Method for automatic execution of security policies
By performing policy set calculations and logical coverage boundary records on the data center equipment floor plan, the problem of lack of visual verification in security policy execution is solved, thereby improving the accuracy and efficiency of policy execution.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HANGZHOU LEMANG TECH CO LTD
- Filing Date
- 2026-04-24
- Publication Date
- 2026-05-29
AI Technical Summary
In existing technologies, the security policy execution process lacks visual verification methods, making it impossible for operations and maintenance personnel to confirm in real time whether the policy is being implemented correctly, and making it difficult to locate the deviation between the logical coverage boundary and the expectation.
By retrieving the data center equipment floor plan, marking the physical partition boundaries, performing policy set calculations, generating equipment subsets, and recording the displacement status of the logical coverage boundary after each rule is written, the predicted and actual logical coverage boundaries are overlaid to mark the deviation areas.
This enables maintenance personnel to directly identify the differences and deviation areas in the coverage of the old and new policies from the equipment floor plan during the automated execution of security policies. This reduces the reliance on manual comparison and improves the accuracy and efficiency of policy execution.
Smart Images

Figure CN122120022A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing technology, and in particular to a method for automating the execution of security policies. Background Technology
[0002] Data center security management relies on security policies to control device access permissions. Security policies define which devices are protected and how the scope of protection is defined in the form of a set of rules. As business changes, data centers need to periodically change security policies, adjusting the initial policies to the target policies to adapt to operational needs such as device offline / removal, and physical partition adjustments.
[0003] During the execution of security policy changes, operations and maintenance personnel typically break down the target policy into several rules and write them one by one into security devices. After each rule is written, the scope of protected devices is dynamically adjusted, forming a new logical coverage area. Because rules have interrelationships and data center devices are distributed across different physical partitions, the actual effective scope of each rule is limited by multiple factors such as physical partition boundaries and rule priority. Therefore, there may be a difference between the actual logical coverage boundary and the expected coverage area of the rule. In the existing execution process, after all rules are written, the execution result is verified by manually comparing the target policy document with the device configuration. This verification relies on static policy text and lacks methods for recording and tracking the dynamic changes in the logical coverage boundary during the rule writing process.
[0004] Therefore, when the actual logical coverage boundary deviates from the expected one, it is difficult to pinpoint which rule writing stage the deviation occurred in, and it is also difficult to determine the physical partition that the deviation area spans and its corresponding security impact level. Summary of the Invention
[0005] This application provides a method for automating the execution of security policies to address the problem that existing technologies lack visual verification methods for the execution process of security policies, making it impossible for operations and maintenance personnel to confirm in real time whether the security policies are being implemented correctly and whether there are any deviations between the actual logical coverage boundaries and expectations throughout the entire process of writing policy rules one by one.
[0006] A first aspect of this application provides a method for automating the execution of security policies, comprising: retrieving a device floor plan of a data center, wherein the device floor plan is marked with security domain boundaries consisting of physical partitions; In response to a security policy change command, a set operation is performed on the set of devices covered by the initial policy and the set of devices covered by the target policy to generate multiple types of device subsets, and the multiple types of device subsets are marked at the corresponding device locations on the device plan. Based on the set of devices covered by the target strategy, the predicted logical coverage boundary is determined, and the target strategy rules are written one by one. After each target strategy rule is written, the displacement state of the logical coverage boundary on the device plan is retained as a trajectory recording node. The final state positions of all the trajectory recording nodes are determined as the actual logical coverage boundary. The predicted logical coverage boundary and the actual logical coverage boundary are superimposed and displayed, and the deviation area is marked. An execution confirmation command is output according to the physical partition where the deviation area is located.
[0007] Optionally, in one possible implementation of the first aspect, the step of performing a set operation on the device set covered by the initial policy and the device set covered by the target policy to generate multiple device subsets includes: The devices that are covered by both the initial policy set and the target policy set are identified as the common coverage subset. Devices covered only by the initial policy are identified as the exit protection subset, and devices covered only by the target policy are identified as the new protection subset; The common coverage subset, the exit protection subset, and the new protection subset are taken as the subset of the multiple types of devices.
[0008] Optionally, in one possible implementation of the first aspect, determining the devices covered only by the initial policy as the exit subset of protection and the devices covered only by the target policy as the new subset of protection includes: When the common coverage subset is determined to be an empty set, the device location corresponding to the exited protection subset on the device plan is determined as the initial policy logic coverage boundary, and the device location corresponding to the new protection subset on the device plan is determined as the target policy logic coverage boundary. When it is determined that the common coverage subset is not an empty set, the common coverage area is determined by the equipment position corresponding to the common coverage subset on the equipment plan. When it is determined that the exit protection subset is not an empty set, the exit area is determined by the device position corresponding to the exit protection subset on the device plan view, and the outer contour boundary of the exit area and the common coverage area on the device plan view is determined as the initial strategy logic coverage boundary. When the exit protection subset is determined to be an empty set, the outer contour boundary of the common coverage area is determined as the initial strategy logical coverage boundary; When it is determined that the newly added protection subset is not an empty set, the newly added area is determined by the device position corresponding to the newly added protection subset on the device plan view, and the outer contour boundary of the newly added area and the common coverage area on the device plan view is determined as the target strategy logical coverage boundary. When the newly added protection subset is determined to be an empty set, the outer contour boundary of the common coverage area is determined as the target strategy logical coverage boundary.
[0009] Optionally, in one possible implementation of the first aspect, determining the outer contour boundary of the exit region and the common coverage region on the device plan as the initial strategy logical coverage boundary includes: When it is determined that the exit area crosses the physical partition boundary on the device plan, the exit area is divided into sub-areas within each physical partition using the physical partition boundary as the dividing line. Each sub-area is merged with the common coverage area within the same physical partition. The segment boundary of the initial strategy logical coverage boundary is marked according to each physical partition. When it is determined that the exit area does not cross the physical partition boundary on the device plan, the outer contour boundary of the exit area and the common coverage area is determined as the initial strategy logical coverage boundary.
[0010] Optionally, in one possible implementation of the first aspect, determining the outer contour boundary of the newly added area and the shared coverage area on the device plan as the target strategy logical coverage boundary includes: When it is determined that the newly added area crosses the physical partition boundary on the device plan, the newly added area is divided into sub-areas within each physical partition using the physical partition boundary as the dividing line. Each sub-area is merged with the common coverage area within the same physical partition. The segment boundary of the target strategy logical coverage boundary is marked according to each physical partition. When it is determined that the newly added area does not cross the physical partition boundary on the device plan, the outer contour boundary of the newly added area and the common coverage area is determined as the target strategy logical coverage boundary.
[0011] Optionally, in one possible implementation of the first aspect, determining the predictive logical coverage boundary based on the set of devices covered by the target strategy includes: When it is determined that the set of devices covered by the target strategy is an empty set, the boundary of the prediction logic coverage is marked as an empty boundary; When it is determined that the set of devices covered by the target strategy is not an empty set, the device positions corresponding to all devices in the set of devices covered by the target strategy on the device plan are determined as the target coverage area, and the outer contour boundary of each continuous sub-region in the target coverage area on the device plan is determined as the prediction logic coverage boundary. The step of retaining the displacement state of the logical coverage boundary on the device plan as a trajectory recording node after each target strategy rule is written includes: The coverage area of the target policy rule is compared with the position of the logical coverage boundary to determine all local change areas where the position of the logical coverage boundary changes after the target policy rule is written. The boundary positions of all the local change areas are associated with the target policy rule as the trajectory recording nodes. If the logical coverage boundary does not change position after the target strategy rule is written, the current position state of the logical coverage boundary is retained as the trajectory recording node.
