WO2020258991A1 - 安全组策略管理方法、装置、设备及计算机可读存储介质 - Google Patents

安全组策略管理方法、装置、设备及计算机可读存储介质 Download PDF

Info

Publication number
WO2020258991A1
WO2020258991A1 PCT/CN2020/084226 CN2020084226W WO2020258991A1 WO 2020258991 A1 WO2020258991 A1 WO 2020258991A1 CN 2020084226 W CN2020084226 W CN 2020084226W WO 2020258991 A1 WO2020258991 A1 WO 2020258991A1
Authority
WO
WIPO (PCT)
Prior art keywords
security group
group policy
security
policy
management
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2020/084226
Other languages
English (en)
French (fr)
Inventor
蒋国梁
邹丽丽
邓丽铭
张英
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
WeBank Co Ltd
Original Assignee
WeBank Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by WeBank Co Ltd filed Critical WeBank Co Ltd
Publication of WO2020258991A1 publication Critical patent/WO2020258991A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/101Access control lists [ACL]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/20Network architectures or network communication protocols for network security for managing network security; network security policies in general

Definitions

  • This application relates to the network security field of Fintech, and in particular to a security group policy management method, device, device, and computer-readable storage medium.
  • the cloud service platform is a new enterprise information service model and management method, which can manage massive and highly virtualized enterprise resources and applications to form a unified service that integrates resource pools and enterprise applications.
  • the security group on the cloud service platform of financial institutions such as banks is implemented based on local firewalls. Its use is essentially different from traditional network layer firewalls, and the correspondence between policies and cloud hosts is extremely complex. As time goes by, As more and more new systems go online, there will be more and more security group policies on the cloud. In view of the fact that the security group policy can directly affect the network security of the corporate public cloud, the eligibility of the security group policy is extremely important. The existing audit of the compliance of the security group policy is manually reviewed one by one. In the face of a large number of security group policies, it is impossible to make a comprehensive and automated audit of the compliance of the security group policy.
  • the main purpose of this application is to provide a security group policy management method, device, device, and readable storage medium, aiming to solve the technical problem that the prior art cannot perform a comprehensive automated audit of the security group policy compliance.
  • the present application provides a security group policy management method, which includes the following steps:
  • the source IP in the security group policy matches the corresponding source area, and the target IP matches the corresponding target area;
  • the security group policy is security controlled.
  • the method before the step of matching the source IP in the security group policy to the corresponding source area and the target IP matching the corresponding target area according to the preset area mapping relationship, the method further includes:
  • the step is performed: according to the preset area mapping relationship, the source IP and the target IP in the security group policy match the corresponding area.
  • the method before the step of matching the source IP in the security group policy to the corresponding source area and the target IP matching the corresponding target area according to the preset area mapping relationship, the method further includes:
  • the security group policy includes a offline IP, then the security group policy is offline.
  • the step of judging whether the security group policy is in violation according to preset audit rules, the source area and the target area includes:
  • the source area is not included in the preset audit rules, or the target area is not included in the preset audit rules, or a preset corresponding to the source area in the preset audit rules If the target area does not include the target area, it is determined that the security group policy is not in violation;
  • the preset audit rule includes the source area and the target area, and the preset target area corresponding to the source area in the preset audit rule includes the target area, determine that the Security group policy violation.
  • the step of performing security management and control on the security group policy includes:
  • the step of performing security management and control on the security group policies in the deduplication violation policy alarm table includes:
  • the security management and control content includes adding the security group policy to the whitelist, Suspend the security group policy or raise an IT service management ITSM work order for the security group policy.
  • the method further includes:
  • the security control situation of the security group policy in the violation policy alarm table is counted to obtain the completion rate of management and control and the time rate of management and control.
  • the number of security group policies that have been security controlled in the violation policy alarm table is divided by
  • the total number of security group policies in the violation policy alarm table is the control completion rate, and the number of security group policies in the violation policy alarm table that perform security management and control within a preset time period divided by the violation policy alarm table
  • the total number of security group policies is the time rate of management and control;
  • control completion rate and the control time rate are sent to a preset review terminal for review.
  • this application also provides a security group policy management device, the security group policy management device includes:
  • the matching module is used to match the source IP in the security group policy to the corresponding source area and the target IP to the corresponding target area according to the preset area mapping relationship;
  • the judgment module is used to judge whether the security group policy is in violation according to preset audit rules, the source area and the target area;
  • the management and control module is configured to perform security management and control on the security group policy if the security group policy violates regulations.
  • the present application also provides a security group policy management device.
  • the security group policy management device includes a memory, a processor, and a security device stored on the memory and running on the processor.
  • a group policy management program which implements the steps of the above-mentioned security group policy management method when the security group policy management program is executed by the processor.
  • the present application also provides a computer-readable storage medium having a security group policy management program stored on the computer-readable storage medium, and when the security group policy management program is executed by a processor, the above The steps of the security group policy management method.
  • the source IP in the security group policy matches the corresponding source area and the target IP according to the preset area mapping relationship, and the target IP matches the corresponding target area; the security group is determined according to the preset audit rules, the source area and the target area. Whether the policy violates the regulations; if the security group policy violates the regulations, security management and control are performed on the security group policy. Automatically determine whether the security group policy is in violation according to the source IP, the area to which the target IP belongs and the preset audit rules in the security group policy, so that when the security group policy violates the security group policy, the security control is automatically initiated to realize the The automated audit of security group policies improves the audit efficiency of security group policies, so that a large number of security group policies can be audited comprehensively.
  • FIG. 1 is a schematic structural diagram of the device hardware operating environment involved in the solution of the security group policy management device embodiment of this application;
  • FIG. 3 is a schematic diagram of the functional modules of the security group policy management device of this application.
  • the security groups on the cloud service platforms of banks and other financial institutions are implemented based on local firewalls, and their use is essentially different from traditional network layer firewalls, and the correspondence between the strategies and cloud hosts is extremely complicated.
  • Over time as more and more new systems go online, there will be more and more security group policies on the cloud.
  • the security group policy can directly affect the network security of the corporate public cloud, the eligibility of the security group policy is extremely important.
  • the existing audit of the compliance of the security group policy is manually reviewed one by one. In the face of a large number of security group policies, it is impossible to make a comprehensive and automated audit of the compliance of the security group policy.
  • FIG. 1 is a schematic structural diagram of a device hardware operating environment involved in an embodiment of the security group policy management device solution of this application.
  • the security group policy management device may include a processor 1001, such as a CPU, a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005.
  • the communication bus 1002 is used to implement connection and communication between these components.
  • the user interface 1003 may include a display screen (Display) and an input unit such as a keyboard (Keyboard), and the optional user interface 1003 may also include a standard wired interface and a wireless interface.
  • the network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface).
  • the memory 1005 may be a high-speed RAM memory, or a non-volatile memory (non-volatile memory), such as a magnetic disk memory.
  • the memory 1005 may also be a storage device independent of the foregoing processor 1001.
  • the hardware structure of the security group policy management device shown in FIG. 1 does not constitute a limitation on the security group policy management device, and may include more or less components than shown in the figure, or a combination of some Components, or different component arrangements.
  • a memory 1005 as a computer-readable storage medium may include an operating system, a network communication module, a user interface module, and a security group policy management program.
  • the operating system is a program that manages and controls security group policy management equipment and software resources, and supports the operation of network communication modules, user interface modules, security group policy management programs, and other programs or software;
  • network communication modules are used to manage and control the network Interface 1004:
  • the user interface module is used to manage and control the user interface 1003.
  • the network interface 1004 is mainly used to connect to the back-end server and communicate with the back-end server;
  • the user interface 1003 is mainly used to connect to the client (user side) and communicate with the client Data communication:
  • the processor 1001 can call the security group policy management program stored in the memory 1005, and perform the following operations:
  • the source IP in the security group policy matches the corresponding source area, and the target IP matches the corresponding target area;
  • the security group policy is security controlled.
  • the processor 1001 is further configured to call the security stored in the memory 1005 Group Policy Manager, and do the following:
  • the step is performed: according to the preset area mapping relationship, the source IP and the target IP in the security group policy match the corresponding area.
  • the processor 1001 is further configured to call the security stored in the memory 1005 Group Policy Manager, and do the following:
  • the security group policy includes a offline IP, then the security group policy is offline.
  • the step of judging whether the security group policy is in violation according to preset audit rules, the source area and the target area includes:
  • the source area is not included in the preset audit rules, or the target area is not included in the preset audit rules, or a preset corresponding to the source area in the preset audit rules If the target area does not include the target area, it is determined that the security group policy is not in violation;
