Automatic detection method and apparatus for next-generation firewall

By generating SKB messages, performing multiple security detections, automatically recording and notification of abnormal modules, the problems of difficulty in positioning and long recovery time of the next generation of firewall are solved, and rapid fault recovery and diagnosis are achieved.

WO2025156588A1PCT designated stage Publication Date: 2025-07-31HANGZHOU DPTECH TECH

Patent Information

Application Number
PCT/CN2024/108539
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-25
Filing Date
2024-07-30
Publication Date
2025-07-31

AI Technical Summary

Technical Problem

The next-generation firewall is difficult to locate faults in the event of network failure and cannot quickly recover the network. The existing technology can only diagnose after the fault, which takes a long time.

Method used

By generating SKB messages, they are sent regularly to the software package portal of the next generation firewall, multiple security detections are performed, abnormal modules are recorded, and alarm logs are generated to automatically notify users.

Benefits of technology

It realizes automatic and rapid recovery of the network in the event of a firewall failure, provides the efficiency of diagnosis of the cause of failure and reduces the troubleshooting time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024108539_31072025_PF_FP_ABST
    Figure CN2024108539_31072025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to an automatic detection method and apparatus for a next-generation firewall. The method comprises: generating an SKB message on the basis of message header information and a probe table; periodically sending the SKB message to a software packet receiving entry of a next-generation firewall; the next-generation firewall performing multiple security inspections on the SKB message on the basis of a preset policy; storing the inspection results of the multiple security inspections into the probe table; determining an abnormal software module on the basis of the probing results in the probe table; and generating an alert log on the basis of the abnormal software module to automatically notify a user. In the present application, software modules along a forwarding path in the next-generation firewall can be automatically detected, and an abnormal module can be automatically recorded, so that the network can be automatically and quickly recovered when the firewall fails; and fault causes can also be provided to improve the diagnosis efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Automatic detection method and device for next generation firewall Technical Field

[0001] The present disclosure relates to the field of computer information processing, and in particular to an automatic detection method and apparatus for a next-generation firewall. Background Art

[0002] In the network security hardware market, firewalls are the largest single product, with the widest range of applications. Even today, in the face of cloud computing, firewalls still hold the top position in terms of volume. Firewalls are deployed extensively at the network perimeter. With the growing prosperity of the internet, the types and number of network applications have greatly increased, as has the number of people online and bandwidth. At the same time, network applications have become increasingly complex, and perimeter security protection has become increasingly complex. This often requires a combination of firewalls, IPS, WAFs, auditing, and cleaning devices to form perimeter security protection. Multiple security devices are deployed serially at the perimeter to implement diverse security services. However, this deployment poses significant challenges to network maintenance and failure rates. In response to this environment, next-generation firewalls have emerged. While implementing the routing and switching functions of basic network devices, next-generation firewalls inherit the functionality of traditional firewalls and add a rich set of application-layer protection features. This enables a perimeter security pool with a single next-generation firewall deployed at the perimeter to provide a rich set of security protection capabilities.

[0003] The next-generation firewall integrates a very rich set of network features and security protection features. When the message is forwarded by software inside the next-generation wall, it must not only go through the necessary routing switching and traditional firewall protection, but also go through a large number of security protection processes. This increases the probability of failure for the next-generation wall. No matter which software link fails, it will cause network transmission abnormalities. Moreover, since the messages are forwarded between software, it is very difficult to locate the fault. Simple packet capture can no longer meet the diagnostic needs. Software means can only be analyzed after the incident, and the time to restore the business is too long, which undoubtedly cannot meet the high real-time requirements of the current network.

[0004] Therefore, a new automatic detection method and device for next-generation firewalls are needed.

[0005] The above information disclosed in this Background section is only for enhancement of understanding of the background of the application and therefore it may contain information that does not form the prior art that is already known to a person of ordinary skill in the art.

[0006] Summary of the Invention

[0007] In view of this, the present application provides an automatic detection method and device for a next-generation firewall, which can automatically detect each software module of the forwarding path in the next-generation firewall and automatically record abnormal modules, so that the network can be automatically and quickly restored when a firewall failure occurs, and the cause of the failure can be provided to improve diagnostic efficiency.

[0008] Other features and advantages of the present application will become apparent from the following detailed description, or may be learned in part by practice of the present application.

[0009] According to one aspect of the present application, an automatic detection method for a next-generation firewall is proposed, the method comprising: generating an SKB message based on message header information and a detection table; periodically sending the SKB message to a software packet receiving entrance of the next-generation firewall; the next-generation firewall performing multiple security checks on the SKB message based on a preset policy; storing the detection results of the multiple security checks in the detection table; determining an abnormal software module based on the detection results in the detection table; and generating an alarm log based on the abnormal software module to automatically notify a user.

[0010] In an exemplary embodiment of the present application, an SKB message is generated based on message header information and a detection table, including: generating message header information through configuration information of a next-generation firewall; determining a detection table field according to table entries in the detection table; and generating the SKB message through the message header information and the detection table field.

