The invention relates to a method for automatically extracting and analyzing firewall logs based on an
XML rule model. The method includes the following steps of defining
XML log analysis templates, automatically extracting the firewall logs and analyzing the firewall logs. According to the method, quintuple information of time, a source
IP address, a source port, a destination
IP address and a destination port contained in each log is extracted. The
XML templates are formulated according to the structural features of each type of firewall log files,
record type defined feature identification contained in the firewall log files is contained in the XML template, according to the identification, the firewall log files are extracted, the quintuple information in the firewall logs is automatically identified, and whether the operating state of a destination device is normal or not is automatically judged according to predefined safety rules. By the adoption of the method, a large amount of firewall log information can be automatically rapidly extracted, abnormal network access behaviors are analyzed, and a basis is provided for network safety analysis and management.