A security policy division method and device, a storage medium and a computing device
By dividing security policies into different initial policy partitioning intervals, the matching efficiency problem caused by the increase in the number of firewall security policies in cloud computing multi-tenant scenarios is solved, the policy matching efficiency and performance are improved, and the sensitivity to the threshold of the number of leaf node policies is reduced.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HANGZHOU DPTECH TECH
- Filing Date
- 2026-01-20
- Publication Date
- 2026-04-17
AI Technical Summary
In cloud computing multi-tenant scenarios, the increase in the number of firewall security policies makes policy matching efficiency highly sensitive to the threshold of the number of policies in leaf nodes. Existing technologies cannot reduce the linear traversal overhead of security policies inside leaf nodes while reducing tree depth, thus affecting matching performance.
By dividing the security policies in the leaf nodes into different initial policy partitioning intervals according to the target policy matching domain, the number of policies in each interval is reduced, and the matching is performed according to each partitioning interval during policy matching, thus avoiding traversing all security policies in the leaf nodes.
It improves the matching efficiency of security policies and the matching performance of the security policy tree, reduces the sensitivity of matching efficiency to the threshold size of the number of policies in leaf nodes, and reduces the overhead of traversing security policies inside leaf nodes.
Smart Images

Figure CN121567468B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and more specifically, to a security policy partitioning method, apparatus, storage medium, and computing device. Background Technology
[0002] In multi-tenant cloud computing scenarios, the number of firewall security policies increases with the number of tenants. To improve the matching efficiency of security policies during tenant access, building a security policy tree for security policy matching is becoming increasingly common. When building a security policy tree, it is necessary to balance the depth of the security policy tree and the number of security policies stored in the leaf nodes, so as to achieve a balance between the latency of traversing nodes within the tree and the overhead of linear traversing security policies in the leaf nodes during policy matching.
[0003] When the number of security policies is large, the depth of the security policy tree and the number of security policies stored in the leaf nodes are directly affected by the set threshold for the number of policies in the leaf nodes. This makes the matching efficiency of security policies highly sensitive to the size of the threshold. Therefore, how to reduce the sensitivity of matching efficiency to the size of the threshold for the number of policies in the leaf nodes, and simultaneously reduce the overhead of linear traversal of security policies within the leaf nodes while minimizing the tree depth, has become an urgent technical problem to be solved. Summary of the Invention
[0004] In view of this, this application provides a security policy partitioning method, apparatus, storage medium, and computing device to reduce the sensitivity of security policy matching to the threshold size of the number of leaf node policies and improve policy matching efficiency.
[0005] Specifically, this application is implemented through the following technical solution:
[0006] In a first aspect, embodiments of this application provide a method for partitioning security policies, including:
[0007] For any leaf node in the security policy tree, determine each policy endpoint under each policy matching domain based on the policy scope of each security policy stored in the leaf node under each policy matching domain.
[0008] Based on the policy endpoints and the number of endpoints under each policy matching domain, construct the initial policy partitioning intervals of the leaf nodes under the target policy matching domain; wherein the policy ranges of each initial policy partitioning interval do not intersect.
[0009] Based on the target policy range of each security policy under the target policy matching domain, determine at least one initial policy partitioning interval to which each security policy belongs from each initial policy partitioning interval under the target policy matching domain, and assign each security policy to its respective initial policy partitioning interval.
[0010] Secondly, embodiments of this application also provide a security policy partitioning device, comprising:
[0011] The first determining module is used to determine, for any leaf node in the security policy tree, each policy endpoint under each policy matching domain based on the policy range of each security policy stored in the leaf node under each policy matching domain.
[0012] The partitioning module is used to construct the initial policy partitioning intervals of the leaf node under the target policy matching domain based on the policy endpoints and the number of endpoints under each policy matching domain; wherein the policy ranges of each initial policy partitioning interval do not intersect.
[0013] The second determining module is used to determine, based on the target policy range of each security policy under the target policy matching domain, at least one initial policy partitioning interval to which each security policy belongs from each initial policy partitioning interval under the target policy matching domain, and to partition each security policy into its respective initial policy partitioning interval.
[0014] Thirdly, an optional implementation of this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the steps of the first aspect described above.
[0015] Fourthly, an optional implementation of this application also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to perform the steps of the first aspect described above.
[0016] The security policy partitioning method, apparatus, storage medium, and computing device provided in this application divide the security policies stored in leaf nodes into different initial policy partitioning intervals according to the target policy matching domain. This allows for the partitioning of security policies in leaf nodes into as many intervals as possible while minimizing the number of policies in each interval. Consequently, during policy matching, security policies can be matched according to each partitioned interval, eliminating the need to traverse all security policies in the leaf nodes, effectively improving the efficiency of security policy matching and the matching performance of the security policy tree. Thus, by dividing the security policies in leaf nodes into different intervals to improve matching efficiency, this approach can maximize the threshold for the number of policies in a leaf node to reduce the depth of the security policy tree while minimizing the overhead of traversing security policies within the leaf nodes, thereby effectively reducing the sensitivity of matching efficiency to the size of the threshold for the number of policies in a leaf node.
[0017] For a description of the effects of the aforementioned security policy partitioning device, computer-readable storage medium, and computer equipment, please refer to the description of the aforementioned security policy partitioning method; it will not be repeated here.
[0018] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description
[0019] Figure 1 This is a flowchart illustrating a security policy partitioning method according to an exemplary embodiment of this application;
[0020] Figure 2 This is a schematic diagram illustrating a specific process of a security policy partitioning method in mode 1, as shown in an exemplary embodiment of this application;
[0021] Figure 3 This is a schematic diagram illustrating a specific process of a security policy partitioning method in mode 2, as shown in an exemplary embodiment of this application;
[0022] Figure 4 This is a flowchart illustrating a security policy matching process according to an exemplary embodiment of this application;
[0023] Figure 5 This is a schematic diagram of a security policy partitioning device shown in an exemplary embodiment of this application;
[0024] Figure 6 This is a schematic diagram of the structure of a computer device shown in an exemplary embodiment of this application. Detailed Implementation
[0025] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0026] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.
[0027] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."
[0028] Research has revealed that when constructing a firewall security policy tree, whether by introducing security policy replication in the leaf nodes or by eliminating replication in the leaf nodes, a balance must be struck between the tree's depth and the number of security policies within each leaf node. This is because, for any set of security policies, constructing the tree using these policies often presents one of two scenarios: Scenario 1: If the pre-set threshold for the number of policies in a leaf node is too high, while reducing the tree's depth, it leads to an excessive number of policies in each leaf node. This increases the overhead of linear matching within the leaf nodes, resulting in longer matching times. Scenario 2: If the threshold for the number of policies in a leaf node is too low, while reducing the overhead of linear matching within leaf nodes, it increases the tree's depth. This requires traversing more nodes during policy matching, increasing traversal latency and impacting matching performance. In other words, the smaller the threshold for the number of policies in a leaf node, the greater the depth of the security policy tree may be, increasing the tree node traversal latency, but increasing the number of leaf nodes and reducing the overhead of linear search within leaf nodes. Conversely, the larger the threshold for the number of policies in a leaf node, the smaller the depth of the security policy tree may be, reducing the tree node traversal latency, but decreasing the number of leaf nodes and increasing the number of security policies within leaf nodes, leading to increased overhead of linear search within leaf nodes. Therefore, it can be seen that the total matching latency of a security policy tree consists of two parts: the tree node traversal latency and the linear search latency within leaf nodes, and there exists an optimal balance point. However, existing solutions often fail to find this optimal balance point, resulting in the need to improve the matching performance and efficiency of security policy trees.