  • the preset audit rule includes the source area and the target area, and the preset target area corresponding to the source area in the preset audit rule includes the target area, determine that the Security group policy violation.
  • the step of performing security management and control on the security group policy includes:
  • step of performing security management and control on the security group policy in the policy alarm table after deduplication includes:
  • the security management and control content includes adding the security group policy to the whitelist, Suspend the security group policy or raise an IT service management ITSM work order for the security group policy.
  • the processor 1001 is further configured to call the security group policy management program stored in the memory 1005 and perform the following operations:
  • the security control situation of the security group policy in the violation policy alarm table is counted to obtain the completion rate of management and control and the time rate of management and control.
  • the number of security group policies that have been security controlled in the violation policy alarm table is divided by
  • the total number of security group policies in the violation policy alarm table is the control completion rate, and the number of security group policies in the violation policy alarm table that perform security management and control within a preset time period divided by the violation policy alarm table
  • the total number of security group policies is the time rate of management and control;
  • control completion rate and the control time rate are sent to a preset review terminal for review.
  • This application also provides a security group policy management method.
  • the embodiments of the present application provide an embodiment of a security group policy management method. It should be noted that although the logical sequence is shown in the flowchart, in some cases, the sequence shown here can be executed in a different order. Or the steps described.
  • FIG. 2 is a schematic flowchart of a first embodiment of a security group policy management method according to this application.
  • the security group policy management method includes:
  • Step S10 According to the preset area mapping relationship, the source IP in the security group policy matches the corresponding source area, and the target IP matches the corresponding target area;
  • the security group on the cloud service platform of financial institutions such as banks is implemented based on local firewalls. Its use is essentially different from traditional network layer firewalls, and the correspondence between policies and cloud hosts is extremely complex. As time goes by, As more and more new systems go online, there will be more and more security group policies on the cloud. In view of the fact that the security group policy can directly affect the network security of the corporate public cloud, the eligibility of the security group policy is extremely important. The existing compliance audits of security group policies are manually reviewed one by one. Faced with a large number of security group policies, it is impossible to make a comprehensive automated audit of the compliance of security group policies.
  • the security group policy management device in order to perform comprehensive automated management of the security group policy, the security group policy management device first needs to match the source IP and target IP in all security group policies to their corresponding areas according to the preset area mapping relationship.
  • the preset area mapping relationship refers to the preset area (such as production area, management area, development area, etc.) divided into IP addresses by managers according to needs (such as internal network division of the enterprise), and each area is a series of IP A collection of addresses, each IP has a unique corresponding area.
  • a step of whitelisting the security group policy may be included, that is: judging Whether the security group policy is in the white list, and a preset activation policy list is stored in the white list; if the security group policy is not in the white list, step S10 is executed. That is, after obtaining all the security group policies, the security group policy management device can first determine whether the security group policy hits the preset activation policy list in the whitelist.
  • the preset activation policy list is customized and must be activated according to the needs of the administrator Security group policy list, if the security group policy hits the preset activation policy list in the white list, that is, the security group policy is in the white list, no subsequent security group policy management operations will be performed on the policy; if the security group policy does not hit the white list
  • a step of performing offline IP filtering on the security group policy may be included, that is: according to Whether the source IP and the target IP in the security group policy exist in the offline IP library, determine whether the security group policy includes the offline IP; if the security group policy does not include the offline IP, perform step S10 ; If the security group policy includes offline IP, then the security group policy is offline. Among them, the offline IP is an IP that has been discontinued. It should be noted that the step of performing offline IP filtering on the security group policy may be before or after the step of performing whitelist filtering on the security group policy, which is not specifically limited in this embodiment.
  • Security group policy refers to the control of incoming and/or outgoing flow of source IP and target IP.
  • the above security group policy management device performs whitelist filtering and offline IP filtering on the security group policy.
  • One of the solutions can be implemented, or they can be implemented in combination, which is not limited in this embodiment.
  • Step S20 judging whether the security group policy violates the rules according to preset audit rules, the source area and the target area;
  • the security group policy management device after the security group policy management device matches the source IP and target IP in all security group policies to the corresponding source area and target area, it judges the location according to the preset audit rules, the source area and the target area. Whether the security group policy is in violation, specifically: if the source area is not included in the preset audit rules, or the target area is not included in the preset audit rules, or in the preset audit rules The preset target area corresponding to the source area does not include the target area, then it is determined that the security group policy is not in violation; if the preset audit rule includes the source area and the target area, and If the preset target area corresponding to the source area in the preset audit rule includes the target area, it is determined that the security group policy is in violation.
  • Step S30 if the security group policy violates the regulations, perform security management and control on the security group policy.
  • the security group policy management apparatus determines that the security group policy is in violation, it performs security management and control on the security group policy. Specifically: if the security group policy is in violation, the security group policy is added to Violation policy alarm table; deduplicate the security group policy in the violation policy alarm table; send the deduplicated violation policy alarm table to the preset control terminal; after receiving the security management control sent by the preset control terminal When instructing, perform corresponding security management and control operations according to the security management and control content carried by the security management and control instruction.
  • the security management and control content includes but is not limited to adding the security group policy to the whitelist, suspending the security group policy, or The security group policy refers to one of the ITSM work orders.
  • the source IP in the security group policy matches the corresponding source area and the target IP according to the preset area mapping relationship, and the target IP matches the corresponding target area; the security is determined according to preset audit rules, the source area and the target area. Whether the group policy violates the regulations; if the security group policy violates the regulations, security management and control are performed on the security group policy. Automatically determine whether the security group policy is in violation according to the source IP, the area to which the target IP belongs and the preset audit rules in the security group policy, so that when the security group policy violates the security group policy, the security control is automatically initiated to realize the The automated audit of security group policies improves the audit efficiency of security group policies, so that a large number of security group policies can be audited comprehensively.
  • a second embodiment of the security group policy management method of the present application is proposed, and before the above step S10, the method further includes:
  • Step S11 judging whether the security group policy is in the white list
  • step S10 is executed.
  • a whitelist setting step is also included.
  • the policy list created by the operation and maintenance personnel for security group policies that must be activated for special reasons and does not require security audits is the whitelist. The specific reasons are The embodiment is not limited.
  • Before performing the violation audit of the security group policy first determine whether the policy is in the whitelist. If the policy is not in the whitelist, perform the violation audit on the policy, that is, perform step S10; if the policy is in the whitelist, then A whitelist flag can be added to the policy, and no violation audit is performed on such security group policies with whitelist flags added, so as to reduce the computational pressure of the security group policy management device.
  • the method further includes:
  • Step S12 judging whether the security group policy includes the offline IP according to whether the source IP and the target IP in the security group policy exist in the offline IP library;
  • Step S13 if the security group policy includes a offline IP, then the security group policy is offline;
  • step S10 is executed.
  • step S12 the step of setting and updating the offline IP library is also included.
  • the offline IP library stores IP addresses that have been discontinued, and the offline IP library is updated at a preset frequency or It is updated when the number of IP addresses is greater than a preset threshold, and this embodiment does not make specific restrictions.
  • step of performing offline IP filtering on the security group policy may be before or after the step of performing whitelist filtering on the security group policy, which is not specifically limited in this embodiment.
  • step S20 includes:
  • Step S21 if the source area is not included in the preset audit rule, or the target area is not included in the preset audit rule, or the source area is corresponding to the preset audit rule If the preset target area does not include the target area, it is determined that the security group policy is not in violation;
  • a step of setting preset audit rules is further included, and the operation and maintenance personnel set the preset audit rules according to the internal system of the enterprise, network security specifications, and the like.
  • the preset audit rules are the settings for the mutual access permissions between the preset areas in the preset area mapping relationship.
  • the preset area is the core.
  • the preset audit rules include the source area and the corresponding source area.
  • the preset target area that the area cannot access.
  • the security group policy management device After the security group policy management device matches the source IP and target IP in all security group policies to the corresponding source area and target area, judge whether the security group policy violates the rules according to preset audit rules, the source area and the target area That is, it is determined whether the source area and the target area are included in the preset audit rule, and the preset target area corresponding to the source area in the preset audit rule includes the target area.