[0011] In an exemplary embodiment of the present application, message header information is generated through the configuration information of the next-generation firewall, including: extracting the forwarding software module identifier and forwarding principle through the configuration information of the next-generation firewall; and generating the message header information through the software module identifier and forwarding principle.

[0012] In an exemplary embodiment of the present application, the SKB message is generated through the message header information and the detection table field, including: determining the data segment information; determining the detection identifier; and assembling the message header information, the data segment information, the detection table field and the detection identifier to generate the SKB message.

[0013] In an exemplary embodiment of the present application, the SKB message is periodically sent to the software packet receiving entrance of the next-generation firewall, including: the network card driver periodically sends the SKB message to the software packet receiving entrance of the next-generation firewall.

[0014] In an exemplary embodiment of the present application, the next-generation firewall performs multiple security checks on the SKB message based on a preset policy, including: the next-generation firewall performs a message legitimacy check on the SKB message; and / or the next-generation firewall matches a layer 2 or layer 3 table entry for the SKB message; and / or the next-generation firewall matches the destination NAT for the SKB message; and / or the next-generation firewall performs a protocol status check on the SKB message; and / or the next-generation firewall matches a blacklist and whitelist for the SKB message; and / or the next-generation firewall performs a security domain check on the SKB message; and / or the next-generation firewall matches packet filtering for the SKB message; and / or the next-generation firewall performs a security protection check on the SKB message.

[0015] In an exemplary embodiment of the present application, the detection results of the multiple safety detections are stored in the detection table, including: during the detection process of the multiple safety detections, determining a detection identifier according to the detection items; and updating the detection identifier according to the detection results, wherein the detection identifier includes: 1 and 0.

[0016] In an exemplary embodiment of the present application, an alarm log is generated based on the abnormal software module to automatically notify the user, including: generating an alarm log according to the identification, detection table number, and error code of the abnormal software module; and automatically sending the alarm log to the associated user.

[0017] In an exemplary embodiment of the present application, the method further includes discarding the SKB message after multiple security checks are completed.

[0018] According to one aspect of the present application, an automatic detection device for a next-generation firewall is proposed, comprising: a message module for generating an SKB message based on message header information and a detection table; a generation module for periodically sending the SKB message to a software packet receiving entrance of the next-generation firewall; a detection module for performing multiple security checks on the SKB message based on a preset policy by the next-generation firewall; a storage module for storing the detection results of the multiple security checks in the detection table; a detection module for determining an abnormal software module based on the detection results in the detection table; and an alarm module for generating an alarm log based on the abnormal software module to automatically notify a user.

[0019] According to one aspect of the present application, an electronic device is proposed, which includes: one or more processors; a storage device for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the method as described above.

[0020] According to one aspect of the present application, a computer-readable medium is provided, on which a computer program is stored. When the program is executed by a processor, the method described above is implemented.

[0021] According to the automatic detection method and device for a next-generation firewall of the present application, an SKB message is generated based on message header information and a detection table; the SKB message is periodically sent to the software packet receiving entrance of the next-generation firewall; the next-generation firewall performs multiple security checks on the SKB message based on a preset policy; the detection results of the multiple security checks are stored in the detection table; abnormal software modules are determined based on the detection results in the detection table; an alarm log is generated based on the abnormal software module to automatically notify the user. In this way, each software module of the forwarding path in the next-generation firewall can be automatically detected, and the abnormal module can be automatically recorded, so that the network can be automatically and quickly restored when a firewall failure occurs, and the cause of the failure can also be provided to improve diagnostic efficiency.

[0022] It should be understood that the foregoing general description and the following detailed description are merely illustrative and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] The above and other objects, features, and advantages of the present application will become more apparent by describing in detail exemplary embodiments thereof with reference to the accompanying drawings. The drawings described below are merely some embodiments of the present application, and it is apparent to those skilled in the art that other drawings can be derived from these drawings without inventive effort.

[0024] FIG1 is a flow chart showing an automatic detection method for a next generation firewall according to an exemplary embodiment.

[0025] Fig. 2 is a flow chart showing an automatic detection method for a next generation firewall according to another exemplary embodiment.

[0026] Fig. 3 is a flow chart showing an automatic detection method for a next generation firewall according to another exemplary embodiment.

[0027] Fig. 4 is a block diagram showing an automatic detection device for a next generation firewall according to an exemplary embodiment.

[0028] Fig. 5 is a block diagram of an electronic device according to an exemplary embodiment.

[0029] Fig. 6 is a block diagram showing a computer-readable medium according to an exemplary embodiment. DETAILED DESCRIPTION

[0030] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be embodied in many forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete and will fully convey the concepts of the example embodiments to those skilled in the art. Like reference numerals in the drawings represent like or similar parts, and thus repetitive description thereof will be omitted.

[0031] In addition, described feature, structure or characteristic can be combined in one or more embodiments in any suitable manner.In the following description, many specific details are provided so as to provide a full understanding of the embodiments of the present application. However, it will be appreciated by those skilled in the art that the technical scheme of the present application can be put into practice without one or more of the specific details, or other methods, components, devices, steps etc. can be adopted. In other cases, known methods, devices, implementations or operations are not shown or described in detail to avoid blurring the various aspects of the application.