[0029] For example, one existing solution directly utilizes a user-specified threshold for the number of leaf node policies to construct a security policy tree without copying security policies. This approach makes the depth of the security policy tree sensitive to the externally set threshold for the number of leaf node policies, easily leading to situations 1 or 2 mentioned above, resulting in poor security policy matching performance. To improve the rationality of the threshold for the number of leaf node policies, offline analysis can be used to select the optimal threshold and construct the security policy tree. Furthermore, when the number of security policy trees in the security policy set is relatively small, online analysis can use a method similar to offline analysis to determine the optimal threshold for the number of leaf node policies and construct the security policy tree. In this case, the determination time of the optimal threshold for the number of leaf node policies and the construction time of the security policy tree will be within an ideal range due to the small number of security policy trees. However, when the number of security policy trees is large, such as hundreds of thousands or millions, determining the optimal threshold for the number of leaf node policies online and constructing the security policy tree will significantly increase the construction time of the security policy tree, making it difficult to use the security policies for policy matching, resulting in obvious drawbacks. Therefore, how to reduce the impact of the leaf node policy number threshold on the construction of the security policy tree and improve the matching performance of the security policy tree has become a technical challenge worth paying attention to.
[0030] Based on the above research, this application provides a security policy partitioning method, apparatus, storage medium, and computing device. By dividing the security policies stored in leaf nodes into different initial policy partitioning intervals according to the target policy matching domain, it is possible to divide the security policies in leaf nodes into as many intervals as possible while minimizing the number of policies in each interval. Therefore, during policy matching, security policies can be matched according to each partitioned interval, eliminating the need to traverse all security policies in the leaf nodes, effectively improving the efficiency of security policy matching and the matching performance of the security policy tree. Thus, by dividing the security policies in leaf nodes into different intervals to improve matching efficiency, it is possible to maximize the threshold for the number of policies in leaf nodes to reduce the depth of the security policy tree while reducing the overhead of traversing security policies within leaf nodes, thereby effectively reducing the sensitivity of matching efficiency to the size of the threshold for the number of policies in leaf nodes.
[0031] The shortcomings of the above solutions are the result of the inventor's practical experience and careful research. Therefore, the discovery process of the above problems and the solutions proposed in this application below should be considered as the inventor's contributions to this application.
[0032] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0033] It is understood that before using the technical solutions disclosed in the various embodiments of this application, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this application in an appropriate manner in accordance with relevant laws and regulations, and user authorization should be obtained.
[0034] It should be noted that the specific terms mentioned in the embodiments of this application include:
[0035] Class Bench: A toolset for testing the performance of message classification algorithms and classification devices, which includes parameter files, rule set generators, and message generators;
[0036] ACL_100k: refers to the 100,000-rule set of an Access Control List. ACL rules mainly rely on information such as the five-tuple of a data packet (source IP address, destination IP address, source port, destination port, and protocol number) to control whether the data packet is allowed or blocked. It is a basic rule type for network security and traffic management.
[0037] FW_100k: refers to the 100,000 rule set of the firewall (FW). Firewall rules, based on ACLs, further integrate more complex logic such as traffic filtering and security policy control. They can not only achieve basic access control, but also accurately identify and process specific application layer protocols and malicious traffic characteristics.
[0038] IPC_100k: refers to the 100,000 rule set of the IP chain. IP chain rules are often used in scenarios such as link-layer forwarding control of network packets and traffic routing planning. The rule design focuses more on defining the transmission path and forwarding strategy of data packets between different network links.
[0039] To facilitate understanding of this embodiment, a detailed description of the security policy partitioning method disclosed in this application embodiment will be provided first. The execution subject of the security policy partitioning method provided in this application embodiment is generally a terminal device or other processing device with certain computing capabilities. The terminal device can be a user equipment (UE), mobile device, user terminal, terminal, personal digital assistant device (PDA), handheld device, computer device, etc. In some possible implementations, the security policy partitioning method can be implemented by the processor calling computer-readable instructions stored in the memory.
[0040] The following uses a cloud computing server as an example to illustrate the security policy partitioning method provided in this application.
[0041] like Figure 1 The flowchart shown is a security policy partitioning method provided in an embodiment of this application, which may include the following steps:
[0042] S101: For any leaf node in the security policy tree, determine the policy endpoints under each policy matching domain based on the policy scope of each security policy stored in the leaf node under each policy matching domain.
[0043] Here, the policy matching domain is a pre-defined domain, which can be pre-determined based on the various attributes corresponding to the information contained in the security policy and the various attributes corresponding to the information contained in the message to be matched. The message to be matched is the data packet carried by the access request initiated by the tenant. The security policy can be the firewall's security policy, and each security policy can contain policy information under at least some policy matching domains. For example, the policy matching domain can include source port domain, destination port domain, source Internet Protocol (IP) domain, destination IP domain, client identifier domain, physical address domain, client attribute domain, client name domain, etc. The security policy can include policy range information under different policy matching domains and their corresponding policy rules. For example, a security policy may allow or deny access to messages to be matched that have a source port range of 80-90 and a destination port range of 100-120. A message to be matched carries message information such as source port 85 and destination port 110.
[0044] For example, the policy matching domain F of a security policy may include m domains, where the number of m is not specifically limited in this application and can be set according to actual application scenarios and experience. That is, the domain dimension of the policy matching domain F is m, and the policy matching domains... ,in, This indicates the first policy matching field. This indicates the second strategy matching field. This represents the matching domain of the m-th strategy. , ... They are all different.
[0045] The security policy tree can be either a security policy tree under construction or a security policy tree that has already been initially constructed. For a security policy tree that has been initially constructed, all tree nodes in the policy tree are determined, and the security policies that each leaf node needs to store are also determined. The number of security policies stored in a leaf node is less than or equal to a preset threshold for the number of leaf node policies. This application does not specifically limit the size or determination method of the threshold for the number of leaf node policies; the security policy partitioning method provided in this application is applicable to various sizes of leaf node policy number thresholds. Different security policies are stored in different leaf nodes.
[0046] The number of security policy trees can be one or more, and this application does not limit the number of security policy trees. For any security policy tree, the security policies that need to be stored in its leaf nodes can be divided according to the security policy partitioning method provided in the embodiments of this application. The security policy corresponding to each security policy tree can be a set of security policies stored in each leaf node of the security policy tree. There is no policy duplication between security policies corresponding to different security policy trees, that is, the security policies corresponding to different security policy trees are different. In the security policy tree, only leaf nodes are used to store security policies, and other tree nodes other than leaf nodes do not store any security policies, that is, the non-leaf nodes of the security policy tree do not store security policies.
[0047] The policy scope indicates the range of domains corresponding to a security policy under the policy matching domain. For example, for the source port domain, if the source port range in the security policy is 10~20, then the policy scope of the security policy under the source port domain is 10~20; if the source port range in the security policy is 30, then the policy scope of the security policy under the source port domain is 30.
[0048] Policy endpoints are used to indicate the range of policy endpoint values. For example, if the source port range is 10~20, then the endpoint values include 10 and 20. If the policy ranges of three security policies under the source port domain are 1~30, 2~10, and 9~20 respectively, then the endpoint values include 1, 2, 9, 10, 20, and 30.
[0049] For any policy matching domain, the policy endpoints under that policy matching domain are determined by the policy range of all security policies stored in the leaf node under that policy matching domain, and there is no overlap between policy endpoints. For example, for any leaf node, the target port ranges of the various security policies stored in that leaf node under a certain policy matching domain are 1~10, 12~15, and 15~30, respectively, and the policy endpoints under that policy matching domain include 1, 10, 12, 15, and 30.
[0050] In practice, for any leaf node in any security policy tree, all security policies stored in that leaf node can be traversed to determine the policy scope of each security policy under each policy matching domain. Understandably, since different security policies have different rules and are applicable to different scenarios, some security policies may not have policy information in a certain policy matching domain. Therefore, the policy scope of these security policies under that policy matching domain is either empty or the entire scope of that policy matching domain by default. Then, for each policy matching domain, based on the policy scope of each security policy stored in that leaf node under that policy matching domain, the policy endpoints of each security policy under that policy matching domain can be determined. The policy endpoints of each security policy are then sorted in ascending order from smallest to largest and deduplicated to obtain the policy endpoints under that policy matching domain (i.e., the policy endpoints of the leaf node under that policy matching domain).