  • the source area is not included in the preset audit rules, or the target area is not included in the preset audit rules, or the source area and the target area are included in the preset audit rules, However, if the target area is not included in the preset target area corresponding to the source area and inaccessible to the source area in the preset audit rule, it is determined that the security group policy is not in violation.
  • Step S22 If the preset audit rule includes the source area and the target area, and the preset target area corresponding to the source area in the preset audit rule includes the target area, then Determine that the security group policy violates regulations.
  • the preset audit rule includes the source area and the target area, and in the preset audit rule, the source area corresponding to the source area cannot be accessed. If the target area is included in the target area, it is determined that the security group policy is in violation.
  • the above step S20 may further include: if the source area is not included in the preset audit rule, or the preset audit rule does not include all The target area, or the preset target area corresponding to the source area in the preset audit rule does not include the target area, then it is determined that the security group policy violates; if the preset audit rule is If the source area and the target area are included, and the preset target area corresponding to the source area in the preset audit rule includes the target area, it is determined that the security group policy is not in violation.
  • the preset audit rule includes the source area and the corresponding preset target area that the source area can access.
  • security group policies that do not need to be audited for violations can be filtered out, and the number of security group policies that need to be audited for violations can be reduced, thereby reducing the operational pressure of the security group policy management device, thereby increasing violations Audit efficiency: According to the source area, target area and preset audit rules of the security group policy, it can automatically determine whether the security group policy violates the rules, realize the automatic audit of the security group policy, and improve the audit efficiency of the security group policy.
  • step S30 includes:
  • Step S31 If the security group policy violates regulations, add the security group policy to the violation policy alarm table;
  • the security group policy is added to the violation policy alarm table.
  • the violation policy alarm table stores the security group policies that are determined to be in violation in this violation audit and the history The security group policy that has been determined to be in violation during the violation audit and has not yet been subject to security control.
  • Step S32 De-duplicate the security group policy in the violation policy alarm table
  • the security group policy in the violation policy alarm table is hashed to obtain the corresponding hash value, and the corresponding hash value is obtained according to whether there is a current hash value in the violation policy alarm table.
  • the same value determines whether there are duplicate security group policies; if so, only one of the duplicate security group policies is retained.
  • the hash functions for performing hash operations include, but are not limited to, the SHA series of secure hash algorithms (such as SHA-1, SHA-256, SHA-384, etc.), and the MD series of message digest algorithms (such as MD2, MD3, MD4, MD5). Etc.) or one or more of the hash functions such as the advanced encryption standard AES, which is not specifically limited in this embodiment.
  • Step S33 Perform security management and control on the security group policy in the violation policy alarm table after deduplication.
  • the security group policies in the deduplication violation policy alarm table are security controlled.
  • step S33 includes:
  • Step S331 Send the de-duplicated violation policy alarm table to a preset control terminal
  • Step S332 upon receiving the security management and control instruction sent by the preset management and control terminal, perform corresponding security management and control operations according to the security management and control content carried by the security management and control instruction, and the security management and control content includes adding the security group policy Whitelist, suspend the security group policy or initiate an ITSM work order for the security group policy.
  • the deduplicated violation policy alarm table is sent to the preset control terminal, so that the administrator of the preset control terminal can follow the violation policy
  • the specific type determines the specific control operation, and sends a security management control instruction to the security group policy management device.
  • the security management control instruction includes specific security management and control content.
  • the security group policy management device receives the security management control instruction sent by the preset control terminal At the time, perform corresponding security management and control operations according to the security management and control content carried by the security management and control instruction.
  • the security management and control content includes adding the security group policy to the whitelist, suspending the security group policy, or raising an ITSM (IT Service Management) work order for the security group policy.
  • ITSM IT Service Management
  • the management personnel of the preset control terminal determines that the current violating security group policy must be activated for special reasons, the violating security group policy can be activated and added to the whitelist; the management personnel of the preset management control terminal will violate the regulations but cannot be resolved in the short term.
  • the security group policy is suspended; the security group policy management can be connected with the ITSM platform, and the management personnel of the preset control terminal will initiate an ITSM work order through the interface of the ITSM platform that violates the security group policy and must be handled.
  • step S332 it further includes:
  • the security control situation of the security group policy in the violation policy alarm table is counted to obtain the completion rate of management and control and the time rate of management and control.
  • the number of security group policies that have been security controlled in the violation policy alarm table is divided by
  • the total number of security group policies in the violation policy alarm table is the control completion rate, and the number of security group policies in the violation policy alarm table that perform security management and control within a preset time period divided by the violation policy alarm table
  • the total number of security group policies is the time rate of management and control; the completion rate of management and control and the time rate of management and control are sent to a preset review terminal for review.
  • the application also provides a security group policy management device.
  • FIG. 3 is a schematic diagram of the functional modules of the first embodiment of the security group policy management apparatus of this application, and the security group policy management apparatus includes:
  • the matching module 10 is configured to match the source IP in the security group policy with the corresponding source area and the target IP with the corresponding target area according to the preset area mapping relationship;
  • the judging module 20 is configured to judge whether the security group policy is in violation according to preset audit rules, the source area and the target area;
  • the management and control module 30 is configured to perform security management and control on the security group policy if the security group policy violates the regulations.
  • security group policy management device further includes:
  • the white list judgment module is used to judge whether the security group policy is in the white list
  • the matching module 10 is further configured to, if the security group policy is not in the whitelist, perform the step of matching the source IP and the target IP in the security group policy to the corresponding area according to the preset area mapping relationship.
  • security group policy management device further includes:
  • the IP judgment module is used to judge whether the security group policy includes the offline IP according to whether the source IP and the target IP in the security group policy exist in the offline IP library;
  • the matching module 10 is further configured to, if the offline IP is not included in the security group policy, perform the step of matching the source IP and the target IP in the security group policy to the corresponding area according to the preset area mapping relationship;
  • the offline module is configured to offline the security group policy if the offline IP is included in the security group policy.
  • judgment module 20 further includes:
  • the compliance determination unit is configured to: if the source area is not included in the preset audit rules, or the target area is not included in the preset audit rules, or the preset audit rules are combined with the If the preset target area corresponding to the source area does not include the target area, it is determined that the security group policy is not in violation;
  • a violation determination unit configured to: if the source area and the target area are included in the preset audit rule, and the preset target area corresponding to the source area in the preset audit rule includes the target Area, it is determined that the security group policy violates.
  • management and control module 30 further includes:
  • An alarm adding unit configured to add the security group policy to the violation policy alarm table if the security group policy violates regulations
  • the de-duplication unit is used to de-duplicate the security group policy in the violation policy alarm table
  • the deduplication management and control unit is used to perform security management and control on the security group policies in the policy violation alarm table after deduplication.
  • de-duplication management and control unit further includes:
  • a sending subunit configured to send the de-duplicated policy violation alarm table to a preset control terminal
  • the execution subunit is configured to execute corresponding security management and control operations according to the security management and control content carried by the security management and control instruction when receiving the security management and control instruction sent by the preset management and control terminal.
  • the security management and control content includes The group policy is added to the whitelist, the security group policy is suspended, or an IT service management ITSM work order is initiated for the security group policy.
  • security group policy management device further includes:
  • the statistics module is used to perform statistics on the security management and control situation of the security group policies in the violation policy alarm table according to the preset statistical frequency, to obtain the completion rate of management and control and the timely rate of management and control, and the security groups that have performed security management and control in the violation policy alarm table
  • the number of policies divided by the total number of security group policies in the violation policy alarm table is the control completion rate, and the number of security group policies that perform security management and control within a preset time period in the violation policy alarm table is divided by the
  • the total number of security group policies in the violation policy alarm table is the time rate of management and control;
  • the review module is used to send the control completion rate and the control time rate to the preset review terminal for review.
  • the specific implementation manner of the security group policy management device of the present application is basically the same as the foregoing embodiments of the security group policy management method, and will not be repeated here.
  • the embodiment of the present application also proposes a computer-readable storage medium.
  • the computer-readable storage medium stores a security group policy management program, and when the security group policy management program is executed by a processor, the steps of the above-mentioned security group policy management method are realized.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Storage Device Security (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

