffic.

[0057] The expected security state is the ideal processing result determined according to policy rules. The actual security state is the current processing state of the data flow. Discrepancy traffic represents data flows whose actual state differs from the expected state. In large-scale network environments, changes to security policies can have unexpected impacts. To mitigate these risks, administrators typically need to conduct policy rehearsals, that is, to simulate and calculate the expected security state after a new policy takes effect using a policy engine without actual deployment. However, when the rehearsal results (expected security state) deviate from the actual monitored traffic processing state (actual security state), it often reflects potential problems in the policy configuration, such as policy conflicts, improper priority settings, or missing policy dependencies. This application compares the differences between the expected and actual states and visualizes them in conjunction with network topology relationships, helping administrators to identify and resolve these problems in a timely manner before the formal deployment of policies, thereby ensuring the smooth implementation of policy changes.

[0058] Specifically, this step identifies abnormal traffic by comparing the expected and actual states. First, based on the execution actions recorded in the traffic-policy matching matrix, the expected security state of each data flow is determined. For example, traffic matching whitelist rules should have an expected state of "protected," while traffic matching blacklist rules should have an expected state of "rejected." Then, the expected state is compared with the actual security state identified in step 102. If a data flow's expected state is "protected" but its actual state is "unprotected," it indicates a policy execution deviation and is marked as differential traffic. Finally, a list of all differential traffic is output, including traffic identifiers, expected states, and actual states, providing a basis for subsequent policy optimization.

[0059] Step 104: Construct network node connection relationships based on the source and destination addresses in the differential traffic. Using the network node corresponding to the differential traffic as the starting node, construct a policy conflict propagation chain based on the network node connection relationships, and calculate the attenuation coefficient of the policy conflict propagation chain.

[0060] In this context, a network node refers to a device terminal in the network that has a source address or a destination address. Network node connections represent data transmission paths between nodes. A policy conflict propagation chain refers to the path along which a policy conflict caused by discrepancy traffic gradually spreads along network connections. The starting node represents the network node where the policy conflict initially occurred. The attenuation coefficient is a quantitative indicator of how much the impact of a policy conflict weakens as the propagation distance increases. Discrepancy traffic represents data flows where the actual security state differs from the expected security state. The source address and destination address represent the network location identifiers of the sender and receiver of the data flow, respectively.

[0061] Specifically, this step is performed after identifying the differential traffic to analyze the impact range of policy conflicts. First, based on the source and destination addresses in the differential traffic, relevant network nodes are identified, and a connection graph between these nodes is constructed. For each differential traffic item, its source node is set as the starting propagation point of the policy conflict. Then, based on the network connection relationships, the first-level nodes directly connected to the starting node, and the second-level nodes connected to the first-level nodes, are determined, and so on, constructing a complete propagation chain. For each node in the propagation chain, its hop count from the starting node is calculated, and an attenuation coefficient is calculated based on the hop count. The attenuation coefficient decreases as the hop count increases, using an exponential attenuation formula: Attenuation coefficient = Baseline influence × (Attenuation rate)^Hop count, where the baseline influence represents the degree of influence of the starting node, and the attenuation rate is a constant less than 1.

[0062] In some embodiments, policy conflict propagation analysis can be implemented in several ways: Optionally, a depth-first search approach can be used to construct the propagation chain: First, the starting node is added to the queue to be visited; then, a node is taken from the queue each time and visited, recording its hop count; next, all unvisited neighboring nodes of that node are added to the queue; finally, the propagation chain is constructed when the queue is empty. Optionally, a breadth-first search approach can be used to construct the propagation chain: First, the starting node is marked as level 0; then, all neighboring nodes of the nth level node are traversed, and unvisited nodes are marked as level (n+1); then, the decay coefficient of each level node is calculated; finally, the propagation chain is constructed when no more neighboring nodes can be found. It is understood that other methods, such as shortest path first algorithms and dynamic programming algorithms, can also be used to implement policy conflict propagation analysis, which are not limited here.

[0063] Based on the above embodiments, as an optional embodiment, in step 104: constructing network node connection relationships based on the source and destination addresses in the differential traffic, taking the network node corresponding to the differential traffic as the starting node, constructing a policy conflict propagation chain based on the network node connection relationships, and calculating the attenuation coefficient of the policy conflict propagation chain, this step may further include the following steps: Step 301: Treat the source and destination addresses in the differential traffic as network nodes, and construct the network node connection relationship according to the data flow direction.

[0064] Here, differential traffic represents data flows where the actual security state differs from the expected security state. The source and destination addresses represent the network location identifiers of the sender and receiver of the data packet, respectively. A network node is a device terminal with an independent address within the network. Network node connections represent data transmission links between nodes. Data flow direction refers to the transmission path of network data packets from the source address to the destination address.