[0051] For example, the policy endpoint of each security policy under the policy matching domain f can be represented as:
[0052] ;
[0053] Wherein, policy represents the security policy in the leaf node. leaf Represents a leaf node. This indicates the security policy in the leaf node within the policy matching domain. f The policy endpoint below, This represents the minimum endpoint value of the security policy in the leaf node under the policy matching domain f. This indicates the security policy in the leaf node within the policy matching domain. f The maximum endpoint value below.
[0054] For each security policy, sort the policy endpoints under the policy matching domain f in ascending order and remove duplicate endpoint values to obtain the policy endpoints and the number of endpoints M for each security policy under the policy matching domain f. For example, the policy endpoints and the number of endpoints M for each security policy under the policy matching domain f can be expressed as:
[0055] ;
[0056] in, This indicates the various security policies in the leaf nodes within the policy matching domain. f The various strategy endpoints are defined by `sort`, which indicates ascending order sorting from smallest to largest. Deduplicat policy endpoints, where M represents the number of policy endpoints.
[0057] S102: Based on the policy endpoints and the number of endpoints under each policy matching domain, construct the initial policy partitioning intervals of the leaf nodes under the target policy matching domain; wherein the policy ranges of each initial policy partitioning interval do not intersect.
[0058] Here, the target policy matching domain is the matching domain selected from various policy matching domains. There is no intersection between the initial policy division intervals under the same target policy matching domain. The policy ranges between the initial policy division intervals under different target policy matching domains may or may not intersect.
[0059] The initial policy partition is used to store security policies in leaf nodes. Security policies stored in different initial policy partitions may or may not overlap. The number of endpoints is the total number of policy endpoints under the policy matching domain.
[0060] In practice, the target policy matching domain can be selected from each policy matching domain based on the number of endpoints under each policy matching domain. For example, policy matching domains with more than a set number of endpoints can be selected as target policy matching domains, the policy matching domain with the largest number of endpoints can be selected as the target policy matching domain, or policy matching domains with an ascending order of endpoint counts that are greater than a set order can be selected as target policy matching domains. Alternatively, all policy matching domains can be selected as target policy matching domains. After determining the target policy matching domain, initial policy partitioning intervals can be constructed based on the policy endpoints under the target policy matching domain, according to the principle that policy ranges do not overlap.
[0061] For example, if the policy ranges of each security policy under the target policy matching domain are 1~30, 2~10, and 9~20 respectively, then the policy endpoints under the target policy matching domain include 1, 2, 9, 10, 20, and 30. The initial policy division intervals constructed based on the policy endpoints are 1, 2, 3~8, 9, 10, 11~19, 20, 21~29, and 30, which are nine initial policy division intervals that do not intersect with each other, and some of the initial policy division intervals contain a single value.
[0062] S103: Based on the target policy range of each security policy under the target policy matching domain, determine at least one initial policy partitioning interval to which each security policy belongs from each initial policy partitioning interval under the target policy matching domain, and assign each security policy to its respective initial policy partitioning interval.
[0063] Here, the target policy scope refers to the policy scope of the security policy within the target policy matching domain. For example, the security policy within the policy matching domain... The policy ranges are 1 to m respectively. If the target policy matching domain is If the security policy's target policy range within the target policy matching domain is range 1, then the target policy range is range 1; if the target policy matching domain is... Then, the range of the target policy under the target policy matching domain is the range m.
[0064] The initial policy segmentation interval to which a security policy belongs is related to whether the target policy range under the target policy matching domain intersects with the initial policy segmentation interval. A security policy can belong to one or more initial policy segmentation intervals. For example, if the target policy range is 2~10, and the initial policy segmentation intervals are 1, 2, 3~8, 9, 10, 11~19, 20, 21~29, 30 respectively, then the initial policy segmentation interval to which the security policy belongs includes 2, 3~8, 9, and 10; if the target policy range is 10~13, then the initial policy segmentation interval to which the security policy belongs includes 10 and 11~19.
[0065] In practice, for each security policy in the leaf node, based on the target policy range of the security policy under the target policy matching domain and the initial policy partitioning intervals under the target policy matching domain, the policy partitioning intervals that intersect with the target policy range in the initial policy partitioning intervals are determined. These policy partitioning intervals are taken as the initial policy partitioning intervals to which the security policy belongs, and the security policy is partitioned into the respective initial policy partitioning intervals, thereby realizing the interval partitioning of the security policy in the leaf node.
[0066] Understandably, if there is only one target policy matching domain, then this target policy matching domain can be used as the partitioning domain of the leaf node. Furthermore, based on the initial policy partitioning intervals under this target policy matching domain, the policy partitioning intervals are determined to determine the policy partitioning intervals of the leaf node. This allows for security policy matching based on the partitioning domain, the policy partitioning intervals, and the security policies stored within those intervals. Security policy matching will be discussed in detail later.
[0067] If there are multiple target policy matching domains, one can be selected as the partitioning domain for the leaf node. The policy partitioning intervals for the leaf node are then determined based on the initial policy partitioning intervals within that domain. For example, the target policy matching domain with the most initial policy partitioning intervals can be selected as the partitioning domain; alternatively, the partitioning domain with the most evenly distributed number of security policies can be selected from the multiple target policy matching domains based on the distribution of security policies among the initial policy partitioning intervals.
[0068] In one embodiment, to further improve the rationality of the divided policy partitioning intervals, this application also proposes a method for merging policy partitioning intervals. Specifically, after dividing each security policy into its respective initial policy partitioning intervals, interval merging can be performed according to the following steps 1-2:
[0069] Step 1: Based on the security policies divided in each initial policy partitioning interval and the adjacency relationships between each initial policy partitioning interval, determine whether there are adjacent intervals with the same security policies to be merged from the initial policy partitioning intervals.
[0070] Here, adjacency indicates whether different initial policy partitioning intervals are adjacent. The adjacency of initial policy partitioning intervals is related to the order of their ranges. Since the initial policy partitioning intervals are divided according to the policy endpoints in ascending order, initially policy partitioning intervals with adjacent partitioning orders are often adjacent. The intervals to be merged are at least two consecutive, adjacent initial policy partitioning intervals that include the same security policies. The security policies partitioned within an initial policy partitioning interval are the security policies included within that initial policy partitioning interval.
[0071] In practical implementation, for any initial policy partitioning interval under any target policy matching domain, the adjacent initial policy partitioning intervals can be determined according to the partitioning order of the initial policy partitioning interval. This yields the adjacency relationships between the initial policy partitioning intervals. Then, for any two adjacent initial policy partitioning intervals, it can be determined whether the security policies partitioned in these two initial policy partitioning intervals are completely identical. If so, these two initial policy partitioning intervals can be considered as a group of intervals to be merged. If not, it can be determined that these two initial policy partitioning intervals do not need to be considered as a group of intervals to be merged. The intervals to be merged in the same group are consecutively adjacent and include the same security policies.
[0072] Understandably, if three or more consecutive initial policy partitioning intervals have the same security policy, these initial policy partitioning intervals can all be considered as the same group of intervals to be merged. Different groups of intervals to be merged will have different security policies.
[0073] For example, if the initial policy partitioning intervals under a certain target policy matching domain are intervals A, B, C, and D respectively, then intervals A and B are two adjacent initial policy partitioning intervals, intervals B and C are two adjacent initial policy partitioning intervals, and intervals C and D are two adjacent initial policy partitioning intervals. If the security policies in intervals A and B are consistent, then intervals A and B can be considered as one set of intervals to be merged. If the security policies in intervals A, B, and C are consistent, then intervals A, B, and C can be considered as one set of intervals to be merged, where intervals A, B, and C are consecutive intervals. If the security policies in intervals A and B are consistent, and the security policies in intervals C and D are consistent, then two sets of intervals to be merged can be obtained: the first set includes intervals A and B, and the second set includes intervals C and D.
