Heterogeneous firewall automatic control method, device, equipment and medium

By converting heterogeneous firewall policies into a unified model and automating their control, the problems of low resource utilization and low operational efficiency were solved, thereby improving business continuity and security.

CN121887461APending Publication Date: 2026-04-17CHINA MERCHANTS FINANCE HLDG CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA MERCHANTS FINANCE HLDG CO LTD
Filing Date
2025-12-23
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

In private cloud data centers, heterogeneous firewalls have low resource utilization and low operation and maintenance efficiency. In addition, the traditional master-slave deployment mode has long business interruption time, frequent policy configuration errors and conflicts, resulting in security vulnerabilities and high operation and maintenance complexity.

Method used

By converting policies from different firewall vendors into a unified intermediate representation model, using a policy normalization model to identify and filter conflicting policies, generating compatible configuration scripts, and enabling simultaneous distribution of active-active policies, the system monitors link status through dynamic routing protocols, compares policy hit rates with traffic matching status in real time, and provides automated control and alarm mechanisms.

Benefits of technology

It improves the resource utilization and operational efficiency of heterogeneous firewalls, ensures business continuity, reduces configuration errors and security vulnerabilities, and achieves policy consistency and high availability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121887461A_ABST
    Figure CN121887461A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and discloses a heterogeneous firewall automatic control method and device, equipment and a medium, and the method comprises the steps: collecting a heterogeneous strategy of a preset first firewall and a preset second firewall, and converting the heterogeneous strategy into a strategy normalization model through unified modeling; based on the model and a preset rule base, automatically identifying and screening strategy conflicts to obtain optimized double strategies, utilizing the model to generate corresponding first and second configuration scripts for the optimization strategies, executing dual-active strategy synchronous issuing, and monitoring the link state of the issued double firewalls in real time through a dynamic routing protocol, so as to realize real-time configuration of the double firewalls. And comparing the strategy hit rate and the flow matching state of the double firewalls in real time by combining a system log and a link state, and outputting a comparison result. According to the method, the resource utilization rate and the operation and maintenance efficiency during automatic control of the heterogeneous firewall are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to an automated control method, apparatus, device, and medium for heterogeneous firewalls. Background Technology

[0002] In current private cloud data centers, especially in industries with high reliability requirements such as finance and government, firewalls, as the core line of defense for network security, are of paramount importance in terms of high availability and policy management capabilities.

[0003] Traditional mainstream solutions typically employ an active-standby deployment model, where one firewall is active handling all traffic while the other remains idle as a backup. When the primary firewall fails, the switch to the standby firewall can result in service interruptions lasting seconds or even longer, failing to meet the stringent continuity requirements of core business operations. Furthermore, in this model, the standby firewall's hardware computing resources remain idle for extended periods, reducing resource utilization. To mitigate the risks of vendor lock-in, existing solutions often deploy heterogeneous firewalls from multiple vendors in data centers. The significant differences in policy configuration languages, models, and syntax across vendors make unified policy management difficult. Manual cross-vendor policy comparison, conflict analysis, and synchronized deployment are highly susceptible to configuration errors, rule redundancy, policy hiding, or conflicts (such as the same traffic being processed with opposite actions by different devices). This not only introduces security vulnerabilities but also significantly increases operational complexity and compliance risks. Summary of the Invention

[0004] This invention provides a method, apparatus, computer equipment, and medium for automated control of heterogeneous firewalls, in order to solve the problems of low resource utilization and low operation and maintenance efficiency of existing heterogeneous firewall control methods on the market.

[0005] Firstly, a method for automated control of heterogeneous firewalls is provided, including: Obtain the first defense policy of the first firewall and the second defense policy of the second firewall pre-deployed in the target system, and convert the first defense policy and the second defense policy into a unified intermediate representation model to obtain the policy normalization model. The strategy normalization model and the pre-set rule base are used to identify and filter out conflicting strategies in the first defense strategy and the second defense strategy to obtain the optimized first defense strategy and the optimized second defense strategy. The policy normalization model is used to generate configuration scripts for the first firewall and the second firewall based on the optimized first defense policy and the optimized second defense policy, resulting in a first configuration script and a second configuration script. The active-active policy is then synchronously distributed to the first firewall and the second firewall based on the first configuration script and the second configuration script. Based on a preset dynamic routing protocol, the real-time link status information of the first firewall and the second firewall after the dual-active policy is synchronously issued is monitored respectively. Based on the log data obtained in advance from the target system's backend and the real-time link status information, the policy hit rate and traffic matching status of the first firewall and the second firewall are compared in real time to obtain the comparison result.

[0006] Secondly, an automated control device for heterogeneous firewalls is provided, comprising: The configuration conversion module is used to obtain the first defense policy of the first firewall and the second defense policy of the second firewall pre-deployed in the target system, and convert the first defense policy and the second defense policy into a unified intermediate representation model to obtain the policy normalization model. The conflict detection module is used to identify and filter out conflicting strategies in the first defense strategy and the second defense strategy using the strategy normalization model and the preset rule base, so as to obtain the optimized first defense strategy and the optimized second defense strategy. The dual-active deployment module is used to generate configuration scripts for the first firewall and the second firewall based on the optimized first defense policy and the optimized second defense policy using the policy normalization model, thereby obtaining the first configuration script and the second configuration script, and to synchronously deploy the dual-active policy to the first firewall and the second firewall based on the first configuration script and the second configuration script. The dynamic scheduling module is used to monitor the real-time link status information of the first firewall and the second firewall after the dual-active policy is synchronously issued, based on a preset dynamic routing protocol. The comparison alarm module is used to compare the policy hit rate and traffic matching status of the first firewall and the second firewall in real time based on the log data obtained in advance from the target system backend and the real-time link status information, and obtain the comparison result.

[0007] Thirdly, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the above-described heterogeneous firewall automated control method.

[0008] Fourthly, a computer-readable storage medium is provided, which stores a computer program that, when executed by a processor, implements the steps of the above-described heterogeneous firewall automated control method.