[0065] Specifically, this step constructs network topology relationships by analyzing differential traffic. First, all unique source and destination addresses are extracted from the differential traffic list, and each address is mapped to a network node. Then, directed connections are established between nodes based on the source and destination addresses of the differential traffic, with the connection direction pointing from the source node to the destination node. For example, if the source address of a differential traffic is 192.168.1.1 and the destination address is 10.0.0.1, a directed connection is established between these two nodes, pointing from 192.168.1.1 to 10.0.0.1. This process is repeated for all differential traffic, ultimately forming a complete network node connection graph that reflects all network nodes involved in the differential traffic and their data transmission relationships.

[0066] Step 302: Select a network node with policy execution deviation as the starting conflict node; starting from the starting conflict node, propagate the search downstream and upstream along the network node connection relationship to construct the policy conflict propagation chain.

[0067] Policy execution deviation refers to a situation where the actual security processing result of a network node does not match the expectation. The initiating conflict node is the network node where the policy deviation first occurs. Downstream direction indicates the destination direction of data flow transmission. Upstream direction indicates the source direction of data flow transmission. The policy conflict propagation chain refers to the node path through which the impact of the policy deviation spreads.

[0068] Specifically, this step constructs the propagation path of policy conflicts. First, nodes with policy execution deviations are marked in the network node connection graph; these nodes serve as the initial conflict nodes. Then, starting from each initial conflict node, the search proceeds downstream along the node connections to find directly connected nodes; these nodes constitute the first layer of propagation nodes. The search continues downstream from the first layer of propagation nodes to obtain the second layer of propagation nodes, and so on, until no new downstream nodes can be found. Simultaneously, the same search process is repeated upstream from the initial conflict node to find all upstream propagation nodes. Finally, a policy conflict propagation chain is obtained, centered on the initial conflict node and containing all relevant upstream and downstream nodes.

[0069] Step 303: Calculate the attenuation coefficient of each node on the propagation path based on the propagation distance and the number of node connections in the strategy conflict propagation chain.

[0070] Here, propagation distance represents the number of hops from a node to the node where the conflict originates. The number of node connections represents the number of direct connections between a node and other nodes. The attenuation coefficient is a quantitative indicator of how much the impact of a policy conflict decreases as the propagation distance increases. The propagation path refers to the route through which a policy conflict propagates from the originating node to a specific node.

[0071] Specifically, this step calculates the attenuation of the impact of policy conflicts. First, the distance from each node in the propagation chain to the initial conflict node is calculated, i.e., the number of hops in the shortest path. Then, the number of connections for each node is counted, including the sum of in-degree (upstream connections) and out-degree (downstream connections). The attenuation coefficient of each node is calculated based on the distance and the number of connections, using the formula: Attenuation Coefficient = Baseline Influence × (Attenuation Rate)^Distance × (1 + Connection Coefficient × Number of Connections). Here, the baseline influence represents the influence of the initial node (usually set to 1), the attenuation rate is a constant less than 1 (e.g., 0.8), and the connection coefficient is a positive weighting factor (e.g., 0.1). In this way, nodes farther away have smaller attenuation coefficients, while nodes with more connections have relatively smaller attenuation, more accurately reflecting the actual impact range of policy conflicts.

[0072] Based on the above embodiments, as an optional embodiment, step 303, which calculates the attenuation coefficient of each node on the propagation path according to the propagation distance and the number of node connections in the policy conflict propagation chain, may further include the following steps: Step 313: Calculate the number of propagation steps between each node in the strategy conflict propagation chain and the initial conflict node as the propagation distance.

[0073] In this context, the policy conflict propagation chain represents the node path through which the impact of policy deviations spreads. A node is a device terminal with an independent address within the network. The initial conflict node is the network node where the policy deviation first occurs. The propagation steps refer to the minimum number of hops required to reach a specific node from the initial node. The propagation distance quantifies the length of the path through which policy impacts are transmitted between nodes.

[0074] Specifically, this step calculates the shortest path between nodes in the propagation chain. First, the propagation step count for the initial conflict node is set to 0. Then, a breadth-first search algorithm is used to sequentially visit nodes directly connected to the initial node, setting the propagation step count for these first-level nodes to 1. Next, the unvisited adjacent nodes of the first-level nodes are visited, setting the propagation step count for these second-level nodes to 2. This process is repeated until all nodes in the propagation chain have been visited. In cases where multiple paths exist, the shortest propagation step count is selected as the propagation distance for that node. For example, if there are two paths from node A to node B, one requiring 2 steps and the other requiring 3 steps, then the propagation distance for node B is set to 2.

[0075] Step 323: Count the number of connection edges for each node in the network node connection relationship; set a distance attenuation factor based on the propagation distance, which is positively correlated with the propagation distance; set a node influence factor based on the number of connection edges, which is positively correlated with the number of connection edges.