[0032] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically separate entities. That is, these functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0033] The flowcharts shown in the accompanying drawings are for illustrative purposes only and do not necessarily include all contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps may be decomposed, while others may be combined or partially combined. Therefore, the actual execution order may vary depending on the actual situation.

[0034] It should be understood that although the terms first, second, third, etc. may be used herein to describe various components, these components should not be limited by these terms. These terms are used to distinguish one component from another. Thus, the first component discussed below could be referred to as the second component without departing from the teachings of the present invention. As used herein, the term "and / or" includes any one and all combinations of one or more of the associated listed items.

[0035] Those skilled in the art will understand that the drawings are merely schematic diagrams of example embodiments, and the modules or processes in the drawings are not necessarily necessary for implementing the present application, and therefore cannot be used to limit the scope of protection of the present application.

[0036] The technical abbreviations involved in this application are explained as follows:

[0037] Next-generation firewalls (NGFWs) are high-performance firewalls that comprehensively address application-layer threats. Building upon the fundamental functions of traditional firewalls (packet filtering, NAT translation, protocol stateful inspection, VPN, etc.), they offer new security protection against application-layer attacks. While attack behavior is a macro concept, it can be broken down into multiple security services, such as attack defense, vulnerability protection, and virus protection. NGFWs integrate multiple service functions, supporting traditional routing and switching features alongside traditional firewall features, as well as a rich set of application-layer security protection capabilities.

[0038] In this application, the next-generation firewall functions are mainly divided into three parts: routing and switching functions (layer 2 and 3 forwarding), traditional FW functions (packet filtering, NAT, protocol status inspection, blacklist and whitelist, VPN, etc.) and application security protection functions (traffic cleaning, vulnerability protection, website protection, attack defense, virus protection, threat intelligence blocking, application access control, bandwidth management, behavior management, etc.).

[0039] Routing and switching function: The present invention mainly refers to the second / third layer forwarding, which is the function of forwarding by matching the MAC table / routing table.

[0040] Traditional FW functions: This invention mainly involves security domains, packet filtering, NAT, protocol status detection, and blacklists and whitelists.

[0041] Application security protection function: The present invention mainly involves traffic cleaning, vulnerability protection, website protection, attack defense, virus protection, threat intelligence blocking, application access control, bandwidth management, and behavior management.

[0042] SKB message: SKB is the abbreviation of the socket buffer (sk_buff), a key data structure in the Linux TCP / IP protocol stack, which represents the header information of received or sent data packets. In this application, SKB messages mainly refer to messages forwarded by the NGFW, which contain the complete header information and data information of the message.

[0043] The applicants in this case discovered that the current main technical solutions rely on developing their own debugging methods for each software module, or using software tracking and packet capture after a fault occurs, to identify the fault and then circumvent it by bypassing the software module or modifying the configuration. Existing technical solutions can only diagnose network faults after they occur, and the numerous NGFW software modules make troubleshooting difficult and time-consuming.

[0044] In view of this, the present application proposes an automatic detection method for the next-generation firewall, which regularly simulates the SKB message through the complete software forwarding process through software. If an abnormal situation occurs, the abnormal software module will be automatically BYPASSed and the abnormal situation information will be recorded. The detected SKB messages are mainly ICMP and TCP messages. Each detection of ICMP messages includes request and reply messages. Each TCP detection is a three-way handshake. The header information of the message (layer 2 MAC header, VLAN tag header, layer 3 IP header, layer 4 port number) is filtered out according to the second and third layer forwarding table items combined with security domains, packet filtering, NAT, and black and white lists. The present application can solve the problem that NGFW network troubleshooting is difficult and cannot be quickly restored. The content of the present application is described in detail below with the help of specific embodiments.

[0045] Fig. 1 is a flow chart showing an automatic detection method for a next generation firewall according to an exemplary embodiment. The automatic detection method 10 for a next generation firewall includes at least steps S102 to S112.

[0046] As shown in Figure 1, in S102, an SKB message is generated based on the message header information and the detection table. For example, the message header information can be generated using the configuration information of the next-generation firewall; the detection table fields are determined based on the table entries in the detection table; and the SKB message is generated based on the message header information and the detection table fields.

[0047] In S104, the SKB message is sent to the software packet receiving entrance of the next generation firewall at a fixed time. The network card driver sends the SKB message to the software packet receiving entrance of the next generation firewall at a fixed time.

[0048] More specifically, for example, a timer task can be implemented in the driver to periodically send SKB packets to the firewall. This can be done by using the timer mechanism provided by the Linux kernel, such as the mod_timer function. Alternatively, a network protocol processing function can be registered to pass the SKB to the firewall software's packet receiving entry.

