White list policy generation method, electronic device, and storage medium

By integrating predefined and deep learning models to generate whitelist policies, the problem of low accuracy in static rule configuration of industrial firewalls is solved, and efficient whitelist policy generation and operation and maintenance support in dynamic network scenarios are achieved.

CN122640221APending Publication Date: 2026-08-25DAWNING NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610921042.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-24
Publication Date
2026-08-25

AI Technical Summary

Technical Problem

Existing industrial firewall control policies are based on static rules, which are difficult to meet the actual needs of dynamic security protection, resulting in configuration errors and low configuration accuracy.

Method used

A whitelist strategy generation method is adopted, which dynamically updates the configuration items of the whitelist template by integrating predefined whitelist templates and configuration items determined by deep learning models. By utilizing the mapping relationship between industrial protocol types and whitelist template identifiers, the whitelist template can be quickly located, thereby realizing whitelist strategy generation in dynamic network scenarios.

Benefits of technology

It improves the accuracy and adaptability of whitelist configuration items, reduces manual configuration errors, enhances the accuracy and deployment efficiency of whitelist policies, and supports real-time monitoring and policy adjustment by operations and maintenance personnel.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122640221A_ABST
    Figure CN122640221A_ABST
Patent Text Reader

Abstract

The application provides a white list strategy generation method, an electronic device and a storage medium, and relates to the technical field of network security. The method comprises the following steps: in response to receiving a message, analyzing the message according to a message analysis rule to obtain a plurality of target message information, wherein the target message information comprises an industrial protocol type; in the case that the plurality of target message information and a plurality of predefined message information are matched, obtaining a target white list template related to the message based on a mapping relationship between the industrial protocol type and a white list template identifier, wherein the configuration items of the target white list template are determined by fusing the configuration items in the predefined white list template and the configuration items determined based on a deep learning model; and in the case that the target white list template is in a learning mode, determining the configuration items of the target white list template by using the protocol operation information obtained by analyzing the message to obtain a white list strategy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and more specifically, to a method for generating a whitelist policy, an electronic device, and a storage medium. Background Technology

[0002] Industrial firewalls, deployed within industrial control systems, block unauthorized commands and intercept non-controller protocols, thereby protecting critical infrastructure from cyberattacks. Current industrial firewall control strategies rely on static rules for endpoint protection. However, as attack techniques become increasingly diverse and sophisticated, static rules are insufficient to meet the practical needs of dynamic security protection. Summary of the Invention

[0003] In view of this, this application provides a method for generating a whitelist policy, an electronic device, and a storage medium.

[0004] One aspect of this application provides a method for generating a whitelist policy, comprising: in response to receiving a message, parsing the message according to message parsing rules to obtain multiple target message information, the target message information including industrial protocol types; when multiple target message information matches multiple predefined message information, obtaining a target whitelist template related to the message based on the mapping relationship between industrial protocol types and whitelist template identifiers, wherein the configuration items of the target whitelist template are determined by fusing configuration items in predefined whitelist templates and configuration items determined based on a deep learning model; when the target whitelist template is in learning mode, determining the configuration items of the target whitelist template using protocol operation information obtained from parsing the message to obtain a whitelist policy.

[0005] According to embodiments of this application, in response to a received message, the message is parsed according to message parsing rules to obtain multiple target message information. This allows for the identification of the message's service type, communication direction, and industrial protocol type, providing a data foundation for subsequent message information matching. When multiple target message information matches multiple predefined message information, a target whitelist template related to the message is obtained based on the mapping relationship between industrial protocol types and whitelist template identifiers. The configuration items of this target whitelist template are determined by fusing configuration items from predefined whitelist templates and configuration items determined based on a deep learning model. This avoids configuration errors and low accuracy due to reliance on manual configuration, thereby improving the accuracy of whitelist configuration items. When the target whitelist template is in learning mode, the configuration items of the target whitelist template are determined using protocol operation information obtained from parsing the message, resulting in a whitelist policy. This allows for the learning of more comprehensive configuration items in dynamic network scenarios, thereby improving the accuracy and adaptability of the whitelist policy.

[0006] According to an embodiment of this application, obtaining a target whitelist template related to a message based on the mapping relationship between industrial protocol types and whitelist template identifiers includes: determining a target whitelist template identifier corresponding to a message based on the mapping relationship between industrial protocol types and whitelist template identifiers; and obtaining a target whitelist template related to the message based on the target whitelist template identifier.

[0007] According to the embodiments of this application, the whitelist template corresponding to the message can be quickly located by mapping the industrial protocol type to the whitelist template identifier, avoiding traversing all whitelist templates and improving matching efficiency and response speed.

[0008] According to an embodiment of this application, the configuration items of the target whitelist template are determined by parsing the protocol operation information obtained from the parsed message, and a whitelist policy is obtained. The process includes: parsing the message to obtain the protocol operation information of the message; determining the learning duration threshold of the learning mode; and determining the configuration items of the target whitelist template based on the learning duration threshold and the protocol operation information of the message, thereby obtaining a whitelist policy.

[0009] According to the embodiments of this application, the configuration items of the whitelist template are dynamically updated by parsing the protocol operation information obtained from the message protocol, so as to realize the configuration items of the whitelist template corresponding to different industrial protocols, thereby improving the matching accuracy at the protocol granularity.

[0010] According to an embodiment of this application, based on a learning duration threshold, the configuration items of the target whitelist template are determined using the protocol operation information of the message to obtain a whitelist policy, including: in response to a mode start command for the target whitelist template being in learning mode, if the configuration items of the target whitelist template are empty, adding the protocol operation information of the message as a new configuration item to the target whitelist template; if the configuration items of the target whitelist template contain predefined configuration content, updating the predefined configuration content using the protocol operation information of the message; and generating a whitelist policy based on the configured target whitelist template when the learning duration of the learning mode reaches the learning duration threshold.

[0011] According to the embodiments of this application, by adopting a learning mode to dynamically fill or update the whitelist template configuration items, and automatically generating the whitelist policy after the learning time reaches a threshold, the administrator does not need to have an in-depth understanding of the content of various industrial protocols, and does not need to manually intervene in configuring the whitelist, thus avoiding configuration errors caused by manual configuration. This enables the whitelist policy to be dynamically constructed to adapt to actual packet traffic, thereby improving the efficiency and accuracy of whitelist deployment.