[0076] Here, the number of connected edges represents the number of direct connections between a node and other nodes. The distance decay factor is a parameter used to calculate how the policy's influence decays with distance. The node influence factor is a parameter used to calculate the influence of node connectivity on the policy. Positive correlation indicates a relationship where the dependent variable increases as the independent variable increases.

[0077] Specifically, this step determines the influence weighting parameters of nodes. First, the in-degree (the number of connections pointing to that node) and out-degree (the number of connections from that node to other nodes) of each node are calculated; the sum of these two is the number of edges connected to that node. Then, the distance attenuation factor is calculated based on the propagation distance using the formula: Distance Attenuation Factor = Baseline Attenuation Rate^Propagation Distance, where the base attenuation rate is a constant less than 1 (e.g., 0.8). Next, the node influence factor is calculated based on the number of edges connected using the formula: Node Influence Factor = 1 + Connection Coefficient × Number of Edges Connected, where the connection coefficient is a positive weighting factor (e.g., 0.1). Thus, nodes farther away experience greater attenuation, and nodes with more connections have a greater influence.

[0078] Step 333: Perform a weighted calculation of the distance attenuation factor and node influence factor for each node to determine the attenuation coefficient of each node.

[0079] Weighted calculation refers to allocating and comprehensively calculating weights based on the importance of different factors. The attenuation coefficient is a comprehensive indicator that quantifies the degree of impact of strategy conflicts. Weights refer to the relative importance of different factors in the calculation.

[0080] Specifically, this step comprehensively calculates the influence of nodes. First, weight coefficients are assigned to the distance decay factor and the node influence factor, with the sum of the weights being 1. The weight of the distance decay factor is usually relatively large (e.g., 0.7) because distance is a major factor affecting strategy propagation; the weight of the node influence factor is relatively small (e.g., 0.3), serving as a correction parameter. Then, for each node, its distance decay factor and node influence factor are multiplied by their corresponding weights, and the sum of these two is the decay coefficient of that node. The calculation formula is: Decay coefficient = Distance decay factor × Distance weight + Node influence factor × Node weight. Finally, the decay coefficients of all nodes in the propagation chain are obtained, used to quantify the scope and degree of influence of the strategy conflict.

[0081] Step 105: Calculate the data flow line width and arrow triangle size based on the flow rate, and generate a highlight pattern to identify the difference in flow rate based on the data flow line width and arrow triangle size.

[0082] In this context, traffic volume represents the amount of network data packets transmitted per unit of time. Data flow line width refers to the thickness of the lines representing data flow in the visualization. The size of the arrow triangle indicates the size of the data flow direction indicator. Highlighted patterns are visual markers used to highlight differential traffic. Differential traffic represents data flows where the actual security state differs from the expected security state. Visual markers are graphic elements used to enhance visualization. Data flow direction refers to the direction in which network data packets are transmitted.

[0083] Specifically, this step is performed after identifying the differential traffic and is used to generate a visual representation of it. First, the magnitude of each differential traffic flow is obtained. Then, the baseline width of the data flow connection is calculated and adjusted based on this magnitude to obtain the width of the connection. Next, the dimensions of the arrow triangle are calculated based on the connection width, maintaining a proportional relationship with the connection width. The base length of the arrow triangle is set to twice the connection width, and the height is set to 1.5 times the base length. Finally, the connection and arrow are combined to form a complete highlighted pattern, using a striking color (such as red) and appropriate transparency to identify the differential traffic in the visualization interface.

[0084] In some embodiments, the visualization of differential flow can be achieved in several ways: Optionally, a gradient effect can be used: First, a gradient color band for the connecting lines is set according to the flow size, with larger flows displayed in darker colors and smaller flows displayed in lighter colors; then, a flowing animation effect is superimposed on the connecting lines, with the movement of gradient color blocks indicating the data flow direction; finally, an arrow pattern with gradient fill is drawn at the end of the connecting lines to achieve a unified expression of flow and direction. Optionally, a pulse animation can be used: First, a basic connecting line with a glowing border effect is drawn; then, an animation of light spots propagating along the direction of the connecting lines is added, with the size of the light spots proportional to the flow; finally, a blinking arrow marker is drawn at the endpoint of the connecting lines, with the blinking frequency changing with the flow. It is understood that other methods such as texture fill and 3D effects can also be used to visually highlight differential flow, which is not limited here.

[0085] Based on the above embodiments, as an optional embodiment, in step 105: calculating the data flow connection width and the arrow triangle size according to the traffic volume, and generating a highlight pattern for identifying differential traffic based on the data flow connection width and the arrow triangle size, this step may further include the following steps: Step 401: Correct the baseline width of the data stream connection based on the traffic volume to obtain the width of the data stream connection; calculate the size of the arrow triangle based on the width of the data stream connection.

[0086] Here, traffic volume represents the total amount of network data packets transmitted per unit time. Baseline width refers to the default thickness of the data flow line under standard conditions. The data flow line width represents the actual thickness of the lines representing the data flow in the visualization. The arrow triangle dimensions include the length of the triangle's base and its height. Correction refers to the calculation process of adjusting the baseline value based on the actual traffic volume.