[0049] In S106, the next-generation firewall performs multiple security checks on the SKB message based on a preset policy. For example, the next-generation firewall may perform a message legitimacy check on the SKB message; another example, the next-generation firewall may match a Layer 2 or Layer 3 table entry for the SKB message; another example, the next-generation firewall may match a destination NAT for the SKB message; another example, the next-generation firewall may perform a protocol state check on the SKB message; another example, the next-generation firewall may match a blacklist or whitelist for the SKB message; another example, the next-generation firewall may perform a security domain check on the SKB message; another example, the next-generation firewall may match a packet filter for the SKB message; another example, the next-generation firewall may perform a security protection check on the SKB message.

[0050] In one embodiment, the method further includes discarding the SKB message after multiple security checks are completed. After the SKB message completes the last check item, the message is discarded to avoid affecting normal message forwarding.

[0051] In this application, the software modules mainly include routing and switching functions (MAC table / routing table matching), traditional FW functions (security domain, packet filtering, NAT, protocol status detection, black and white lists), and application security protection functions (traffic cleaning, vulnerability protection, website protection, attack defense, virus protection, threat intelligence blocking, application access control, bandwidth management, and behavior management).

[0052] In S108, the detection results of the multiple safety tests are stored in the detection table. For example, during the detection process of the multiple safety tests, a detection flag is determined according to the detection items; and the detection flag is updated according to the detection results. The detection flag includes: 1 and 0.

[0053] In S110, abnormal software modules are identified based on the detection results in the detection table. For example, query and filtering rules can be developed based on the abnormality conditions to extract records related to the abnormality from the detection table. For example, records marked as 1 or with error codes within a certain range can be filtered out. The abnormal records are associated with specific software modules. The software module with the abnormal forwarding result is determined using a number or other identifier.

[0054] In a specific application scenario, after the probe message completes the last forwarding module, the bypass mark is set for the software module marked with an abnormality according to the probe table information in the SKB, and the probe table information log is notified to the user. Subsequent business messages skip the corresponding module. Among them, the routing switching function and NAT module cannot be skipped because they involve forwarding path queries and can only be logged.

[0055] In S112, an alarm log is generated based on the abnormal software module to automatically notify the user. The alarm log is generated according to the identifier of the abnormal software module, the detection table number, and the error code; and the alarm log is automatically sent to the associated user.

[0056] More specifically, the alarm log can contain detailed information about each exception, including the software module identifier, occurrence time, and error code. Further in-depth analysis can be performed to determine the root cause of the exception. This may involve reviewing relevant logs, reviewing the software module code, and debugging.

[0057] In actual applications, appropriate measures can be taken to resolve the problem based on the results of the anomaly analysis, which may include fixing errors in software modules, optimizing configurations, and updating software versions.

[0058] According to the automatic detection method for a next-generation firewall of the present application, an SKB message is generated based on message header information and a detection table; the SKB message is periodically sent to a software packet receiving entrance of the next-generation firewall; the next-generation firewall performs multiple security checks on the SKB message based on a preset policy; the detection results of the multiple security checks are stored in the detection table; abnormal software modules are determined based on the detection results in the detection table; an alarm log is generated based on the abnormal software module to automatically notify the user, thereby automatically detecting each software module in the forwarding path of the next-generation firewall and automatically recording the abnormal module, so that the network can be automatically and quickly restored when a firewall failure occurs, and the cause of the failure can also be provided to improve diagnostic efficiency.

[0059] The automated detection method for next-generation firewalls described in this application establishes a continuous monitoring mechanism to ensure timely detection and resolution of anomalies. This can include regular analysis of detection tables and the setting of automatic alerts. Based on the results of continuous monitoring, the anomaly detection system can be optimized and improved. This may require adjusting anomaly conditions and refining data analysis methods.

[0060] It should be clearly understood that this application describes how to form and use specific examples, but the principles of this application are not limited to any details of these examples. On the contrary, based on the teaching of the content disclosed in this application, these principles can be applied to many other embodiments.

[0061] Figure 2 is a flow chart of an automatic detection method for a next generation firewall according to an exemplary embodiment. The process 20 shown in Figure 2 is a detailed description of S102 "generating an SKB message based on message header information and a detection table" in the process shown in Figure 1.

[0062] As shown in Figure 2, in S202, the packet header information is generated by using the configuration information of the next generation firewall. The forwarding software module identifier and forwarding principle can be extracted from the configuration information of the next generation firewall; and the packet header information is generated based on the software module identifier and forwarding principle.

[0063] In one embodiment, the header information of the detection message can be filtered out through configuration information so that the detection packet sending module can assemble the detection message. The screening principle is that the message must be able to pass through all forwarding software modules, such as complying with the security domain forwarding principle, packet filtering, the existence of second and third layer table entries, and matching NAT if it is third layer.

[0064] In S204, the detection table fields are determined according to the entries in the detection table.

[0065] In actual applications, the probe table can be used to record the results of the probe message forwarding process. The format of the probe table is as follows. The number, tag, and error code in the probe table can fully record the forwarding results of each module. The SKB adds a probe table field to store this table entry.

[0066] Number: The code corresponds to each software module one by one. The number can be used to confirm whose forwarding result the current record is.

[0067] Flag: The flag indicates whether the message is abnormal. 0 indicates normal forwarding, and 1 indicates abnormal forwarding.