本申请公开了一种安全组策略管理方法、装置、设备及计算机可读存储介质,涉及金融科技领域,该方法包括以下步骤:根据预设区域映射关系为安全组策略中的源IP匹配相应的源区域,和目标IP匹配相应的目标区域;根据预设审计规则、所述源区域和目标区域判断所述安全组策略是否违规;若所述安全组策略违规,则对所述安全组策略进行安全管控。实现了自动根据安全组策略中的源IP、目标IP所属的区域和预设审计规则判断安全组策略是否违规,从而在安全组策略违规时自动对该安全组策略提起安全管控,进而实现了对安全组策略的自动化审计,提升了安全组策略的审计效率,从而能够对海量的安全组策略进行全面的审计。

Description

安全组策略管理方法、装置、设备及计算机可读存储介质
本申请要求于2019年6月28日提交中国专利局、申请号为201910584234.8、发明名称为“安全组策略管理方法、装置、设备及计算机可读存储介质”的中国专利申请的优先权,其全部内容通过引用结合在申请中。
技术领域
本申请涉及金融科技(Fintech)的网络安全领域,尤其涉及一种安全组策略管理方法、装置、设备及计算机可读存储介质。
背景技术
随着计算机技术的发展,越来越多的技术应用在金融领域,传统金融业正在逐步向金融科技(Fintech)转变,但由于金融行业的安全性、实时性要求,也对技术提出了更高的要求
云服务平台是一种新的企业信息化服务模式和管理方式,能够把海量的、高度虚拟化的企业资源和应用管理起来,组成一个集资源池、企业应用为一体的统一服务。
银行等金融机构的云服务平台上的安全组是基于本地防火墙实现的,其使用与传统的网络层防火墙有本质的区别,且其中的策略与云主机的对应关系极其复杂,随着时间推移,伴随着越来越多的新系统上线,云上就会有越来越多的安全组策略。鉴于安全组策略能够直接影响企业公有云的网络安全,因此安全组策略的合格性就极其重要。现有的对安全组策略的合规性的审计是通过人工逐条审核的,面对海量的安全组策略,无法对安全组策略的合规性做出全面的、自动化的审计。显然面对与云主机具有复杂对应关系的安全组策略,现有的安全组策略审计方案无法做到对越来越多的安全组策略的自动化审计,这种情况不符合银行等金融机构的业务需求,影响银行等金融机构对各种业务平台(如开发贷款业务平台、存款业务平台等)的安全组策略管理。
发明概述
技术问题
问题的解决方案
技术解决方案
本申请的主要目的在于提供一种安全组策略管理方法、装置、设备及可读存储介质,旨在解决现有技术无法对安全组策略的合规性做出全面的自动化审计的技术问题。
为实现上述目的,本申请提供一种安全组策略管理方法,所述安全组策略管理方法包括以下步骤:
根据预设区域映射关系为安全组策略中的源IP匹配相应的源区域,和目标IP匹配相应的目标区域;
根据预设审计规则、所述源区域和目标区域判断所述安全组策略是否违规;
若所述安全组策略违规,则对所述安全组策略进行安全管控。
可选地,所述根据预设区域映射关系为安全组策略中的源IP匹配相应的源区域,和目标IP匹配相应的目标区域的步骤之前,还包括:
判断所述安全组策略是否在白名单中;
若所述安全组策略不在白名单中,则执行步骤:根据预设区域映射关系为安全组策略中的源IP和目标IP匹配相应的所属区域。
可选地,所述根据预设区域映射关系为安全组策略中的源IP匹配相应的源区域,和目标IP匹配相应的目标区域的步骤之前,还包括:
根据所述安全组策略中的源IP和目标IP是否存在于下线IP库中判断所述安全组策略中是否包括下线IP;
若所述安全组策略中不包括下线IP,则执行步骤:根据预设区域映射关系为安全组策略中的源IP和目标IP匹配相应的所属区域;
若所述安全组策略中包括下线IP,则将所述安全组策略下线。
可选地,所述根据预设审计规则、所述源区域和目标区域判断所述安全组策略是否违规的步骤包括:
若所述预设审计规则中不包括所述源区域,或者所述预设审计规则中不包括所述目标区域,或者,在所述预设审计规则中与所述源区域相对应的预设目标区 域不包括所述目标区域,则判定所述安全组策略不违规;
若所述预设审计规则中包括所述源区域和所述目标区域,且在所述预设审计规则中与所述源区域相对应的预设目标区域包括所述目标区域,则判定所述安全组策略违规。
可选地,所述若所述安全组策略违规,则对所述安全组策略进行安全管控的步骤包括:
若所述安全组策略违规,则将所述安全组策略加入违规策略告警表;
对所述违规策略告警表中的安全组策略进行去重;
对去重后的违规策略告警表中的安全组策略进行安全管控。
可选地,所述对去重后的违规策略告警表中的安全组策略进行安全管控的步骤包括:
将所述去重后的违规策略告警表发送给预设管控终端;
在接收到所述预设管控终端发送的安全管控指令时,根据所述安全管控指令携带的安全管控内容执行相应的安全管控操作,所述安全管控内容包括将所述安全组策略加入白名单、将所述安全组策略挂起或者对所述安全组策略提起IT服务管理ITSM工单。
可选地,所述根据所述安全管控指令携带的安全管控内容执行相应的安全管控操作的步骤之后,还包括:
按照预设统计频率对违规策略告警表中的安全组策略的安全管控情况进行统计,得到管控完成率和管控及时率,所述违规策略告警表中已进行安全管控的安全组策略的数量除以所述违规策略告警表中的安全组策略的总数为所述管控完成率,所述违规策略告警表中在预设时长内进行安全管控的安全组策略的数量除以所述违规策略告警表中的安全组策略的总数为所述管控及时率;
将所述管控完成率和管控及时率发送至预设检阅终端,以供检阅。
进一步地,为实现上述目的,本申请还提供一种安全组策略管理装置,所述安全组策略管理装置包括:
匹配模块,用于根据预设区域映射关系为安全组策略中的源IP匹配相应的源区域,和目标IP匹配相应的目标区域;
判断模块,用于根据预设审计规则、所述源区域和目标区域判断所述安全组策略是否违规;
管控模块,用于若所述安全组策略违规,则对所述安全组策略进行安全管控。
进一步地,为实现上述目的,本申请还提供一种安全组策略管理设备,所述安全组策略管理设备包括存储器、处理器以及存储在所述存储器上并可在所述处理器上运行的安全组策略管理程序,所述安全组策略管理程序被所述处理器执行时实现如上述所述的安全组策略管理方法的步骤。
进一步地,为实现上述目的,本申请还提供一种计算机可读存储介质,所述计算机可读存储介质上存储有安全组策略管理程序,所述安全组策略管理程序被处理器执行时实现如上所述的安全组策略管理方法的步骤。
本申请通过根据预设区域映射关系为安全组策略中的源IP匹配相应的源区域,和目标IP匹配相应的目标区域;根据预设审计规则、所述源区域和目标区域判断所述安全组策略是否违规;若所述安全组策略违规,则对所述安全组策略进行安全管控。实现了自动根据安全组策略中的源IP、目标IP所属的区域和预设审计规则判断安全组策略是否违规,从而在安全组策略违规时自动对该安全组策略提起安全管控,进而实现了对安全组策略的自动化审计,提升了安全组策略的审计效率,从而能够对海量的安全组策略进行全面的审计。
发明的有益效果
对附图的简要说明
附图说明
图1为本申请安全组策略管理设备实施例方案涉及的设备硬件运行环境的结构示意图;
图2为本申请安全组策略管理方法第一实施例的流程示意图;
图3为本申请安全组策略管理装置的功能模块示意图。
本申请目的的实现、功能特点及优点将结合实施例,参照附图做进一步说明。
发明实施例
本发明的实施方式
应当理解,此处所描述的具体实施例仅用以解释本申请,并不用于限定本申请。
需要说明的是,银行等金融机构的云服务平台上的安全组是基于本地防火墙实现的,其使用与传统的网络层防火墙有本质的区别,且其中的策略与云主机的对应关系极其复杂,随着时间推移,伴随着越来越多的新系统上线,云上就会有越来越多的安全组策略。鉴于安全组策略能够直接影响企业公有云的网络安全,因此安全组策略的合格性就极其重要。现有的对安全组策略的合规性的审计是通过人工逐条审核的,面对海量的安全组策略,无法对安全组策略的合规性做出全面的、自动化的审计。显然面对与云主机具有复杂对应关系的安全组策略,现有的安全组策略审计方案无法做到对越来越多的安全组策略的自动化审计,这种情况不符合银行等金融机构的业务需求,影响银行等金融机构对各种业务平台(如开发贷款业务平台、存款业务平台等)的安全组策略管理。
基于上述缺陷,本申请提供一种安全组策略管理设备,参照图1,图1为本申请安全组策略管理设备实施例方案涉及的设备硬件运行环境的结构示意图。
如图1所示,该安全组策略管理设备可以包括:处理器1001,例如CPU,通信总线1002、用户接口1003,网络接口1004,存储器1005。其中,通信总线1002用于实现这些组件之间的连接通信。用户接口1003可以包括显示屏(Display)、输入单元比如键盘(Keyboard),可选用户接口1003还可以包括标准的有线接口、无线接口。网络接口1004可选的可以包括标准的有线接口、无线接口(如WI-FI接口)。存储器1005可以是高速RAM存储器,也可以是稳定的存储器(non-volatile memory),例如磁盘存储器。存储器1005可选的还可以是独立于前述处理器1001的存储设备。
本领域技术人员可以理解,图1中示出的安全组策略管理设备的硬件结构并不构成对安全组策略管理设备的限定,可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置。
如图1所示,作为一种计算机可读存储介质的存储器1005中可以包括操作系统、网络通信模块、用户接口模块以及安全组策略管理程序。其中,操作系统是管理和控制安全组策略管理设备与软件资源的程序,支持网络通信模块、用户 接口模块、安全组策略管理程序以及其他程序或软件的运行;网络通信模块用于管理和控制网络接口1004;用户接口模块用于管理和控制用户接口1003。
在图1所示的安全组策略管理设备硬件结构中,网络接口1004主要用于连接后台服务器,与后台服务器进行数据通信;用户接口1003主要用于连接客户端(用户端),与客户端进行数据通信;处理器1001可以调用存储器1005中中存储的安全组策略管理程序,并执行以下操作:
根据预设区域映射关系为安全组策略中的源IP匹配相应的源区域,和目标IP匹配相应的目标区域;