[0087] Specifically, this step is performed after determining the basic attributes of the differential traffic. First, the baseline width of the data flow connection is obtained, typically set to 2-5 pixels. Then, a correction factor is calculated based on the traffic volume using the logarithmic mapping formula: Correction factor = 1 + log(current traffic / baseline traffic) / log(maximum traffic / baseline traffic). The baseline width is multiplied by the correction factor to obtain the actual data flow connection width. Next, the dimensions of the arrow triangle are determined based on the connection width. The base length of the triangle is set to twice the connection width, and the height is set to 1.5 times the base length, ensuring visual harmony between the arrow and the connection. For example, when the connection width is 4 pixels, the base of the arrow triangle is 8 pixels, and the height is 12 pixels.

[0088] Step 402: Generate a highlighted rectangle pattern based on the width of the data stream connection line, and generate a highlighted triangle pattern based on the size of the arrow triangle.

[0089] In this context, a highlighted rectangle is a rectangular marker used to emphasize data flow lines. A highlighted triangle is a triangular marker used to emphasize the direction of an arrow. A reference point refers to a standard dimension used for reference. Generation refers to the process of creating graphic elements with specific attributes.

[0090] Specifically, this step is performed after the graphic dimensions are determined. First, a highlight rectangle is created based on the width of the data flow connection. The rectangle's width is set to 1.5 times the width of the connection, ensuring it completely covers the original connection and creates a clear highlight effect. The length of the rectangle is consistent with the data flow connection. Then, a highlight triangle is created based on the dimensions of the arrow triangle. The triangle's base and height are both set to 1.5 times the original arrow's size. The highlight pattern uses a semi-transparent effect, with the internal fill color being a striking warning color (such as red), and the transparency is set to 50%, ensuring it stands out without affecting the visibility of the underlying graphic.

[0091] Step 403: Set the highlighted rectangle pattern on the data flow line and the highlighted triangle pattern at the arrow position to obtain the highlighted pattern used to identify the differential flow.

[0092] In this context, data flow lines refer to lines representing the path of network data transmission. Arrow positions indicate the endpoints that indicate the direction of data flow. Differential flow indicators are visual elements used to distinguish and highlight abnormal data flows. Highlighted patterns are complete markers formed by a combination of rectangles and triangles.

[0093] Specifically, this step is performed after the highlighted graphic is generated. First, align the highlighted rectangle along the data flow line, ensuring the center line of the rectangle coincides with the line. Then, place the highlighted triangle at the end of the line, with the vertices of the triangle pointing in the direction of data flow and the midpoint of the triangle's base coinciding with the end of the line. Adjust the hierarchy of the two highlighted graphics so that they appear on top of the original graphic. This ultimately forms a complete differential traffic highlighting mark, clearly identifying abnormal data flows in the visualization interface. The highlighted graphics, through their striking visual effect, help administrators quickly identify network traffic that requires focused attention.

[0094] Step 106: Combine the attenuation coefficient of the policy conflict propagation chain to set the transparency and color of the highlighted pattern, and visualize the differential traffic in the global topology view and the security policy topology view.

[0095] The attenuation coefficient of the policy conflict propagation chain refers to a numerical indicator that quantifies how much the impact of a policy weakens with propagation distance. The transparency of a highlighted pattern indicates the opacity of the graphic element, ranging from 0 to 1. Color is a visual attribute used to identify differential traffic. The global topology view is a visual interface displaying the entire network connection structure. The security policy topology view is a visual interface highlighting the configuration and execution status of security policies. Differential traffic refers to data flows where the actual security state differs from the expected security state. Visualization represents a way of converting data into intuitive graphical representations.

[0096] Specifically, this step is executed after the highlighted pattern is generated to achieve hierarchical display of differentiated traffic. First, the attenuation coefficient of each node in the policy conflict propagation chain is obtained; this coefficient ranges from 0 to 1. The attenuation coefficient is mapped to the transparency of the highlighted pattern; the larger the attenuation coefficient, the lower the transparency, and the more obvious the visual effect. Simultaneously, a color gradient effect is set based on the attenuation coefficient, using a gradient from red to yellow; nodes with larger attenuation coefficients are displayed as dark red, and nodes with smaller attenuation coefficients are displayed as light yellow. Then, the overall differentiated traffic distribution is displayed in the global topology view, while the security policy topology view highlights abnormal nodes and connections related to security policies. The two views interact and link together, allowing administrators to analyze and handle policy conflicts at different levels.

