Unlock instant, AI-driven research and patent intelligence for your innovation.

Deployment optimization method of software-defined firewall based on openstack cloud platform

A software-defined and firewall technology, applied in electrical components, digital transmission systems, secure communication devices, etc., can solve problems such as slow deployment of security resources, deployment bottlenecks, and inability to satisfy tenants' rapid response to security services

Active Publication Date: 2022-01-14
STATE GRID CORP OF CHINA +1
View PDF10 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0005] As a cloud computing framework, OpenStack has the capability of software-defined firewall (FWaaS), but as a security resource, the firewall simply instantiates the firewall without optimizing the deployment and scheduling of the firewall instance. Deployment is slow, deployment distribution is unreasonable, and cannot satisfy tenants' rapid response to security services
[0006] From the perspective of OpenStack firewall deployment, all virtual routers of tenants are deployed on network nodes in OpenStack, and firewall instances are actually virtual routers. Network nodes not only provide virtual routing services, but also provide dhcp and metadata services at the same time; a large number of centralized Deploying firewall instances on network nodes will cause deployment bottlenecks. From the tenant's business perspective, there will also be traffic bottlenecks.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Deployment optimization method of software-defined firewall based on openstack cloud platform

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0019] The present invention will be described in further detail below in conjunction with the accompanying drawings and specific embodiments.

[0020] Such as figure 1 As shown, the deployment optimization method of a software-defined firewall based on the openstack cloud platform provided by the present invention includes:

[0021] 1) The firewall is used as the specific implementation module of the FWAAS standard interface, and the firewall interface originally supported by FWAAS is implemented through the firewall.

[0022] 2) The tenant divides the business security domain according to its own business through the business security domain module, and each business security domain has an independent business security goal, and can independently configure, implement, manage and operate the security business.

[0023] 3) In the independent business security domain, security resource pool management is realized. A security resource pool consists of one or more security nodes...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a deployment optimization method of a software-defined firewall based on the openstack cloud platform. The firewall is used as a specific implementation module of the FWAAS standard interface; the business security domain is divided by the tenant business; and the security resource pool management is realized in the independent business security domain; The security resources in the security resource pool adopt a pre-allocation mechanism; the optimization scheduling module can dynamically select nodes in the security business domain when creating a firewall according to the tenant's demand for traffic, and deploy the firewall instance in the security node that meets the tenant's needs . The method of the present invention can quickly respond to the needs of tenants for security services; through the optimized scheduling module, the FWAAS of Openstack provides the ability to quickly deploy security services; through the service security domain module, the security requirements corresponding to different services are separated, and tenants can quickly obtain firewalls Instances, so as to quickly configure security policies, and avoid problems such as slow firewall instance deployment and untimely response in the original Openstack solution.

Description

technical field [0001] The invention belongs to the field of network security protection, and in particular relates to a deployment optimization method of a software-defined firewall based on an openstack cloud platform. Background technique [0002] With the popularization of cloud computing, the IT transformation brought about by the software-defined data center is unstoppable. The improvement of IT efficiency and the saving of IT cost have benefited major enterprises, institutions and operators, but at the same time, it has also made traditional data The network security architecture of the center is no longer applicable to the data center after cloudification. The concept of software defined security (Software Defined Security, SDS) is based on the principle of combining physical or virtual network security devices with their access modes, deployment methods, and functional implementations. For decoupling, the bottom layer is abstracted as resources in the security resou...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L9/40H04L41/0803H04L67/1036H04L67/1031
CPCH04L41/0803H04L63/02H04L67/1031H04L67/1036
Inventor 叶卫蔡昊洋王以良王红凯郭亚琼陈超龚小刚沈潇军戚伟强沈志豪裴旭斌耿继朴陈可王剑刘秀喻谦曾君军王豪磊
Owner STATE GRID CORP OF CHINA