[0012] According to an embodiment of this application, the method further includes: extracting structured fields from historical messages to obtain a set of structured fields, the set of structured fields including multiple structured fields, each structured field representing a configuration item; determining the matching granularity of each structured field in the set of structured fields in the whitelist template; obtaining the matching granularity of each configuration item in the predefined whitelist template; fusing the matching granularity of each structured field in the set of structured fields in the whitelist template with the matching granularity of each configuration item in the predefined whitelist template, and using the fused configuration items as configuration items of the target whitelist.

[0013] According to the embodiments of this application, by fusing the matching granularity of the structured fields obtained by parsing historical messages as configuration items in the whitelist template with the matching granularity of configuration items based on the predefined whitelist template, it is possible to avoid the matching granularity of each configuration item being too coarse or too fine due to manual templates, and to prevent noise in each configuration item determined by the deep learning model. The two complement each other and work together to improve the granularity accuracy of configuration items in the whitelist template, thereby improving the accuracy of the whitelist strategy.

[0014] According to an embodiment of this application, the method further includes: generating log information with the topic of learning mode, and forwarding the message to the target receiver indicated by the target receiver address carried in the message.

[0015] According to the embodiments of this application, by generating log information when the target whitelist template is in learning mode, the whitelist policy generation process can be visualized, enabling operation and maintenance personnel to grasp the stage of self-learning in real time through log information. When false alarms or missed alarms occur in the whitelist policy, the granularity selection basis of a specific field within a certain learning cycle can be directly located when tracing back the problem, thereby reducing the backtracking overhead of false alarms and missed alarms.

[0016] According to an embodiment of this application, the method further includes: when the target whitelist template is in alarm mode, determining whether the protocol operation information obtained by parsing the message matches the whitelist policy; when it is determined that the protocol operation information does not match the whitelist policy, generating log information with an alarm mode as the topic, and forwarding the message to the target receiver indicated by the target receiver address carried in the message.

[0017] According to the embodiments of this application, by generating log information in alarm mode, abnormal events and their triggered whitelist policies can be marked in real time, distinguishing whether the received packets are normal traffic or attack behavior, while also providing accurate event tracing for operation and maintenance personnel and supporting rapid location of policy defects.

[0018] According to an embodiment of this application, the method further includes: when the target whitelist template is in protection mode, determining whether the protocol operation information obtained by parsing the message matches the whitelist policy; when it is determined that the protocol operation information does not match the whitelist policy, generating log information with the topic of protection mode, and performing an interception operation on the message.

[0019] According to the embodiments of this application, by generating log information in protection mode, it is possible to record the actions of intercepting or allowing packets, matching strategies and handling results in real time, providing operation and maintenance personnel with visual monitoring of protection status. In addition, log information can be used for subsequent security audits and attack tracing, which helps to dynamically adjust the granularity of whitelist policy configuration items and improve industrial control security protection.

[0020] Another aspect of this application provides an electronic device comprising:

[0021] One or more processors;

[0022] Memory, used to store one or more programs.

[0023] Specifically, when one or more programs are executed by one or more processors, the one or more processors implement the methods described above.

[0024] Another aspect of this application provides a computer-readable storage medium storing computer-executable instructions that, when executed, are used to implement the method described above.

[0025] Another aspect of this application provides a computer program product including computer-executable instructions that, when executed, implement the method described above. Attached Figure Description

[0026] The above and other objects, features and advantages of this application will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:

[0027] Figure 1 An exemplary system architecture is shown, comprising a method for generating a whitelist strategy, an electronic device, and a storage medium to which a whitelist strategy can be applied, according to embodiments of this application.

[0028] Figure 2 A flowchart illustrating a method for generating a whitelist policy according to an embodiment of this application is shown;

[0029] Figure 3 A schematic diagram of a method for generating a whitelist policy according to an embodiment of this application is shown;

[0030] Figure 4 A schematic diagram of the system architecture of a method for generating a whitelist policy according to an embodiment of this application is shown;

[0031] Figure 5 A block diagram of a whitelist policy generation apparatus according to an embodiment of this application is shown; and

[0032] Figure 6 A block diagram of an electronic device suitable for implementing the whitelist policy generation method described above, according to an embodiment of this application, is shown. Detailed Implementation

[0033] The embodiments of this application will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of this application. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of this application for ease of explanation. However, it will be apparent that one or more embodiments may be implemented without these specific details. Furthermore, descriptions of well-known structures and technologies are omitted in the following description to avoid unnecessarily obscuring the concepts of this application.

[0034] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the scope of this application. The terms “comprising,” “including,” etc., as used herein indicate the presence of features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0035] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.

[0036] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).

[0037] In the embodiments of this application, the collection, updating, analysis, processing, use, transmission, provision, disclosure, and storage of data (e.g., including but not limited to user personal information) comply with relevant laws and regulations, are used for legitimate purposes, and do not violate public order and good morals. In particular, necessary measures have been taken to prevent unauthorized access to user personal information data and to maintain user personal information security and network security. In the embodiments of this application, user authorization or consent has been obtained before acquiring or collecting user personal information.

[0038] In scenarios involving automated decision-making using personal information, the methods, devices, and systems provided in this application all offer users corresponding entry points for choosing to agree to or reject the automated decision-making results. If the user chooses to reject, the process proceeds to the expert decision-making stage. Here, "automated decision-making" refers to the activity of automatically analyzing and evaluating an individual's behavioral habits, interests, or economic, health, and credit status through computer programs, and then making a decision. Here, "expert decision-making" refers to the activity of making decisions by personnel who specialize in a particular field, possess specialized experience, knowledge, and skills, and have reached a certain level of professional expertise.

[0039] The automatic generation and deployment method for industrial firewall policies in related technologies is based on a set of intelligent modules working together. The administrator first sets parameters such as learning duration and granularity through the automatic policy learning configuration module. Then, the intelligent traffic analysis module begins deep analysis of network traffic, extracting multi-dimensional metadata such as the five-tuple (source / destination IP, MAC address, protocol type), application-layer industrial protocol data, data flow direction, and traffic rate, and storing it in the storage module.