[0097] In some embodiments, the hierarchical visualization of differential traffic can be achieved in several ways: Optionally, a multi-level view can be used: First, differential traffic is marked with different shades of red in the global view; then, clicking on a region switches to a region view, displaying detailed policy information within that region; finally, a hover tooltip displays the specific attenuation coefficient and policy conflict details. Optionally, a dynamic highlighting method can be used: First, all differential traffic is displayed with the same visual effect; then, the transparency is dynamically adjusted according to the attenuation coefficient threshold selected by the user; finally, a blinking animation effect is added, with a higher blinking frequency for larger attenuation coefficients. It is understood that other methods, such as 3D stereoscopic display or matrix views, can also be used to achieve multi-dimensional visualization of differential traffic, and this is not limited here.

[0098] Based on the above embodiments, as an optional embodiment, in step 106: setting the transparency and color of the highlighted pattern in conjunction with the attenuation coefficient of the policy conflict propagation chain, and visually displaying the differential traffic in the global topology view and the security policy topology view, this step may further include the following steps: Step 501: Determine the color of the highlight pattern based on the preset pattern color template library and the type corresponding to the differential flow.

[0099] The pattern color template library refers to a predefined set of color configurations corresponding to different types of differential traffic. Differential traffic types include four states: unprotected, protected, rejected, and allowed by default. Highlighted patterns represent visual markers used to highlight differential traffic. Color refers to the graphic fill attribute represented in RGB or RGBA format.

[0100] Specifically, this step is performed when setting the visual attributes of the highlight pattern. First, a preset pattern color template library is read. This library defines the base color value corresponding to each differential traffic type. For example, unprotected type corresponds to red (RGB: 255, 0, 0), protected type corresponds to yellow (RGB: 255, 255, 0), rejected type corresponds to orange (RGB: 255, 165, 0), and the default allowed type corresponds to blue (RGB: 0, 0, 255). Then, based on the current differential traffic type, the corresponding color value is searched and extracted from the template library as the base color attribute of the highlight pattern.

[0101] Step 502: Calculate the transparency of the highlight pattern based on the attenuation coefficient. Transparency is positively correlated with the attenuation coefficient.

[0102] The attenuation coefficient is a numerical indicator that quantifies the impact of policy conflicts, ranging from 0 to 1. Transparency represents the opacity of graphic elements, also ranging from 0 to 1. Positive correlation indicates that a larger attenuation coefficient corresponds to greater transparency.

[0103] Specifically, this step is performed after the base color is determined. First, the decay coefficient of the current node in the policy conflict propagation chain is obtained. Then, the decay coefficient is converted into a transparency value through linear mapping, using the formula: Transparency = Minimum Transparency + (Maximum Transparency - Minimum Transparency) × Decay Coefficient. The minimum transparency is typically set to 0.2, and the maximum transparency is set to 0.8, ensuring that the highlighted pattern is neither completely transparent nor completely obscures the underlying graphic.

[0104] Step 503: Input the color and transparency as parameters into the color attribute of the highlight pattern to generate a highlight pattern with the specified color and transparency.

[0105] The color attribute refers to the set of parameters that define the visual effect of a graphic. These parameters include color values ​​and transparency values. A highlighted pattern specifying color and transparency refers to a graphic marker to which a specific visual attribute is applied.

[0106] Specifically, this step is performed after the color and transparency are calculated. First, the color value is converted from RGB format to RGBA format, and a transparency channel is added. Then, the calculated transparency value is set to the alpha channel of the RGBA color. Finally, the full RGBA color value is applied to the fill property of the highlighted pattern, while the border color is set to the same RGB value but with slightly higher transparency to enhance the visual effect of the edges.

[0107] Step 504: Construct a global topology view containing all network nodes and data flow connections, and construct a security policy topology view containing network nodes and associated data flow connections in the policy conflict propagation chain.

[0108] The global topology view is a visual interface that displays the complete network structure. The security policy topology view is a visual interface that focuses on nodes related to policy conflicts. Network nodes represent the location identifiers of network devices. Data flow lines represent the data transmission paths between nodes.

[0109] Specifically, this step is performed when preparing the differential traffic visualization environment. First, a global topology view is drawn, including all network nodes and their connections. Nodes are represented by circular or square icons, and connections are represented by straight lines with arrows. Then, a security policy topology view is constructed, showing only the nodes involved in the policy conflict propagation chain and their directly related connections, highlighting the scope of the policy conflict's impact.

[0110] Step 505: Overlay highlighted patterns at the locations corresponding to the differential traffic in the global topology view and the security policy topology view.

[0111] Overlay display refers to adding new visual elements on top of the existing graphics. Position represents the spatial coordinates of differential flow within the topology view. Highlighted patterns are visual markers with specific colors and transparency.

[0112] Specifically, this step is performed after the view construction is complete. First, locate the data flow connection corresponding to each differential traffic flow in the global topology view. Then, draw a highlight pattern with a specified color and transparency on top of these locations. The same operation is applied to the security policy topology view, overlaying highlight marks on the relevant data flow connections. In this way, differential traffic is highlighted simultaneously in two different layers of views, facilitating administrators to perform global analysis and detailed local inspections.

