This invention relates to a firewall
data processing method based on
endpoint security protection. It establishes an endpoint
connection management mechanism, maintains an active
connection table and a state hook mapping table, and associates outbound connections with process identifiers, user identities, data
payload summaries, and creation times to form state hooks. Hook
verification is triggered when the endpoint state changes. If sensitive
privilege escalation or behavior deviating from the initial digest is detected, the connection priority is dynamically adjusted, and
rate limiting, blocking, or transition to observation mode is implemented. Access path consistency
verification is performed on outbound connections, comparing DNS requests, process calls, and actual packet paths. If unexplained path offsets exist, the source is traced and the path is reconstructed. Connection behavior is periodically split according to
operating system event
granularity, and concurrent or abrupt behavior is logically redefined into multiple sub-sessions with corresponding policies applied. Transmission delays are applied to reversible connection operations, and action chain tracing is activated to determine whether to restore or terminate the connection.