A detection method and device for network security in a cloud computing network

A cloud computing network and network security technology, applied in the field of cloud computing, can solve problems such as attack, threat VMM, virtual machine infection virus, etc., to achieve the effect of ensuring security

CN104219211BActive Publication Date: 2017-11-21CHINA MOBILE COMM GRP CO LTD
7 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Publication Date
2017-11-21

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention discloses a method for detecting network security in a cloud computing network. The method includes: after learning that a virtual machine is started, checking whether the current security information of the virtual machine has been modified; repair operation. The invention also discloses a detection device for network security in a cloud computing network. By adopting the method and the device of the invention, it can effectively prevent virtual machines with security risks from pairing with virtual machine monitors (VMMs) belonging to the same physical host. and other virtual machines, as well as the entire cloud computing network.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention relates to network security technology in the field of cloud computing, in particular to a method and device for detecting network security in a cloud computing network. Background technique

[0002] In cloud computing technology, virtualization technology can be used to implement multiple virtual machines running on the same physical host at the same time, and data packets between virtual machines belonging to the same physical host are forwarded without going through a physical switch. That is to say, the communication flow between virtual machines belonging to the same physical host is not monitored and managed by physical switches or other network devices in the network. The virtual machine initiates internal attacks such as abnormal traffic, which in turn threatens the security of the entire cloud computing network.

[0003] In the prior art, in order to prevent a virtual machine from initiating an attack to other virtual machines b...

Examples

Embodiment 1

[0071] The detection method of network security in the cloud computing network of this embodiment, such as Figure 4 shown, including the following steps:

[0072] Step 401: When it is necessary to apply for a virtual machine, the user sends a service request to the cloud computing operation management platform through the self-service portal of the cloud computing operation management platform;

[0073] Step 402: the cloud computing operation and management platform receives the service request and, after reviewing the received service request, issues an instruction to allocate resources to the resource pool management platform through the management interface;

[0074] Step 403: After receiving the instruction, the resource pool management platform allocates a corresponding virtual machine to the user;

[0075] Here, the specific implementation of steps 401-403 is the prior art, and will not be repeated here.

[0076] Steps 404-405: The resource pool management platform tr...

Embodiment 2

[0107] The detection method of network security in cloud computing in this embodiment, such as Figure 5 shown, including the following steps:

[0108] Step 501: When it is necessary to apply for a virtual machine, the user sends a service request to the cloud computing operation management platform through the self-service portal of the cloud computing operation management platform;

[0109] Step 502: the cloud computing operation and management platform receives the service request and, after reviewing the received service request, issues an instruction to allocate resources to the resource pool management platform through the management interface;

[0110] Step 503: After receiving the instruction, the resource pool management platform allocates a corresponding virtual machine to the user;

[0111] Here, the specific implementation of steps 501-503 is the prior art, and will not be repeated here.

[0112] Steps 504-505: the resource pool management platform triggers the c...