[0012] Optionally, in one possible implementation of the first aspect, associating the boundary positions of all the local change regions with the target policy rule as the trajectory recording nodes includes: For each of the local change regions, when it is determined that the local change region covers the physical partition boundary on the device plan, the local change region is split into corresponding partition change regions according to each physical partition, and the boundary position of each partition change region is associated with the target strategy rule and the corresponding physical partition, respectively, as the trajectory recording node; For each of the local change regions, when it is determined that the local change region does not cover the physical partition boundary on the device plan, the boundary position of the local change region is associated with the target policy rule and the physical partition in which it is located, and is used as the trajectory recording node.
[0013] Optionally, in one possible implementation of the first aspect, associating the boundary positions of each of the partition change regions with the target policy rule and the corresponding physical partition as the trajectory recording nodes includes: When the partition change area is determined to be a physical partition between the DMZ and the intranet, the trajectory recording node corresponding to the partition change area is marked as a high-interest node; When the partition change area is determined to be a physical partition between the intranet area and the core area, the trajectory recording node corresponding to the partition change area is marked as the second most important node. When it is determined that the partition change area is located in another physical partition, the trajectory recording node corresponding to the partition change area is marked as a normal attention node.
[0014] Optionally, in one possible implementation of the first aspect, associating the boundary positions of all the local change regions with the target policy rule as the trajectory recording nodes further includes: When the boundary position of the local change area exceeds the boundary range of all physical partitions on the device plan, the trajectory recording node corresponding to the local change area is marked as an abnormal node, the writing of the target policy rule is paused, the target policy rule is marked as an abnormal rule and an abnormal prompt instruction is output. When it is determined that the boundary position of the local change region does not exceed the boundary range of all physical partitions on the device plan, the boundary position of the local change region is associated with the target strategy rule and used as the trajectory recording node.
[0015] Optionally, in one possible implementation of the first aspect, determining the final state position of all the trajectory recording nodes as the actual logical coverage boundary includes: Arrange all the trajectory recording nodes in the writing order to form the boundary movement trajectory; When it is determined that there is an abnormal node in the boundary movement trajectory, the position state of the preceding trajectory record node of the abnormal node is used as the final position of the boundary movement trajectory, and is determined as the actual logical coverage boundary. When it is determined that there are no abnormal nodes in the boundary movement trajectory, the final position of the boundary movement trajectory is determined as the actual logical coverage boundary.
[0016] Optionally, in one possible implementation of the first aspect, the step of overlaying and displaying the predicted logic coverage boundary and the actual logic coverage boundary and marking the deviation area includes: The predicted logic coverage boundary and the actual logic coverage boundary are superimposed on the device plan view. When the predicted logic coverage boundary and the actual logic coverage boundary completely coincide, no deviation area is generated, and an execution confirmation command is output. When it is determined that there is a device whose boundary position does not coincide with the actual logical coverage boundary, the area corresponding to the device on the device plan is marked as the deviation area.
[0017] Optionally, in one possible implementation of the first aspect, marking the area corresponding to the device on the device plan as the deviation area includes: When it is determined that the deviation region covers the boundary of adjacent physical partitions on the equipment plan, the deviation region is divided into corresponding sub-deviation regions according to each physical partition, and each sub-deviation region is associated with the corresponding physical partition as the partition association result of the deviation region. When it is determined that the deviation area does not cover the boundary of the adjacent physical partition on the device plan, the deviation area is associated with the physical partition in which it is located, and this association is taken as the partition association result of the deviation area.
[0018] Optionally, in one possible implementation of the first aspect, the step of outputting an execution confirmation instruction based on the physical partition where the deviation region is located includes: From all the trajectory recording nodes, determine the trajectory recording node corresponding to the partition change region within the physical partition where the deviation region is located; When it is determined that there is a high-interest node within the physical partition where the deviation area is located, the execution confirmation instruction is marked as a high-impact confirmation instruction; When it is determined that there are no high-interest nodes but there are second-highest-interest nodes within the physical partition where the deviation area is located, the execution confirmation instruction is marked as the second-highest-impact confirmation instruction; When it is determined that only ordinary nodes of interest exist within the physical partition where the deviation area is located, the execution confirmation instruction is marked as an ordinary impact confirmation instruction.
[0019] The automated security policy execution method provided in this application has the following advantages: 1. This application marks the results of the set operation of the coverage of the initial policy and the target policy on the equipment plan as three types of device subsets. It preserves the displacement status of each logical coverage boundary during the writing of the target policy rules as trajectory record nodes. After all rules are written, the predicted logical coverage boundary and the actual logical coverage boundary are superimposed and displayed on the same equipment plan. Before initiating a change, maintenance personnel can directly read the set differences of the coverage of the old and new policies from the equipment plan. During the rule writing process, they can compare the positional relationship between the predicted logical coverage boundary and the current logical coverage boundary at any time. After execution, they can directly confirm the location and range of the deviation area from the equipment plan, without having to compare each rule in the text rule list and execution log. This solves the problem that maintenance personnel lack effective evidence to confirm whether the security policy is correctly implemented throughout the entire process of automated security policy execution. 2. This application introduces the physical partition boundaries on the equipment floor plan as a stable reference into the confirmation process of security policy execution. In the trajectory recording nodes, the concern level is pre-marked according to the physical partition type crossed by the partition change area. After the deviation area is marked, the impact level of the execution confirmation command is directly assessed based on the concern level within the physical partition where the deviation area is located. Physical partitions with different security isolation levels, such as between the DMZ and the intranet, and between the intranet and the core area, naturally correspond to different security trust levels. The physical partition boundaries serve as a stable reference for security domain division, directly linking the spatial location of the deviation area to the degree of security isolation impact without additional configuration. This allows operations personnel to determine the impact of the deviation on data center security isolation upon receiving the execution confirmation command, transforming the confirmation of execution results from a uniform qualitative judgment into a structured conclusion independently verified by physical partition. Attached Figure Description
[0020] Figure 1 This is a flowchart illustrating the automated execution method of security policies provided in an embodiment of this application; Figure 2 This is a schematic diagram of the strategy logic coverage boundary determination process provided in the embodiments of this application; Figure 3 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0021] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0022] The technical solutions of this application will be described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.
[0023] See Figure 1 This is a schematic diagram of the automated execution method of security policies provided in the embodiments of this application. Figure 1 The execution entity of the method shown can be a software and / or hardware device. The execution entity of this application can include, but is not limited to, at least one of the following: user equipment, network equipment, etc. User equipment can include, but is not limited to, computers, smartphones, personal digital assistants (PDAs), and the aforementioned electronic devices. Network equipment can include, but is not limited to, a single network server, a server group consisting of multiple network servers, or a cloud based on cloud computing consisting of a large number of computers or network servers. Cloud computing is a type of distributed computing, consisting of a super virtual computer composed of a group of loosely coupled computers. This embodiment does not limit this. Steps S1 to S4 are detailed as follows: S1, retrieve the equipment floor plan of the data center, which shows the security domain boundaries formed by physical partitions.