[0074] Step 2: If so, merge the intervals to be merged into the target policy partitioning interval, and take the target policy partitioning interval and the intervals in the initial policy partitioning interval other than the intervals to be merged as the policy partitioning intervals of the leaf nodes under the target policy matching domain.
[0075] In practice, when it is determined that there are intervals to be merged, for each group of intervals to be merged, the group of intervals to be merged can be merged into a target policy partitioning interval. The range of the target policy partitioning interval is the union of the ranges of the intervals of the group of intervals to be merged. The security policy partitioned in the target policy partitioning interval is the security policy partitioned for any interval in the group of intervals to be merged.
[0076] Understandably, if there are multiple sets of intervals to be merged, merging these multiple sets of intervals can result in multiple target policy partitioning intervals. Furthermore, for multiple target policy partitioning intervals, if adjacent target policy partitioning intervals have the same security policy, then adjacent target policy partitioning intervals can be further merged to obtain new target policy partitioning intervals.
[0077] Furthermore, after merging the various target policy partitioning intervals, each target policy partitioning interval, along with the intervals in the initial policy partitioning interval excluding the interval to be merged, can be used as the various policy partitioning intervals of the leaf node under the target policy matching domain. Simultaneously, a maximum number can be determined from the number of security policies in each policy partitioning interval of the leaf node under the target policy matching domain as the maximum number of security policies for the leaf node under the target policy matching domain. .
[0078] In another embodiment, if there are no adjacent intervals with the same security policy to be merged in the initial policy partitioning interval, each initial policy partitioning interval can be directly used as the leaf node's policy partitioning interval under the target policy matching domain.
[0079] For example, if the initial policy partitioning intervals are 1, 2, 3~8, 9, 10, 11~19, 20, 21~29, and 30 respectively, and if the security policies in the initial policy partitioning intervals 1, 2, and 3~8 are all policies 1~3, then the initial policy partitioning intervals 1, 2, and 3~8 can be merged into a single target policy partitioning interval 1~8, and the security policies in this interval are policies 1~3. Similarly, if the security policies in the initial policy partitioning intervals 11~19 and 20 are all policies 8 and 9, then the initial policy partitioning intervals 11~19 and 20 can be merged into a single target policy partitioning interval 11~20, and the security policies in this interval are policies 8 and 9. Furthermore, the target policy partitioning intervals 1~8, the initial policy partitioning interval 9, the initial policy partitioning interval 10, the target policy partitioning intervals 11~20, the initial policy partitioning intervals 21~29, and the initial policy partitioning interval 30 can be used as leaf nodes representing the various policy partitioning intervals under the target policy matching domain. If there are no two adjacent intervals with the same security policy in the initial policy partitioning intervals 1, 2, 3~8, 9, 10, 11~19, 20, 21~29, and 30, then the initial policy partitioning intervals 1, 2, 3~8, 9, 10, 11~19, 20, 21~29, and 30 can be directly used as leaf nodes in the target policy matching domain for each policy partitioning interval.
[0080] Regarding S102 above, different methods can be used to select the target policy matching domain and divide the initial policy partitioning interval. The selection and partitioning processes corresponding to Method 1 and Method 2 are described below:
[0081] For method 1, it can be achieved by following steps A1 to A3:
[0082] A1: Select the policy matching domain with the largest number of endpoints from all policy matching domains as the target policy matching domain.
[0083] In practice, for each policy matching domain, the number of endpoints M under that policy matching domain can be determined based on the various policy endpoints within that domain. Then, the policy matching domain with the largest number of endpoints M can be selected. The target policy matching domain can be selected as follows: If multiple policy matching domains with the largest number of endpoints M exist, one can be randomly selected as the target policy matching domain. Alternatively, the most evenly distributed policy matching domain can be selected based on the distribution of the policy endpoints corresponding to each of the multiple policy matching domains. Or, the domain with the highest importance can be selected as the target policy matching domain. Alternatively, if multiple policy matching domains with the largest number of endpoints M exist, all of these policy matching domains can be used as target policy matching domains first, and then the security policy can be divided and the domain selected based on method 2.
[0084] A2: Determine the number of the first interval based on the number of endpoints in the target strategy matching domain.
[0085] Here, the first interval number is used to indicate the maximum number of initial policy partition intervals under the target policy matching domain.
[0086] For example, the number of endpoints M under the target policy matching domain can be twice the number of endpoints M minus 1 to obtain the number of the first interval. That is, the number of the first interval = 2M - 1.
[0087] A3: Based on the policy endpoints under the target policy matching domain and the ascending order of the policy endpoints, construct the initial policy partitioning intervals of the leaf nodes under the target policy matching domain; the number of initial policy partitioning intervals is less than or equal to the number of the first intervals.
[0088] In practice, based on the policy endpoints under the target policy matching domain and the policy range of each security policy under the target policy matching domain, the policy range of each security policy under the target policy matching domain can be divided into initial policy partitioning intervals in ascending order of the policy endpoints; wherein, the number of leaf nodes in each initial policy partitioning interval under the target policy matching domain is less than or equal to the number of the first interval.
[0089] For example, if the target policy ranges of each security policy under the target policy matching domain are 1~30, 2~10, and 9~20 respectively, then after sorting the endpoint values in ascending order, they are 1, 2, 9, 10, 20, and 30, with 6 endpoints and 11 first intervals. The resulting initial policy division intervals are 1, 2, 3~8, 9, 10, 11~19, 20, 21~29, and 30. At this time, there are 9 initial policy division intervals, which is less than the number of first intervals of 11. If the target policy ranges of each security policy under the target policy matching domain are 1~30, 3~11, and 9~20 respectively, then the endpoint values, after ascending sorting, are 1, 3, 9, 11, 20, and 30, with 6 endpoints and 11 first intervals. The resulting initial policy division intervals are 1, 2, 3, 4~8, 9, 10, 11, 12~19, 20, 21~29, and 30. At this point, there are 11 initial policy division intervals, which is equal to the number of first intervals of 11.
[0090] Furthermore, after each security policy is divided into its respective initial policy partitioning intervals, the target policy matching domain can be used as the partitioning domain corresponding to the leaf node.
[0091] In other words, after dividing the target policy matching domain and the initial policy partitioning interval using Method 1, the unique target policy matching domain selected in Method 1 can be used as the partitioning domain corresponding to the leaf node. If there is at least one set of intervals to be merged in the initial policy partitioning intervals under the target policy matching domain, these intervals can be merged to obtain various target policy partitioning intervals. These target policy partitioning intervals, along with the intervals in the initial policy partitioning intervals excluding the intervals to be merged, are then used as the various policy partitioning intervals under the partitioning domain. If there are no intervals to be merged in the initial policy partitioning intervals under the target policy matching domain, these initial policy partitioning intervals can be directly used as the various policy partitioning intervals under the partitioning domain. Simultaneously, based on the number of security policies in each policy partitioning interval under the partitioning domain, a maximum number can be determined as the maximum number of security policies for the leaf node under the partitioning domain. It also saves the relationship between each policy division interval and the security policies divided therein.
[0092] like Figure 2 The diagram illustrates a specific flowchart of a security policy partitioning method in Mode 1 provided in this application embodiment. For any leaf node in the security policy tree, all policy matching domains can be traversed sequentially. For the currently traversed policy matching domain f, the policy endpoints corresponding to each security policy are determined based on the policy ranges of each security policy stored in the leaf node within that policy matching domain. Then, the policy endpoints corresponding to each security policy are sorted in ascending order and deduplicated to obtain the policy endpoints and the number of endpoints within that policy matching domain. Compare the M values, which are the number of endpoints matching the candidate strategy in the matching domain. The number of endpoints of the currently traversed policy matching domain f After comparing the size of the policy matching domains, if there are any untraversed policy matching domains, the process can return to iterating through all policy matching domains sequentially until all policy matching domains have been traversed. The candidate policy matching domain is the policy matching domain with the largest number of endpoints among all the traversed policy matching domains. When traversing the first policy matching domain, since there are no candidate policy matching domains, the first policy matching domain can be directly used as a candidate policy matching domain. If the number of endpoints of the currently traversed policy matching domain f is... If the number of endpoints in the currently traversed policy matching domain f is larger, then update the domain (i.e., use the currently traversed policy matching domain f as a candidate policy matching domain). If the value is smaller, the candidate policy matching domain remains unchanged. After traversing all policy matching domains, the target policy matching domain is determined based on each candidate policy matching domain, and the number of endpoints under the target policy matching domain is used as the basis for the determination. Divide into the most The system first divides the space into initial policy intervals, then assigns each security element in the leaf node to an initial policy interval, and merges adjacent intervals with the same security policy. The target policy matching domain is then used as the partitioning domain corresponding to the leaf node.