[0040] However, this method, which relies on administrators to configure parameters such as self-learning granularity to implement whitelist protection strategies, places certain demands on administrators. They need to be very familiar with the content of various industrial control protocols in order to configure the granularity of the corresponding protocols. This may also result in different protocols having the same control granularity, which cannot achieve precise control and the policy content is not clear enough. When access control problems occur, it is not conducive to troubleshooting the problem.

[0041] In view of this, embodiments of this application provide a method for generating a whitelist policy, comprising: in response to receiving a message, parsing the message according to message parsing rules to obtain multiple target message information, the target message information including industrial protocol types; when multiple target message information matches multiple predefined message information, obtaining a target whitelist template related to the message based on the mapping relationship between industrial protocol types and whitelist template identifiers, the configuration items of the target whitelist template being determined by fusing configuration items in predefined whitelist templates and configuration items determined based on a deep learning model; when the target whitelist template is in learning mode, determining the configuration items of the target whitelist template using protocol operation information obtained from parsing the message to obtain a whitelist policy.

[0042] Figure 1 An exemplary system architecture is shown, illustrating a method for generating a whitelist strategy, an electronic device, and a storage medium to which a whitelist strategy can be applied according to embodiments of this application. It should be noted that... Figure 1The examples shown are merely examples of system architectures that can be applied to the embodiments of this application, in order to help those skilled in the art understand the technical content of this application, but do not mean that the embodiments of this application cannot be used in other devices, systems, environments or scenarios.

[0043] like Figure 1 As shown, the system architecture 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 serves as a medium for providing communication links between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired and / or wireless communication links, etc.

[0044] Users can use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 via the network 104 to receive or send messages, etc. Various communication client applications can be installed on the first terminal device 101, the second terminal device 102, and the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, and / or social media platform software, etc. (for example only).

[0045] The first terminal device 101, the second terminal device 102, and the third terminal device 103 can be various electronic devices with displays and support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.

[0046] Server 105 can be a server that provides various services, such as a backend management server that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103 (this is just an example). The backend management server can analyze and process data such as received user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.

[0047] It should be noted that the whitelist policy generation method provided in this application embodiment can generally be executed by server 105. Correspondingly, the whitelist policy generation device provided in this application embodiment can generally be located in server 105. The whitelist policy generation method provided in this application embodiment can also be executed by a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105. Correspondingly, the whitelist policy generation device provided in this application embodiment can also be located in a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105. Alternatively, the whitelist policy generation method provided in this application embodiment can also be executed by the first terminal device 101, the second terminal device 102, or the third terminal device 103, or it can be executed by other terminal devices different from the first terminal device 101, the second terminal device 102, or the third terminal device 103. Accordingly, the whitelist strategy generation device provided in this application embodiment can also be set in the first terminal device 101, the second terminal device 102 or the third terminal device 103, or in other terminal devices different from the first terminal device 101, the second terminal device 102 or the third terminal device 103.

[0048] For example, the received message may originally be stored in any one of the first terminal device 101, the second terminal device 102, or the third terminal device 103 (e.g., the first terminal device 101, but not limited thereto), or it may be stored on an external storage device and imported into the first terminal device 101. Then, the first terminal device 101 may locally execute the whitelist policy generation method provided in the embodiments of this application, or send the received message to other terminal devices, servers, or server clusters, and have the other terminal devices, servers, or server clusters that receive the message execute the whitelist policy generation method provided in the embodiments of this application.

[0049] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.

[0050] Figure 2 A flowchart illustrating a method for generating a whitelist policy according to an embodiment of this application is shown.

[0051] like Figure 2 As shown, the method includes operations S210~S230.

[0052] In operation S210, in response to receiving a message, the message is parsed according to the message parsing rules to obtain multiple target message information, including the industrial protocol type.

[0053] The message can be a data packet traffic sent to the industrial firewall via a website or user client. Administrators log into the industrial firewall, receive the message through the service network interface card in the firewall, parse the message based on the parsing rules, and extract multiple target message information from the message.

[0054] The target message information may include at least the following fields: industry protocol type, source Virtual Local Area Network ID (VLAN ID), source security zone, destination security zone, source IP address, destination IP address, service (i.e., port), action, and the current time corresponding to the traffic timestamp. Industry protocol types may include: Modbus protocol, OLE for Process Control (OPC), S7 protocol, Multimedia Messaging Service (MMS), etc.

[0055] In operation S220, when multiple target message information matches multiple predefined message information, the target whitelist template related to the message is obtained based on the mapping relationship between industrial protocol type and whitelist template identifier.

[0056] Administrators can log in to the industrial firewall to configure pre-processing content and send it to the industrial firewall process through the policy distribution module. Pre-filtering security policies can be configured first to perform initial filtering, quickly determining whether packets belong to permitted communication sessions, thus achieving coarse-grained access control. The configuration dimensions of pre-filtering security policies can include: source Virtual Local Area Network ID (VLAN ID), source security zone, destination security zone, source IP address, destination IP address, service (i.e., port), action, time period, and enabling the corresponding industrial protocol type. In other words, different configuration dimensions of pre-filtering security policies can correspond to different enabled industrial protocol types.

[0057] After configuring the pre-filtering security policy, target whitelist templates can be enabled based on this policy, one target whitelist template at a time. The configuration items for a target whitelist template can be predefined whitelist templates, or they can be determined by fusing configuration items from predefined whitelist templates with configuration items determined based on a deep learning model. Configuration items can be the content in the whitelist template that needs to be matched with the protocol content corresponding to the industrial protocol type associated with the received message.

[0058] When a predefined whitelist template is used as the target whitelist template, the configuration items of the protocol content can be predefined based on different industrial protocol types when the product is shipped. For example, the function codes that need to be matched for the Modbus protocol, the transport layer protocol, the start and end addresses of the registers, etc., are all pre-set by the manufacturer when the product is shipped.

[0059] Alternatively, configuration items based on a predefined whitelist template and configuration items of a whitelist template determined by learning from protocol content parsed from historical packets using a deep learning model can be fused together to ultimately determine the configuration items of the target whitelist.