[0068] Error code: The error code represents the error type and is set by each module. It can serve as data support for subsequent problem analysis.

[0069] The following is an example of a probe table:

[0070] In S206, the SKB message is generated using the message header information and the detection table fields. For example, data segment information is determined; a detection identifier is determined; and the message header information, the data segment information, the detection table fields, and the detection identifier are assembled to generate the SKB message.

[0071] Assemble the messages to form a complete SKB. The complete SKB mainly includes:

[0072] Message header segment: The message header information filtered out by the message header filtering module is filled into the SKB message header part.

[0073] Data segment: ICMP request and reply and TCP three-way handshake (SYN / SY N ACK / ACK).

[0074] Detection table field: SKB adds a new detection table field and fills the detection table into SKB.

[0075] Detection flag: SKB adds a new detection flag with a value of 1, indicating that this is a detection message.

[0076] The assembled message (SKB) is sent to the software forwarding entrance (simulating business message) by the network card driver at regular intervals.

[0077] Fig. 3 is a flow chart showing an automatic detection method for a next generation firewall according to another exemplary embodiment. The process 30 shown in Fig. 3 is a detailed description of S102 in the process shown in Fig. 2 .

[0078] As shown in FIG3 , in S302 , the message header information of the detection message is filtered out.

[0079] In S304, detection entry data is prepared.

[0080] In S306, the message header segment, data segment, detection table field, and detection identifier are assembled into an SKB message, and the network card driver sends it to the software packet receiving entrance at regular intervals.

[0081] In S308, it is determined whether the forwarding is layer 2 or layer 3.

[0082] In S310, if it is a Layer 2 connection, the MAC table entry is matched, the egress information is filled into the SKB, and the matching result is stored in the detection table of the SKB;

[0083] In S312, the destination NAT is matched, the destination NAT translation is performed, and the result is stored in the detection table of the SKB.

[0084] In S314, the routing table structure is matched, and the matching result is stored in the detection table of the SKB.

[0085] In S316, the protocol status is detected and the result is stored in the detection table of the SKB.

[0086] In S318 , the blacklist and whitelist are matched, and the result is stored in the detection table of the SKB.

[0087] In S320, the security domain is detected and the result is stored in the detection table of the SKB.

[0088] In S322, the matching packet is filtered and the result is stored in the detection table of the SKB.

[0089] In S324, other security protection detections may include, for example, traffic cleaning, vulnerability protection, website protection, attack defense, virus protection, threat intelligence blocking, application access control, bandwidth management, behavior management, etc., and the results are stored in the detection table of the SKB.

[0090] In S326, it is determined whether the forwarding is layer 2 or layer 3.

[0091] In S328, source NAT is matched, source NAT translation is performed, and the result is stored in the detection table of the SKB.

[0092] In S330, the automatic bypass module detects the detection table in the SKB. When the mark is 1, it is considered that the software module corresponding to the number is abnormal, and the software module is set to the bypass mark. The detection table number, mark, and error code are notified to the user through the log.

[0093] In S332, the detection flag of SKB is detected. If it is 1, 330 is set.

[0094] According to the automatic detection method for the next-generation firewall of the present application, the message header, ICMP / TCP data content, detection table, and detection identifier are screened and automatically assembled, so that the faulty software module can be automatically bypassed and the fault information can be notified based on the detection table results.

[0095] Those skilled in the art will appreciate that all or part of the steps implementing the above embodiments can be implemented as a computer program executed by a CPU. When executed by the CPU, the computer program performs the functions defined in the above method provided herein. The program can be stored in a computer-readable storage medium, such as a read-only memory, a magnetic disk, or an optical disk.

[0096] Furthermore, it should be noted that the aforementioned figures are merely illustrative of the processes included in the methods according to exemplary embodiments of the present application and are not intended to be limiting. It is readily understood that the processes illustrated in the aforementioned figures do not indicate or limit the temporal order of these processes. Furthermore, it is readily understood that these processes may be executed synchronously or asynchronously, for example, in multiple modules.

[0097] The following are device embodiments of the present application, which can be used to implement the method embodiments of the present application. For details not disclosed in the device embodiments of the present application, please refer to the method embodiments of the present application.

[0098] Figure 4 is a block diagram of an automatic detection device for a next-generation firewall, according to an exemplary embodiment. As shown in Figure 4, the automatic detection device 40 for a next-generation firewall includes: a message module 402, a generation module 404, a detection module 406, a storage module 408, a detection module 410, and an alarm module 412.

[0099] The message module 402 is used to generate an SKB message based on the message header information and the detection table; the message module 402 is also used to generate the message header information through the configuration information of the next-generation firewall; determine the detection table field according to the table entry of the detection table; and generate the SKB message through the message header information and the detection table field.

[0100] The generating module 404 is used to send the SKB message to the software packet receiving entrance of the next generation firewall at a regular time; the generating module 404 is also used to control the network card driver to send the SKB message to the software packet receiving entrance of the next generation firewall at a regular time.