[0009] In the aforementioned scheme implemented by the heterogeneous firewall automated control method, device, computer equipment, and storage medium, the first defense policy of the first firewall and the second defense policy of the second firewall pre-deployed within the target system can be obtained. The first and second defense policies are then converted into a unified intermediate representation model to obtain a policy normalization model. This achieves a unified and standardized representation of the policies, laying a reliable foundation for subsequent automated analysis and processing. The policy normalization model and a pre-set rule base are used to identify and filter conflicting policies in the first and second defense policies, resulting in optimized first and second defense policies. This reduces configuration errors and security vulnerabilities, enhancing the accuracy and reliability of the policies. The policy normalization model is then used to generate the first defense policy based on the optimized first and second defense policies. The invention generates first and second configuration scripts from the configuration scripts of a first firewall and a second firewall, improving the efficiency and accuracy of script generation. Based on these scripts, active-active policies are synchronously distributed to both firewalls, effectively preventing service interruptions due to policy asynchrony. A preset dynamic routing protocol monitors the real-time link status information of the first and second firewalls after the synchronous distribution of the active-active policies. Using log data pre-obtained from the target system's backend and the real-time link status information, the policy hit rate and traffic matching status of the first and second firewalls are compared in real-time. The comparison results allow for timely detection of policy execution deviations, traffic scheduling anomalies, and other issues, providing a basis for operational alarms and automatic repair, thereby ensuring system consistency and security. This invention improves resource utilization and operational efficiency when automating the control of heterogeneous firewalls. Attached Figure Description

[0010] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0011] Figure 1 This is a schematic diagram of an application environment for an automated control method for heterogeneous firewalls according to an embodiment of the present invention; Figure 2 This is a flowchart illustrating an automated control method for heterogeneous firewalls according to an embodiment of the present invention; Figure 3 This is a schematic diagram of a heterogeneous firewall automated control device in one embodiment of the present invention; Figure 4 This is a schematic diagram of the structure of a computer device according to an embodiment of the present invention; Figure 5 This is another structural schematic diagram of a computer device according to one embodiment of the present invention. Detailed Implementation

[0012] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0013] The heterogeneous firewall automated control method provided in this embodiment of the invention can be applied to, for example... Figure 1In this application environment, the client communicates with the server via the network. The server can use the client to parse and convert heterogeneous security defense policies from different firewall vendors into a unified policy normalization model. Based on this unified model, the system uses a pre-built rule base to perform automated conflict detection and risk analysis, identifying redundant, hidden conflicts, and illegal policies. Subsequently, the automation engine synchronously converts the verified policy model into configuration scripts specific to each firewall vendor's device, and uses a collaborative control mechanism to ensure consistent policy distribution to the two firewalls deployed in a dual-active architecture, ensuring lossless business updates. At the traffic scheduling level, the system deeply integrates BFD millisecond-level fault detection with dynamic routing protocols such as OSPF / BGP, monitoring link health status in real time. Under normal circumstances, intelligent load balancing between dual-active devices is achieved by dynamically adjusting routing overhead, greatly improving resource utilization. Once a link or node failure is detected, a millisecond-level switching of the routing path is immediately triggered, with the healthy firewall seamlessly taking over all traffic, ensuring zero business interruption. Finally, by collecting and comparing the policy hit logs and traffic matching status of the dual-active firewall in real time, the consistency of policy execution and the accuracy of traffic scheduling are continuously monitored. Any anomalies, such as load imbalance, path errors, or action conflicts, will trigger tiered alarms and can be automatically compensated through a self-healing mechanism. This achieves a fundamental simplification of firewall policies, a revolutionary improvement in business continuity, and a significant optimization of operational efficiency in complex heterogeneous environments, improving resource utilization and operational efficiency when automating the control of heterogeneous firewalls. The client can be, but is not limited to, various personal computers, laptops, smartphones, tablets, and portable wearable devices. The server can be implemented using a standalone server or a server cluster consisting of multiple servers. The invention will be described in detail below through specific embodiments.

[0014] Please see Figure 2 As shown, Figure 2 A flowchart illustrating the automated control method for heterogeneous firewalls provided in this embodiment of the invention includes the following steps: S1. Obtain the first defense policy of the first firewall and the second defense policy of the second firewall pre-deployed in the target system, and convert the first defense policy and the second defense policy into a unified intermediate representation model to obtain the policy normalization model.

[0015] In this embodiment of the invention, the step of converting the first defense strategy and the second defense strategy into a unified intermediate representation model to obtain a strategy normalization model includes: Using preset regular expressions, extract the rule fields in the first defense policy and the second defense policy that represent source address, destination address, port, protocol and action to obtain the first target field and the second target field; Based on the syntax parsers preset by the first firewall and the second firewall, the first target field and the second target field are parsed into structured policy objects to obtain a first policy object list and a second policy object list. Based on a preset field mapping table, the fields of the first strategy object list and the second strategy object list are unified, and the strategy values ​​of the unified strategy object list are standardized to obtain the first standardized strategy object list and the second standardized strategy object list. Construct a model framework based on the preset target model structure, the first standardized strategy object list, and the second standardized strategy object list; The first and second standardized strategy object lists are deduplicated, and the deduplicated first and second standardized strategy object lists are filled into the model framework to obtain the strategy normalization model.

[0016] In detail, the step of using preset regular expressions to extract rule fields representing source address, destination address, port, protocol, and action within the first and second defense policies to obtain the first target field and the second target field involves using regular expressions to extract key rule elements (such as source address, destination address, port, protocol, and action) from the original defense policies based on the API interface provided by the firewall vendor, and organizing them into a structured policy object.

[0017] In detail, the construction of the model framework based on the preset target model structure, the first standardized policy object list, and the second standardized policy object list is achieved by defining a general policy model structure (usually implemented in the form of classes or JSON Schema), which includes core attributes common to all firewall policies (such as ID, name, source IP, destination IP, port, protocol, action, direction, etc.). Each standardized policy object is instantiated according to this structure and supplemented with metadata information (such as original firewall vendor, original rule text, execution priority, timestamp, etc.), thereby forming a model framework entity with a unified interface.

[0018] In detail, the deduplication process for the first standardized strategy object list and the second standardized strategy object list refers to removing duplicate and highly similar strategy rule objects from the structured strategy objects.

[0019] In detail, the step of transforming the set of security policy objects into a policy normalization model according to the policy normalization model structure involves serializing and encapsulating the set of security policy objects according to the policy normalization model structure to generate the final policy normalization model.

[0020] In detail, the step of filling the deduplicated first and second standardized policy object lists into the model framework to obtain the policy normalization model involves filling the deduplicated first standardized policy object list into the corresponding field positions in the model framework one by one according to the definition and mapping relationship of unified core fields such as source address, destination address, port, protocol, and action in the preset target model structure. The first defense strategy and the second defense strategy are integrated and converged within a unified structural framework to finally obtain the policy normalization model.