[0060] After pre-setting each target whitelist template, you can configure the working mode of each target whitelist template. The working modes include learning mode, alarm mode and protection mode.

[0061] Before performing whitelist template matching on the received packets, the parsed target packet information can be matched one by one with the predefined packet information in the pre-filtering security policy. If at least one match fails, the packet is discarded; if all packet information matches successfully, it indicates that the packet belongs to a permitted communication session. Then, based on the industrial protocol type of the packet, the association between the industrial protocol type in the pre-filtering security policy and the corresponding enabled whitelist identifier is determined, and the target whitelist template related to the packet is obtained.

[0062] When operating S230, if the target whitelist template is in learning mode, the configuration items of the target whitelist template are determined by using the protocol operation information obtained from parsing the message, and the whitelist policy is obtained.

[0063] Protocol operation information can be obtained through deep parsing of application layer fields in the packets. This information can be derived from parsing the content fields corresponding to different industrial protocol types. The field content varies depending on the industrial protocol type. In learning mode, the firewall can use the application layer information obtained from parsing each received packet to determine the configuration items of the target whitelist template, thereby generating a whitelist policy.

[0064] According to embodiments of this application, in response to a received message, the message is parsed according to message parsing rules to obtain multiple target message information. This allows for the identification of the message's service type, communication direction, and industrial protocol type, providing a data foundation for subsequent message information matching. When multiple target message information matches multiple predefined message information, a target whitelist template related to the message is obtained based on the mapping relationship between industrial protocol types and whitelist template identifiers. The configuration items of this target whitelist template are determined by fusing configuration items from predefined whitelist templates and configuration items determined based on a deep learning model. This avoids configuration errors and low accuracy due to reliance on manual configuration, thereby improving the accuracy of whitelist configuration items. When the target whitelist template is in learning mode, the configuration items of the target whitelist template are determined using protocol operation information obtained from parsing the message, resulting in a whitelist policy. This allows for the learning of more comprehensive configuration items in dynamic network scenarios, thereby improving the accuracy and adaptability of the whitelist policy.

[0065] According to an embodiment of this application, obtaining a target whitelist template related to a message based on the mapping relationship between industrial protocol types and whitelist template identifiers includes: determining a target whitelist template identifier corresponding to a message based on the mapping relationship between industrial protocol types and whitelist template identifiers; and obtaining a target whitelist template related to the message based on the target whitelist template identifier.

[0066] According to embodiments of this application, the mapping relationship can be a correspondence between industrial protocol types and whitelist template identifiers in a pre-filtering security policy. Based on the industrial protocol types in the target message information obtained from the aforementioned message parsing, the whitelist template identifier can be determined based on the mapping relationship, and then bound to the message based on the whitelist template identifier. This allows the configuration items of the target whitelist template to be obtained based on the whitelist identifier bound to the message.

[0067] For example, Table 1 shows a target whitelist template using the Modbus industrial protocol type as an example. As shown in Table 1:

[0068]

[0069] As shown in Table 1, the packet information such as source IP, destination IP, source IP mask, and destination IP mask in Table 1 can be filled into the whitelist template by parsing the target packet information through the interface during the determination of the target whitelist template.

[0070] According to the embodiments of this application, the whitelist template corresponding to the message can be quickly located by mapping the industrial protocol type to the whitelist template identifier, avoiding traversing all whitelist templates and improving matching efficiency and response speed.

[0071] According to an embodiment of this application, the configuration items of the target whitelist template are determined by parsing the protocol operation information obtained from the parsed message, and a whitelist policy is obtained. The process includes: parsing the message to obtain the protocol operation information of the message; determining the learning duration threshold of the learning mode; and determining the configuration items of the target whitelist template based on the learning duration threshold and the protocol operation information of the message, thereby obtaining a whitelist policy.

[0072] Protocol parsing of a message can be the process of parsing application-layer fields of the message. The learning duration threshold can be a pre-set duration for the firewall to learn the message.

[0073] The configuration items of the target whitelist template can be dynamically updated based on the protocol operation information parsed from the packets received by the firewall. The dynamic configuration update process can include populating the configuration items of the target whitelist template or updating the configuration items of the target whitelist template.

[0074] When the learning time for the firewall's whitelist template reaches the learning time threshold, the learning mode can be terminated, and the corresponding whitelist policy can be obtained.

[0075] According to the embodiments of this application, the configuration items of the whitelist template are dynamically updated by parsing the protocol operation information obtained from the message protocol, so as to realize the configuration items of the whitelist template corresponding to different industrial protocols, thereby improving the matching accuracy at the protocol granularity.

[0076] According to an embodiment of this application, based on a learning duration threshold, the configuration items of the target whitelist template are determined using the protocol operation information of the message to obtain a whitelist policy, including: in response to a mode start command for the target whitelist template being in learning mode, if the configuration items of the target whitelist template are empty, adding the protocol operation information of the message as a new configuration item to the target whitelist template; if the configuration items of the target whitelist template contain predefined configuration content, updating the predefined configuration content using the protocol operation information of the message; and generating a whitelist policy based on the configured target whitelist template when the learning duration of the learning mode reaches the learning duration threshold.

[0077] The instruction to enable learning mode is given when the working mode of the target whitelist template obtained by the firewall is learning mode. If the configuration items of the target whitelist template are empty, it can mean that the protocol operation information obtained after deep parsing of the packet does not exist in the target whitelist template, or that no configuration item exists in the target whitelist template. In this case, the protocol operation information can be filled into the target whitelist template.

[0078] If the target whitelist template has predefined configuration content in its configuration items, the protocol operation information obtained after deep parsing of the packets can be dynamically updated to the corresponding configuration items, so as to obtain the target whitelist template configuration items that are adaptive to the network scenario.

[0079] When the learning time in the learning mode reaches the learning time threshold, the aforementioned filled or configured target whitelist template can be used as the whitelist strategy.