[0101] The detection module 406 is used for the next-generation firewall to perform multiple security checks on the SKB message based on preset policies; the detection module 406 is also used to control the next-generation firewall to perform message legitimacy verification on the SKB message; the detection module 406 is also used to control the next-generation firewall to match the second-layer or third-layer table entry for the SKB message; the detection module 406 is also used to control the next-generation firewall to match the destination NAT for the SKB message; the detection module 406 is also used to control the next-generation firewall to perform protocol status detection on the SKB message; the detection module 406 is also used to control the next-generation firewall to match the blacklist and whitelist for the SKB message; the detection module 406 is also used to control the next-generation firewall to perform security domain detection on the SKB message; the detection module 406 is also used to control the next-generation firewall to match packet filtering for the SKB message; the detection module 406 is also used to control the next-generation firewall to perform security protection detection for the SKB message.

[0102] The storage module 408 is used to store the detection results of the multiple safety tests in the detection table; the storage module 408 is also used to determine the detection identifier according to the detection items during the detection process of the multiple safety tests; and update the detection identifier according to the detection results, the detection identifier including: 1 and 0.

[0103] The detection module 410 is used to determine abnormal software modules based on the detection results in the detection table;

[0104] The alarm module 412 is used to generate an alarm log based on the abnormal software module to automatically notify the user. The alarm module 412 is also used to generate an alarm log according to the identification, detection table number, and error code of the abnormal software module; and automatically send the alarm log to the associated user.

[0105] According to the automatic detection device for a next-generation firewall of the present application, an SKB message is generated based on message header information and a detection table; the SKB message is periodically sent to the software packet receiving entrance of the next-generation firewall; the next-generation firewall performs multiple security checks on the SKB message based on a preset strategy; the detection results of the multiple security checks are stored in the detection table; abnormal software modules are determined based on the detection results in the detection table; an alarm log is generated based on the abnormal software module to automatically notify the user, thereby automatically detecting each software module in the forwarding path of the next-generation firewall and automatically recording the abnormal module, so that the network can be automatically and quickly restored when a firewall failure occurs, and the cause of the failure can also be provided to improve diagnostic efficiency.

[0106] Fig. 5 is a block diagram of an electronic device according to an exemplary embodiment.

[0107] The electronic device 500 according to this embodiment of the present application is described below with reference to Figure 5. The electronic device 600 shown in Figure 5 is only an example and should not bring any limitation to the functions and scope of use of the embodiment of the present application.

[0108] As shown in FIG5 , electronic device 600 is implemented as a general-purpose computing device. Components of electronic device 600 may include, but are not limited to, at least one processing unit 610, at least one storage unit 620, a bus 630 connecting various system components (including storage unit 620 and processing unit 610), a display unit 640, and the like.

[0109] The storage unit stores program code, which can be executed by the processing unit 610 to enable the processing unit 610 to perform the steps described in this specification according to various exemplary embodiments of the present application. For example, the processing unit 610 can perform the steps shown in Figures 2, 3, and 4.

[0110] The storage unit 620 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 6201 and / or a cache memory unit 6202 , and may further include a read-only memory unit (ROM) 6203 .

[0111] The storage unit 620 may also include a program / utility 6204 having a set (at least one) of program modules 6205, such program modules 6205 including but not limited to: an operating system, one or more application programs, other program modules and program data, each of which or some combination may include an implementation of a network environment.

[0112] Bus 630 may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0113] The electronic device 600 can also communicate with one or more external devices 600' (e.g., a keyboard, a pointing device, a Bluetooth device, etc.), devices that allow a user to interact with the electronic device 600, and / or any device that allows the electronic device 600 to communicate with one or more other computing devices (e.g., a router, a modem, etc.). This communication can occur via an input / output (I / O) interface 650. Furthermore, the electronic device 600 can communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network such as the Internet) via a network adapter 660. The network adapter 660 can communicate with other modules of the electronic device 600 via the bus 630. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in conjunction with the electronic device 600, including but not limited to microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0114] Through the description of the above embodiments, it is easy for those skilled in the art to understand that the example embodiments described here can be implemented by software or by combining software with necessary hardware. Therefore, as shown in Figure 6, the technical solution according to the embodiment of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, or a network device, etc.) to execute the above method according to the embodiment of the present application.