[0113] Reference Figure 2 This application provides a visualization system for network security strategies, comprising: an information acquisition module, a differential traffic determination module, a pattern generation module, and a visualization display module, wherein: The information acquisition module is used to acquire network traffic information and user-set security policy information. The network traffic information includes the source address, destination address and traffic size, and the security policy information includes firewall whitelist and firewall blacklist. The differential traffic determination module is used to classify network traffic information into multiple types of data streams according to preset security status, including unprotected, protected, denied, and allowed by default; it constructs a traffic-policy matching matrix based on network traffic information and security policy information, and identifies differential traffic in each type of data stream through the traffic-policy matching matrix; The pattern generation module is used to construct network node connection relationships based on the source and destination addresses in the differential traffic, take the network node corresponding to the differential traffic as the starting node, construct a policy conflict propagation chain based on the network node connection relationship, and calculate the attenuation coefficient of the policy conflict propagation chain; calculate the width of the data flow connection line and the size of the arrow triangle based on the traffic size, and generate a highlight pattern to identify the differential traffic based on the width of the data flow connection line and the size of the arrow triangle. The visualization module is used to set the transparency and color of the highlighted pattern based on the attenuation coefficient of the policy conflict propagation chain, and to visualize the differential traffic in the global topology view and the security policy topology view.

[0114] Based on the above embodiments, the differential traffic determination module is further configured to: extract the source and destination addresses of various types of data flows as corresponding traffic identifiers based on network traffic information; parse the policy rules in the firewall whitelist and firewall blacklist to obtain the matching conditions and execution actions of the policy rules, wherein the matching conditions of the policy rules follow priority decision-making; compare each traffic identifier with the matching conditions of the policy rules to construct a traffic-policy matching matrix, wherein the traffic-policy matching matrix records the policy rules and execution actions corresponding to each traffic identifier; determine the expected security status of each type of data flow based on the execution actions in the traffic-policy matching matrix; compare the actual security status of each type of data flow with the corresponding expected security status, and mark the data flows with inconsistent security statuses as differential traffic.

[0115] Based on the above embodiments, the differential traffic determination module is also used to extract allowed policy rules from the firewall whitelist and prohibited policy rules from the firewall blacklist; match the source address and destination address in each traffic identifier with the allowed policy rules and prohibited policy rules respectively; when a traffic identifier matches multiple policy rules, determine the final applicable execution action according to the priority of the policy rules; and generate a traffic-policy matching matrix including the traffic identifier, the policy rules matched by the traffic identifier, and the corresponding execution action based on the matching results.

[0116] Based on the above embodiments, the pattern generation module is also used to take the source address and destination address in the differential traffic as network nodes, construct the network node connection relationship according to the data flow direction; select the network node with policy execution deviation as the starting conflict node; start from the starting conflict node, and perform propagation search in the downstream and upstream directions along the network node connection relationship to construct the policy conflict propagation chain; calculate the attenuation coefficient of each node on the propagation path according to the propagation distance and the number of node connections of the policy conflict propagation chain.

[0117] Based on the above embodiments, the pattern generation module is also used to calculate the number of propagation steps between each node in the strategy conflict propagation chain and the initial conflict node as the propagation distance; count the number of connection edges of each node in the network node connection relationship; set a distance attenuation factor based on the propagation distance, which is positively correlated with the propagation distance; set a node influence factor based on the number of connection edges, which is positively correlated with the number of connection edges; and perform weighted calculation on the distance attenuation factor and node influence factor of each node to determine the attenuation coefficient of each node.

[0118] Based on the above embodiments, the pattern generation module is also used to correct the reference width of the data flow connection based on the traffic volume to obtain the data flow connection width; calculate the size of the arrow triangle based on the data flow connection width; generate a highlighted rectangular pattern based on the data flow connection width and a highlighted triangle pattern based on the size of the arrow triangle; set the highlighted rectangular pattern on the data flow connection and set the highlighted triangle pattern at the arrow position to obtain a highlighted pattern used to identify different traffic volumes.

[0119] Based on the above embodiments, the visualization module is also used to determine the color of the highlighted pattern according to the preset pattern color template library and the type corresponding to the differential traffic; calculate the transparency of the highlighted pattern based on the attenuation coefficient, where transparency is positively correlated with the attenuation coefficient; input the color and transparency as parameters into the color attribute of the highlighted pattern to generate a highlighted pattern with the specified color and transparency; construct a global topology view containing all network nodes and data flow connections, and construct a security policy topology view containing network nodes and associated data flow connections in the policy conflict propagation chain; and overlay the highlighted pattern at the position corresponding to the differential traffic in the global topology view and the security policy topology view.

[0120] It should be noted that the above embodiments of the apparatus are only illustrated by the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus and method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.