[0080] According to the embodiments of this application, by adopting a learning mode to dynamically fill or update the whitelist template configuration items, and automatically generating the whitelist policy after the learning time reaches a threshold, the purpose is to perform a second-level filtering, quickly determine whether the specific protocol fields of the industrial protocol of the packet at the application layer are allowed, so that the administrator does not need to have in-depth knowledge of the content of various industrial protocols, and does not need to manually intervene in configuring the whitelist, avoiding configuration errors caused by manual configuration, thereby enabling the whitelist policy to be dynamically constructed to adapt to the actual packet traffic, and improving the efficiency and accuracy of whitelist deployment.

[0081] According to an embodiment of this application, the configuration items of the target whitelist template are determined by fusing configuration items in a predefined whitelist template with configuration items determined based on a deep learning model. This is achieved through the following steps: extracting structured fields from historical packets to obtain a set of structured fields, which includes multiple structured fields, each representing a configuration item; determining the matching granularity of each structured field in the whitelist template; obtaining the matching granularity of each configuration item in the predefined whitelist template; fusing the matching granularity of each structured field in the whitelist template with the matching granularity of each configuration item in the predefined whitelist template, and using the fused configuration items as the configuration items of the target whitelist.

[0082] Historical messages can be industrial protocol messages captured by the system in real time over a period of time. Through deep parsing, the original binary messages are converted into structured feature vectors, and these structured feature vectors are used as input to a deep learning model for supervised learning. This results in the output of the matching granularity of the protocol fields in the structured feature vector. For example, it determines which protocol fields have fixed values, which protocol fields fluctuate within a certain range, and which protocol fields are random, thereby determining the protocol fields for which the matching granularity should be refined.

[0083] In one embodiment, for example, in a session targeting the same industrial protocol type, the matching granularity of the configuration item is function code 03, but the register address of each received message changes, and the specification address is a key feature. Based on a deep learning model, it is predicted that the register start and end address fields that need to be matched for function code 03 of this industrial protocol type are 40001~40020, and they do not appear in the same industrial protocol as function code 15.

[0084] For the same industrial protocol type in the aforementioned example, the matching granularity of the configuration items in the predefined whitelist template is function code 03, function code 15, and start / end addresses 40001~40047. Therefore, the configuration items determined based on the deep learning model are merged with those in the predefined whitelist template, ultimately determining the merged configuration item as function code 03, with start / end addresses 40001~40020. This allows us to determine the matching granularity and dependencies of each configuration item in the target whitelist template.

[0085] According to the embodiments of this application, by fusing the matching granularity of the structured fields obtained by parsing historical messages as configuration items in the whitelist template with the matching granularity of configuration items based on the predefined whitelist template, it is possible to avoid the matching granularity of each configuration item being too coarse or too fine due to manual templates, and to prevent noise in each configuration item determined by the deep learning model. The two complement each other and work together to improve the granularity accuracy of configuration items in the whitelist template, thereby improving the accuracy of the whitelist strategy.

[0086] According to an embodiment of this application, the method further includes: generating log information with the topic of learning mode, and forwarding the message to the target receiver indicated by the target receiver address carried in the message.

[0087] According to an embodiment of this application, when the working mode of the target whitelist template is learning mode, during the process of generating the whitelist policy, the log information of the current log topic is in learning mode. The log fields in the log information may include the industrial protocol type and the fields corresponding to the protocol, as well as fields such as timestamp, transport layer protocol type, number of packets, and number of bytes in the packet.

[0088] According to an embodiment of this application, after generating log information with a learning mode as the log subject, the message is forwarded to the target receiver indicated by the target receiver address carried in the message. The target receiver address can be a target IP address.

[0089] According to the embodiments of this application, by generating log information when the target whitelist template is in learning mode, the whitelist policy generation process can be visualized, enabling operation and maintenance personnel to grasp the stage of self-learning in real time through log information. When false alarms or missed alarms occur in the whitelist policy, the granularity selection basis of a specific field within a certain learning cycle can be directly located when tracing back the problem, thereby reducing the backtracking overhead of false alarms and missed alarms.

[0090] According to an embodiment of this application, the method further includes: when the target whitelist template is in alarm mode, determining whether the protocol operation information obtained by parsing the message matches the whitelist policy; when it is determined that the protocol operation information does not match the whitelist policy, generating log information with an alarm mode as the topic, and forwarding the message to the target receiver indicated by the target receiver address carried in the message.

[0091] According to an embodiment of this application, when the target whitelist template is in alarm mode, it indicates that the firewall's learning mode based on the target whitelist template has ended, a whitelist policy is generated, and in alarm mode, the whitelist policy is used as the firewall policy to monitor the system and confirm whether the received packet matches the whitelist policy. If it matches, the packet is forwarded to the target receiver indicated by the target receiver address carried in the packet; if it does not match, the current log topic is recorded as the log information of alarm mode.

[0092] Log information with an alarm theme can include, in addition to the industrial protocol and the corresponding fields, fields such as timestamp, transport layer protocol type, number of packets, and number of bytes per packet.

[0093] According to an embodiment of this application, after generating log information with an alarm mode as the log subject, the message is forwarded to the target receiver indicated by the target receiver address carried in the message.

[0094] According to the embodiments of this application, by generating log information in alarm mode, abnormal events and their triggered whitelist policies can be marked in real time, distinguishing whether the received packets are normal traffic or attack behavior, while also providing accurate event tracing for operation and maintenance personnel and supporting rapid location of policy defects.

[0095] According to an embodiment of this application, the method further includes: when the target whitelist template is in protection mode, determining whether the protocol operation information obtained by parsing the message matches the whitelist policy; when it is determined that the protocol operation information does not match the whitelist policy, generating log information with the topic of protection mode, and performing an interception operation on the message.

[0096] When the target whitelist template is in protection mode, the whitelist policy is used as the firewall policy for system monitoring. The system checks whether the received packet matches the whitelist policy. If it matches, the packet is forwarded to the target receiver indicated by the target receiver address carried in the packet. If it does not match, the system records the current log information with the protection mode as the log topic.

[0097] Log messages with a protected theme can include, in addition to the industry protocol and its corresponding fields, fields such as timestamp, transport layer protocol type, number of packets, and packet byte count. After generating log messages with a protected theme, the packets are intercepted.