[0093] For method 2, the following steps B1 to B3 can be followed:
[0094] B1: Each policy matching domain is used as the target policy matching domain.
[0095] For example, in method 2, all policy matching domains can be used as target policy matching domains.
[0096] B2: For each target policy matching domain, determine the number of second intervals for that target policy matching domain based on the number of endpoints under that target policy matching domain.
[0097] Here, the second interval quantity is used to indicate the maximum number of initial policy division intervals under the target policy matching domain in method 2.
[0098] For example, in Method 2, for each target policy matching domain, the number of second intervals under the target policy matching domain can be calculated according to the formula 2M-1 based on the number of endpoints M under the target policy matching domain.
[0099] B3: Based on the policy endpoints and their ascending order in the target policy matching domain, construct the initial policy partitioning intervals for each leaf node in the target policy matching domain; wherein the number of initial policy partitioning intervals in the target policy matching domain is less than or equal to the number of second intervals in the target policy matching domain.
[0100] Regarding step B3, the specific process of determining the initial policy partitioning intervals under each target policy matching domain selected in method 2 for the leaf node is similar to the process of partitioning the initial policy partitioning intervals in A3 above. Therefore, the specific implementation process of B3 can refer to the description in A3 above, and will not be repeated here. In method 2, the number of initial policy partitioning intervals under each target policy matching domain is less than or equal to the number of second intervals under that target policy matching domain.
[0101] Furthermore, after using method 2 to divide the initial policy partitioning intervals under each target policy matching domain and determining the security policy belonging to each initial policy partitioning interval, for each initial policy partitioning interval under each target policy matching domain, the initial policy partitioning intervals under each target policy matching domain can be merged according to the steps in steps 1 and 2 above, resulting in each target policy partitioning interval under each target policy matching domain. Then, since a leaf node ultimately selects only one partitioning domain, while method 2 selects multiple target policy matching domains, it is necessary to filter the multiple target policy matching domains selected by method 2 to obtain a uniquely retained partitioning domain. Specifically, the partitioning domain can be determined using the following steps C1 and C2:
[0102] C1: Determine the number of third intervals under each target strategy matching domain.
[0103] Here, the number of third intervals is used to indicate the number of policy division intervals under the target policy matching domain. One target policy matching domain corresponds to one number of third intervals.
[0104] Specifically, if there are intervals to be merged in the initial policy partitioning intervals under the target policy matching domain, the number of third intervals under the target policy matching domain can be determined based on the number of target policy partitioning intervals obtained after merging, and the number of intervals in the initial policy partitioning intervals excluding the intervals to be merged. If there are no intervals to be merged in the initial policy partitioning intervals under the target policy matching domain, the number of third intervals under the target policy matching domain can be determined based on the number of initial policy partitioning intervals under the target policy matching domain.
[0105] For example, for each target policy matching domain selected in Method 2, the number of target policy partitioning intervals under that target policy matching domain, plus the sum of the number of intervals (excluding the intervals to be merged) in the initial policy partitioning intervals under that target policy matching domain, can be used as the number of third intervals under that target policy matching domain. The minimum number of target policy partitioning intervals is 0. The minimum number of intervals (excluding the intervals to be merged) in the initial policy partitioning intervals under that target policy matching domain is 0, and the maximum number is the total number of initial policy partitioning intervals under that target policy matching domain.
[0106] C2: Based on the number of the third interval, determine a partitioning domain corresponding to the leaf node from each target policy matching domain, and take the policy partitioning interval of the leaf node under the partitioning domain as the policy partitioning interval of the leaf node.
[0107] To minimize the overhead of linear search in leaf nodes during policy matching, this can be achieved by maximizing the number of policy partitioning intervals within each leaf node. Therefore, in practice, the target policy matching domain with the largest number of third intervals can be determined based on the number of third intervals under each target policy matching domain, and this target policy matching domain can be used as the partitioning domain corresponding to the leaf node. Simultaneously, the policy partitioning intervals of each leaf node within its partitioning domain can be used as the actual policy partitioning intervals used by the leaf node. Furthermore, target policy matching domains other than the partitioning domain can be proposed, and the policy partitioning intervals corresponding to these target policy matching domains can be removed. The policy partitioning intervals of each leaf node within its partitioning domain are determined based on whether there is a merging of the initial policy partitioning intervals within the partitioning domain. For example, if some initial policy partitioning intervals within the partitioning domain contain intervals to be merged, the merged target policy partitioning intervals and the initial policy partitioning intervals excluding those to be merged can be used as the policy partitioning intervals corresponding to the leaf node, and the association between each policy partitioning interval and the security policies it is partitioned into can be preserved. If no initial policy partitioning intervals within the partitioning domain contain intervals to be merged, then the initial policy partitioning intervals within the partitioning domain can be used as the policy partitioning intervals corresponding to the leaf node. If each initial strategy partition interval under the partition domain belongs to the interval to be merged, then each target strategy partition interval after merging can be used as the strategy partition interval corresponding to the leaf node.
[0108] In one embodiment, the process of determining the partition domain in C2 above can also be implemented according to the following steps:
[0109] When there are multiple target policy matching domains with the largest number in the third interval, the partitioning domain corresponding to the leaf node is determined according to the maximum number of security policies corresponding to each of the multiple target policy matching domains with the largest number in the third interval; wherein, the maximum number of security policies corresponding to the target policy matching domain is related to the number of security policies divided in each policy partitioning interval under the target policy matching domain.
[0110] In specific implementation, in Method 2, after determining the initial policy partitioning intervals under each target policy matching domain, and assigning each security policy to its respective initial policy partitioning interval and merging the intervals, for each target policy matching domain, the policy partitioning interval with the largest number of security policies can be determined based on the number of security policies divided in the policy partitioning intervals under that target policy matching domain. The number of security policies divided in that policy partitioning interval is taken as the maximum number of security policies corresponding to each target policy matching domain. Furthermore, based on the number of third intervals under each target policy matching domain, the target policy matching domain with the largest number of third intervals can be determined. If there is only one target policy matching domain with the largest number of third objectives, it can be directly used as the partitioning domain corresponding to the leaf node. If there are multiple target policy matching domains with the largest number of third objectives, in order to reduce the overhead of policy matching in each policy partitioning interval within the partitioning domain, the target policy matching domain with the smallest maximum number of security policies among the multiple target policy matching domains with the largest number of third objectives can be used as the partitioning domain corresponding to the leaf node, and the policy partitioning intervals under this partitioning domain can be used as the policy partitioning intervals corresponding to the leaf node.
[0111] For example, in method 2, the number P of policy partitioning intervals and the maximum number of security policies under each target policy matching domain can be determined. Then, the partitioning region can be selected using the following formula:
[0112] (Formula 1)
[0113] in, Represents the partitioned domain. This represents the target policy matching domain with the largest number of occurrences in the third interval. Indicates the target policy matching domain f The number of the third interval is defined below, with "if unique" indicating that there is only one. This represents the target policy matching domain with the largest number of items in the third interval and the smallest maximum number of security policies. This represents the maximum number of security policies that the target policy matches. The third interval represents the target strategy matching domain with the largest number of occurrences, while else indicates that there is more than one such domain.