[0024] It should be noted that in step S1, the equipment floor plan of the data center is retrieved from the DCIM (Data Center Infrastructure Management) system. This floor plan shows the security domain boundaries formed by physical partitions. These security domain boundaries divide the data center into physical partitions such as the DMZ, intranet, and core areas. Devices within each physical partition are distributed according to the logical coverage range of the security policy. The equipment floor plan simultaneously carries the physical locations of the devices and the security domain boundaries, providing a unified spatial basis for the spatial labeling of the aggregate operation results in step S2, the recording of changes in the logical coverage boundaries in step S3, and the determination of the physical partition affixation of the deviation area in step S4.
[0025] In some embodiments, step S1 includes steps S11 to S13: Step S11: Retrieve the equipment floor plan of the data center from the DCIM system, extract the equipment identifiers and equipment location coordinates in each physical partition on the equipment floor plan, as well as the security domain boundary locations between each physical partition.
[0026] It should be noted that the DCIM system stores rack locations and physical partitioning information for all equipment in the data center. Using the DCIM system as the data source to retrieve equipment floor plans can ensure that equipment identification and location coordinates are consistent with the actual deployment status of the data center. If equipment location coordinates are obtained through manual input, the risk of incorrect spatial labeling of subsequent logical coverage boundaries due to input deviations will be difficult to eliminate.
[0027] Step S12: Compare the device identifier and device location coordinates with the set of devices covered by the initial policy in the initial policy definition to determine the initial position of each device in the set of devices covered by the initial policy on the device plan.
[0028] It is easy to understand that the security policy defines the coverage area by using the device identifier as an index. By using the device identifier, the set of devices covered by the initial policy is established to correspond with the device location coordinates on the device plan. The logical coverage area of the initial policy can be spatially located on the device plan, providing a location basis for the spatial labeling of the set operation results in step S2.
[0029] Step S13: Mark the security domain boundary location on the device floor plan. Output the device floor plan with the initial location and security domain boundary marked as the data center's device floor plan for use in steps S2 to S4. The security domain boundary and the initial device location are presented synchronously on the same device floor plan, allowing the spatial annotation of the set operation result in step S2 to be directly compared with the security domain boundary to determine the physical partition affiliation of each device subset, avoiding omissions in cross-partition judgments due to the lack of boundary references later.
[0030] S2 responds to the security policy change command, performs set operations on the set of devices covered by the initial policy and the set of devices covered by the target policy, generates multiple device subsets, and marks the multiple device subsets at the corresponding device locations on the device plan.
[0031] It's important to note that before security policy changes, operations and maintenance personnel could only perceive the changes in coverage by comparing the text rule lists of the old and new policies. They couldn't visually understand on the device floor plan which devices would be removed from protection, which would be added to protection, or which devices would be protected both before and after the change. By using set operations to decompose the differences between the device set covered by the initial policy and the device set covered by the target policy into multiple device subsets, and marking these subsets at their corresponding device locations on the device floor plan, operations and maintenance personnel can visually grasp the set differences between the coverage of the old and new policies and their spatial distribution on the device floor plan before implementing the change.
[0032] In some embodiments, step S2 involves performing a set operation on the device set covered by the initial policy and the device set covered by the target policy to generate multiple device subsets, including steps A1 to A3: Step A1: Determine the devices that are covered by both the initial policy-covered device set and the target policy-covered device set as the common coverage subset.
[0033] It is easy to understand that the devices in the common coverage subset are in a protected state before and after the policy change. By identifying the common coverage subset separately, the range of devices that remain in a protected state throughout the policy change can be clearly marked on the device plan, providing a stable spatial reference area for subsequently determining the initial policy logical coverage boundary and the target policy logical coverage boundary.
[0034] Step A2: Determine the devices covered only by the initial policy as the exit protection subset, and determine the devices covered only by the target policy as the new protection subset.
[0035] In some embodiments, such as Figure 2 As shown, in step A2, the determination of the corresponding logical coverage boundaries of the common coverage subset, the exited protection subset, and the newly added protection subset on the equipment plan is handled according to the following cases.
[0036] When the common coverage subset is determined to be an empty set, there are no overlapping devices between the device set covered by the initial policy and the device set covered by the target policy. The device location corresponding to the exited protection subset on the device plan is determined as the logical coverage boundary of the initial policy, and the device location corresponding to the new protection subset on the device plan is determined as the logical coverage boundary of the target policy.
[0037] When it is determined that the common coverage subset is not an empty set, the common coverage area is determined by the equipment location corresponding to the common coverage subset on the equipment plan. Based on the common coverage area, the initial policy logical coverage boundary and the target policy logical coverage boundary are determined according to the cases of exiting the protection subset and adding the protection subset, respectively.
[0038] When it is determined that the excluded protection subset is not empty, the excluded area is determined by the location of the corresponding equipment on the equipment plan. The outer contour boundary of the excluded area and the common coverage area on the equipment plan is determined as the logical coverage boundary of the initial policy. The equipment in the excluded protection subset will no longer be protected after the change. The excluded area and the common coverage area together constitute the complete spatial coverage of the initial policy. Using the outer contour boundary of the merged area as the logical coverage boundary of the initial policy ensures that the coverage of the initial policy is fully expressed on the equipment plan.
[0039] Specifically, the outer contour boundary of the exit area and the common coverage area on the device plan is determined as the initial policy logical coverage boundary. It is necessary to distinguish between two cases: whether the exit area crosses the physical partition boundary on the device plan.
[0040] When determining that the exit area crosses the physical partition boundary on the device plan, the exit area is divided into sub-areas within each physical partition using the physical partition boundary as the dividing line. Each sub-area is then merged with the common coverage area within the same physical partition, and the segment boundaries of the initial policy logical coverage boundary are marked for each physical partition.
[0041] When it is determined that the exit area does not cross the physical partition boundary on the device plan, the entire exit area is located within the same physical partition, and the outer contour boundary of the exit area and the common coverage area is directly determined as the initial strategy logical coverage boundary.
[0042] It should be noted that security domain boundaries constitute clear security isolation between physical partitions. If devices exiting the protection subset are distributed across physical partitions, the exited area spans physical partitions of different security levels. If the overall outline boundary across partitions is used as the initial policy logical coverage boundary, the boundary markings will overlap with the security domain boundaries, making it impossible for maintenance personnel to distinguish the coverage changes of each physical partition from the device floor plan. By dividing the exited area into sub-regions within each physical partition using the physical partition boundaries as dividing lines, and marking the segment boundaries for each physical partition, the initial policy logical coverage boundary within each partition remains aligned with the security domain boundary. Maintenance personnel can then independently verify the shrinkage of the coverage area by physical partition.
[0043] When the subset to be removed from protection is determined to be empty, the policy change does not involve shrinking the protection range, and the outer contour boundary of the common coverage area is determined as the initial policy logical coverage boundary.
