Testing method for network isolation of cloud platform tenants

A technology of network isolation and testing method, applied in the field of cloud security testing and tenant network isolation testing based on cloud platform, which can solve problems such as damage, inability to effectively locate and isolate failure points, and failure to consider tenant network access equipment status testing.

Active Publication Date: 2018-04-24
BEIJING UNIV OF TECH
View PDF7 Cites 25 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

Yan Liyu et al. proposed to distribute the virtual routers / firewalls originally concentrated on the Openstack network nodes to each computing node to isolate tenant virtual machines. However, if the virtual router / firewall policy changes, it is easy to isolate the virtual machines of the same tenant on different nodes. The problem of inconsistency; the metering component Ceilometer proposed by Openstack collects cloud platform network data for traffic analysis, and can find abnormal traffic according to some known traffic rules, but it cannot quickly locate the abnormal problem; Yang Xu proposes A method for checking the consistency of the network status of each layer of the control node and the host terminal, but it does not fully cover all the network devices in the cloud platform, resulting in the inability to fully test whether the isolation is broken. If the tenant network access is not considered Equipment status test, etc.
[0005] The above solution has studied tenant network isolation and testing issues to a certain extent, but there are still problems such as inability to effectively locate isolation failure points and insufficient testing, which will make it difficult for cloud internal auditors or third-party auditors to intuitively understand the cloud platform Whether the isolation strategy and mechanism of the multi-tenant network is damaged, which is not conducive to the safe operation of the cloud platform and accountability

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Testing method for network isolation of cloud platform tenants
  • Testing method for network isolation of cloud platform tenants
  • Testing method for network isolation of cloud platform tenants

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0021] The present invention will be further described below in conjunction with the drawings and specific embodiments.

[0022] The invention is suitable for cloud platforms that adopt network virtualization technology, such as cloud platforms that adopt cloud management software such as CloudStack, Eucalyptus, Openstack, etc. The internal network of the cloud platform may adopt VLAN, GRE or VXLAN modes to isolate tenant network traffic. The present invention takes the current cloud platform management software Openstack with the highest market occupancy rate as an example to illustrate the cloud platform tenant network isolation test method, which is suitable for all the above isolation modes.

[0023] The tenant network isolation scenario on the cloud platform under Openstack is such as figure 1 Shown. Openstack uses Neutron network components for tenant network management. Tenant stands for tenant name, VM stands for virtual machine, Linux Bridge stands for traditional network...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention discloses a testing method for network isolation of cloud platform tenants and belongs to the technical field of computer cloud security testing. The method comprises the following steps: establishing an expectant cloud platform tenant network isolation matrix; acquiring basic information of all tenant networks on tenant control nodes and all computing nodes; acquiring isolation information of networks with three layers or above of all tenant networks on the network nodes; acquiring second-layer isolation information of tenant sub-networks on the network nodes and the computing nodes; acquiring network access information of the tenants and the tenant sub-networks on the computing nodes to generate an actual cloud platform tenant network isolation matrix Ma; comparing the generated cloud platform tenant network isolation matrix Ma with the expectant cloud platform tenant network isolation matrix. The isolating conditions of the tenant networks in the operation environmentare acquired from a bottom layer of the cloud platform network, whether the isolation of the current cloud platform network is abnormal or not is detected in real time, a visual network isolation report is provided for a cloud auditor, and an accountability path is provided for possible security problems of network services of the cloud tenants.

Description

Technical field [0001] The method relates to cloud security testing, in particular to a tenant network isolation testing method based on a cloud platform, and belongs to the field of computer technology. Background technique [0002] With the continuous maturity of cloud computing technology, more and more enterprises and individuals choose to deploy their systems on cloud platforms. However, cloud platforms are equivalent to "black boxes" for cloud tenants. Cloud providers cannot answer cloud tenants’ inquiries about security issues, nor can they provide tenants with isolated reports on cloud platform multi-tenant networks. The tenant cannot fully understand the cloud platform environment, and cannot find out whether the data in the tenant network is safe in time, so that the tenant cannot fully trust the cloud platform environment. [0003] The existing cloud platform management software mainly includes Openstack, CloudStack, Eucalyptus, etc., all of which include basic manageme...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06H04L29/08
CPCH04L63/02H04L67/10
Inventor 詹静高雅琪赵勇樊旭东王霞韩瑾
Owner BEIJING UNIV OF TECH
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products