[0114] like Figure 3 The diagram illustrates a specific flowchart of a security policy partitioning method in Method 2 provided in this application embodiment. For any leaf node in the security policy tree, all policy matching domains can be traversed sequentially. For the currently traversed policy matching domain f, the policy endpoints corresponding to each security policy are determined based on the policy ranges of each security policy stored in the leaf node within that policy matching domain. Then, the policy endpoints corresponding to each security policy are sorted in ascending order and deduplicated to obtain the policy endpoints and the number of endpoints within that policy matching domain. Under this strategy matching domain, the most... The system first divides the policy into intervals, assigns each security policy in the leaf nodes to the initial policy interval, and merges adjacent intervals with the same security policy. It also records the number of policy intervals under the matching domain of each policy. and maximum number of security policies If there are untraversed policy matching domains, return to the steps of traversing all policy matching domains sequentially until all policy matching domains have been traversed. Select from all policy matching domains... Largest partition In the selection During the process, determine whether If there are multiple maximum policy matching domains, then the maximum number of security policies can be selected. The smallest policy matching domain is used as the partitioning domain. If not, then you can choose The largest policy matching domain, used as the partitioning domain .
[0115] In one embodiment, after completing the security policy partitioning of each leaf node in the security policy tree, the partition domain corresponding to each leaf node in the security policy tree, the various policy partitioning regions under the partition domain, and the security policies partitioned in each policy partitioning region can be obtained. Then, the security policy tree after security policy partitioning can be used for security policy matching. Specifically, security policy matching can be performed according to the following S1~S4:
[0116] S1: In response to receiving a message to be matched, determine the target leaf node that matches the message in the security policy tree based on the message information of the message to be matched under each policy matching field.
[0117] Here, the message to be matched can be a data packet carried in an access request initiated by any tenant. The message information is the message value corresponding to the message to be matched under the policy matching domain. For example, for the source port domain, the message information can be the source port value carried in the message to be matched; for the IP domain, the message information can be the IP address carried in the message to be matched.
[0118] The target leaf node is a leaf node in the security policy tree that may store a security policy that matches the message to be matched.
[0119] In practical implementation, in response to receiving any message to be matched, the message information of the message to be matched under each policy matching field can be determined based on each policy matching field and the information carried by the message. Then, starting from the root node of the security policy tree, the tree nodes are traversed. For the currently traversed tree node, it is determined whether the node type is an internal node (i.e., a non-leaf node) or a leaf node. If it is an internal node, it can be determined whether the message to be matched matches the tree node based on the target matching field corresponding to the tree node and the message information of the message to be matched under each target matching field. Alternatively, it can be determined whether the message to be matched matches the tree node based on the target bit corresponding to the tree node and the values of each target bit of the message to be matched. The target matching field or target bit corresponding to the tree node can be determined when constructing the security policy tree. Regarding the determination of the target matching field or target bit corresponding to the tree node, the process of constructing a security policy tree based on discrete / continuous multi-bit technology in existing technologies can be referred to, and will not be elaborated here. If no match is found, it can be determined that there is no security policy in the current security policy tree that matches the message to be matched. If there are other untraversed security policy trees, the traversal of other security policy trees can continue. If there are no other untraversed security policy trees, the matching result can be returned directly. If a match is found, the matching tree node is determined from the subtree corresponding to the tree node, and the steps of traversing the tree nodes of the security policy tree are returned. This tree node is used as the current traversal tree node until the target leaf node of the node type is reached or until the matching result is returned.
[0120] S2: Determine the target message information of the message to be matched in the partition domain corresponding to the target leaf node from the message information.
[0121] Here, the target message information is the partition domain of the message to be matched under the partition domain corresponding to the target leaf node. Values. For example, if the domain is a port domain, the target packet information is the port value of the packet to be matched; if the domain is an IP domain, the target packet information is the IP address of the packet to be matched.
[0122] In practice, the partitioning domain corresponding to the target leaf node can be determined, and then the target message information under the partitioning domain can be selected from the message information under each policy matching domain of the message to be matched.
[0123] S3: Based on the target message information, perform a binary search in each policy partitioning interval corresponding to the target leaf node to determine whether there is a matching policy partitioning interval that matches the message to be matched.
[0124] Here, the matching policy division interval is the interval in each policy division interval corresponding to the target leaf node that may contain a security policy that matches the message to be matched.
[0125] In practice, a binary search can be performed within each policy partitioning interval corresponding to the target leaf node, based on the target message information and the interval range corresponding to each policy partitioning interval of the target leaf node, to determine whether there exists a matching policy partitioning interval that matches the message to be matched. Whether a policy partitioning interval matches the message to be matched can be determined by whether the value of the partitioning field corresponding to the target message information falls within the interval range of the policy partitioning interval.
[0126] If no matching strategy divides the interval, subsequent matching can be performed or a matching result can be returned. Subsequent matching means continuing to traverse other security policy trees if they exist. Returning a matching result means directly returning an empty matching result if no other untraversed security policy tree exists.
[0127] S4: If so, then if the security policies in the matching policy division interval are not empty, determine the security policy matching result corresponding to the message to be matched from the security policies in the matching policy division interval.
[0128] Here, the security policy belonging to the matching policy division interval is the security policy defined within that interval. The security policy matching result can be a matched security policy, or it can be empty, indicate that no matching security policy exists, or show a matching failure.
[0129] In practice, if a matching policy segmentation interval exists, it can be determined whether the number of security policies within that interval is empty (i.e., whether the matching policy segmentation interval is a valid interval). If it is empty, subsequent matching can be performed or the matching result can be returned. If it is not empty, it can iterate through each security policy within the matching policy segmentation interval to determine whether there is a security policy that matches the packet to be matched, thus obtaining the security policy matching result.
[0130] Whether a security policy matches a message to be matched can be determined based on the policy information of the security policy and the information carried in the message to be matched. The method for determining whether a security policy matches a message to be matched can refer to existing technologies. For example, it can be determined by whether the message information of the message to be matched under each policy matching field conforms to the policy scope of the security policy under the corresponding policy matching field.
[0131] The process of traversing the security policies within a defined matching policy interval can begin with the first security policy in that interval. For each security policy being traversed, it's determined whether it matches the packet to be matched. If it does, the security policy is returned as the matching result. If the match fails, it's checked whether there are any untraversed security policies. If so, the process returns to traversing all security policies within the defined interval until a traversed security policy matches the packet to be matched or all security policies have been traversed. If no untraversed security policies exist, the matching result of the failed security policy is returned. If all security policies have been traversed and no successful match is found, the matching result of the failed security policy is returned.
[0132] In this way, by dividing the security policies in the leaf nodes into different policy partitioning intervals, when a valid target leaf node is determined, the matching performance of the target leaf node can be guaranteed to be limited only by the binary search time of the policy partitioning interval of that node and the maximum security policy in the matching policy partitioning interval. The number of leaf nodes is reduced, thus decreasing the sensitivity to the threshold for the number of leaf node strategies.
[0133] like Figure 4 The diagram shows a flowchart of a security policy matching process provided in an embodiment of this application, including a packet extraction step, which determines the packet information of the packet to be matched under each policy matching domain. The security policy tree traversal step is described in detail above for S1, and will not be repeated here. The binary search step is also described in detail above for S2-S4, and will not be repeated here.
[0134] This application improves the performance of security policy tree matching by introducing preferred partitioning domains into the leaf nodes of the security policy tree. This divides the security policies within the leaf nodes into as many policy partitioning intervals as possible, minimizing the number of security policies in each policy partitioning interval. This effectively reduces the sensitivity to the threshold number of policies in the leaf nodes. Furthermore, this application can reduce the depth of the security policy tree by setting a relatively large threshold number of policies in the leaf nodes, while still utilizing the partitioned policy partitioning intervals for security policy matching. The worst-case matching performance occurs when only the security policies within the matched policy partitioning interval of the target leaf node are matched, rather than all security policies in the leaf node, thus improving the matching performance of the security policy tree.