[0044] When it is determined that the newly added protection subset is not an empty set, the newly added area is determined by the location of the corresponding equipment on the equipment plan. The outer contour boundary of the newly added area and the common coverage area on the equipment plan is determined as the logical coverage boundary of the target strategy. The equipment in the newly added protection subset will be included in the protection range after the change. The newly added area and the common coverage area together constitute the complete spatial coverage of the target strategy. Using the outer contour boundary of the merged area as the logical coverage boundary of the target strategy can ensure that the expected coverage of the target strategy is fully expressed on the equipment plan, providing a spatial basis for determining the predicted logical coverage boundary in step S3.
[0045] Among them, the outer contour boundary of the newly added area and the shared coverage area on the device plan is determined as the target strategy logical coverage boundary. It is also necessary to distinguish between two cases: whether the newly added area crosses the physical partition boundary on the device plan.
[0046] When determining that a new area crosses the physical partition boundary on the device plan, the new area is divided into sub-areas within each physical partition using the physical partition boundary as the dividing line. Each sub-area is then merged with the common coverage area within the same physical partition, and the segment boundaries of the target strategy logical coverage boundary are marked separately for each physical partition.
[0047] When it is determined that the newly added area does not cross the physical partition boundary on the equipment plan, the outer contour boundary of the newly added area and the shared coverage area is directly determined as the target strategy logical coverage boundary.
[0048] It should be noted that the handling method for adding a new area that crosses the physical partition boundary is logically consistent with the handling method for leaving a region that crosses the physical partition boundary: the new area is split into segments with the physical partition boundary as the dividing line, and the segment boundaries of the target policy logical coverage boundary are marked separately for each physical partition. This ensures that the expansion range of the target policy is presented independently for each physical partition on the device plan, so that maintenance personnel can confirm whether the new protection range meets expectations by physical partition before executing the change, avoiding errors in partition ownership judgment caused by overlapping markings across partition boundaries.
[0049] When the newly added protected subset is determined to be an empty set, the policy change does not involve the expansion of the protection scope, and the outer contour boundary of the common coverage area is determined as the target policy logical coverage boundary.
[0050] It should be noted that step A2 extracts the exited protection subset and the newly added protection subset separately from the set operation result, and determines the initial policy logical coverage boundary and the target policy logical coverage boundary separately by combining them with the common coverage subset. This solves the problem that maintenance personnel cannot perceive the difference between the old and new policy coverage sets from the equipment plan before policy changes. On this basis, for the case where the exited area and the newly added area cross the physical partition boundary, the segment boundary is marked separately for each partition, so that the marking of the logical coverage boundary is aligned with the security domain boundary. This provides a spatial basis for the determination of the physical partition ownership of the deviation area and the assessment of the impact level of the execution confirmation command in step S4.
[0051] Step A3: Take the common coverage subset determined in step A1, the exit protection subset determined in step A2, and the new protection subset as multiple device subsets, and mark the multiple device subsets at the corresponding device locations on the device plan output in step S1.
[0052] Preferably, in step S2, when marking multiple device subsets on the device floor plan, different visual identifiers are used to distinguish common coverage subsets, excluded protection subsets, and newly added protection subsets. This allows maintenance personnel to simultaneously see the distribution locations of the three types of device subsets, the initial policy logical coverage boundary and the target policy logical coverage boundary, as well as the spatial relationship between the three types of subsets and the security domain boundary on the device floor plan. This enables them to form a complete spatial understanding of the changes in protection scope involved in the policy change before executing the change, reducing the risk of policy execution deviation due to insufficient coverage perception.
[0053] S3. Based on the set of devices covered by the target strategy, determine the predicted logical coverage boundary, write the target strategy rules one by one, and after each target strategy rule is written, retain the displacement state of the logical coverage boundary on the device plan as a trajectory recording node.
[0054] It should be noted that the execution process of security policy changes consists of writing multiple target policy rules one by one. After each rule is written, the scope of protected devices is adjusted accordingly, and the logical coverage boundary changes positionally on the device plan. If the execution result is only verified after all rules have been written, the operation and maintenance personnel cannot know which rule caused the logical coverage boundary to deviate from the expectation, nor can they detect rule configuration anomalies in a timely manner during the execution process. Step S3 determines the predicted logical coverage boundary as a reference before writing the rules. During the rule writing process, the boundary displacement status is recorded with trajectory recording nodes, so that every positional change of the logical coverage boundary during the change execution process can be traced back to the specific target policy rule that triggered the change. This provides a complete process basis for tracing the deviation between the actual logical coverage boundary and the predicted logical coverage boundary in step S4.
[0055] In some embodiments, step S3 includes steps S31 and S32: Step S31: Determine the predicted logical coverage boundary based on the set of devices covered by the target strategy.
[0056] In some embodiments, step S31 includes steps S311 and S312: Step S311: When it is determined that the set of devices covered by the target strategy is an empty set, the predicted logical coverage boundary is marked as an empty boundary.
[0057] Step S312: When it is determined that the set of devices covered by the target strategy is not an empty set, the device positions corresponding to all devices in the set of devices covered by the target strategy on the device plan are determined as the target coverage area, and the outer contour boundaries of each continuous sub-region in the target coverage area on the device plan are determined as the pre-judgment logical coverage boundary.
[0058] It should be noted that the devices in the target policy's covered device set may not be distributed continuously on the device plan. For example, when the target policy simultaneously covers a server cluster in the DMZ and a database cluster in the core area, the two clusters form two spatially independent target coverage areas on the device plan. If the entire target coverage area is represented by a single outer contour boundary, the blank area between the two independent areas will be incorrectly included in the predicted logical coverage range. By determining the outer contour boundary for each continuous sub-region, the predicted logical coverage boundary on the device plan is composed of several independent contour segments, strictly corresponding to the actual spatial distribution of the device set covered by the target policy. This ensures that the superposition comparison result of the predicted logical coverage boundary and the actual logical coverage boundary in step S4 accurately reflects the true coverage deviation.
[0059] It should be noted that the predicted logical coverage boundary is marked before the rule writing begins in step S32 and continuously displayed as a fixed reference on the equipment floor plan. During the rule writing process, maintenance personnel can visually compare the positional relationship between the current logical coverage boundary and the predicted logical coverage boundary at any time. Once the current logical coverage boundary deviates from the predicted logical coverage boundary, the anomaly can be detected immediately without having to wait until all rules are written to notice the deviation.
[0060] Step 32: Write the target strategy rules one by one. After each target strategy rule is written, retain the displacement state of the logical coverage boundary on the device plan as a trajectory recording node.
[0061] In some embodiments, step S32 includes steps S321 and S322: Step S321: Compare the coverage area of the target policy rule with the logical coverage boundary to determine all local change areas where the logical coverage boundary changes position after the target policy rule is written. Associate the boundary positions of all local change areas with the target policy rule as trajectory recording nodes.
[0062] It's easy to understand that after a target policy rule is written, the logical coverage boundary may change at one or more local locations on the device plan. For example, after a rule that simultaneously covers two independent device clusters is written, the boundaries of the areas where both clusters are located may shift, forming two locally changed regions. The boundary positions of all locally changed regions are associated with the target policy rule that triggered the change, ensuring that each trajectory recording node carries both boundary position information and rule source information. This allows the trajectory recording node corresponding to the deviation area in step S4 to directly locate the specific target policy rule that caused the deviation.