[0098] According to the embodiments of this application, by generating log information in protection mode, it is possible to record the actions of intercepting or allowing packets, matching strategies and handling results in real time, providing operation and maintenance personnel with visual monitoring of protection status. In addition, log information can be used for subsequent security audits and attack tracing, which helps to dynamically adjust the granularity of whitelist policy configuration items and improve industrial control security protection.

[0099] After generating log information in the aforementioned working mode, the current process, as the producer, forwards the log information to the log processing module. The log processing module caches the log information generated by the industrial firewall in a message queue for consumers to consume.

[0100] The backend processing module, acting as a consumer, processes the log information after receiving it, generating files with specific content formats. These files are then stored in the log storage module. The log storage module uses a time-series database, supports structured query language, employs columnar storage, and features timestamped data ingestion, querying, and aggregation. This makes it suitable for processing continuously generated message data streams that arrive in chronological order.

[0101] With a pre-set learning duration threshold of one learning cycle, such as 24 hours or 15 days, after the scheduled task in the learning mode ends, the log information in the log storage module can be matched to the time range corresponding to the learning duration threshold of the scheduled task (e.g., from 0:00 on day x of month x to 0:00 on day y of month x). The log information within this time range is then distributed to the policy distribution module through the application interface according to the field information of the configuration items in the target whitelist template. This enables the subsequent authentication and access control of the system based on the whitelist policy distributed by the policy distribution module.

[0102] Figure 3 A schematic diagram of a method for generating a whitelist policy according to an embodiment of this application is shown.

[0103] like Figure 3As shown, in response to a received message, the message is parsed according to the message parsing rules to obtain multiple target message information (S301); it is determined whether the multiple target message information matches multiple predefined message information in the pre-filtering security policy (S302); if at least one does not match, the message is intercepted (S303); if all match, the target whitelist template related to the message is obtained based on the mapping relationship between the industrial protocol type and the whitelist identifier related to the message (S304); it is determined whether the working mode of the whitelist template is learning mode, alarm mode, or protection mode (S305); if it is learning mode, the configuration items of the target whitelist template are determined using the parsed protocol operation information to obtain the whitelist policy (S306); based on the protocol operation information obtained from the deep parsing of the message... The system records the current log topic as the log information corresponding to the learning mode (S307) and forwards the message to the target receiver (S308). If it is in alarm mode, it determines whether the message hits the whitelist policy in alarm mode (S309). If it does, it executes S308. If it does not, it records the current log topic as the log information corresponding to the alarm mode based on the protocol operation information obtained from deep parsing of the message (S310) and executes S308. If it is in protection mode, it determines whether the message hits the whitelist policy in protection mode (S311). If it does, it executes S308. If it does not, it records the current log topic as the log information corresponding to the protection mode based on the protocol operation information obtained from deep parsing of the message (S312) and executes S303.

[0104] Figure 4 A schematic diagram of the system architecture of a method for generating a whitelist policy according to an embodiment of this application is shown.

[0105] like Figure 4As shown, the system architecture can include a data control module 401, which may include a pre-filtering security policy distribution submodule, a packet deep analysis feature library, and a whitelist template distribution submodule. The data control module stores the policy data distributed by the data control module according to a specific model structure and sends the pre-configured policy data to the policy distribution module 402 via socket communication. The policy distribution module 402 then sends the received policy data to the data forwarding module 403. The data forwarding module 403 is a user-space-based data forwarding process. It actively polls the network interface card (NIC) using user-space drive, collecting up to 256 packets at a time from the service NIC's receive queue in the industrial firewall to form a vector. This vector is then processed in batches according to the data flow graph. Each node in the data flow graph handles the same service. When processing this vector, the first packet is "warmed up," while subsequent packets, due to executing similar instruction flows, can directly hit the cache, thus distributing the overhead of cache misses evenly across the entire packet group, significantly shortening the processing cycle of a single packet. The data forwarding module 403 includes several processing nodes: a message sending and receiving node, responsible for sending and receiving messages; a security policy matching node, responsible for matching pre-filtered security policies; a message deep parsing node, responsible for performing deep parsing of messages and associating the parsed content with the target whitelist template related to the message; and a whitelist policy matching node, responsible for matching whitelist policies and generating corresponding logs and release actions according to the working mode configured by the user's whitelist policy template. Specifically: a. Alarm mode: If the message matches the whitelist rule, it is forwarded normally; if it does not match the whitelist policy, it is forwarded normally and a log with the topic "alarm" is generated. The alarm log includes the industrial protocol, and in addition to the fields corresponding to the protocol, it also includes the timestamp, transport layer protocol type, number of messages, and number of bytes in the message. b. Protection mode: If the message matches the whitelist rule, it is forwarded normally; if it does not match the whitelist policy, the message is discarded; at the same time, log information with the topic "protection mode" is generated. The log information includes the industrial protocol, and in addition to the fields corresponding to the protocol, it also includes the timestamp, transport layer protocol type, number of messages, and number of bytes in the message. c. Learning Mode: After enabling learning mode and configuring the learning duration threshold, the current configuration time is recorded. When a packet arrives at the deep parsing node, the deep parsing node will associate the parsed content with the packet based on the fields of different industrial protocols in the predefined whitelist template. When the packet is forwarded to the whitelist policy matching node, the result of the deep packet parsing node is obtained from the packet, generating an information including the industrial protocol (see table), and in addition to the fields corresponding to the protocol, it also includes the timestamp, transport layer protocol type, number of packets, and number of bytes in the packet. This information is then forwarded to the log processing module. The log processing module 404 is used to process the logs generated in the data forwarding module and forward the log information to the data control module 401.The log storage module 405 is used to store the log information parsed by the data control module 401 and to provide the data control module 401 with the ability to query historical log information.

[0106] Figure 5 A block diagram of a whitelist policy generation apparatus according to an embodiment of this application is shown.

[0107] like Figure 5 As shown, the whitelist policy generation device 500 includes: a message parsing module 510, a template acquisition module 520, and a configuration item determination module 530.

[0108] The message parsing module 510 is used to respond to a received message, parse the message according to the message parsing rules, and obtain multiple target message information, including industrial protocol types.