[0135] When the threshold for the number of leaf node policies in the leaf node of the security policy tree is set large, this application can not only reduce the depth of the security policy tree, but also divide all security policies of the leaf node into different policy partitioning intervals through partitioning domains. When matching security policies in leaf nodes, a binary search method can be used to find matching policy partitioning intervals in the leaf nodes, and security policy matching is performed only within the matching policy partitioning intervals, effectively improving matching performance. To demonstrate the performance improvement effect of the security policy partitioning method provided in this application, a comparative experiment was also conducted. Specifically, this application used ACL_100k, FW_100k, and IPC_100k in Class Bench for comparative testing. For ACL_100k, FW_100k, and IPC_100k, security policy trees were constructed using existing security policy tree construction methods, and security policy trees were constructed using the security policy partitioning method provided in this application, respectively. Then, security policy matching tests were conducted on the security policy tree constructed by existing technologies and the security policy tree constructed based on the security policy partitioning method provided in this application. It can be found that the performance of policy matching using the security policy tree constructed based on the security policy partitioning method provided in this application is 1.2 to 1.5 times higher than that of policy matching using the security policy tree constructed by existing technologies.
[0136] Based on the same inventive concept, this application also provides a security policy partitioning device corresponding to the security policy partitioning method. Since the principle of the device in this application is similar to the security policy partitioning method described above in this application, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be described again.
[0137] like Figure 5 The diagram shown is a schematic of a security policy partitioning device provided in an embodiment of this application, comprising:
[0138] The first determining module 501 is used to determine, for any leaf node in the security policy tree, each policy endpoint under each policy matching domain according to the policy range of each security policy stored in the leaf node under each policy matching domain.
[0139] The partitioning module 502 is used to construct each initial policy partitioning interval of the leaf node under the target policy matching domain based on each policy endpoint and the number of endpoints under each policy matching domain; wherein the policy ranges of each initial policy partitioning interval do not intersect.
[0140] The second determining module 503 is used to determine, based on the target policy range of each security policy under the target policy matching domain, at least one initial policy partitioning interval to which each security policy belongs from each initial policy partitioning interval under the target policy matching domain, and to partition each security policy into its respective initial policy partitioning interval.
[0141] In one possible implementation, the apparatus further includes a merging module 504, which, after dividing each of the security policies into its respective initial policy partitioning intervals, is configured to:
[0142] Based on the security policies divided in each initial policy partitioning interval and the adjacency relationship between each initial policy partitioning interval, determine whether there are adjacent intervals with the same security policies to be merged from the initial policy partitioning intervals;
[0143] If so, the interval to be merged is merged into the target policy partitioning interval, and the target policy partitioning interval and the intervals in the initial policy partitioning interval other than the interval to be merged are used as the policy partitioning interval of the leaf node under the target policy matching domain.
[0144] In one possible implementation, the partitioning module 502, when constructing the initial policy partitioning intervals of the leaf nodes under the target policy matching domain based on the policy endpoints and the number of endpoints under each policy matching domain, is used to:
[0145] From each of the policy matching domains, select the policy matching domain with the largest number of endpoints as the target policy matching domain;
[0146] The number of the first interval is determined based on the number of endpoints under the target strategy matching domain;
[0147] Based on the policy endpoints under the target policy matching domain and the ascending order of the policy endpoints, construct the initial policy partitioning intervals of the leaf nodes under the target policy matching domain; the number of the initial policy partitioning intervals is less than or equal to the number of the first intervals.
[0148] The second determining module 503, after dividing each security policy into its respective initial policy division interval, is further configured to:
[0149] The target strategy matching domain is used as the partitioning domain corresponding to the leaf node.
[0150] In one possible implementation, the partitioning module 502, when constructing the initial policy partitioning intervals of the leaf nodes under the target policy matching domain based on the policy endpoints and the number of endpoints under each policy matching domain, is used to:
[0151] Each of the aforementioned policy matching domains is used as the target policy matching domain;
[0152] For each target policy matching domain, the number of second intervals of the target policy matching domain is determined based on the number of endpoints under the target policy matching domain;
[0153] Based on the policy endpoints under the target policy matching domain and the ascending order of the policy endpoints, the leaf nodes are constructed into initial policy partitioning intervals under the target policy matching domain; wherein the number of initial policy partitioning intervals under the target policy matching domain is less than or equal to the number of second intervals under the target policy matching domain.
[0154] In one possible implementation, the second determining module 503, after merging the intervals to be merged into the target strategy partitioning interval, is further configured to:
[0155] Determine the number of third intervals under each target strategy matching domain;
[0156] Based on the number of the third interval, a partitioning domain corresponding to the leaf node is determined from each of the target policy matching domains, and the policy partitioning interval of the leaf node under the partitioning domain is taken as the policy partitioning interval of the leaf node.
[0157] In one possible implementation, the second determining module 503, when determining a partition corresponding to the leaf node from each of the target strategy matching domains based on the number of third intervals, is configured to:
[0158] When there are multiple target policy matching domains with the largest number in the third interval, the partitioning domain corresponding to the leaf node is determined according to the maximum number of security policies corresponding to the multiple target policy matching domains with the largest number in the third interval.
[0159] The maximum number of security policies corresponding to the target policy matching domain is related to the number of security policies that are divided into each policy division interval under the target policy matching domain.
[0160] In one possible implementation, the device further includes a matching module 505, for:
[0161] In response to receiving a message to be matched, the target leaf node that matches the message to be matched is determined in the security policy tree based on the message information of the message to be matched under each policy matching domain.
[0162] From the message information, determine the target message information of the message to be matched under the partitioning domain corresponding to the target leaf node;
[0163] Based on the target message information, perform a binary search in each policy partitioning interval corresponding to the target leaf node to determine whether there is a matching policy partitioning interval that matches the message to be matched.
[0164] If so, then if the security policies in the matching policy division interval are not empty, determine the security policy matching result corresponding to the message to be matched from the security policies in the matching policy division interval.
[0165] The processing flow of each module in the device and the interaction flow between each module can be referred to the relevant descriptions in the above method embodiments, and will not be detailed here.
[0166] Based on the same technical concept, embodiments of this application also provide a computer device. (Refer to...) Figure 6 The diagram shown is a structural schematic of a computer device provided in an embodiment of this application, comprising:
[0167] The system comprises a processor 601, a memory 602, and a bus 603. The memory 602 stores machine-readable instructions executable by the processor 601. The processor 601 executes these machine-readable instructions, and when executed, performs the following steps: S101: For any leaf node in the security policy tree, based on the policy range of each security policy stored in the leaf node under each policy matching domain, determine each policy endpoint under each policy matching domain; S102: Based on the policy endpoints and the number of endpoints under each policy matching domain, construct each initial policy partitioning interval of the leaf node under the target policy matching domain; wherein the policy ranges of each initial policy partitioning interval do not intersect; and S103: Based on the target policy range of each security policy under the target policy matching domain, determine at least one initial policy partitioning interval to which each security policy belongs from the initial policy partitioning intervals under the target policy matching domain, and assign each security policy to its respective initial policy partitioning interval.
[0168] The aforementioned memory 602 includes a main memory 6021 and an external memory 6022. The main memory 6021, also known as internal memory, is used to temporarily store the computational data in the processor 601, as well as the data exchanged with external memory such as a hard disk 6022. The processor 601 exchanges data with the external memory 6022 through the main memory 6021. When the computer device is running, the processor 601 and the memory 602 communicate through the bus 603, so that the processor 601 executes the execution instructions mentioned in the above method embodiments.
[0169] This application also provides a computer-readable storage medium storing a computer program. When a processor executes the program, it performs the steps of the security policy partitioning method described in the above-described method embodiments. The storage medium can be either volatile or non-volatile computer-readable storage.
[0170] This application also provides a computer program product, which carries program code. The instructions included in the program code can be used to execute the steps of the security policy partitioning method described in the above method embodiments. For details, please refer to the above method embodiments, which will not be repeated here.