[0063] In some embodiments, step S321, which associates the boundary positions of all locally changing regions with the target policy rules as trajectory recording nodes, includes steps B1 and B2: Step B1: For each local change area, when determining the physical partition boundary on the device plan view, the local change area is divided into corresponding partition change areas according to the physical partition it belongs to. The boundary position of each partition change area is associated with the target strategy rule and the corresponding physical partition, and used as trajectory recording nodes.
[0064] Specifically, step B1, which associates the boundary positions of each partition's changing region with the target policy rule and the corresponding physical partition as trajectory recording nodes, includes steps B11 to B13: Step B11: When the partition change area is determined to be a physical partition between the DMZ and the intranet area, the trajectory recording node corresponding to the partition change area is marked as a high-interest node.
[0065] Step B12: When the partition change area is determined to be a physical partition between the intranet area and the core area, the trajectory recording node corresponding to the partition change area is marked as the second most important node.
[0066] Step B13: When it is determined that the partition change area is located in another physical partition, mark the trajectory recording node corresponding to the partition change area as a normal node of interest.
[0067] It should be noted that the level of concern classification in steps B11 to B13 is determined based on the differences in the security isolation functions between physical partitions in the data center network architecture. The DMZ zone receives access requests from the external network, while the intranet zone deploys internal business systems. The physical partition between the DMZ zone and the intranet zone is the first line of defense against unauthorized external access to the internal network. A change in the logical coverage boundary in this area signifies a shift in the protection boundary between external access and the internal network, having the most direct impact on the overall security isolation of the data center. The corresponding trajectory recording node is marked as a high-concern node. The physical partition between the intranet zone and the core zone isolates ordinary business access from core data assets. Changes in the boundary of this area directly affect the protection scope of core data assets, and the corresponding trajectory recording node is marked as a second-highest-concern node. Changes in the boundaries between other physical partitions involve security isolation levels other than the above two categories, and the corresponding trajectory recording nodes are marked as ordinary-concern nodes. Since the concern level is pre-marked on the trajectory recording nodes, when determining the impact level of the physical partition where the deviation area is located in step S4, the concern level can be directly read from the trajectory recording node, without needing to re-determine the security isolation attributes of the physical partition in step S4.
[0068] Step B2: For each local change area, when it is determined that the local change area does not cover the physical partition boundary on the device plan, the boundary position of the local change area is associated with the target policy rule and the physical partition it belongs to, and used as a trajectory recording node.
[0069] It should be noted that steps B1 and B2 fully cover all scenarios where the local change region crosses the physical partition boundary. When the local change region crosses the physical partition boundary, it means that a single rule write simultaneously affects the logical coverage range within multiple physical partitions. If the cross-partition local change region is recorded as a whole in a single trajectory recording node, this node cannot distinguish which physical partition the boundary change occurred in. Therefore, when associating the deviation region with the physical partition in step S4, the partition attribution information cannot be directly obtained from this node. By splitting the local change region into partition change regions within each physical partition using the physical partition boundary as the dividing line, and recording each partition change region as an independent trajectory recording node associated with its corresponding physical partition, it is ensured that each trajectory recording node corresponds to a unique physical partition. The partition attribution of the deviation region in step S4 can be directly read from the trajectory recording node without needing to re-split the cross-partition node in step S4.
[0070] In other embodiments, step S321, which associates the boundary positions of all locally changed regions with the target policy rules as trajectory recording nodes, further includes steps C1 and C2: Step C1: When the boundary position of the local change area exceeds the boundary range of all physical partitions on the device plan, mark the trajectory recording node corresponding to the local change area as an abnormal node, pause the writing of the target policy rule, mark the target policy rule as an abnormal rule, and output an abnormal prompt command.
[0071] Step C2: When the boundary position of the local change area does not exceed the boundary range of all physical partitions on the device plan, the boundary position of the local change area is associated with the target strategy rule and used as a trajectory recording node.
[0072] It should be noted that the boundary range of all physical partitions on the device floor plan constitutes the complete spatial range to which actual devices belong in the data center. Changes in the position of the logical coverage boundary should not exceed this range at the physical level. If the boundary position of a locally changed area exceeds the boundary range of all physical partitions, it indicates that the coverage of the target policy rule points to an area on the device floor plan to which no actual device belongs, which is an abnormal state caused by a rule configuration error. If writing is not immediately paused upon detecting the anomaly, subsequent target policy rules will continue to be written based on the abnormal logical coverage boundary, and the logical coverage boundary will continue to shift outside the physical partition range. The final position of the actual logical coverage boundary in step S4 will completely deviate from the valid physical partition range, causing the partition ownership determination of the deviation area to lose its basis. Step C1 immediately pauses the writing of the target policy rule upon detecting the anomaly, marks the target policy rule that triggered the anomaly as an abnormal rule, and outputs an anomaly prompt command, enabling maintenance personnel to intervene before the anomaly spreads, limiting the impact of the rule configuration error to the boundary position corresponding to the abnormal node.
[0073] Step S322: If the logical coverage boundary does not change position after the target strategy rule is written, retain the current position state of the logical coverage boundary as a trajectory recording node.
[0074] It should be noted that the lack of positional change in the logical coverage boundary may be due to overlap between the target policy rule and already written rules, or the target policy rule not actually taking effect. Regardless of the situation, the current positional state of the logical coverage boundary is retained as the trajectory recording node, ensuring that all target policy rules have corresponding records in the trajectory recording node sequence. In step S4, when all trajectory recording nodes are arranged in the order of writing to form the boundary movement trajectory, the node sequence corresponds one-to-one with the writing order of the target policy rules, preventing node loss due to a rule not triggering boundary displacement, thus ensuring the integrity of the boundary movement trajectory.
[0075] It should be noted that step S32, by retaining trajectory recording nodes after each target strategy rule is written, associates the writing process of each target strategy rule with each displacement change of the logical coverage boundary on the device plan view, forming a boundary movement trajectory that can be traced back according to the rules during execution. Each trajectory recording node simultaneously carries boundary position information, trigger rule information, physical partition attribution information, and attention level labeling. This allows the final state determination of the actual logical coverage boundary, the partition attribution judgment of the deviation area, and the impact level assessment of the execution confirmation command in step S4 to directly read the required information from the trajectory recording node, eliminating the need to repeatedly perform partition splitting and level judgment in step S4. This effectively transmits the boundary change information accumulated during execution to the confirmation stage of step S4.
[0076] Preferably, step S3 dynamically presents the displacement process of the logical coverage boundary on the device plan view as each target policy rule is written. The predicted logical coverage boundary remains normally displayed on the device plan view, and the position status of the current logical coverage boundary after each target policy rule is written is superimposed and marked on the device plan view in the form of trajectory record nodes. Maintenance personnel can compare the positional relationship between the predicted and current logical coverage boundaries at any time during the rule writing process. Once the current logical coverage boundary deviates from the predicted logical coverage boundary, the target policy rule triggering the deviation can be immediately located, thus advancing the discovery of policy execution deviations from after all rules have been written to during the rule writing process itself.