[0109] The template acquisition module 520 is used to acquire the target whitelist template related to the message based on the mapping relationship between the industrial protocol type and the whitelist template identifier when multiple target message information matches multiple predefined message information. The configuration items of the target whitelist template are determined by fusing the configuration items in the predefined whitelist template and the configuration items determined based on the deep learning model.

[0110] The configuration item determination module 530 is used to determine the configuration items of the target whitelist template by using the protocol operation information obtained from parsing the message when the target whitelist template is in learning mode, and thus obtain the whitelist policy.

[0111] According to an embodiment of this application, the template acquisition module 520 includes: an identifier determination submodule and a template acquisition submodule.

[0112] The identifier determination submodule is used to determine the target whitelist template identifier corresponding to the message based on the mapping relationship between industrial protocol types and whitelist template identifiers.

[0113] The template acquisition submodule is used to obtain the target whitelist template related to the message based on the target whitelist template identifier.

[0114] According to an embodiment of this application, the configuration item determination module 530 includes: a protocol parsing submodule, a duration determination submodule, and a configuration item determination submodule.

[0115] The protocol parsing submodule is used to parse the message according to the protocol and obtain the message's protocol operation information.

[0116] The duration determination submodule is used to determine the learning duration threshold for the learning mode.

[0117] The configuration item determination submodule is used to determine the configuration items of the target whitelist template based on the learning duration threshold and the protocol operation information of the message, so as to obtain the whitelist policy.

[0118] According to an embodiment of this application, the configuration item determination submodule includes: an information addition unit, a configuration item update unit, and a policy generation unit.

[0119] The information addition unit is used to add the protocol operation information of the message as a new configuration item to the target whitelist template when the target whitelist template is in learning mode, in response to the mode start command.

[0120] The configuration item update unit is used to update the predefined configuration content using the protocol operation information of the message when the target whitelist template has predefined configuration content configured in the configuration item.

[0121] The strategy generation unit is used to generate a whitelist strategy based on the configured target whitelist template when the learning time in the learning mode reaches the learning time threshold.

[0122] According to an embodiment of this application, the device 500 further includes: a field extraction module, a granularity determination module, a granularity acquisition module, and a granularity fusion module. The field extraction module is used to extract structured fields from historical messages to obtain a set of structured fields, which includes multiple structured fields, each representing a configuration item.

[0123] The granularity determination module is used to determine the matching granularity of each structured field in the structured field set within the whitelist template.

[0124] The granularity acquisition module is used to obtain the matching granularity of each configuration item in the predefined whitelist template.

[0125] The granularity fusion module is used to merge the matching granularity of each structured field in the structured field set in the whitelist template with the matching granularity of each configuration item in the predefined whitelist template, and use the merged configuration items as the configuration items of the target whitelist.

[0126] According to an embodiment of this application, the device 500 further includes: a first log generation module.

[0127] The first log generation module is used to generate log information with the topic of learning mode and forward the message to the target receiver indicated by the target receiver address carried in the message.

[0128] According to an embodiment of this application, the device 500 further includes: a first policy matching module and a second log generation module.

[0129] The first policy matching module is used to determine whether the protocol operation information obtained from parsing the message matches the whitelist policy when the target whitelist template is in alarm mode.

[0130] The second log generation module is used to generate log information with an alarm theme when it is determined that the protocol operation information does not match the whitelist policy, and forward the message to the target receiver indicated by the target receiver address carried in the message.

[0131] According to an embodiment of this application, the device 500 further includes a second strategy matching module and a third log generation module.

[0132] The second policy matching module is used to determine whether the protocol operation information obtained from parsing the message matches the whitelist policy when the target whitelist template is in protection mode.

[0133] The third log generation module is used to generate log information with the topic of protection mode when it is determined that the protocol operation information does not match the whitelist policy, and to perform interception operations on the packets.

[0134] Any one or more of the modules, submodules, and units according to the embodiments of this application, or at least part of the functions of any one or more of them, can be implemented in one module. Any one or more of the modules, submodules, and units according to the embodiments of this application can be implemented by dividing them into multiple modules. Any one or more of the modules, submodules, and units according to the embodiments of this application can be at least partially implemented as hardware circuits, such as field-programmable gate arrays (FPGAs), programmable logic arrays (PLAs), systems-on-a-chip, systems-on-a-substrate, systems-on-package, application-specific integrated circuits (ASICs), or implemented by hardware or firmware in any other reasonable manner by integrating or packaging circuits, or implemented in any one of software, hardware, and firmware, or in a suitable combination of any of these. Alternatively, one or more of the modules, submodules, and units according to the embodiments of this application can be at least partially implemented as computer program modules, which, when run, can perform corresponding functions.

[0135] For example, any plurality of the message parsing module 510, template acquisition module 520, and configuration item determination module 530 can be combined into one module / submodule / unit, or any one of these modules / submodules / units can be split into multiple modules / submodules / units. Alternatively, at least part of the functionality of one or more of these modules / submodules / units can be combined with at least part of the functionality of other modules / submodules / units and implemented in one module / submodule / unit. According to embodiments of this application, at least one of the message parsing module 510, template acquisition module 520, and configuration item determination module 530 can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, at least one of the message parsing module 510, template acquisition module 520, and configuration item determination module 530 may be implemented at least partially as a computer program module, which can perform corresponding functions when the computer program module is run.

[0136] It should be noted that the whitelist policy generation device part in the embodiments of this application corresponds to the whitelist policy generation method part in the embodiments of this application. For a detailed description of the whitelist policy generation device part, please refer to the whitelist policy generation method part, which will not be repeated here.

[0137] Figure 6 A block diagram of an electronic device suitable for implementing the whitelist policy generation method described above, according to an embodiment of this application, is shown. Figure 6 The electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.

[0138] like Figure 6 As shown, an electronic device 600 according to an embodiment of this application includes a processor 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage portion 608 into a random access memory (RAM) 603. The processor 601 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 601 may also include onboard memory for caching purposes. The processor 601 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of this application.