[0021] In this embodiment of the invention, the policy normalization model parses and transforms the native firewall policy configurations (including vendor-specific command formats and field definitions) from different firewall vendors into a standardized policy logic carrier containing unified core fields such as source IP, destination IP, port, and action. This solves the problem of heterogeneous policies not being able to communicate with each other in traditional solutions, and also supports automatic detection of cross-device policy conflicts, single-device rule redundancy, and full-pass risks based on a pre-built rule base. It provides a unified benchmark for generating vendor-compatible configuration scripts for optimized policies, ensuring the consistency of policy configuration in subsequent dual-active policy synchronous distribution.

[0022] S2. Using the strategy normalization model and the preset rule base, identify and filter out conflicting strategies in the first defense strategy and the second defense strategy to obtain the optimized first defense strategy and the optimized second defense strategy.

[0023] In this embodiment of the invention, the step of identifying and filtering conflicting strategies in the first and second defense strategies using the strategy normalization model and a pre-set rule base to obtain optimized first and second defense strategies includes: Establish a policy index for the first defense policy and the second defense policy, and calculate the feature hash value of each policy in the first defense policy and the second defense policy to obtain a preprocessed policy set; The preprocessed policy set is redundant policy detection is performed using the policy normalization model to obtain a list of redundant policies. Based on the redundant policy list, redundant policies in the preprocessed policy set are deleted to obtain the optimized policy set. The strategies in the optimized strategy set are reordered based on a preset strategy execution order to obtain a sorted strategy set. Using the strategy normalization model, upstream strategies in the sorting strategy set whose condition range covers downstream strategies but whose actions differ from those of downstream strategies are examined according to the sorting order of the sorting strategy set, and the condition coverage analysis results are obtained. Based on the condition coverage analysis results, identify the strategies in the sorting strategy set that have failed due to execution order conflicts, and obtain the hidden conflict detection results; Identify the intersection of each strategy in the ranking strategy set with other strategies; Based on the intersection of the strategies, check whether the execution actions contained in each strategy of the sorting strategy set are the same as those contained in other strategies to obtain the consistency check result; Using the strategy normalization model, the traffic range affected by the conflicting strategies in the sorting strategy set is identified based on the consistency check results, thus obtaining the action conflict detection results; Based on the hidden conflict detection results and the action conflict detection results, conflicting strategies in the first defense strategy and the second defense strategy are filtered out to obtain the optimized first defense strategy and the optimized second defense strategy.

[0024] In detail, the process of establishing a policy index for the first and second defense strategies and calculating the feature hash value of each strategy in the first and second defense strategies to obtain a preprocessed policy set involves extracting key fields (including source IP, destination IP, port, protocol, action, etc.) from each strategy in the first and second defense strategies, and using a hash function to perform calculations on the key field combinations to generate a unique feature hash value. Simultaneously, a multi-dimensional index structure is constructed for rapid retrieval and comparison. The index is implemented using in-memory data structures (such as trie or hash table), and an index pointer is added to each strategy. The final output is a preprocessed policy set containing feature hash values ​​and index information.

[0025] In detail, the step of checking upstream strategies in the sorting strategy set whose condition ranges cover downstream strategies but whose actions differ from downstream strategies, to obtain the condition coverage analysis result, is achieved by traversing the sorting strategy set and, for the current strategy, searching backwards through all upstream strategies. A condition coverage judgment algorithm is used to check whether the source IP, destination IP, port, protocol, and other conditions of the upstream strategies cover the corresponding conditions of the current strategy (e.g., the source IP range of the upstream strategy includes the source IP range of the current strategy). If they cover each other and the actions are different, it is recorded as a condition coverage relationship. The algorithm utilizes the established index to accelerate retrieval and achieves precise matching through IP range inclusion judgment and port range inclusion judgment. The condition coverage analysis result is output, containing all coverage relationship pairs.

[0026] In detail, the step of using the policy normalization model to identify policies in the sorting policy set that have failed due to execution order conflicts based on the condition coverage analysis results, and obtaining hidden conflict detection results, involves analyzing the condition coverage analysis results. For each policy that is covered by an upstream policy but has a different action, it is marked as a "failed policy." This is because traffic will preferentially match the upstream policy and will never reach that policy. For example, if an upstream policy allows a certain IP range to access all ports, while the current policy denies that IP range access to a specific port, then the current policy is invalid.

[0027] In detail, the identification of the intersection of each strategy in the ranking strategy set with other strategies includes: IP segment intersection (converting IP ranges into integer intervals for intersection), port range intersection, and protocol intersection (e.g., TCP and UDP have no intersection, while TCP and TCP have an intersection). A multi-dimensional intersection algorithm is used, and strategies are considered to have an intersection only when conditions in all dimensions overlap.

[0028] In detail, the step of checking whether the execution actions contained in each strategy of the ranking strategy set are the same as those contained in other strategies, based on the intersection of the strategies, to obtain a consistency check result, refers to checking whether the actions of strategy pairs that have intersection in the ranking strategy set are consistent. For example, if one strategy action is "allow" and the other is "deny", then the actions are inconsistent.

[0029] In detail, the step of using the policy normalization model to identify the traffic range affected by conflicting policies in the ranking policy set based on the consistency check results, and obtaining the action conflict detection result, refines the conflict range by using an intersection algorithm. For each pair of conflicting policies, the conditional intersection is taken to form a specific conflict traffic definition. For example, if policy A allows 10.0.0.0 / 24 to access port 80, and policy B denies 10.0.0.10 access to port 80, then the conflict range is IP 10.0.0.10, port 80, and protocol TCP.

[0030] In this embodiment of the invention, the step of using the policy normalization model to perform redundant policy detection on the preprocessed policy set to obtain a redundant policy list includes: The key fields contained in each preprocessing strategy in the preprocessing strategy set are concatenated to obtain a concatenated string set; The hash value of each string in the concatenated string set is calculated using a hash algorithm to obtain the strategy identifier string of each preprocessing strategy in the preprocessing strategy set; Traverse the set of preprocessing strategies and group the preprocessing strategies with identical strategy identifier strings into a set of strategy groups. The strategies corresponding to strategy groups that contain more than one strategy are marked as redundant strategies, thus obtaining a list of redundant strategies.

[0031] S3. Using the policy normalization model, generate configuration scripts for the first firewall and the second firewall based on the optimized first defense policy and the optimized second defense policy, to obtain the first configuration script and the second configuration script, and synchronously distribute the dual-active policy to the first firewall and the second firewall according to the first configuration script and the second configuration script.