[0077] S4 determines the final position of all trajectory recording nodes as the actual logical coverage boundary, overlays the predicted logical coverage boundary with the actual logical coverage boundary and marks the deviation area, and outputs the execution confirmation command according to the physical partition where the deviation area is located.
[0078] It should be noted that after step S3 completes the writing of all target policy rules, the boundary movement trajectory accumulates the logical coverage boundary displacement state after each target policy rule is written. Step S4 uses the final position of the boundary movement trajectory as the actual logical coverage boundary, and compares it with the predicted logical coverage boundary determined in step S31 on the device plan. Device areas with positional differences between the two are marked as deviation areas. Then, combined with the physical partition affiliation information and attention level markings already carried by each trajectory recording node in step S3, the security isolation attributes of the physical partition where the deviation area is located are judged, and the execution confirmation command with the corresponding impact level is output. The entire step S4 shifts the verification of the execution result from rule text comparison to spatial position comparison on the device plan. Operation and maintenance personnel can directly confirm on the device plan whether the security policy change has been correctly implemented, and the degree of impact of the execution deviation on the security isolation of each physical partition of the data center.
[0079] In some embodiments, step S4 includes steps S41 to S43: Step S41: Determine the final state position of all trajectory recording nodes as the actual logical coverage boundary.
[0080] Step S41 includes steps S411 to S413: Step S411: Arrange all trajectory recording nodes in the writing order to form the boundary movement trajectory.
[0081] In step S3, after each target policy rule is written, a corresponding trajectory recording node is retained. These trajectory recording nodes are arranged sequentially according to the writing order of the target policy rules, forming a complete boundary movement trajectory from the start to the end of the change. The trajectory recording node at the end of the boundary movement trajectory corresponds to the final landing point of the logical coverage boundary after all target policy rules are written, which is the final state position of the boundary movement trajectory. Steps S412 and S413 determine the actual logical coverage boundary based on the final state position.
[0082] In step S3, after each target policy rule is written, a corresponding trajectory recording node is retained. The trajectory recording nodes are arranged in the writing order of the target policy rules to form a complete boundary movement trajectory from the start of the change to the end of the change. The node sequence in the boundary movement trajectory corresponds one-to-one with the writing order of the target policy rules.
[0083] Step S412: When it is determined that there is an abnormal node in the boundary movement trajectory, the position state of the node recorded in the preceding trajectory of the abnormal node is used as the final position of the boundary movement trajectory, and it is determined as the actual logical coverage boundary.
[0084] It should be noted that in step S3, when step C1 detects that the boundary position of the local change area exceeds the boundary range of all physical partitions, the target policy rule that triggers the anomaly is marked as an abnormal rule and subsequent writing is paused. The boundary position corresponding to the abnormal node has exceeded the effective physical partition range and does not represent the protection status of any actual device in the data center. If the position state of the abnormal node is taken as the final state, the actual logical coverage boundary will fall outside the physical partition range, and the superposition comparison between the predicted logical coverage boundary and the actual logical coverage boundary in step S42 will lose a valid spatial reference. By taking the position state of the preceding trajectory record node of the abnormal node as the final state, that is, taking the last effective logical coverage boundary position before the abnormal target policy rule is written as the actual logical coverage boundary, it is ensured that the actual logical coverage boundary always falls within the effective physical partition range. The superposition comparison result in step S42 can accurately reflect the actual coverage of the target policy rule within the effective execution range.
[0085] Step S413: When it is determined that there are no abnormal nodes in the boundary movement trajectory, the final position of the boundary movement trajectory is determined as the actual logical coverage boundary.
[0086] It should be noted that step S41 transforms the final position of the boundary movement trajectory into an actual logical coverage boundary that can be directly displayed on the device plan view. This allows the actual coverage area after all target policy rules have been written to be expressed as a spatial boundary on the device plan view. Compared to checking the effectiveness of each rule in the execution log, the actual logical coverage boundary directly reflects the overall execution result of the target policy rules on the device plan view, providing a clear spatial location basis for the superposition and comparison with the predicted logical coverage boundary in step S42.
[0087] Step S42: Overlay the predicted logic coverage boundary with the actual logic coverage boundary and mark the deviation area.
[0088] Step S42 includes steps S421 and S422: Step S421: Overlay the predicted logical coverage boundary and the actual logical coverage boundary on the device plan. When the predicted logical coverage boundary and the actual logical coverage boundary are completely coincident, it means that the actual execution result of all target policy rules is completely consistent with the prediction made based on the device set covered by the target policy before the change. No deviation area is generated, and the execution confirmation command is directly output.
[0089] Step S422: When it is determined that there are devices whose boundary positions do not coincide with the predicted logical coverage boundary and the actual logical coverage boundary, it indicates that there is a difference in the protection status of some devices between the prediction and the actual execution. The area corresponding to the device whose boundary position does not coincide is marked as the deviation area on the device plan.
[0090] It should be noted that there are two opposite scenarios when the boundary locations do not coincide: If the device is predicted to be covered by the logical coverage boundary but is actually not, it means that the device that the target policy expected to protect was not included in the protection scope after actual execution, and the device is in a state of expected protection gap; if the device is actually covered by the logical coverage boundary but is not predicted to be covered, it means that the device that the target policy did not expect to cover was included in the protection scope after actual execution, and the device is in a state of unexpected expansion of protection. Both scenarios indicate that the actual execution result deviates from the expected range defined by the set of devices covered by the target policy, and both need to be marked as deviation areas. Maintenance personnel should determine whether intervention is needed based on the impact level of the execution confirmation command output in step S43, to avoid security risks caused by focusing only on the direction of the protection gap and ignoring deviations in the direction of unexpected expansion.
[0091] Step S422 marks the area corresponding to the equipment on the equipment plan as the deviation area, including steps D1 and D2: Step D1: When determining the boundaries of adjacent physical partitions on the plan view of the deviation area, the deviation area is divided into corresponding sub-deviation areas according to each physical partition. Each sub-deviation area is associated with its corresponding physical partition, which is the partition association result of the deviation area.
[0092] It should be noted that when the deviation area crosses the boundary of adjacent physical partitions, the devices within the deviation area belong to different physical partitions, and the security isolation attributes of different physical partitions are different. If the entire deviation area that crosses partitions is directly used to determine the impact level in step S43, step S43 cannot distinguish the differences in the attention levels of the physical partitions where the devices within the deviation area are located, resulting in the impact level assessment result not accurately corresponding to the actual physical partition where the deviation is located. The deviation area is divided into sub-deviation areas within each physical partition using the physical partition boundary as the dividing line. Each sub-deviation area is associated with its corresponding physical partition. In step S43, the attention level of each sub-deviation area is determined independently to ensure that the impact level of executing the confirmation command strictly corresponds to the security isolation attribute of the physical partition where the deviation is located.
[0093] Step D2: When it is determined that the deviation area does not cover the boundary of the adjacent physical partition on the equipment plan, all equipment with non-overlapping boundary positions in the deviation area are located in the same physical partition. The deviation area is associated with the physical partition it belongs to, which is the partition association result of the deviation area.