[0121] This application also discloses an electronic device. (See reference...) Figure 3 , Figure 3 This is a schematic diagram of the structure of an electronic device disclosed in an embodiment of this application. The electronic device 300 may include: at least one processor 301, at least one network interface 304, a user interface 303, a memory 305, and at least one communication bus 302.

[0122] The communication bus 302 is used to enable communication between these components.

[0123] The user interface 303 may include a display interface and a camera interface. Optionally, the user interface 303 may also include a standard wired interface and a wireless interface.

[0124] The network interface 304 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface).

[0125] The processor 301 may include one or more processing cores. The processor 301 connects to various parts of the server using various interfaces and lines, and performs various server functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 305, and by calling data stored in the memory 305. Optionally, the processor 301 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 301 may integrate one or a combination of several of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem. The CPU primarily handles the operating system, user interface graphics, and applications; the GPU is responsible for rendering and drawing the content required for display; and the modem handles wireless communication. It is understood that the modem may also not be integrated into the processor 301 and may be implemented as a separate chip.

[0126] The memory 305 may include random access memory (RAM) or read-only memory. Optionally, the memory 305 may include a non-transitory computer-readable storage medium. The memory 305 may be used to store instructions, programs, code, code sets, or instruction sets. The memory 305 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-described method embodiments, etc.; the data storage area may store data involved in the above-described method embodiments, etc. Optionally, the memory 305 may also be at least one storage device located remotely from the aforementioned processor 301. (Refer to...) Figure 3 The memory 305, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and an application program for visualizing network security strategies.

[0127] exist Figure 3In the illustrated electronic device 300, the user interface 303 is mainly used to provide an input interface for the user and to acquire user input data; while the processor 301 can be used to call an application program storing a visualization method for a network security policy in the memory 305. When executed by one or more processors 301, the electronic device 300 performs one or more methods as described in the above embodiments. It should be noted that, for the foregoing method embodiments, for the sake of simplicity, they are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, because according to this application, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also understand that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0128] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0129] In the various embodiments provided in this application, it should be understood that the disclosed apparatus can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some service interface; the indirect coupling or communication connection between apparatuses or units may be electrical or other forms.

[0130] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0131] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0132] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as USB flash drives, portable hard drives, magnetic disks, or optical disks.

[0133] The above are merely exemplary embodiments of this disclosure and should not be construed as limiting the scope of this disclosure. Any equivalent changes and modifications made in accordance with the teachings of this disclosure shall still fall within the scope of this disclosure. Other embodiments of this disclosure will be readily apparent to those skilled in the art upon consideration of the specification and practical disclosure.

[0134] This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not described in this disclosure. The specification and embodiments are to be considered exemplary only.

Claims

1. A method for visualizing network security strategies, characterized in that, include: Obtain network traffic information and user-set security policy information, wherein the network traffic information includes source address, destination address and traffic volume, and the security policy information includes firewall whitelist and firewall blacklist; The network traffic information is divided into multiple types of data streams according to a preset security status, including unprotected, protected, denied, and allowed by default. A traffic-policy matching matrix is ​​constructed based on the network traffic information and the security policy information, and the traffic-policy matching matrix is ​​used to identify the different traffic in each type of data stream. Based on the source and destination addresses in the differential traffic, a network node connection relationship is constructed. Taking the network node corresponding to the differential traffic as the starting node, a policy conflict propagation chain is constructed based on the network node connection relationship, and the attenuation coefficient of the policy conflict propagation chain is calculated. The width of the data stream connection and the size of the arrow triangle are calculated based on the traffic volume, and a highlight pattern for identifying the differential traffic volume is generated based on the width of the data stream connection and the size of the arrow triangle. The transparency and color of the highlighted pattern are set according to the attenuation coefficient of the policy conflict propagation chain, and the differential traffic is visualized in the global topology view and the security policy topology view.

2. The visualization method for network security strategies according to claim 1, characterized in that, The step of constructing a traffic-policy matching matrix based on the network traffic information and the security policy information, and identifying the differences in traffic among the various types of data streams using the traffic-policy matching matrix, includes: Based on the network traffic information, the source address and destination address of each type of data stream are extracted as the corresponding traffic identifier; The policy rules in the firewall whitelist and the firewall blacklist are parsed to obtain the matching conditions and execution actions of the policy rules. The matching conditions of the policy rules follow priority decision-making. The traffic identifiers are compared with the matching conditions of the policy rules to construct the traffic-policy matching matrix. The traffic-policy matching matrix records the policy rules and execution actions corresponding to each traffic identifier. The expected security status of each type of data flow is determined based on the execution actions in the traffic-policy matching matrix; Compare the actual security status of each type of data stream with the corresponding expected security status, and mark the data streams with inconsistent security status as differential traffic.