[0032] In this embodiment of the invention, the step of generating configuration scripts for the first firewall and the second firewall based on the optimized first defense strategy and the optimized second defense strategy using the policy normalization model, resulting in the first configuration script and the second configuration script, is achieved by calling the vendor-preset configuration syntax rule library (containing command formats, protocol adaptation requirements, etc. for the corresponding devices) of the first firewall or the second firewall. The optimized first defense strategy and the optimized second defense strategy are then converted into configuration scripts adapted to the configuration specifications of the first firewall and the second firewall using the policy normalization model and the configuration syntax rule library. Complete configuration paragraphs are generated through logical combination. Finally, the generated configuration paragraphs are simulated and verified to check the syntactic correctness and policy semantic consistency, thereby outputting the configuration script.

[0033] In this embodiment of the invention, the simultaneous distribution of active-active policies to the first firewall and the second firewall based on the first configuration script and the second configuration script involves using a preset automation engine to first pre-check and back up the existing configurations of the first firewall and the second firewall. Then, according to a preset collaborative strategy (such as "backup firewall first, then primary firewall"), the distribution order is controlled, and the first and second configuration scripts generated for the first firewall and the second firewall are pushed and executed sequentially via API. During this process, the target system ensures that session information is not lost through a state synchronization channel. After the configuration is submitted and saved on each device, a real-time consistency check is immediately performed to compare whether the effective policies of the two firewalls are completely consistent with the expected model. Finally, the automation engine summarizes the script execution results, configuration comparison reports, and business impact assessments to generate a "distribution result status" containing "success / failure / partial success" status indicators and detailed process logs. This ensures that the synchronous update of policies and high availability are achieved while ensuring that business traffic is not interrupted.

[0034] S4. Determine whether the distribution was successful based on the status of the distribution result.

[0035] When the distribution result status indicates that the distribution has failed, execute S5 to send an error message to the preset developer client.

[0036] S6 is executed to monitor the real-time link status information of the first firewall and the second firewall after the dual-active policy is synchronously issued, based on the preset dynamic routing protocol.

[0037] In this embodiment of the invention, the step of monitoring the real-time link status information of the first firewall and the second firewall after the simultaneous issuance of the dual-active policy based on a preset dynamic routing protocol includes: Based on a preset bidirectional forwarding detection protocol, link information of the direct connection links between the first firewall and the second firewall is obtained in real time. Determine whether there is a fault in either the first firewall or the second firewall based on the link information; If there is no fault, the traffic load of the first firewall and the second firewall is dynamically balanced and allocated based on the dynamic routing protocol, and the real-time link status information of the first firewall and the second firewall after the traffic load allocation is obtained. If a fault exists, the firewall path is switched between the first firewall and the second firewall based on the fault information in the link information, and the real-time link status information of the switched firewall is obtained.

[0038] In detail, the real-time acquisition of link information of the direct link between the first firewall and the second firewall based on a preset bidirectional forwarding detection protocol is achieved by establishing a bidirectional forwarding detection session between the uplink switch or router interface connecting the two firewalls and the corresponding interface of the firewall. The target system configures the bidirectional forwarding detection session to send detection control messages to each other at a millisecond frequency and continuously monitors the message reception status; at the same time, it collects and aggregates key status data of each bidirectional forwarding detection session in real time, including session status, detected link round-trip time, packet loss rate, and session oscillation count, to obtain link information.

[0039] In detail, the determination of whether there is a fault in the first firewall and the second firewall based on the link information is based on a combination of conditions and thresholds. For example, if the bidirectional forwarding detection session status of a certain link is continuously "Down", or its real-time round-trip latency suddenly increases and exceeds the service tolerance threshold, or the packet loss rate continuously exceeds the severe threshold, then the engine determines that there is a fault in the link or its associated firewall network interface.

[0040] In detail, the firewall path switching between the first firewall and the second firewall based on the fault information in the link information is performed by programming a command to the network device to set the dynamic routing protocol parameters of the link corresponding to the faulty firewall to an invalid state (for example, setting the OSPF interface Cost to the maximum value of 65535, or closing the BGP peer session), triggering a fast reconvergence of the routing protocol (OSPF / BGP). The routing protocol will recalculate the optimal path within milliseconds, automatically and seamlessly redirecting all affected traffic to the path of the other healthy firewall.

[0041] In this embodiment of the invention, the dynamic allocation of traffic load balancing between the first firewall and the second firewall based on the dynamic routing protocol includes: The load data of the first firewall and the second firewall are obtained based on the dynamic routing protocol to obtain the first load data and the second load data; The first load data and the second load data are converted into numerical indicators to obtain the first load indicator and the second load indicator. Determine whether both the first load indicator and the second load indicator are less than a preset load threshold; If both the first load metric and the second load metric are less than the preset load threshold, then the traffic allocation of the first firewall and the second firewall will not be changed. If either the first load metric or the second load metric has a load metric greater than or equal to the load threshold, then the firewall corresponding to the larger load metric is marked as an overloaded firewall, and the traffic load of the overloaded firewall is reduced.

[0042] S7. Based on the log data obtained in advance from the target system backend and the real-time link status information, the policy hit rate and traffic matching status of the first firewall and the second firewall are compared in real time to obtain the comparison result.

[0043] In this embodiment of the invention, the step of comparing the policy hit rate and traffic matching status of the first firewall and the second firewall in real time based on log data obtained in advance from the target system backend and the real-time link status information to obtain the comparison result includes: Obtain a real-time link status snapshot of the log data, perform traffic path analysis and expected status calculation based on the real-time link status snapshot, and obtain a traffic path expected status table; The real-time system logs of the first firewall and the second firewall in the log data are aligned with the bidirectional forwarding detection session state to obtain the aligned first firewall log dataset and the aligned second firewall log dataset. The aligned first firewall log dataset and the aligned second firewall log dataset are parsed to obtain a first policy hit record set and a second policy hit record set. Based on the expected traffic path status table, the first policy hit record set, and the second policy hit record set, the policy hit rate and traffic matching status of the first firewall and the second firewall are compared in real time to obtain the comparison results.

[0044] In detail, the process of obtaining a real-time link state snapshot of the log data, and performing traffic path analysis and expected state calculation based on the real-time link state snapshot to obtain a traffic path expected state table, involves real-time collection and parsing of dynamic routing protocol (such as OSPF / BGP) status information and BFD (Bidirectional Forwarding Detection) session status on network devices (such as switches and routers) to obtain a status snapshot containing link costs, neighbor relationships, path reachability, and real-time fault status. Based on this status snapshot and predefined network topology and load balancing strategies (such as allocation by source IP hash or VLAN), a path calculation algorithm is used to deduce which firewall (first firewall or second firewall) various types of service traffic should ideally pass through for processing, and these mapping relationships are generated into a structured traffic path expected state table.