[0094] It is easy to understand that if the deviation area does not cross the boundary of an adjacent physical partition, it means that there is no ambiguity in the physical partition affiliation of the devices within the deviation area. Therefore, the unique physical partition corresponding to the deviation area can be directly determined without splitting it. The deviation area as a whole is associated with its corresponding physical partition. In step S43, when filtering the trajectory recording nodes within the corresponding physical partition from all trajectory recording nodes using the partition association result of the deviation area as an index, the partition association result can be read directly without further spatial processing of the deviation area. This ensures that steps D1 and D2 provide consistent partition association results to step S43 in both cases where the deviation area crosses or does not cross the boundary of an adjacent physical partition, maintaining consistency in the impact level judgment process of step S43 for both scenarios.
[0095] It should be noted that step S42 overlays the predicted logical coverage boundary and the actual logical coverage boundary on the device plan view. The operation and maintenance personnel can directly observe the spatial difference between the predicted coverage range and the actual coverage range from the device plan view. The deviation area is presented intuitively in the form of annotation on the device plan view, so that the operation and maintenance personnel can confirm whether the execution result meets the expectations without comparing the policy rule text line by line.
[0096] Based on this, steps D1 and D2 complete the partition association of the deviation area, providing a clear partition classification basis for evaluating the impact level of the execution confirmation instruction according to physical partition in step S43, and transforming the confirmation of the execution result from a qualitative judgment into a structured conclusion that can be independently verified by physical partition. Step S43 outputs the execution confirmation instruction according to the physical partition where the deviation area is located.
[0097] Step S43 includes steps S431 to S434: Step S431: Determine the trajectory recording node corresponding to the partition change area within the physical partition where the deviation area is located from all trajectory recording nodes.
[0098] It is easy to understand that in step S3, step B1 has already associated the boundary positions of each partition change area with the corresponding physical partition and recorded them as trajectory recording nodes, and marked the level of concern according to the security isolation attribute of the physical partition where the partition change area is located. Step S431 uses the partition association result of the deviation area as an index to filter the trajectory recording nodes corresponding to the physical partition where the deviation area is located from all trajectory recording nodes. Subsequent steps S432 to S434 directly read the level of concern markings in the filtering results, without needing to re-determine the security isolation attribute of the physical partition.
[0099] In step S432, when it is determined that there is a high-concern node within the physical partition where the deviation area is located, the confirmation instruction will be marked as a high-impact confirmation instruction.
[0100] When it is determined that there are high-concern nodes within the physical partition where the deviation area is located, it indicates that the physical partition where the deviation area is located covers the isolation position between the DMZ area and the internal network area. The boundary changes within this physical partition directly affect the isolation barrier for external access to the internal network, and the confirmation command will be marked as a high-impact confirmation command.
[0101] Step S433: If it is determined that there are no high-concern nodes but there are second-highest-concern nodes in the physical partition where the deviation area is located, it means that the physical partition where the deviation area is located covers the isolation position between the intranet area and the core area. The boundary change in this physical partition involves the protection scope of core data assets, and the execution confirmation instruction will be marked as the second-highest impact confirmation instruction.
[0102] Step S434: If it is determined that there are only ordinary nodes of concern within the physical partition where the deviation area is located, it means that the security isolation level involved in the boundary change within the physical partition where the deviation area is located is outside of the high concern and second highest concern levels. The confirmation instruction will be marked as an ordinary impact confirmation instruction.
[0103] It should be noted that step S432 prioritizes the presence of a high-priority node within the physical partition containing the deviation area, step S433 prioritizes the presence of a second-highest-priority node but no high-priority node, and step S434 prioritizes the presence of only ordinary-priority nodes. These three branches are logically mutually exclusive and comprehensively cover all scenarios. When both a high-priority node and a second-highest-priority node exist within the physical partition containing the deviation area, the case falls under the high-impact confirmation instruction branch of step S432. The reason for prioritizing the presence of a high-priority node is that it corresponds to a boundary change within the physical partition between the DMZ and the intranet. If the security isolation barrier at this location experiences a coverage deviation, the isolation layer for external access to the internal network will be directly affected. The scope and urgency of the security isolation impact are higher than those of the isolation location between the intranet and core areas corresponding to the second-highest-priority node. Using the highest level of concern as the criterion for executing the confirmation instruction ensures that the most severe security isolation impact within the deviation area is not downgraded due to the presence of a second-highest-priority node.
[0104] Preferably, step S4 simultaneously displays the predicted logical coverage boundary, the actual logical coverage boundary, and the deviation area on the equipment floor plan. The deviation area is distinguished by different visual identifiers according to high impact, second-highest impact, and ordinary impact. Maintenance personnel can obtain a one-time comparison of the spatial location of the execution result and the predicted result, the physical partitioning of the deviation area, and the corresponding impact level on the equipment floor plan. This allows for visualized confirmation of the entire process of security policy changes before, during, and after execution, solving the problem of maintenance personnel lacking effective evidence to confirm whether security policies are correctly implemented throughout the automated execution process.
[0105] See Figure 3 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application. The electronic device 40 includes: a processor 41, a memory 42, and a computer program; wherein, The memory 42 is used to store computer programs, and the memory may also be flash memory. Computer programs may be, for example, application programs or functional modules that implement the methods described above.
[0106] The processor 41 is used to execute the computer program stored in the memory to implement the various steps performed by the device in the above method. For details, please refer to the relevant descriptions in the preceding method embodiments.
[0107] Alternatively, the memory 42 can be either standalone or integrated with the processor 41.
[0108] When the memory 42 is a device independent of the processor 41, the device may also include: Bus 43 is used to connect memory 42 and processor 41.
[0109] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
Claims
1. A method for automating the execution of security policies, characterized in that, include: Retrieve the equipment floor plan of the data center, which shows the security domain boundaries formed by physical partitions; In response to a security policy change command, a set operation is performed on the set of devices covered by the initial policy and the set of devices covered by the target policy to generate multiple types of device subsets, and the multiple types of device subsets are marked at the corresponding device locations on the device plan. Based on the set of devices covered by the target strategy, the predicted logical coverage boundary is determined, and the target strategy rules are written one by one. After each target strategy rule is written, the displacement state of the logical coverage boundary on the device plan is retained as a trajectory recording node. The final state positions of all the trajectory recording nodes are determined as the actual logical coverage boundary. The predicted logical coverage boundary and the actual logical coverage boundary are superimposed and displayed, and the deviation area is marked. An execution confirmation command is output according to the physical partition where the deviation area is located.
2. The method according to claim 1, characterized in that, The set operation is performed on the device set covered by the initial policy and the device set covered by the target policy to generate multiple device subsets, including: The devices that are covered by both the initial policy set and the target policy set are identified as the common coverage subset. Devices covered only by the initial policy are identified as the exit protection subset, and devices covered only by the target policy are identified as the new protection subset; The common coverage subset, the exit protection subset, and the new protection subset are taken as the subset of the multiple types of devices.