根据预设审计规则、所述源区域和目标区域判断所述安全组策略是否违规;
若所述安全组策略违规,则对所述安全组策略进行安全管控。
进一步地,所述根据预设区域映射关系为安全组策略中的源IP匹配相应的源区域,和目标IP匹配相应的目标区域的步骤之前,处理器1001还用于调用存储器1005中存储的安全组策略管理程序,并执行以下操作:
判断所述安全组策略是否在白名单中;
若所述安全组策略不在白名单中,则执行步骤:根据预设区域映射关系为安全组策略中的源IP和目标IP匹配相应的所属区域。
进一步地,所述根据预设区域映射关系为安全组策略中的源IP匹配相应的源区域,和目标IP匹配相应的目标区域的步骤之前,处理器1001还用于调用存储器1005中存储的安全组策略管理程序,并执行以下操作:
根据所述安全组策略中的源IP和目标IP是否存在于下线IP库中判断所述安全组策略中是否包括下线IP;
若所述安全组策略中不包括下线IP,则执行步骤:根据预设区域映射关系为安全组策略中的源IP和目标IP匹配相应的所属区域;
若所述安全组策略中包括下线IP,则将所述安全组策略下线。
进一步地,所述根据预设审计规则、所述源区域和目标区域判断所述安全组策略是否违规的步骤包括:
若所述预设审计规则中不包括所述源区域,或者所述预设审计规则中不包括所述目标区域,或者,在所述预设审计规则中与所述源区域相对应的预设目标区 域不包括所述目标区域,则判定所述安全组策略不违规;
若所述预设审计规则中包括所述源区域和所述目标区域,且在所述预设审计规则中与所述源区域相对应的预设目标区域包括所述目标区域,则判定所述安全组策略违规。
进一步地,所述若所述安全组策略违规,则对所述安全组策略进行安全管控的步骤包括:
若所述安全组策略违规,则将所述安全组策略加入违规策略告警表;
对所述违规策略告警表中的安全组策略进行去重;
对去重后的违规策略告警表中的安全组策略进行安全管控。
进一步地,所述对去重后的违规策略告警表中的安全组策略进行安全管控的步骤包括:
将所述去重后的违规策略告警表发送给预设管控终端;
在接收到所述预设管控终端发送的安全管控指令时,根据所述安全管控指令携带的安全管控内容执行相应的安全管控操作,所述安全管控内容包括将所述安全组策略加入白名单、将所述安全组策略挂起或者对所述安全组策略提起IT服务管理ITSM工单。
进一步地,所述根据所述安全管控指令携带的安全管控内容执行相应的安全管控操作的步骤之后,处理器1001还用于调用存储器1005中存储的安全组策略管理程序,并执行以下操作:
按照预设统计频率对违规策略告警表中的安全组策略的安全管控情况进行统计,得到管控完成率和管控及时率,所述违规策略告警表中已进行安全管控的安全组策略的数量除以所述违规策略告警表中的安全组策略的总数为所述管控完成率,所述违规策略告警表中在预设时长内进行安全管控的安全组策略的数量除以所述违规策略告警表中的安全组策略的总数为所述管控及时率;
将所述管控完成率和管控及时率发送至预设检阅终端,以供检阅。
本申请安全组策略管理设备的具体实施方式与下述安全组策略管理方法各实施例基本相同,在此不再赘述。
本申请还提供一种安全组策略管理方法。
本申请实施例提供了安全组策略管理方法的实施例,需要说明的是,虽然在流程图中示出了逻辑顺序,但是在某些情况下,可以以不同于此处的顺序执行所示出或描述的步骤。
在安全组策略管理方法的各个实施例中,为了便于描述,省略执行主体进行阐述各个实施例。参照图2,图2为本申请安全组策略管理方法第一实施例的流程示意图,所述安全组策略管理方法包括:
步骤S10,根据预设区域映射关系为安全组策略中的源IP匹配相应的源区域,和目标IP匹配相应的目标区域;
银行等金融机构的云服务平台上的安全组是基于本地防火墙实现的,其使用与传统的网络层防火墙有本质的区别,且其中的策略与云主机的对应关系极其复杂,随着时间推移,伴随着越来越多的新系统上线,云上就会有越来越多的安全组策略。鉴于安全组策略能够直接影响企业公有云的网络安全,因此安全组策略的合格性就极其重要。现有的对安全组策略的合规性的审计是通过人工逐条审核的,面对海量的安全组策略,无法对安全组策略的合规性做出全面的自动化审计。显然面对与云主机具有复杂对应关系的安全组策略,现有的安全组策略审计方案无法做到对越来越多的安全组策略的自动化审计,这种情况不符合银行等金融机构的业务需求,影响银行等金融机构对各种业务平台(如开发贷款业务平台、存款业务平台等)的安全组策略管理。基于此,提出本申请的技术方案。
在本申请实施例中,要对安全组策略进行全面的自动化管理,安全组策略管理装置首先需要根据预设区域映射关系为所有的安全组策略中的源IP和目标IP匹配其所对应的区域,将源IP所对应的区域定义为源区域,将目标IP所对应的区域定义为目标区域。其中,预设区域映射关系指的是管理人员根据需要(例如企业内部的网络划分)为IP地址划分的预设区域(例如生产区域、管理区域、开发区域等),每个区域为一系列IP地址的集合,每个IP都有唯一对应的区域。
进一步地,为了提高安全组策略管理的灵活性,减轻安全组策略管理装置的运算压力,本实施例中,在步骤S10之前还可以包括对安全组策略进行白名单过滤的步骤,即:判断所述安全组策略是否在白名单中,所述白名单中存储有预设 开通策略名单;若所述安全组策略不在白名单中,则执行步骤S10。即,安全组策略管理装置在获取所有安全组策略后,可先判断安全组策略是否命中白名单中的预设开通策略名单,该预设开通策略名单是管理人员根据需要自定义的必须开通的安全组策略名单,若安全组策略命中白名单中的预设开通策略名单,即安全组策略在白名单中,则不对该策略进行后续的安全组策略管理操作;若安全组策略未命中白名单中的预设开通策略名单,即安全组策略不在白名单中,则对该策略进行区域匹配操作。
进一步地,为了提高安全组策略管理的灵活性,减轻安全组策略管理装置的运算压力,本实施例中,在步骤S10之前还可以包括对安全组策略进行下线IP过滤的步骤,即:根据所述安全组策略中的源IP和目标IP是否存在于下线IP库中判断所述安全组策略中是否包括下线IP;若所述安全组策略中不包括下线IP,则执行步骤S10;若所述安全组策略中包括下线IP,则将所述安全组策略下线。其中,下线IP为已停止使用的IP。需要说明的是,对安全组策略进行下线IP过滤的步骤可以在对安全组策略进行白名单过滤的步骤之前或之后,本实施例不做具体限定。
安全组策略,指的是对源IP和目标IP的入和/或出流量控制。
在本实施例中,以上安全组策略管理装置对安全组策略进行白名单过滤和下线IP过滤的方案可以择其一实施,也可以组合在一起实施,本实施例不做限制。
步骤S20,根据预设审计规则、所述源区域和目标区域判断所述安全组策略是否违规;
在本实施例中,在安全组策略管理装置为所有的安全组策略中的源IP和目标IP匹配对应的源区域和目标区域后,根据预设审计规则、所述源区域和目标区域判断所述安全组策略是否违规,具体地:若所述预设审计规则中不包括所述源区域,或者所述预设审计规则中不包括所述目标区域,或者,在所述预设审计规则中与所述源区域相对应的预设目标区域不包括所述目标区域,则判定所述安全组策略不违规;若所述预设审计规则中包括所述源区域和所述目标区域,且在所述预设审计规则中与所述源区域相对应的预设目标区域包括所述目标区域,则判定所述安全组策略违规。
步骤S30,若所述安全组策略违规,则对所述安全组策略进行安全管控。
在本实施例中,在安全组策略管理装置判定所述安全组策略违规后,对所述安全组策略进行安全管控,具体地:若所述安全组策略违规,则将所述安全组策略加入违规策略告警表;对所述违规策略告警表中的安全组策略进行去重;将去重后的违规策略告警表发送给预设管控终端;在接收到所述预设管控终端发送的安全管控指令时,根据所述安全管控指令携带的安全管控内容执行相应的安全管控操作,所述安全管控内容包括但不限于将所述安全组策略加入白名单、将所述安全组策略挂起或者对所述安全组策略提起ITSM工单中的一种。
本实施例通过根据预设区域映射关系为安全组策略中的源IP匹配相应的源区域,和目标IP匹配相应的目标区域;根据预设审计规则、所述源区域和目标区域判断所述安全组策略是否违规;若所述安全组策略违规,则对所述安全组策略进行安全管控。实现了自动根据安全组策略中的源IP、目标IP所属的区域和预设审计规则判断安全组策略是否违规,从而在安全组策略违规时自动对该安全组策略提起安全管控,进而实现了对安全组策略的自动化审计,提升了安全组策略的审计效率,从而能够对海量的安全组策略进行全面的审计。
进一步地,提出本申请安全组策略管理方法第二实施例,上述步骤S10之前还包括:
步骤S11,判断所述安全组策略是否在白名单中;
若所述安全组策略不在白名单中,则执行步骤S10。
为了提高安全组策略管理的灵活性,减轻安全组策略管理装置的运算压力。在本实施例中,在步骤S11之前还包括对白名单的设置步骤,运维人员为因为特殊原因必须开通,无需进行安全审计的安全组策略而创建的策略名单,即为白名单,具体原因本实施例不做限定。在对安全组策略进行违规审计之前,先判断该策略是否在白名单中,若该策略不在白名单中,则对该策略进行违规审计,即执行步骤S10;若该策略在白名单中,则可为该条策略添加白名单标记位,对此类添加有白名单标记位的安全组策略不进行违规审计,以此减轻安全组策略管理装置的运算压力。
进一步地,上述步骤S10之前还包括:
步骤S12,根据所述安全组策略中的源IP和目标IP是否存在于下线IP库中判断所述安全组策略中是否包括下线IP;
步骤S13,若所述安全组策略中包括下线IP,则将所述安全组策略下线;
若所述安全组策略中不包括下线IP,则执行步骤S10。
为了提高安全组策略管理的灵活性,减轻安全组策略管理装置的运算压力。在本实施例中,在步骤S12之前还包括对下线IP库的设置和更新步骤,下线IP库中存储有已停止使用的IP地址,该下线IP库按照预设频率或者在更新的IP地址数量大于预设阈值时更新,本实施例不做具体限制。在本实施例中,先判断该安全组策略中的源IP和目标IP是否在下线IP库中,若该策略不在下线IP库中,说明该策略中的IP都为有效IP,则可对该策略进行违规审计,即执行步骤S10;若该策略中的源IP和目标IP中的一个或者两个在下线IP库中,说明说明该策略中的IP包括已停止使用的IP地址,则将该策略下线。