[0045] In detail, the step of aligning the real-time system logs of the first firewall and the second firewall in the log data with bidirectional forwarding detection session state to obtain aligned first firewall log datasets and aligned second firewall log datasets is achieved by unifying the time base of all logs using a high-precision time protocol (such as NTP). For each log reflecting traffic processing, the source IP, destination IP, protocol, source port, destination port, and timestamp are extracted. Through a session tracking algorithm, log entries describing the same network connection or session but generated by the two firewalls at different times are associated and paired to form two aligned datasets that can be directly compared in terms of timeline and logical relationship.

[0046] In detail, the step of parsing the aligned first firewall log dataset and the aligned second firewall log dataset to obtain the first policy hit record set and the second policy hit record set is achieved by using a log parser customized for firewalls from different firewall vendors. This process accurately extracts key information from each log entry, and the parsed data is converted into structured records in a unified format, thereby obtaining a clear, standardized policy hit record set that contains only the core information of policy hits.

[0047] In this embodiment of the invention, the step of comparing the policy hit rate and traffic matching status of the first firewall and the second firewall in real time according to the traffic path expected status table, the first policy hit record set, and the second policy hit record set to obtain the comparison result includes: The strategy hit rate is calculated based on the first strategy hit record set, the second strategy hit record set, and the traffic path expected status table to obtain strategy hit statistics. Based on the policy hit statistics, the policy hit rates of the first firewall and the second firewall are compared to obtain the hit rate comparison results. Based on the first policy hit record set and the second policy hit record set, the actual hit traffic is associated with the traffic path expected status table, and the actual processing firewall for each type of traffic is marked as consistent with the expectation, thus obtaining a traffic processing expectation comparison table. Based on the traffic processing expectation comparison table, the first strategy hit record set, and the second strategy hit record set, a traffic matching status consistency analysis is performed to obtain the traffic matching status comparison result. The comparison result is obtained by summarizing the hit rate comparison result and the traffic matching status comparison result.

[0048] In detail, the step of calculating the policy hit rate based on the first policy hit record set, the second policy hit record set, and the traffic path expected status table to obtain policy hit statistics involves aggregating the policy hit records of the two firewalls according to a preset time window (e.g., every 1 minute), calculating the number of hits for each policy and the total number of hits within each window. Then, the actual hit ratio of the traffic category expected to be processed by each firewall within the time window is calculated by combining the traffic path expected status table.

[0049] In detail, the step of comparing the policy hit rates of the first firewall and the second firewall based on the policy hit statistics to obtain a hit rate comparison result is a horizontal comparison of the total hit rate or the hit rate of key policies of the two firewalls within the same time window. By calculating the deviation between the actual hit rate ratio and the expected load distribution ratio derived from the traffic path expected status table, and comparing it with a preset threshold, the load balance is determined, and the comparison result is obtained.

[0050] In detail, the step of associating the actual hit traffic with the traffic path expected state table based on the first policy hit record set and the second policy hit record set, and marking whether the actual processing firewall for each type of traffic is consistent with the expectation, to obtain a traffic processing expectation comparison table, is achieved by traversing each policy hit record and classifying it into a certain traffic category defined in the traffic path expected state table based on its traffic five-tuple information (source IP, destination IP, protocol, source port, destination port). Then, it is checked whether the firewall that actually recorded the traffic is consistent with the firewall specified in the expectation table.

[0051] In detail, the step of performing traffic matching status consistency analysis based on the traffic processing expectation comparison table, the first policy hit record set, and the second policy hit record set to obtain the traffic matching status comparison result is based on the traffic processing expectation comparison table to statistically analyze the proportion and type of traffic with inconsistent paths. For the same traffic session, it checks whether its policy matching actions on the two firewalls are exactly the same to prevent policy execution discrepancies, and checks whether there is traffic that should be processed by a single device is processed by two devices simultaneously, or whether the expected matching records are completely missing.

[0052] In this embodiment of the invention, after performing real-time comparison of the policy hit rate and traffic matching status of the first firewall and the second firewall based on log data pre-obtained from the target system backend and the real-time link status information, the method further includes: Based on the comparison results, extract the abnormal events from the log data to obtain a list of abnormal events; The abnormal event list is matched with abnormal alarms according to the preset alarm rule set to obtain an initial alarm list; Suppression checks, aggregation analysis, and correlation analysis are performed on the initial alarm list to obtain the final alarm list; Based on the final alarm list, alarm information is generated to obtain an alarm information set; Anomaly alerts are generated based on the set of alarm information.

[0053] In detail, the step of extracting abnormal events from the log data based on the comparison results to obtain an abnormal event list involves traversing the comparison results to identify and extract all indicators and states that exceed a preset normal range. The target system will extract corresponding abnormal data points from the comparison results based on predefined abnormal feature templates (e.g., policy hit rate deviation exceeding a threshold, actual traffic path not matching the expected path, conflicting actions of dual firewall policies, etc.). Each identified abnormal point is encapsulated into a standardized event object, resulting in an abnormal event list.

[0054] In detail, the step of matching the abnormal event list with abnormal alarms according to a preset set of alarm rules to obtain an initial alarm list involves traversing the abnormal event list and comparing the type and key attributes (such as outliers) of each event with the conditions of the alarm rules. For example, a rule might specify "when the actions of the two firewalls for the same service traffic are inconsistent, a critical alarm is triggered." All events that successfully match the rules are assigned a corresponding alarm level and rule ID, and an initial alarm list containing details of the alarms to be processed is generated.

[0055] In detail, the initial alarm list is subjected to suppression checks, aggregation analysis, and correlation analysis to obtain the final alarm list. First, suppression checks are performed to filter out duplicate or temporary alarms that do not require immediate notification, based on time windows, maintenance cycles, or specific resource quiescent rules. Next, aggregation analysis is performed to merge multiple alarm events that occur within a short period and address the same underlying problem into a single aggregated alarm, reducing redundancy. Finally, correlation analysis is performed to identify causal chains between alarms using topology and dependencies (e.g., link failure is the root cause, and traffic path errors are a derivative result), thereby determining the alarms that need to be reported first.

[0056] In detail, generating alarm information based on the final alarm list to obtain an alarm information set involves filling each record in the final alarm list with a predefined alarm message template. The template dynamically inserts specific anomaly details, affected resources, occurrence time, severity level, and adds preliminary diagnostic suggestions or handling guidelines based on a rule base.