[0115] In general, the present disclosure is mainly to solve the difficulty of troubleshooting NGFW network faults and the inability to recover quickly. The present invention provides a solution that can automatically detect and escape. The detection mainly covers software modules, mainly routing and switching functions (MAC table / routing table matching), traditional FW functions (security domain, packet filtering, NAT, protocol status detection, black and white lists), and application security protection functions (traffic cleaning, vulnerability protection, website protection, attack defense, virus protection, threat intelligence blocking, application access control, bandwidth management, and behavior management). (1) The network card driver parses the message into SKB and enters the software forwarding entrance. (2) Message legitimacy detection, such as VLAN tag, layer 2 header, layer 3 header, etc. (3) Determine whether it is layer 2 or layer 3. If it is layer 2, match the MAC table entry and fill the export information into the SKB, and then execute step (5). If it is layer 3, match the routing table entry and fill the export information into the SKB, and then execute step (4). (4) Match the destination NAT. If the match is successful, perform destination NAT conversion. (5) Protocol status detection, mainly ICMP and TCP. (6) Match the black and white list. (7) Security domain detection. (8) Matching packet filtering. (9) Carry out traffic cleaning -> vulnerability protection -> website protection -> attack defense -> virus protection -> threat intelligence blocking -> application access control -> bandwidth management -> behavior management in sequence. (10) If it is judged as layer 3 in step (3), match source NAT. If the match is successful, perform source NAT conversion. (11) The network card driver parses the SKB into a data frame format and sends it out. The software simulates the SKB message through the complete software forwarding process at regular intervals. If an abnormality occurs, the abnormal software module is automatically BYPASSed and the abnormality information is recorded. The detected SKB messages are mainly ICMP and TCP messages. Each ICMP message detection includes request and reply messages. Each TCP detection is a three-way handshake. The header information of the message (layer 2 MAC header, VLAN tag header, layer 3 IP header, layer 4 port number) is filtered out according to the layer 2 and layer 3 forwarding table entries combined with security domains, packet filtering, NAT, and black and white lists. The message header filtering module is primarily responsible for filtering the message header information of the probe message through the configuration information, so that the probe packet sending module can assemble the probe message. The principle of screening is that the message must be able to pass through all forwarding software modules. For example, it must comply with the security domain forwarding principle, pass the packet filter, have the second and third layer table entries, and match NAT if it is the third layer. The detection table module is primarily responsible for recording the results of the probe message during the forwarding process. The format of the detection table is as shown in the table below. The number, tag, and error code in the detection table can fully record the forwarding results of each module. The SKB will add a detection table field to store the table entry. Number: The code corresponds to each software module one by one. The number can be used to confirm whose forwarding result is currently recorded. Tag: The tag represents whether it is abnormal. 0 represents normal forwarding and 1 represents forwarding abnormality.Error Code: The error code represents the error type and is determined by each module. It can serve as data support for subsequent problem analysis. The probe packet sending module is primarily responsible for assembling packets to form a complete SKB. A complete SKB primarily consists of: Header: The header information filtered by the header filtering module is populated into the SKB header. Data: The ICMP request and reply, as well as the TCP three-way handshake (SYN / SYN ACK / ACK). Probe Table Field: A new probe table field is added to the SKB, which populates the probe table. Probe Flag: A new probe flag is added to the SKB, with a value of 1, indicating that this is a probe message. The assembled message (SKB) is periodically sent by the network card driver to the software forwarding entry (simulating a service message). After a probe message completes the last forwarding module, the automatic bypass module, based on the probe table information in the SKB, sets the bypass flag for any software modules marked as abnormal and logs the probe table information to the user. Subsequent service messages bypass the corresponding modules. Routing and switching functions and NAT modules cannot be bypassed because they involve forwarding path queries; they can only be logged. The packet loss detection module is mainly responsible for detecting the packet loss of the forwarded detection message. After completing the last check item, the message will be discarded to avoid affecting the normal message forwarding. The present disclosure includes the following processes: (1) The message header screening module filters out the message header information of the detection message. (2) The detection table module formulates the detection table item data. (3) The detection packet sending module assembles the message header segment, data segment, detection table field, and detection identifier into SKB and sends it to the software packet receiving entrance at a fixed time by the network card driver. (*******Start detection (If the module abnormally loses packets and the matching detection identifier is 1, the packet loss will be skipped and the subsequent modules will be detected)********)(4) Determine the second-layer or third-layer forwarding. If it is the second layer, match the MAC table item and fill the export information into the SKB. The matching result is stored in the detection table of the SKB, and then execute (6). If it is the third layer, match the MAC table item and fill the export information into the SKB. The matching result is stored in the detection table of the SKB, and then execute (5). (5) Match destination NAT, perform destination NAT conversion, and store the result in the SKB detection table. (6) Perform protocol status detection and store the result in the SKB detection table. (7) Match blacklist and whitelist, and store the result in the SKB detection table. (8) Perform security domain detection and store the result in the SKB detection table. (9) Match packet filtering and store the result in the SKB detection table. (10) Perform traffic cleaning -> vulnerability protection -> website protection -> attack defense -> virus protection -> threat intelligence blocking -> application access control -> bandwidth management -> behavior management in sequence, and store the results in the SKB detection table respectively. (11) If (4) is judged as layer 3, match source NAT, perform source NAT conversion, and store the result in the SKB detection table.(12) The automatic bypass module checks the detection table in the SKB. If the flag is 1, the software module corresponding to the number is considered abnormal, the bypass flag is set for the software module, and the detection table number, flag, and error code are notified to the user through the log. (13) The packet loss detection module checks the detection flag of the SKB. If it is 1, the message is discarded.

[0116] The software product can be any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, a system, device or component of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination thereof. More specific examples (non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.

[0117] The computer-readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, wherein the readable program code is carried. The data signal propagated may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. The readable storage medium may also be any readable medium other than a readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, device, or component. The program code contained on the readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination thereof.