需要说明的是,对安全组策略进行下线IP过滤的步骤可以在对安全组策略进行白名单过滤的步骤之前或之后,本实施例不做具体限定。
进一步地,上述步骤S20包括:
步骤S21,若所述预设审计规则中不包括所述源区域,或者所述预设审计规则中不包括所述目标区域,或者,在所述预设审计规则中与所述源区域相对应的预设目标区域不包括所述目标区域,则判定所述安全组策略不违规;
在本实施例中,在步骤S21之前还包括对预设审计规则的设置步骤,运维人员根据企业内部制度、网络安全规范等内容设置预设审计规则。预设审计规则是对预设区域映射关系中的预设区域之间互相访问的权限的设置,是以预设区域为核心的,预设审计规则中包括源区域和与之对应的、该源区域不能访问的预设目标区域。
在安全组策略管理装置为所有的安全组策略中的源IP和目标IP匹配对应的源区域和目标区域后,根据预设审计规则、所述源区域和目标区域判断所述安全组策略是否违规,即,判断所述预设审计规则中是否包括所述源区域和所述目标区域,且在所述预设审计规则中与所述源区域相对应的预设目标区域包括所述目标区域。若所述预设审计规则中不包括所述源区域,或者所述预设审计规则 中不包括所述目标区域,或者,所述预设审计规则中包括所述源区域和所述目标区域,但在所述预设审计规则中与所述源区域相对应的该源区域不能访问的预设目标区域中不包括所述目标区域,则判定所述安全组策略不违规。
步骤S22,若所述预设审计规则中包括所述源区域和所述目标区域,且在所述预设审计规则中与所述源区域相对应的预设目标区域包括所述目标区域,则判定所述安全组策略违规。
在本实施例中,若所述预设审计规则中包括所述源区域和所述目标区域,且在所述预设审计规则中与所述源区域相对应的该源区域不能访问的预设目标区域中包括所述目标区域,则判定所述安全组策略违规。
进一步地,为了增加判断安全组策略是否违规的方法的灵活性,上述步骤S20还可以包括:若所述预设审计规则中不包括所述源区域,或者所述预设审计规则中不包括所述目标区域,或者,在所述预设审计规则中与所述源区域相对应的预设目标区域不包括所述目标区域,则判定所述安全组策略违规;若所述预设审计规则中包括所述源区域和所述目标区域,且在所述预设审计规则中与所述源区域相对应的预设目标区域包括所述目标区域,则判定所述安全组策略不违规。这种情况下,预设审计规则中包括源区域和与之对应的、该源区域能访问的预设目标区域。
本实施例通过白名单过滤和下线IP过滤能够过滤掉不需要进行违规审计的安全组策略,减少需要进行违规审计的安全组策略数量,从而减轻安全组策略管理装置的运算压力,进而提升违规审计的效率;根据安全组策略的源区域、目标区域以及预设审计规则自动确定安全组策略是否违规,实现了对安全组策略的自动化审计,提升了安全组策略的审计效率。
进一步地,提出本申请安全组策略管理方法第三实施例,上述步骤S30包括:
步骤S31,若所述安全组策略违规,则将所述安全组策略加入违规策略告警表;
在本实施例中,若判定该安全组策略违规,则将该安全组策略加入违规策略告警表中,该违规策略告警表中存储有本次违规审计中被判定违规的安全组策略,以及历史违规审计中被判定违规,且尚未进行安全管控的安全组策略。
步骤S32,对所述违规策略告警表中的安全组策略进行去重;
对于海量的安全组策略,其中或多或少会有重复的安全组策略,违规的安全组策略也难免重复,若对所有违规的安全组策略都进行安全管控,重复的安全管控会造成不必要的资源浪费,也会增大安全组策略管理装置的运算压力。基于此,提出本实施例的技术方案。
在本申请实施例中,为避免重复的安全管控,对违规策略告警表中的安全组策略进行哈希运算得到对应的哈希值,根据所述违规策略告警表中是否有与当前哈希值相同的值判断是否有重复的安全组策略;若有,则仅保留重复的安全组策略中的一条。其中,进行哈希运算的哈希函数包括但不限于安全散列算法SHA系列(例如SHA-1、SHA-256、SHA-384等)、消息摘要算法MD系列(例如MD2、MD3、MD4、MD5等)或者高级加密标准AES等哈希函数中的一种或多种,本实施例不做具体限制。
步骤S33,对去重后的违规策略告警表中的安全组策略进行安全管控。
在对违规策略告警表中的安全组策略去重之后,对去重后的违规策略告警表中的安全组策略进行安全管控。
进一步地,上述步骤S33包括:
步骤S331,将所述去重后的违规策略告警表发送给预设管控终端;
步骤S332,在接收到所述预设管控终端发送的安全管控指令时,根据所述安全管控指令携带的安全管控内容执行相应的安全管控操作,所述安全管控内容包括将所述安全组策略加入白名单、将所述安全组策略挂起或者对所述安全组策略提起ITSM工单。
在本实施例中,对违规策略告警表中的安全组策略去重后,将所述去重后的违规策略告警表发送给预设管控终端,以使预设管控终端的管理人员根据违规策略的具体类型确定具体地管控操作,并向安全组策略管理装置发送安全管控指令,该安全管控指令中包括具体地安全管控内容,安全组策略管理装置在接收到预设管控终端发送的安全管控指令时,根据所述安全管控指令携带的安全管控内容执行相应的安全管控操作。
其中,所述安全管控内容包括将安全组策略加入白名单、将安全组策略挂起或 者对安全组策略提起ITSM(IT服务管理)工单。具体地,若预设管控终端的管理人员确定当前违规安全组策略存在特殊原因必须开通,可将该违规安全组策略开通,并加入白名单;预设管控终端的管理人员将违规但短期无法解决的安全组策略挂起;安全组策略管理可与ITSM平台对接,预设管控终端的管理人员将违规且必须处理的安全组策略通过与ITSM平台对接接口提起ITSM工单。
进一步地,上述步骤S332之后还包括:
按照预设统计频率对违规策略告警表中的安全组策略的安全管控情况进行统计,得到管控完成率和管控及时率,所述违规策略告警表中已进行安全管控的安全组策略的数量除以所述违规策略告警表中的安全组策略的总数为所述管控完成率,所述违规策略告警表中在预设时长内进行安全管控的安全组策略的数量除以所述违规策略告警表中的安全组策略的总数为所述管控及时率;将所述管控完成率和管控及时率发送至预设检阅终端,以供检阅。
本实施例通过对违规策略告警表中的安全组策略去重,再对去重后违规策略告警表中的安全组策略进行安全管控,能够避免不必要的资源浪费,也减轻了安全组策略管理装置的运算压力;对违规的安全组策略进行相应的安全管控,能够实现从违规安全组策略的审计到处理的运营闭环,进而实现更加完善的安全组策略管理流程。
本申请还提供一种安全组策略管理装置。
参照图3,图3为本申请安全组策略管理装置第一实施例的功能模块示意图,所述安全组策略管理装置包括:
匹配模块10,用于根据预设区域映射关系为安全组策略中的源IP匹配相应的源区域,和目标IP匹配相应的目标区域;
判断模块20,用于根据预设审计规则、所述源区域和目标区域判断所述安全组策略是否违规;
管控模块30,用于若所述安全组策略违规,则对所述安全组策略进行安全管控。
进一步地,所述安全组策略管理装置还包括:
白名单判断模块,用于判断所述安全组策略是否在白名单中;
所述匹配模块10还用于若所述安全组策略不在白名单中,则执行步骤:根据预设区域映射关系为安全组策略中的源IP和目标IP匹配相应的所属区域。
进一步地,所述安全组策略管理装置还包括:
IP判断模块,用于根据所述安全组策略中的源IP和目标IP是否存在于下线IP库中判断所述安全组策略中是否包括下线IP;
所述匹配模块10还用于若所述安全组策略中不包括下线IP,则执行步骤:根据预设区域映射关系为安全组策略中的源IP和目标IP匹配相应的所属区域;
下线模块,用于若所述安全组策略中包括下线IP,则将所述安全组策略下线。
进一步地,所述判断模块20还包括:
合规判定单元,用于若所述预设审计规则中不包括所述源区域,或者所述预设审计规则中不包括所述目标区域,或者,在所述预设审计规则中与所述源区域相对应的预设目标区域不包括所述目标区域,则判定所述安全组策略不违规;
违规判定单元,用于若所述预设审计规则中包括所述源区域和所述目标区域,且在所述预设审计规则中与所述源区域相对应的预设目标区域包括所述目标区域,则判定所述安全组策略违规。
进一步地,所述管控模块30还包括:
告警加入单元,用于若所述安全组策略违规,则将所述安全组策略加入违规策略告警表;
去重单元,用于对所述违规策略告警表中的安全组策略进行去重;
去重管控单元,用于对去重后的违规策略告警表中的安全组策略进行安全管控。
进一步地,所述去重管控单元还包括:
发送子单元,用于将所述去重后的违规策略告警表发送给预设管控终端;
执行子单元,用于在接收到所述预设管控终端发送的安全管控指令时,根据所述安全管控指令携带的安全管控内容执行相应的安全管控操作,所述安全管控内容包括将所述安全组策略加入白名单、将所述安全组策略挂起或者对所述安全组策略提起IT服务管理ITSM工单。
进一步地,所述安全组策略管理装置还包括:
统计模块,用于按照预设统计频率对违规策略告警表中的安全组策略的安全管控情况进行统计,得到管控完成率和管控及时率,所述违规策略告警表中已进行安全管控的安全组策略的数量除以所述违规策略告警表中的安全组策略的总数为所述管控完成率,所述违规策略告警表中在预设时长内进行安全管控的安全组策略的数量除以所述违规策略告警表中的安全组策略的总数为所述管控及时率;
检阅模块,用于将所述管控完成率和管控及时率发送至预设检阅终端,以供检阅。
本申请安全组策略管理装置具体实施方式与上述安全组策略管理方法各实施例基本相同,在此不再赘述。
此外,本申请实施例还提出一种计算机可读存储介质。
计算机可读存储介质上存储有安全组策略管理程序,安全组策略管理程序被处理器执行时实现如上所述的安全组策略管理方法的步骤。
本申请可读存储介质具体实施方式与上述安全组策略管理方法各实施例基本相同,在此不再赘述。
上面结合附图对本申请的实施例进行了描述,但是本申请并不局限于上述的具体实施方式,上述的具体实施方式仅仅是示意性的,而不是限制性的,本领域的普通技术人员在本申请的启示下,在不脱离本申请宗旨和权利要求所保护的范围情况下,还可做出很多形式,凡是利用本申请说明书及附图内容所作的等效结构或等效流程变换,或直接或间接运用在其他相关的技术领域,这些均属于本申请的保护之内。