[0057] In detail, the step of issuing abnormal alarms based on the alarm information set involves calling the corresponding notification channel interface to send alarms according to the severity level of the alarm information and the pre-configured notification policy. For example, for alarms at the "fatal" and "critical" levels, emergency push notifications via SMS, telephone, and instant messaging tools may be triggered simultaneously; for alarms at the "warning" level, only an email may be sent or the alarm may be displayed in the operations and maintenance dashboard.

[0058] As can be seen, the above solution addresses the core pain points of traditional firewall master-slave mode in private cloud data centers, such as single point of failure, policy conflicts, resource idleness, and inefficient management. It proposes an innovative system and method for automated analysis and dual-active deployment of heterogeneous firewall policies. This system parses and converts heterogeneous security policy configurations from different firewall vendors into a unified policy normalization model. Based on this model, the system uses a pre-built rule base for automated conflict detection and risk analysis, identifying redundant, hidden conflicts, and illegal policies. Subsequently, the automation engine synchronously converts the verified policy model into configuration scripts specific to each firewall vendor's device. A collaborative control mechanism ensures consistent policy deployment to the two firewalls deployed in a dual-active architecture, guaranteeing lossless business updates. At the traffic scheduling level, the system deeply integrates BFD millisecond-level fault detection with dynamic routing protocols such as OSPF / BGP, monitoring link health in real time. Under normal circumstances, intelligent load balancing between dual-active devices is achieved by dynamically adjusting routing costs, greatly improving resource utilization. Once a link or node failure is detected, a millisecond-level switching of the routing path is immediately triggered, with the healthy firewall seamlessly taking over all traffic, ensuring zero business interruption. Finally, by collecting and comparing the policy hit logs and traffic matching status of the dual-active firewall in real time, the consistency of policy execution and the accuracy of traffic scheduling are continuously monitored. Any anomalies such as load imbalance, path errors or action conflicts will trigger hierarchical alarms and can be automatically compensated through the self-healing mechanism. This achieves a fundamental simplification of firewall policies, a revolutionary improvement in business continuity, and a significant optimization of operation and maintenance efficiency in complex heterogeneous environments, thereby improving the resource utilization of heterogeneous firewalls.

[0059] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0060] In one embodiment, a heterogeneous firewall automated control device is provided, which corresponds one-to-one with the heterogeneous firewall automated control method described in the above embodiments. For example... Figure 3 As shown, the heterogeneous firewall automated control device includes a configuration conversion module 101, a conflict detection module 102, a dual-active distribution module 103, a dynamic scheduling module 104, and a comparison and alarm module 105. Detailed descriptions of each functional module are as follows: The configuration conversion module 101 is used to obtain the first defense policy of the first firewall and the second defense policy of the second firewall pre-deployed in the target system, and convert the first defense policy and the second defense policy into a unified intermediate representation model to obtain a policy normalization model. The conflict detection module 102 is used to identify and filter out conflicting strategies in the first defense strategy and the second defense strategy using the strategy normalization model and the preset rule base, so as to obtain the optimized first defense strategy and the optimized second defense strategy. The dual-active deployment module 103 is used to generate configuration scripts for the first firewall and the second firewall based on the optimized first defense policy and the optimized second defense policy using the policy normalization model, thereby obtaining the first configuration script and the second configuration script, and to synchronously deploy dual-active policies to the first firewall and the second firewall based on the first configuration script and the second configuration script. The dynamic scheduling module 104 is used to monitor the real-time link status information of the first firewall and the second firewall after the dual-active policy is synchronously issued, based on a preset dynamic routing protocol. The comparison alarm module 105 is used to compare the policy hit rate and traffic matching status of the first firewall and the second firewall in real time based on the log data obtained in advance from the target system backend and the real-time link status information, and obtain the comparison result.

[0061] In one embodiment, the configuration conversion module 101, when performing the conversion of the first defense strategy and the second defense strategy into a unified intermediate representation model to obtain a strategy normalization model, is specifically used for: Using preset regular expressions, extract the rule fields in the first defense policy and the second defense policy that represent source address, destination address, port, protocol and action to obtain the first target field and the second target field; Based on the syntax parsers preset by the first firewall and the second firewall, the first target field and the second target field are parsed into structured policy objects to obtain a first policy object list and a second policy object list. Based on a preset field mapping table, the fields of the first strategy object list and the second strategy object list are unified, and the strategy values ​​of the unified strategy object list are standardized to obtain the first standardized strategy object list and the second standardized strategy object list. Construct a model framework based on the preset target model structure, the first standardized strategy object list, and the second standardized strategy object list; The first and second standardized strategy object lists are deduplicated, and the deduplicated first and second standardized strategy object lists are filled into the model framework to obtain the strategy normalization model.

[0062] In one embodiment, the dynamic scheduling module 104, when executing the real-time link status information of the first firewall and the second firewall after the synchronous issuance of the dual-active policy based on the preset dynamic routing protocol, is specifically used for: Based on a preset bidirectional forwarding detection protocol, link information of the direct connection links between the first firewall and the second firewall is obtained in real time. Determine whether there is a fault in either the first firewall or the second firewall based on the link information; If there is no fault, the traffic load of the first firewall and the second firewall is dynamically balanced and allocated based on the dynamic routing protocol, and the real-time link status information of the first firewall and the second firewall after the traffic load allocation is obtained. If a fault exists, the firewall path is switched between the first firewall and the second firewall based on the fault information in the link information, and the real-time link status information of the switched firewall is obtained.

[0063] In one embodiment, the dynamic scheduling module 104, in the dynamic allocation of traffic load balancing between the first firewall and the second firewall based on the dynamic routing protocol, is specifically used for: The load data of the first firewall and the second firewall are obtained based on the dynamic routing protocol to obtain the first load data and the second load data; The first load data and the second load data are converted into numerical indicators to obtain the first load indicator and the second load indicator. Determine whether both the first load indicator and the second load indicator are less than a preset load threshold; If both the first load metric and the second load metric are less than the preset load threshold, then the traffic allocation of the first firewall and the second firewall will not be changed. If either the first load metric or the second load metric has a load metric greater than or equal to the load threshold, then the firewall corresponding to the larger load metric is marked as an overloaded firewall, and the traffic load of the overloaded firewall is reduced.