3. The method according to claim 2, characterized in that, The step of comparing each traffic identifier with the matching conditions of the policy rules to construct the traffic-policy matching matrix includes: Extract the policy rules that allow passage from the firewall whitelist, and extract the policy rules that prohibit passage from the firewall blacklist; The source address and destination address in each of the traffic identifiers are matched with the allowed passage policy rule and the denied passage policy rule, respectively; When a traffic identifier matches multiple policy rules, the final applicable action is determined based on the priority of the policy rules. Based on the matching results, a traffic-policy matching matrix is ​​generated, which includes traffic identifiers, policy rules matched to the traffic identifiers, and corresponding execution actions.

4. The method according to claim 1, characterized in that, The step of constructing network node connection relationships based on the source and destination addresses in the differential traffic, using the network node corresponding to the differential traffic as the starting node, constructing a policy conflict propagation chain based on the network node connection relationships, and calculating the attenuation coefficient of the policy conflict propagation chain includes: The source and destination addresses in the differential traffic are used as network nodes, and the connection relationship of the network nodes is constructed according to the direction of data flow. Select network nodes with policy execution deviations as the initial conflict nodes; Starting from the initial conflict node, the search is carried out downstream and upstream along the network node connection relationship to construct the policy conflict propagation chain; The attenuation coefficient of each node on the propagation path is calculated based on the propagation distance and the number of node connections in the strategy conflict propagation chain.

5. The method according to claim 4, characterized in that, The calculation of the attenuation coefficient of each node on the propagation path based on the propagation distance and the number of node connections in the policy conflict propagation chain includes: The number of propagation steps between each node in the strategy conflict propagation chain and the initial conflict node is calculated as the propagation distance. Count the number of connection edges for each node in the network node connection relationship; A distance attenuation factor is set based on the propagation distance, and the distance attenuation factor is positively correlated with the propagation distance; A node influence factor is set based on the number of connected edges, and the node influence factor is positively correlated with the number of connected edges. The attenuation coefficient of each node is determined by weighting the distance attenuation factor and the node influence factor.

6. The method according to claim 1, characterized in that, The step of calculating the data stream connection width and the arrow triangle size based on the traffic volume, and generating a highlight pattern to identify the differential traffic volume based on the data stream connection width and the arrow triangle size, includes: The baseline width of the data stream connection is adjusted based on the traffic volume to obtain the width of the data stream connection. Calculate the size of the arrow triangle based on the width of the data stream connection; A highlighted rectangular pattern is generated based on the width of the data stream connection line, and a highlighted triangle pattern is generated based on the size of the arrow triangle. The highlighted rectangular pattern is placed on the data flow line, and the highlighted triangular pattern is placed at the arrow position to obtain a highlighted pattern used to identify the differential flow.

7. The method according to claim 6, characterized in that, The process of setting the transparency and color of the highlighted pattern based on the attenuation coefficient of the policy conflict propagation chain, and visualizing the differential traffic in the global topology view and security policy topology view, includes: The color of the highlighted pattern is determined based on the preset pattern color template library and the type corresponding to the differential flow. The transparency of the highlighted pattern is calculated based on the attenuation coefficient, and the transparency is positively correlated with the attenuation coefficient. The color and transparency are input as parameters into the color attribute of the highlight pattern to generate a highlight pattern with the specified color and transparency. Construct a global topology view containing all network nodes and data flow connections, and construct a security policy topology view containing network nodes and associated data flow connections in the policy conflict propagation chain. The highlighted pattern is displayed overlaid at the location corresponding to the differential traffic in the global topology view and the security policy topology view.

8. A visualization system for network security strategies, characterized in that, The system includes: The information acquisition module is used to acquire network traffic information and user-set security policy information. The network traffic information includes source address, destination address and traffic size. The security policy information includes firewall whitelist and firewall blacklist. The differential traffic determination module is used to classify the network traffic information into multiple types of data streams according to a preset security status, including unprotected, protected, denied, and default allowed; to construct a traffic-policy matching matrix based on the network traffic information and the security policy information; and to identify differential traffic in each type of data stream through the traffic-policy matching matrix. The pattern generation module is used to construct network node connection relationships based on the source address and destination address in the differential traffic, take the network node corresponding to the differential traffic as the starting node, construct a policy conflict propagation chain based on the network node connection relationship, and calculate the attenuation coefficient of the policy conflict propagation chain; calculate the data flow connection width and arrow triangle size based on the traffic size, and generate a highlighted pattern to identify the differential traffic based on the data flow connection width and the arrow triangle size. The visualization module is used to set the transparency and color of the highlighted pattern in conjunction with the attenuation coefficient of the policy conflict propagation chain, and to visualize the differential traffic in the global topology view and the security policy topology view.

9. An electronic device, characterized in that, The device includes a processor, a memory, a user interface, and a network interface. The memory is used to store instructions, the user interface and the network interface are used to communicate with other devices, and the processor is used to execute the instructions stored in the memory to cause the electronic device to perform the visualization method of the network security policy as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed, perform a visualization method for a network security policy as described in any one of claims 1-7.