[0139] RAM 603 stores various programs and data required for the operation of electronic device 600. Processor 601, ROM 602, and RAM 603 are interconnected via bus 604. Processor 601 executes various operations of the method flow according to embodiments of this application by executing programs in ROM 602 and / or RAM 603. It should be noted that programs may also be stored in one or more memories other than ROM 602 and RAM 603. Processor 601 may also execute various operations of the method flow according to embodiments of this application by executing programs stored in one or more memories.

[0140] According to embodiments of this application, the electronic device 600 may further include an input / output (I / O) interface 605, which is also connected to a bus 604. The electronic device 600 may also include one or more of the following components connected to the input / output (I / O) interface 605: an input section 606 including a keyboard, mouse, etc.; an output section 607 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN card, modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the input / output (I / O) interface 605 as needed. A removable medium 611, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 610 as needed so that computer programs read from it can be installed into the storage section 608 as needed.

[0141] According to embodiments of this application, the method flow according to embodiments of this application can be implemented as a computer software program. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable storage medium, the computer program containing program code for performing the methods shown in the flowchart. In such embodiments, the computer program can be downloaded and installed from a network via communication section 609, and / or installed from removable medium 611. When the computer program is executed by processor 601, it performs the functions defined in the system of embodiments of this application. According to embodiments of this application, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0142] This application also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of this application.

[0143] According to embodiments of this application, the computer-readable storage medium can be a non-volatile computer-readable storage medium. Examples include, but are not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this application, the computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0144] For example, according to embodiments of this application, a computer-readable storage medium may include the ROM 602 and / or RAM 603 described above and / or one or more memories other than ROM 602 and RAM 603.

[0145] Embodiments of this application also include a computer program product comprising a computer program containing program code for performing the methods provided in the embodiments of this application. When the computer program product is run on an electronic device, the program code is used to enable the electronic device to implement the methods provided in the embodiments of this application.

[0146] When the computer program is executed by the processor 601, it performs the functions defined in the system / apparatus of this application embodiment. According to the embodiments of this application, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0147] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and downloaded and installed via the communication section 609, and / or installed from the removable medium 611. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.

[0148] According to embodiments of this application, program code for executing the computer programs provided in the embodiments of this application can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C", or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0149] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions. Those skilled in the art will understand that the features described in the various embodiments of this application can be combined and / or combined in various ways, even if such combinations are not explicitly described in this application. In particular, without departing from the spirit and teachings of this application, the features described in the various embodiments of this application can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of this application.

[0150] The embodiments of this application have been described above. However, these embodiments are merely illustrative and not intended to limit the scope of this application. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. Without departing from the scope of this application, those skilled in the art can make various substitutions and modifications, all of which should fall within the scope of this application.

Claims

1. A method for generating a whitelist strategy, characterized in that, The method includes: In response to receiving a message, the message is parsed according to the message parsing rules to obtain multiple target message information, including industrial protocol types; When multiple target message information matches multiple predefined message information, a target whitelist template related to the message is obtained based on the mapping relationship between the industrial protocol type and the whitelist template identifier. The configuration items of the target whitelist template are determined by fusing the configuration items in the predefined whitelist template and the configuration items determined based on the deep learning model. When the target whitelist template is in learning mode, the configuration items of the target whitelist template are determined by parsing the protocol operation information obtained from the message, and the whitelist policy is obtained.

2. The method according to claim 1, characterized in that, The step of obtaining the target whitelist template related to the message based on the mapping relationship between the industrial protocol type and the whitelist template identifier includes: Based on the mapping relationship between the industrial protocol type and the whitelist template identifier, determine the target whitelist template identifier corresponding to the message; Based on the target whitelist template identifier, obtain the target whitelist template related to the message.

3. The method according to claim 1, characterized in that, The step of determining the configuration items of the target whitelist template by parsing the protocol operation information obtained from the message, and obtaining the whitelist policy, includes: The message is parsed to obtain the protocol operation information of the message; Determine the learning duration threshold for the learning mode; Based on the learning duration threshold, the configuration items of the target whitelist template are determined using the protocol operation information of the message, and the whitelist strategy is obtained.

4. The method according to claim 3, characterized in that, The step of determining the configuration items of the target whitelist template based on the learning duration threshold and using the protocol operation information of the message to obtain the whitelist strategy includes: In response to the mode activation command that the target whitelist template is in learning mode, If the configuration items of the target whitelist template are empty, the protocol operation information of the message is added to the target whitelist template as a new configuration item. If the target whitelist template has predefined configuration content configured in its configuration items, the predefined configuration content is updated using the protocol operation information of the message; When the learning time in the learning mode reaches the learning time threshold, the whitelist strategy is generated based on the configured target whitelist template.

5. The method according to claim 1, characterized in that, Also includes: Structured fields are extracted from historical messages to obtain a set of structured fields, which includes multiple structured fields, each of which represents a configuration item. Determine the matching granularity of each structured field in the structured field set within the whitelist template; Obtain the matching granularity of each configuration item in the predefined whitelist template; The matching granularity of each structured field in the structured field set in the whitelist template and the matching granularity of each configuration item in the predefined whitelist template are merged, and the merged configuration items are used as the configuration items of the target whitelist.

6. The method according to claim 1, characterized in that, Also includes: Log messages with the subject "learning mode" are generated, and the messages are forwarded to the target receiver indicated by the target receiver address carried in the messages.

7. The method according to claim 6, characterized in that, Also includes: If the target whitelist template is in alarm mode, determine whether the protocol operation information obtained by parsing the message matches the whitelist policy; If it is determined that the protocol operation information does not match the whitelist policy, a log message with the topic of alarm mode is generated, and the message is forwarded to the target receiver indicated by the target receiver address carried in the message.

8. The method according to claim 6 or 7, characterized in that, Also includes: If the target whitelist template is in protection mode, determine whether the protocol operation information obtained by parsing the message matches the whitelist policy; If it is determined that the protocol operation information does not match the whitelist policy, log information with the topic of protection mode is generated, and the packet is intercepted.

9. An electronic device, comprising: One or more processors; Memory, used to store one or more programs. Wherein, when the one or more programs are executed by the one or more processors, the one or more processors implement the method of any one of claims 1 to 8.

10. A computer-readable storage medium having stored thereon executable instructions that, when executed by a processor, cause the processor to perform the method of any one of claims 1 to 8.