[0064] In one embodiment, the comparison alarm module 105, when performing the real-time comparison of the policy hit rate and traffic matching status of the first firewall and the second firewall based on log data obtained in advance from the target system backend and the real-time link status information, specifically uses the following to obtain the comparison result: Obtain a real-time link status snapshot of the log data, perform traffic path analysis and expected status calculation based on the real-time link status snapshot, and obtain a traffic path expected status table; The real-time system logs of the first firewall and the second firewall in the log data are aligned with the bidirectional forwarding detection session state to obtain the aligned first firewall log dataset and the aligned second firewall log dataset. The aligned first firewall log dataset and the aligned second firewall log dataset are parsed to obtain a first policy hit record set and a second policy hit record set. Based on the expected traffic path status table, the first policy hit record set, and the second policy hit record set, the policy hit rate and traffic matching status of the first firewall and the second firewall are compared in real time to obtain the comparison results.

[0065] In one embodiment, the comparison alarm module 105, when performing the real-time comparison of the policy hit rate and traffic matching status of the first firewall and the second firewall based on the traffic path expected status table, the first policy hit record set, and the second policy hit record set to obtain the comparison result, is specifically used for: The strategy hit rate is calculated based on the first strategy hit record set, the second strategy hit record set, and the traffic path expected status table to obtain strategy hit statistics. Based on the policy hit statistics, the policy hit rates of the first firewall and the second firewall are compared to obtain the hit rate comparison results. Based on the first policy hit record set and the second policy hit record set, the actual hit traffic is associated with the traffic path expected status table, and the actual processing firewall for each type of traffic is marked as consistent with the expectation, thus obtaining a traffic processing expectation comparison table. Based on the traffic processing expectation comparison table, the first strategy hit record set, and the second strategy hit record set, a traffic matching status consistency analysis is performed to obtain the traffic matching status comparison result. The comparison result is obtained by summarizing the hit rate comparison result and the traffic matching status comparison result.

[0066] In one embodiment, after performing the real-time comparison of the policy hit rate and traffic matching status of the first firewall and the second firewall based on the log data obtained in advance from the target system backend and the real-time link status information, the comparison alarm module 105 is further configured to: Based on the comparison results, extract the abnormal events from the log data to obtain a list of abnormal events; The abnormal event list is matched with abnormal alarms according to the preset alarm rule set to obtain an initial alarm list; Suppression checks, aggregation analysis, and correlation analysis are performed on the initial alarm list to obtain the final alarm list; Based on the final alarm list, alarm information is generated to obtain an alarm information set; Anomaly alerts are generated based on the set of alarm information.

[0067] Specific limitations regarding the heterogeneous firewall automated control device can be found in the limitations of the heterogeneous firewall automated control method described above, and will not be repeated here. Each module in the aforementioned heterogeneous firewall automated control device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.

[0068] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 4 As shown, the computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile and / or volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and database. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The network interface is used to communicate with external clients via a network connection. When the computer program is executed by the processor, it implements the functions or steps of a heterogeneous firewall automation control method on the server side.

[0069] In one embodiment, a computer device is provided, which may be a client, and its internal structure diagram may be as follows: Figure 5 As shown, the computer device includes a processor, memory, network interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The network interface is used to communicate with an external server via a network connection. When the computer program is executed by the processor, it implements the functions or steps on the client side of a heterogeneous firewall automation control method.

[0070] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to perform the following steps: Obtain the first defense policy of the first firewall and the second defense policy of the second firewall pre-deployed in the target system, and convert the first defense policy and the second defense policy into a unified intermediate representation model to obtain the policy normalization model. The strategy normalization model and the pre-set rule base are used to identify and filter out conflicting strategies in the first defense strategy and the second defense strategy to obtain the optimized first defense strategy and the optimized second defense strategy. The policy normalization model is used to generate configuration scripts for the first firewall and the second firewall based on the optimized first defense policy and the optimized second defense policy, resulting in a first configuration script and a second configuration script. The active-active policy is then synchronously distributed to the first firewall and the second firewall based on the first configuration script and the second configuration script. Based on a preset dynamic routing protocol, the real-time link status information of the first firewall and the second firewall after the dual-active policy is synchronously issued is monitored respectively. Based on the log data obtained in advance from the target system's backend and the real-time link status information, the policy hit rate and traffic matching status of the first firewall and the second firewall are compared in real time to obtain the comparison result.

[0071] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor: Obtain the first defense policy of the first firewall and the second defense policy of the second firewall pre-deployed in the target system, and convert the first defense policy and the second defense policy into a unified intermediate representation model to obtain the policy normalization model. The strategy normalization model and the pre-set rule base are used to identify and filter out conflicting strategies in the first defense strategy and the second defense strategy to obtain the optimized first defense strategy and the optimized second defense strategy. The policy normalization model is used to generate configuration scripts for the first firewall and the second firewall based on the optimized first defense policy and the optimized second defense policy, resulting in a first configuration script and a second configuration script. The active-active policy is then synchronously distributed to the first firewall and the second firewall based on the first configuration script and the second configuration script. Based on a preset dynamic routing protocol, the real-time link status information of the first firewall and the second firewall after the dual-active policy is synchronously issued is monitored respectively. Based on the log data obtained in advance from the target system's backend and the real-time link status information, the policy hit rate and traffic matching status of the first firewall and the second firewall are compared in real time to obtain the comparison result.

[0072] It should be noted that the functions or steps that can be implemented by the computer-readable storage medium or computer device described above can be referred to the relevant descriptions on the server side and client side in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.

[0073] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0074] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0075] Finally, it should be noted that if any software tools or components not belonging to this company appear in the embodiments of the application, they are merely illustrative examples and do not represent actual use. The embodiments described above are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.

Claims

1. An automated control method for heterogeneous firewalls, characterized in that, include: Obtain the first defense policy of the first firewall and the second defense policy of the second firewall pre-deployed in the target system, and convert the first defense policy and the second defense policy into a unified intermediate representation model to obtain the policy normalization model. The strategy normalization model and the pre-set rule base are used to identify and filter out conflicting strategies in the first defense strategy and the second defense strategy to obtain the optimized first defense strategy and the optimized second defense strategy. The policy normalization model is used to generate configuration scripts for the first firewall and the second firewall based on the optimized first defense policy and the optimized second defense policy, resulting in a first configuration script and a second configuration script. The active-active policy is then synchronously distributed to the first firewall and the second firewall based on the first configuration script and the second configuration script. Based on a preset dynamic routing protocol, the real-time link status information of the first firewall and the second firewall after the dual-active policy is synchronously issued is monitored respectively. Based on the log data obtained in advance from the target system's backend and the real-time link status information, the policy hit rate and traffic matching status of the first firewall and the second firewall are compared in real time to obtain the comparison result.