3. The method according to claim 2, characterized in that, The step of determining devices covered only by the initial policy as the exit subset of protection and devices covered only by the target policy as the new subset of protection includes: When the common coverage subset is determined to be an empty set, the device location corresponding to the exited protection subset on the device plan is determined as the initial policy logic coverage boundary, and the device location corresponding to the new protection subset on the device plan is determined as the target policy logic coverage boundary. When it is determined that the common coverage subset is not an empty set, the common coverage area is determined by the equipment position corresponding to the common coverage subset on the equipment plan. When it is determined that the exit protection subset is not an empty set, the exit area is determined by the device position corresponding to the exit protection subset on the device plan view, and the outer contour boundary of the exit area and the common coverage area on the device plan view is determined as the initial strategy logic coverage boundary. When the exit protection subset is determined to be an empty set, the outer contour boundary of the common coverage area is determined as the initial strategy logical coverage boundary; When it is determined that the newly added protection subset is not an empty set, the newly added area is determined by the device position corresponding to the newly added protection subset on the device plan view, and the outer contour boundary of the newly added area and the common coverage area on the device plan view is determined as the target strategy logical coverage boundary. When the newly added protection subset is determined to be an empty set, the outer contour boundary of the common coverage area is determined as the target strategy logical coverage boundary.
4. The method according to claim 3, characterized in that, The step of determining the outer contour boundary of the exit area and the common coverage area on the device plan as the initial strategy logical coverage boundary includes: When it is determined that the exit area crosses the physical partition boundary on the device plan, the exit area is divided into sub-areas within each physical partition using the physical partition boundary as the dividing line. Each sub-area is merged with the common coverage area within the same physical partition. The segment boundary of the initial strategy logical coverage boundary is marked according to each physical partition. When it is determined that the exit area does not cross the physical partition boundary on the device plan, the outer contour boundary of the exit area and the common coverage area is determined as the initial strategy logical coverage boundary.
5. The method according to claim 3, characterized in that, The step of determining the outer contour boundary of the newly added area and the shared coverage area on the device plan as the target strategy logical coverage boundary includes: When it is determined that the newly added area crosses the physical partition boundary on the device plan, the newly added area is divided into sub-areas within each physical partition using the physical partition boundary as the dividing line. Each sub-area is merged with the common coverage area within the same physical partition. The segment boundary of the target strategy logical coverage boundary is marked according to each physical partition. When it is determined that the newly added area does not cross the physical partition boundary on the device plan, the outer contour boundary of the newly added area and the common coverage area is determined as the target strategy logical coverage boundary.
6. The method according to claim 1, characterized in that, The determination of the predicted logical coverage boundary based on the set of devices covered by the target strategy includes: When it is determined that the set of devices covered by the target strategy is an empty set, the boundary of the prediction logic coverage is marked as an empty boundary; When it is determined that the set of devices covered by the target strategy is not an empty set, the device positions corresponding to all devices in the set of devices covered by the target strategy on the device plan are determined as the target coverage area, and the outer contour boundary of each continuous sub-region in the target coverage area on the device plan is determined as the prediction logic coverage boundary. The step of retaining the displacement state of the logical coverage boundary on the device plan as a trajectory recording node after each target strategy rule is written includes: The coverage area of the target policy rule is compared with the position of the logical coverage boundary to determine all local change areas where the position of the logical coverage boundary changes after the target policy rule is written. The boundary positions of all the local change areas are associated with the target policy rule as the trajectory recording nodes. If the logical coverage boundary does not change position after the target strategy rule is written, the current position state of the logical coverage boundary is retained as the trajectory recording node.
7. The method according to claim 6, characterized in that, Associating the boundary positions of all the local change regions with the target policy rule as the trajectory recording nodes includes: For each of the local change regions, when it is determined that the local change region covers the physical partition boundary on the device plan, the local change region is split into corresponding partition change regions according to each physical partition, and the boundary position of each partition change region is associated with the target strategy rule and the corresponding physical partition, respectively, as the trajectory recording node; For each of the local change regions, when it is determined that the local change region does not cover the physical partition boundary on the device plan, the boundary position of the local change region is associated with the target policy rule and the physical partition in which it is located, and is used as the trajectory recording node.
8. The method according to claim 7, characterized in that, The step of associating the boundary positions of each of the partition change regions with the target policy rule and the corresponding physical partition, respectively, as the trajectory recording nodes, includes: When the partition change area is determined to be a physical partition between the DMZ and the intranet, the trajectory recording node corresponding to the partition change area is marked as a high-interest node; When the partition change area is determined to be a physical partition between the intranet area and the core area, the trajectory recording node corresponding to the partition change area is marked as the second most important node. When it is determined that the partition change area is located in another physical partition, the trajectory recording node corresponding to the partition change area is marked as a normal attention node.
9. The method according to claim 6, characterized in that, Associating the boundary positions of all the local change regions with the target policy rule as the trajectory recording nodes further includes: When the boundary position of the local change area exceeds the boundary range of all physical partitions on the device plan, the trajectory recording node corresponding to the local change area is marked as an abnormal node, the writing of the target policy rule is paused, the target policy rule is marked as an abnormal rule and an abnormal prompt instruction is output. When it is determined that the boundary position of the local change region does not exceed the boundary range of all physical partitions on the device plan, the boundary position of the local change region is associated with the target strategy rule and used as the trajectory recording node.
10. The method according to claim 9, characterized in that, Determining the final state position of all the trajectory recording nodes as the actual logical coverage boundary includes: Arrange all the trajectory recording nodes in the writing order to form a boundary movement trajectory; When it is determined that there is an abnormal node in the boundary movement trajectory, the position state of the preceding trajectory record node of the abnormal node is used as the final position of the boundary movement trajectory, and is determined as the actual logical coverage boundary. When it is determined that there are no abnormal nodes in the boundary movement trajectory, the final position of the boundary movement trajectory is determined as the actual logical coverage boundary.
11. The method according to claim 1, characterized in that, The step of overlaying and displaying the predicted logic coverage boundary and the actual logic coverage boundary and marking the deviation area includes: The predicted logic coverage boundary and the actual logic coverage boundary are superimposed on the device plan view. When the predicted logic coverage boundary and the actual logic coverage boundary completely coincide, no deviation area is generated, and an execution confirmation command is output. When it is determined that there is a device whose boundary position does not coincide with the actual logical coverage boundary, the area corresponding to the device on the device plan is marked as the deviation area.
12. The method according to claim 11, characterized in that, The step of marking the area corresponding to the device on the device plan as the deviation area includes: When it is determined that the deviation region covers the boundary of adjacent physical partitions on the equipment plan, the deviation region is divided into corresponding sub-deviation regions according to each physical partition, and each sub-deviation region is associated with the corresponding physical partition as the partition association result of the deviation region. When it is determined that the deviation area does not cover the boundary of the adjacent physical partition on the device plan, the deviation area is associated with the physical partition in which it is located, and this association is taken as the partition association result of the deviation area.
13. The method according to claim 8, characterized in that, The step of outputting an execution confirmation command based on the physical partition where the deviation region is located includes: From all the trajectory recording nodes, determine the trajectory recording node corresponding to the partition change region within the physical partition where the deviation region is located; When it is determined that there is a high-interest node within the physical partition where the deviation area is located, the execution confirmation instruction is marked as a high-impact confirmation instruction; When it is determined that there are no high-interest nodes but there are second-highest-interest nodes within the physical partition where the deviation area is located, the execution confirmation instruction is marked as the second-highest-impact confirmation instruction; When it is determined that only ordinary nodes of interest exist within the physical partition where the deviation area is located, the execution confirmation instruction is marked as an ordinary impact confirmation instruction.