This invention discloses an
access control policy generation method, device, and medium, relating to the field of
computer technology. The method includes: acquiring
raw data packets, identifying their corresponding protocols, and distributing them to appropriate parsers based
on protocol type, enabling the parsers to parse the data and obtain standardized events; collecting multi-source raw logs from various nodes,
parsing and extracting log
metadata, combining the
metadata with the corresponding log content for
rule matching and structuring; collecting hardware health indicators and monitoring service response status, summarizing the data and performing comprehensive indicator analysis to filter and classify status events; and after cleaning, compression, and
authentication, associating and fusing the cleaned and compressed data to generate
access control policies. This approach constructs a three-dimensional cross-validation
system for security events from the network, host, and application perspectives, reducing
false positives and false negatives, providing a reliable basis for policy generation, improving policy generation efficiency, and enhancing the accuracy and efficiency of
system security protection.