[0171] The computer program product can be implemented specifically through hardware, software, or a combination thereof. In one alternative embodiment, the computer program product is specifically embodied in a computer storage medium; in another alternative embodiment, the computer program product is specifically embodied in a software product, such as a software development kit (SDK), etc.
[0172] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the device described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here. In the several embodiments provided in this application, it should be understood that the disclosed device and method can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division; in actual implementation, there may be other division methods. Furthermore, multiple units or components may be combined, or some features may be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection may be through some communication interface; the indirect coupling or communication connection of devices or units may be electrical, mechanical, or other forms.
[0173] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0174] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0175] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a processor-executable, non-volatile, computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to existing technology, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0176] If the technical solution of this application involves personal information, the product using this technical solution has clearly informed the user of the personal information processing rules and obtained the user's voluntary consent before processing the personal information. If the technical solution of this application involves sensitive personal information, the product using this technical solution has obtained the user's separate consent before processing the sensitive personal information, and also meets the requirement of "express consent". For example, at personal information collection devices such as cameras, clear and prominent signs are set up to inform users that they have entered the scope of personal information collection and that personal information will be collected. If an individual voluntarily enters the collection scope, it is deemed that they have agreed to the collection of their personal information; or on the personal information processing device, with clear signs / information informing users of the personal information processing rules, authorization is obtained from the user through pop-up information or by asking the user to upload their personal information; wherein, the personal information processing rules may include information such as the personal information processor, the purpose of personal information processing, the processing method, and the types of personal information processed.
[0177] Finally, it should be noted that the above-described embodiments are merely specific implementations of this application, used to illustrate the technical solutions of this application, and not to limit them. The scope of protection of this application is not limited thereto. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments, or make equivalent substitutions for some of the technical features, within the scope of the technology disclosed in this application. Such modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A security policy partitioning method, characterized by, The method includes: For any leaf node in the security policy tree, determine each policy endpoint under each policy matching domain based on the policy scope of each security policy stored in the leaf node under each policy matching domain. Based on the policy endpoints and the number of endpoints under each policy matching domain, construct the initial policy partitioning intervals of the leaf nodes under the target policy matching domain; wherein the policy ranges of each initial policy partitioning interval do not intersect. Based on the target policy range of each security policy under the target policy matching domain, determine at least one initial policy partitioning interval to which each security policy belongs from each initial policy partitioning interval under the target policy matching domain, and assign each security policy to its respective initial policy partitioning interval. The step of constructing the initial policy partitioning intervals of the leaf nodes under the target policy matching domain based on the policy endpoints and the number of endpoints under each policy matching domain includes: From each of the policy matching domains, the policy matching domain with the largest number of endpoints is selected as the target policy matching domain; the number of first intervals is determined according to the number of endpoints under the target policy matching domain; based on the policy endpoints under the target policy matching domain and the ascending order of the policy endpoints, each initial policy partitioning interval of the leaf node under the target policy matching domain is constructed; the number of initial policy partitioning intervals is less than or equal to the number of first intervals; after dividing each security policy into its respective initial policy partitioning intervals, the method further includes: using the target policy matching domain as the partitioning domain corresponding to the leaf node; Alternatively, constructing the initial policy partitioning intervals of the leaf nodes under the target policy matching domain based on the policy endpoints and the number of endpoints under each policy matching domain includes: Each of the aforementioned policy matching domains is designated as the target policy matching domain. For each target policy matching domain, the number of second intervals of the target policy matching domain is determined based on the number of endpoints under that target policy matching domain. Based on the policy endpoints under the target policy matching domain and their ascending order, the initial policy partitioning intervals of the leaf nodes under the target policy matching domain are constructed. The number of initial policy partitioning intervals under the target policy matching domain is less than or equal to the number of second intervals of the target policy matching domain.
2. The method of claim 1, wherein, After assigning each security policy to its respective initial policy partitioning interval, the method further includes: Based on the security policies divided in each initial policy partitioning interval and the adjacency relationship between each initial policy partitioning interval, determine whether there are adjacent intervals with the same security policies to be merged from the initial policy partitioning intervals; If so, the interval to be merged is merged into the target policy partitioning interval, and the target policy partitioning interval and the intervals in the initial policy partitioning interval other than the interval to be merged are used as the policy partitioning interval of the leaf node under the target policy matching domain.
3. The method of claim 2, wherein, After merging the intervals to be merged into the target strategy partitioning interval, the method further includes: Determine the number of third intervals under each target strategy matching domain; Based on the number of the third interval, a partitioning domain corresponding to the leaf node is determined from each of the target policy matching domains, and the policy partitioning interval of the leaf node under the partitioning domain is taken as the policy partitioning interval of the leaf node.
4. The method of claim 3, wherein, The step of determining a partition corresponding to the leaf node from each of the target strategy matching domains based on the number of the third interval includes: When there are multiple target policy matching domains with the largest number in the third interval, the partitioning domain corresponding to the leaf node is determined according to the maximum number of security policies corresponding to the multiple target policy matching domains with the largest number in the third interval. The maximum number of security policies corresponding to the target policy matching domain is related to the number of security policies that are divided into each policy division interval under the target policy matching domain.
5. The method of claim 2, wherein, The method further includes: In response to receiving a message to be matched, the target leaf node that matches the message to be matched is determined in the security policy tree based on the message information of the message to be matched under each policy matching domain. From the message information, determine the target message information of the message to be matched under the partitioning domain corresponding to the target leaf node; Based on the target message information, perform a binary search in each policy partitioning interval corresponding to the target leaf node to determine whether there is a matching policy partitioning interval that matches the message to be matched. If so, then if the security policies in the matching policy division interval are not empty, determine the security policy matching result corresponding to the message to be matched from the security policies in the matching policy division interval.
6. A security policy partitioning apparatus characterized by comprising: The device includes: The first determining module is used to determine, for any leaf node in the security policy tree, each policy endpoint under each policy matching domain based on the policy range of each security policy stored in the leaf node under each policy matching domain. The partitioning module is used to construct initial policy partitioning intervals for the leaf node under the target policy matching domain based on the policy endpoints and the number of endpoints under each policy matching domain; wherein the policy ranges of each initial policy partitioning interval do not intersect; wherein, when constructing the initial policy partitioning intervals for the leaf node under the target policy matching domain based on the policy endpoints and the number of endpoints under each policy matching domain, the partitioning module is used to: select the policy matching domain with the largest number of endpoints as the target policy matching domain; determine the number of first intervals based on the number of endpoints under the target policy matching domain; and construct the initial policy partitioning intervals for the leaf node under the target policy matching domain based on the policy endpoints and their ascending sort order. The number of initial strategy partitioning intervals is less than or equal to the number of the first intervals; or, the partitioning module, when constructing the initial strategy partitioning intervals of the leaf node under the target strategy matching domain based on the strategy endpoints and the number of endpoints under each strategy matching domain, is configured to: use each strategy matching domain as the target strategy matching domain; for each target strategy matching domain, determine the number of the second intervals of the target strategy matching domain based on the number of endpoints under the target strategy matching domain; construct the initial strategy partitioning intervals of the leaf node under the target strategy matching domain based on the strategy endpoints under the target strategy matching domain and their ascending order; wherein, the number of initial strategy partitioning intervals under the target strategy matching domain is less than or equal to the number of the second intervals of the target strategy matching domain; The second determining module is configured to determine, based on the target policy range of each security policy under the target policy matching domain, at least one initial policy partitioning interval to which each security policy belongs from each initial policy partitioning interval under the target policy matching domain, and to partition each security policy into its respective initial policy partitioning interval; after each security policy is partitioned into its respective initial policy partitioning interval, the second determining module is further configured to: use the target policy matching domain as the partitioning domain corresponding to the leaf node.
7. A computer-readable storage medium having stored thereon a computer program, characterized in that When the program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 5.
8. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the method as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Strategy matching method and device
CN119071061A
Security policy matching method and device based on IP slice
CN119182606A
Network quintuple matching method based on ordered interval list
CN119254475A