[0118] The program code for performing the operations of the present application can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, C++, etc., and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0119] The computer-readable medium carries one or more programs. When the one or more programs are executed by a device, the computer-readable medium implements the following functions: generating an SKB message based on message header information and a detection table; regularly sending the SKB message to a software packet receiving entrance of a next-generation firewall; the next-generation firewall performs multiple security checks on the SKB message based on preset policies; storing the detection results of the multiple security checks in the detection table; determining an abnormal software module based on the detection results in the detection table; and generating an alarm log based on the abnormal software module to automatically notify a user.

[0120] Those skilled in the art will appreciate that the modules described above can be distributed in the device according to the description of the embodiment, or can be modified accordingly to be used in one or more devices that are different from the embodiment. The modules of the above embodiment can be combined into one module or further divided into multiple submodules.

[0121] Through the description of the above embodiments, it is easy for those skilled in the art to understand that the example embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solution according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present application.

[0122] While the exemplary embodiments of the present application have been specifically illustrated and described above, it should be understood that the present application is not limited to the detailed structures, configurations, or implementations described herein; rather, the present application is intended to encompass various modifications and equivalent configurations within the spirit and scope of the appended claims.

Claims

1. An automatic detection method for next-generation firewalls, characterized in that, It includes: Generate an SKB packet based on the packet header information and the detection table; Periodically send the SKB packet to the software packet receiving entry of the next-generation firewall; The next-generation firewall performs multiple security detections on the SKB packet based on a preset policy; Store the detection results of the multiple security detections in the detection table; Determine an abnormal software module based on the detection results in the detection table; Generate an alarm log based on the abnormal software module to automatically notify the user.

2. The method according to claim 1, characterized in that, Generating an SKB packet based on the packet header information and the detection table includes: Generate packet header information through the configuration information of the next-generation firewall; Determine the detection table fields according to the entries of the detection table; Generate the SKB packet through the packet header information and the detection table fields.

3. The method according to claim 2, wherein Generating packet header information through the configuration information of the next-generation firewall includes: Extract the forwarding software module identifier and forwarding principle through the configuration information of the next-generation firewall; Generate the packet header information through the software module identifier and the forwarding principle.

4. The method according to claim 2, characterized in that Generating the SKB packet through the packet header information and the detection table fields includes: Determine the data segment information; Determine the detection identifier; Assemble the packet header information, the data segment information, the detection table fields, and the detection identifier to generate the SKB packet.

5. The method according to claim 1, wherein Periodically sending the SKB packet to the software packet receiving entry of the next-generation firewall includes: The network card driver periodically sends the SKB packet to the software packet receiving entry of the next-generation firewall.

6. The method according to claim 1, wherein The next-generation firewall performs multiple security detections on the SKB packet based on a preset policy, including: The next-generation firewall performs packet legality verification on the SKB packet; and / or The next-generation firewall matches the SKB packet with layer 2 or layer 3 entries; and / or The next-generation firewall matches the SKB packet with the destination NAT; and / or The next-generation firewall performs protocol status detection on the SKB packet; and / or The next-generation firewall matches the SKB packet with the black and white lists; and / or The next-generation firewall performs security domain detection on the SKB packet; and / or The next-generation firewall matches the SKB packet with packet filtering; and / or The next-generation firewall performs security protection detection on the SKB packet.

7. The method according to claim 1, wherein Storing the detection results of the multiple security detections in the detection table includes: During the detection process of the multiple security detections, determine the detection identifier according to the detection items; Update the detection identifier according to the detection results, and the detection identifier includes: 1 and 0.

8. The method according to claim 1, wherein Generating an alarm log based on the abnormal software module to automatically notify the user includes: Generate an alarm log according to the identifier of the abnormal software module, the detection table number, and the error code; Automatically send the alarm log to the associated user.

9. The method according to claim 1, characterized in that, It also includes: After the multiple security detections are completed, discard the SKB packet.

10. An automatic detection device for a next-generation firewall, characterized in that, It includes: A packet module for generating an SKB packet based on the packet header information and the detection table; A sending module for periodically sending the SKB packet to the software packet receiving entry of the next-generation firewall; A detection module for the next-generation firewall to perform multiple security detections on the SKB packet based on a preset policy; A storage module for storing the detection results of the multiple security detections into the detection table; A detection module for determining an abnormal software module based on the detection results in the detection table; An alarm module for generating an alarm log based on the abnormal software module to automatically notify the user.

Citation Information

Patent Citations

  • Firewall system, safety service platform and firewall system management method

    CN101610264A

  • Method and device for automatically testing application layer protocol

    CN101707608A

  • Wireless network security defense method based on software-defined security

    CN110366170A

  • Security detection method and device, electronic equipment and storage medium

    CN115694998A

  • Automatic detection method and device for next-generation firewall

    CN117955715A

Cited By

  • Automatic detection method and device for next-generation firewall

    CN117955715A

  • Automatic detection method and apparatus for next generation firewall

    CN117955715B