Claims (20)

  1. 一种安全组策略管理方法,其中,所述安全组策略管理方法包括以下步骤:
    根据预设区域映射关系为安全组策略中的源IP匹配相应的源区域,和目标IP匹配相应的目标区域;
    根据预设审计规则、所述源区域和目标区域判断所述安全组策略是否违规;
    若所述安全组策略违规,则对所述安全组策略进行安全管控。
  2. 如权利要求1所述的安全组策略管理方法,其中,所述根据预设区域映射关系为安全组策略中的源IP匹配相应的源区域,和目标IP匹配相应的目标区域的步骤之前,还包括:
    判断所述安全组策略是否在白名单中;
    若所述安全组策略不在白名单中,则执行步骤:根据预设区域映射关系为安全组策略中的源IP和目标IP匹配相应的所属区域。
  3. 如权利要求1所述的安全组策略管理方法,其中,所述根据预设区域映射关系为安全组策略中的源IP匹配相应的源区域,和目标IP匹配相应的目标区域的步骤之前,还包括:
    根据所述安全组策略中的源IP和目标IP是否存在于下线IP库中判断所述安全组策略中是否包括下线IP;
    若所述安全组策略中不包括下线IP,则执行步骤:根据预设区域映射关系为安全组策略中的源IP和目标IP匹配相应的所属区域;
    若所述安全组策略中包括下线IP,则将所述安全组策略下线。
  4. 如权利要求1所述的安全组策略管理方法,其中,所述根据预设审计规则、所述源区域和目标区域判断所述安全组策略是否违规的步骤包括:
    若所述预设审计规则中不包括所述源区域,或者所述预设审计规则中不包括所述目标区域,或者,在所述预设审计规则中与所述源区域相对应的预设目标区域不包括所述目标区域,则判定所述 安全组策略不违规;
    若所述预设审计规则中包括所述源区域和所述目标区域,且在所述预设审计规则中与所述源区域相对应的预设目标区域包括所述目标区域,则判定所述安全组策略违规。
  5. 如权利要求1所述的安全组策略管理方法,其中,所述若所述安全组策略违规,则对所述安全组策略进行安全管控的步骤包括:
    若所述安全组策略违规,则将所述安全组策略加入违规策略告警表;
    对所述违规策略告警表中的安全组策略进行去重;
    对去重后的违规策略告警表中的安全组策略进行安全管控。
  6. 如权利要求5所述的安全组策略管理方法,其中,所述对去重后的违规策略告警表中的安全组策略进行安全管控的步骤包括:
    将所述去重后的违规策略告警表发送给预设管控终端;
    在接收到所述预设管控终端发送的安全管控指令时,根据所述安全管控指令携带的安全管控内容执行相应的安全管控操作,所述安全管控内容包括将所述安全组策略加入白名单、将所述安全组策略挂起或者对所述安全组策略提起IT服务管理ITSM工单。
  7. 如权利要求6所述的安全组策略管理方法,其中,所述根据所述安全管控指令携带的安全管控内容执行相应的安全管控操作的步骤之后,还包括:
    按照预设统计频率对违规策略告警表中的安全组策略的安全管控情况进行统计,得到管控完成率和管控及时率,所述违规策略告警表中已进行安全管控的安全组策略的数量除以所述违规策略告警表中的安全组策略的总数为所述管控完成率,所述违规策略告警表中在预设时长内进行安全管控的安全组策略的数量除以所述违规策略告警表中的安全组策略的总数为所述管控及时率;
    将所述管控完成率和管控及时率发送至预设检阅终端,以供检阅。
  8. 一种安全组策略管理装置,其中,所述安全组策略管理装置包括:
    匹配模块,用于根据预设区域映射关系为安全组策略中的源IP匹配相应的源区域,和目标IP匹配相应的目标区域;
    判断模块,用于根据预设审计规则、所述源区域和目标区域判断所述安全组策略是否违规;
    管控模块,用于若所述安全组策略违规,则对所述安全组策略进行安全管控。
  9. 如权利要求8所述的安全组策略管理装置,其中,所述安全组策略管理装置还包括:
    白名单判断模块,用于判断所述安全组策略是否在白名单中;
    所述匹配模块还用于若所述安全组策略不在白名单中,则执行步骤:根据预设区域映射关系为安全组策略中的源IP和目标IP匹配相应的所属区域。
  10. 如权利要求8所述的安全组策略管理装置,其中,所述安全组策略管理装置还包括:
    IP判断模块,用于根据所述安全组策略中的源IP和目标IP是否存在于下线IP库中判断所述安全组策略中是否包括下线IP;
    所述匹配模块还用于若所述安全组策略中不包括下线IP,则执行步骤:根据预设区域映射关系为安全组策略中的源IP和目标IP匹配相应的所属区域;
    下线模块,用于若所述安全组策略中包括下线IP,则将所述安全组策略下线。
  11. 如权利要求8所述的安全组策略管理装置,其中,所述判断模块还包括:
    合规判定单元,用于若所述预设审计规则中不包括所述源区域,或者所述预设审计规则中不包括所述目标区域,或者,在所述预设审计规则中与所述源区域相对应的预设目标区域不包括所述目 标区域,则判定所述安全组策略不违规;
    违规判定单元,用于若所述预设审计规则中包括所述源区域和所述目标区域,且在所述预设审计规则中与所述源区域相对应的预设目标区域包括所述目标区域,则判定所述安全组策略违规。
  12. 如权利要求8所述的安全组策略管理装置,其中,所述管控模块还包括:
    告警加入单元,用于若所述安全组策略违规,则将所述安全组策略加入违规策略告警表;
    去重单元,用于对所述违规策略告警表中的安全组策略进行去重;
    去重管控单元,用于对去重后的违规策略告警表中的安全组策略进行安全管控。
  13. 如权利要求12所述的安全组策略管理装置,其中,所述去重管控单元还包括:
    发送子单元,用于将所述去重后的违规策略告警表发送给预设管控终端;
    执行子单元,用于在接收到所述预设管控终端发送的安全管控指令时,根据所述安全管控指令携带的安全管控内容执行相应的安全管控操作,所述安全管控内容包括将所述安全组策略加入白名单、将所述安全组策略挂起或者对所述安全组策略提起IT服务管理ITSM工单。
  14. 如权利要求13所述的安全组策略管理装置,其中,所述安全组策略管理装置还包括:
    统计模块,用于按照预设统计频率对违规策略告警表中的安全组策略的安全管控情况进行统计,得到管控完成率和管控及时率,所述违规策略告警表中已进行安全管控的安全组策略的数量除以所述违规策略告警表中的安全组策略的总数为所述管控完成率,所述违规策略告警表中在预设时长内进行安全管控的安全组策略 的数量除以所述违规策略告警表中的安全组策略的总数为所述管控及时率;
    检阅模块,用于将所述管控完成率和管控及时率发送至预设检阅终端,以供检阅。
  15. 一种安全组策略管理设备,其中,所述安全组策略管理设备包括存储器、处理器以及存储在所述存储器上并可在所述处理器上运行的安全组策略管理程序,所述安全组策略管理程序被所述处理器执行时实现如下步骤:
    根据预设区域映射关系为安全组策略中的源IP匹配相应的源区域,和目标IP匹配相应的目标区域;
    根据预设审计规则、所述源区域和目标区域判断所述安全组策略是否违规;
    若所述安全组策略违规,则对所述安全组策略进行安全管控。
  16. 如权利要求15所述的安全组策略管理设备,其中,所述安全组策略管理设备程序被所述处理器执行时还实现如下步骤:
    若所述预设审计规则中不包括所述源区域,或者所述预设审计规则中不包括所述目标区域,或者,在所述预设审计规则中与所述源区域相对应的预设目标区域不包括所述目标区域,则判定所述安全组策略不违规;
    若所述预设审计规则中包括所述源区域和所述目标区域,且在所述预设审计规则中与所述源区域相对应的预设目标区域包括所述目标区域,则判定所述安全组策略违规。
  17. 如权利要求15所述的安全组策略管理设备,其中,所述安全组策略管理设备程序被所述处理器执行时还实现如下步骤:
    若所述安全组策略违规,则将所述安全组策略加入违规策略告警表;
    对所述违规策略告警表中的安全组策略进行去重;
    对去重后的违规策略告警表中的安全组策略进行安全管控。
  18. 一种计算机可读存储介质,其中,所述可读存储介质上存储有安全组策略管理程序,所述安全组策略管理程序被处理器执行时实现如下步骤:
    根据预设区域映射关系为安全组策略中的源IP匹配相应的源区域,和目标IP匹配相应的目标区域;
    根据预设审计规则、所述源区域和目标区域判断所述安全组策略是否违规;
    若所述安全组策略违规,则对所述安全组策略进行安全管控。
  19. 如权利要求18所述的安全组策略管理设备,其中,所述安全组策略管理设备程序被所述处理器执行时还实现如下步骤:
    若所述预设审计规则中不包括所述源区域,或者所述预设审计规则中不包括所述目标区域,或者,在所述预设审计规则中与所述源区域相对应的预设目标区域不包括所述目标区域,则判定所述安全组策略不违规;
    若所述预设审计规则中包括所述源区域和所述目标区域,且在所述预设审计规则中与所述源区域相对应的预设目标区域包括所述目标区域,则判定所述安全组策略违规。
  20. 如权利要求18所述的安全组策略管理设备,其中,所述安全组策略管理设备程序被所述处理器执行时还实现如下步骤:
    若所述安全组策略违规,则将所述安全组策略加入违规策略告警表;
    对所述违规策略告警表中的安全组策略进行去重;
    对去重后的违规策略告警表中的安全组策略进行安全管控。
PCT/CN2020/084226 2019-06-28 2020-04-10 安全组策略管理方法、装置、设备及计算机可读存储介质 Ceased WO2020258991A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201910584234.8A CN110324334B (zh) 2019-06-28 2019-06-28 安全组策略管理方法、装置、设备及计算机可读存储介质
CN201910584234.8 2019-06-28