2. The automated control method for heterogeneous firewalls as described in claim 1, characterized in that, The step of converting the first defense strategy and the second defense strategy into a unified intermediate representation model to obtain a strategy normalization model includes: Using preset regular expressions, extract the rule fields in the first defense policy and the second defense policy that represent source address, destination address, port, protocol and action to obtain the first target field and the second target field; Based on the syntax parsers preset by the first firewall and the second firewall, the first target field and the second target field are parsed into structured policy objects to obtain a first policy object list and a second policy object list. Based on a preset field mapping table, the fields of the first strategy object list and the second strategy object list are unified, and the strategy values ​​of the unified strategy object list are standardized to obtain the first standardized strategy object list and the second standardized strategy object list. Construct a model framework based on the preset target model structure, the first standardized strategy object list, and the second standardized strategy object list; The first and second standardized strategy object lists are deduplicated, and the deduplicated first and second standardized strategy object lists are filled into the model framework to obtain the strategy normalization model.

3. The heterogeneous firewall automated control method as described in claim 1, characterized in that, The method, based on a preset dynamic routing protocol, monitors the real-time link status information of the first and second firewalls after the simultaneous distribution of the dual-active policy, including: Based on a preset bidirectional forwarding detection protocol, link information of the direct connection links between the first firewall and the second firewall is obtained in real time. Determine whether there is a fault in either the first firewall or the second firewall based on the link information; If there is no fault, the traffic load of the first firewall and the second firewall is dynamically balanced and allocated based on the dynamic routing protocol, and the real-time link status information of the first firewall and the second firewall after the traffic load allocation is obtained. If a fault exists, the firewall path is switched between the first firewall and the second firewall based on the fault information in the link information, and the real-time link status information of the switched firewall is obtained.

4. The heterogeneous firewall automated control method as described in claim 3, characterized in that, The dynamic allocation of traffic load balancing between the first firewall and the second firewall based on the dynamic routing protocol includes: The load data of the first firewall and the second firewall are obtained based on the dynamic routing protocol to obtain the first load data and the second load data; The first load data and the second load data are converted into numerical indicators to obtain the first load indicator and the second load indicator. Determine whether both the first load indicator and the second load indicator are less than a preset load threshold; If both the first load metric and the second load metric are less than the preset load threshold, then the traffic allocation of the first firewall and the second firewall will not be changed. If either the first load metric or the second load metric has a load metric greater than or equal to the load threshold, then the firewall corresponding to the larger load metric is marked as an overloaded firewall, and the traffic load of the overloaded firewall is reduced.

5. The automated control method for heterogeneous firewalls as described in claim 1, characterized in that, The step of performing a real-time comparison of the policy hit rate and traffic matching status of the first firewall and the second firewall based on log data obtained in advance from the target system backend and the real-time link status information to obtain the comparison result includes: Obtain a real-time link status snapshot of the log data, perform traffic path analysis and expected status calculation based on the real-time link status snapshot, and obtain a traffic path expected status table; The real-time system logs of the first firewall and the second firewall in the log data are aligned with the bidirectional forwarding detection session state to obtain the aligned first firewall log dataset and the aligned second firewall log dataset. The aligned first firewall log dataset and the aligned second firewall log dataset are parsed to obtain a first policy hit record set and a second policy hit record set. The policy hit rate and traffic matching status of the first firewall and the second firewall are compared in real time based on the traffic path expected status table, the first policy hit record set and the second policy hit record set to obtain the comparison result.

6. The automated control method for heterogeneous firewalls as described in claim 5, characterized in that, The step involves real-time comparison of the policy hit rate and traffic matching status of the first firewall and the second firewall based on the traffic path expected status table, the first policy hit record set, and the second policy hit record set, to obtain the comparison result, including: The strategy hit rate is calculated based on the first strategy hit record set, the second strategy hit record set, and the traffic path expected status table to obtain strategy hit statistics. Based on the policy hit statistics, the policy hit rates of the first firewall and the second firewall are compared to obtain the hit rate comparison results. Based on the first policy hit record set and the second policy hit record set, the actual hit traffic is associated with the traffic path expected status table, and the actual processing firewall for each type of traffic is marked as consistent with the expectation, thus obtaining a traffic processing expectation comparison table. Based on the traffic processing expectation comparison table, the first strategy hit record set, and the second strategy hit record set, a traffic matching status consistency analysis is performed to obtain the traffic matching status comparison result. The comparison result is obtained by summarizing the hit rate comparison result and the traffic matching status comparison result.

7. The automated control method for heterogeneous firewalls as described in claim 1, characterized in that, After comparing the policy hit rate and traffic matching status of the first firewall and the second firewall in real time based on the log data obtained in advance from the target system backend and the real-time link status information, the method further includes: Based on the comparison results, extract the abnormal events from the log data to obtain a list of abnormal events; The abnormal event list is matched with abnormal alarms according to the preset alarm rule set to obtain an initial alarm list; Suppression checks, aggregation analysis, and correlation analysis are performed on the initial alarm list to obtain the final alarm list; Based on the final alarm list, alarm information is generated to obtain an alarm information set; Anomaly alerts are generated based on the set of alarm information.

8. An automated control device for a heterogeneous firewall, characterized in that, include: The configuration conversion module is used to obtain the first defense policy of the first firewall and the second defense policy of the second firewall pre-deployed in the target system, and convert the first defense policy and the second defense policy into a unified intermediate representation model to obtain the policy normalization model. The conflict detection module is used to identify and filter out conflicting strategies in the first defense strategy and the second defense strategy using the strategy normalization model and the preset rule base, so as to obtain the optimized first defense strategy and the optimized second defense strategy. The dual-active deployment module is used to generate configuration scripts for the first firewall and the second firewall based on the optimized first defense policy and the optimized second defense policy using the policy normalization model, thereby obtaining the first configuration script and the second configuration script, and to synchronously deploy the dual-active policy to the first firewall and the second firewall based on the first configuration script and the second configuration script. The dynamic scheduling module is used to monitor the real-time link status information of the first firewall and the second firewall after the dual-active policy is synchronously issued, based on a preset dynamic routing protocol. The comparison alarm module is used to compare the policy hit rate and traffic matching status of the first firewall and the second firewall in real time based on the log data obtained in advance from the target system backend and the real-time link status information, and obtain the comparison result.

9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the heterogeneous firewall automated control method as described in any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the heterogeneous firewall automated control method as described in any one of claims 1 to 7.