Publications (1)

Publication Number Publication Date
WO2020258991A1 true WO2020258991A1 (zh) 2020-12-30

Family

ID=68122136

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2020/084226 Ceased WO2020258991A1 (zh) 2019-06-28 2020-04-10 安全组策略管理方法、装置、设备及计算机可读存储介质

Country Status (2)

Country Link
CN (1) CN110324334B (zh)
WO (1) WO2020258991A1 (zh)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113965343A (zh) * 2021-09-06 2022-01-21 锐捷网络股份有限公司 一种基于局域网的终端设备隔离方法及装置
US11405426B2 (en) * 2019-11-04 2022-08-02 Salesforce.Com, Inc. Comparing network security specifications for a network to implement a network security policy for the network
CN115834205A (zh) * 2022-11-23 2023-03-21 贵州电网有限责任公司 一种监控系统违规外联告警系统

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110324334B (zh) * 2019-06-28 2023-04-07 深圳前海微众银行股份有限公司 安全组策略管理方法、装置、设备及计算机可读存储介质
CN113904859B (zh) * 2021-10-20 2024-03-01 京东科技信息技术有限公司 安全组源组信息管理方法、装置、存储介质及电子设备
CN116137600B (zh) * 2021-11-17 2025-05-27 中移动信息技术有限公司 防火墙的安全度预测方法及装置

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7516492B1 (en) * 2003-10-28 2009-04-07 Rsa Security Inc. Inferring document and content sensitivity from public account accessibility
CN106034131A (zh) * 2015-03-18 2016-10-19 北京启明星辰信息安全技术有限公司 一种基于流Flow分析的业务合规检测方法和系统
CN107135187A (zh) * 2016-02-29 2017-09-05 阿里巴巴集团控股有限公司 网络攻击的防控方法、装置及系统
CN108449444A (zh) * 2018-03-29 2018-08-24 江苏省未来网络创新研究院 区域数据传输方法、自循环域名解析系统及方法
CN110324334A (zh) * 2019-06-28 2019-10-11 深圳前海微众银行股份有限公司 安全组策略管理方法、装置、设备及计算机可读存储介质

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101714997B (zh) * 2010-01-15 2012-11-28 中国工商银行股份有限公司 防火墙策略生成方法、装置及系统
CN103391216B (zh) * 2013-07-15 2016-08-10 中国科学院信息工程研究所 一种违规外联报警及阻断方法
US9998434B2 (en) * 2015-01-26 2018-06-12 Listat Ltd. Secure dynamic communication network and protocol
CN106230627B (zh) * 2016-07-28 2019-05-07 浪潮软件股份有限公司 一种基于可定制策略的web访问高峰缓解方法
CN109040089B (zh) * 2018-08-15 2021-06-08 深圳前海微众银行股份有限公司 网络策略审计方法、设备及计算机可读存储介质
CN109120448B (zh) * 2018-08-24 2020-05-05 武汉思普崚技术有限公司 一种告警方法及系统
CN109067770B (zh) * 2018-09-05 2021-04-23 高新兴科技集团股份有限公司 物联网系统的流量攻击控制方法及计算机存储介质

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7516492B1 (en) * 2003-10-28 2009-04-07 Rsa Security Inc. Inferring document and content sensitivity from public account accessibility
CN106034131A (zh) * 2015-03-18 2016-10-19 北京启明星辰信息安全技术有限公司 一种基于流Flow分析的业务合规检测方法和系统
CN107135187A (zh) * 2016-02-29 2017-09-05 阿里巴巴集团控股有限公司 网络攻击的防控方法、装置及系统
CN108449444A (zh) * 2018-03-29 2018-08-24 江苏省未来网络创新研究院 区域数据传输方法、自循环域名解析系统及方法
CN110324334A (zh) * 2019-06-28 2019-10-11 深圳前海微众银行股份有限公司 安全组策略管理方法、装置、设备及计算机可读存储介质

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11405426B2 (en) * 2019-11-04 2022-08-02 Salesforce.Com, Inc. Comparing network security specifications for a network to implement a network security policy for the network
US11716358B2 (en) 2019-11-04 2023-08-01 Salesforce, Inc. Comparing network security specifications for a network
CN113965343A (zh) * 2021-09-06 2022-01-21 锐捷网络股份有限公司 一种基于局域网的终端设备隔离方法及装置
CN115834205A (zh) * 2022-11-23 2023-03-21 贵州电网有限责任公司 一种监控系统违规外联告警系统

Also Published As

Publication number Publication date
CN110324334B (zh) 2023-04-07
CN110324334A (zh) 2019-10-11

Similar Documents

Publication Publication Date Title
WO2020258991A1 (zh) 安全组策略管理方法、装置、设备及计算机可读存储介质
US11030027B2 (en) System for technology anomaly detection, triage and response using solution data modeling
US20190097807A1 (en) Network access control based on distributed ledger
US8812342B2 (en) Managing and monitoring continuous improvement in detection of compliance violations
CN107634951A (zh) Docker容器安全管理方法、系统、设备及存储介质
CN104270467A (zh) 一种用于混合云的虚拟机管控方法
CN103475727A (zh) 一种基于桥模式的数据库审计方法
CN118484267A (zh) 一种基于云计算在线服务算力优化方法及系统
CN107463839A (zh) 一种管理应用程序的系统和方法
WO2021164194A1 (zh) 一种基于区块链的积分管理方法及相关装置
CN111680900A (zh) 一种工单发布方法、装置、电子设备及存储介质
CN115238247A (zh) 基于零信任数据访问控制系统的数据处理方法
CN116226865A (zh) 云原生应用的安全检测方法、装置、服务器、介质及产品
CN104063669A (zh) 一种实时监测文件完整性的方法
CN113934494A (zh) 一种云桌面管理方法、装置、电子设备及存储介质
WO2017107792A1 (zh) 一种数据信息处理方法以及数据存储系统
CN113158149A (zh) 一种操作权限的处理方法及装置
CN115174219B (zh) 一种可适配多种工业防火墙的管理系统
CN116228195A (zh) 适用于工单的数据处理方法、装置、设备及存储介质
CN107451469A (zh) 一种进程管理系统及方法
CN115688133A (zh) 一种数据处理方法、装置、设备以及存储介质
Jie et al. Industrial control system security
US10970406B2 (en) System for mitigating exposure associated with identified unmanaged devices in a network using solution data modelling
CN117272401A (zh) 一种数据隔离保护系统、方法、设备及存储介质
CN102238037A (zh) 协作式目标策略细化方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 20832379

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 20832379

Country of ref document: EP

Kind code of ref document: A1