A method and apparatus for processing a secure network element, and a medium
By parsing the addresses of north-south traffic data and determining the security service chain according to policy routing, the custom arrangement of security network elements is realized, which solves the problems of complex arrangement and high cost in existing technologies and improves the security of data transmission.
Patent Information
- Application Number
- CN202310348777.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-30
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2043-03-30
AI Technical Summary
The existing security network elements have complex orchestration methods, and in ordinary cloud environments, the hardware equipment is costly and the software equipment requires professional technicians to configure, making it difficult to manage flexibly.
By acquiring packet data of north-south traffic, parsing address data, and determining the security service chain based on policy routing and single/dual-arm modes, security network elements are automatically configured, enabling customizable network element arrangement order.
It reduces the complexity of processing and orchestrating security network elements, saves labor costs, and improves the security of data transmission.
Smart Images

Figure CN116319045B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, in particular to a security network element processing method and device and medium. BACKGROUND
[0002] With the development of cloud computing technology, more and more enterprises choose to build their own cloud environment as the basis of internal office platform. The business running on the cloud platform not only connects the external network to obtain relevant information to provide services for internal users, but also needs to communicate with the external network across the wide area network for off-site office. The above situations face security risks because of the access to the Internet.
[0003] In order to deal with the security risk problem, the existing security equipment manufacturers provide physical hardware devices and software security devices for security services for the network. For physical hardware devices, the procurement cost and maintenance cost are high when they are applied to the scene with less running task and lower throughput requirement in ordinary cloud environment, which is not suitable. For software security devices, although the use cost of security network element is saved and the maintenance method is flexible, the skill requirement of professional technicians is still high, and manual configuration and management of security network element are needed. When facing more security network elements, the arrangement of security network element is more complex.
[0004] Therefore, it is urgent for those skilled in the art to seek an arrangement method of security network element to reduce the operation complexity. SUMMARY
[0005] The purpose of the present application is to provide a security network element processing method, device and medium, to provide a custom network element arrangement order, to save labor cost, to reduce the processing and arrangement complexity of security network element, and to improve the transmission security of data.
[0006] To solve the above technical problems, the present application provides a security network element processing method, comprising:
[0007] Obtain the message data corresponding to the current north-south traffic data, wherein the current north-south traffic data is the data transmitted between the virtual machine and the external network;
[0008] The message data is analyzed to obtain address data;
[0009] When the address data meets the preset condition of policy routing, determine the security service chain according to the address data, the security network element address data corresponding to the policy routing and the single / double arm mode;
[0010] According to the security service chain, the current north-south traffic data is transmitted to the target subnet, wherein the target subnet is the subnet corresponding to the virtual machine or the external network.
[0011] Preferably, the number of routing manners of the policy-based routing is the same as the number of the security network elements, and the number of the security network elements is at least one.
[0012] Preferably, the address data at least includes a destination Internet Protocol address, a source Internet Protocol address, a destination Media Access Control address and a source Media Access Control address, when the current north-south traffic data is northbound traffic data, the number of the security network elements is two, and the two security network elements are both in the double-arm mode of the single-double-arm mode, the preset condition includes a first preset condition and a second preset condition, the first preset condition is that the source Internet Protocol address is a first subnet Internet Protocol address and the destination Media Access Control address is a subnet gateway Media Access Control address where the first subnet is located, and the second preset condition is that the source Internet Protocol address is the first subnet Internet Protocol address and the destination Media Access Control address is a subnet gateway Media Access Control address where a first security subnet is located, and the determining of the security service chain according to the address data of the security network elements corresponding to the policy-based routing and the single-double-arm mode includes:
[0013] obtaining the first subnet Internet Protocol address of the virtual machine corresponding to the first subnet, the subnet gateway Media Access Control address where the first subnet is located and the subnet gateway Media Access Control address where the first security subnet is located, wherein the address data of the security network elements includes address data corresponding to the first security subnet and a second security subnet;
[0014] judging whether the source Internet Protocol address and the destination Media Access Control address are respectively the first subnet Internet Protocol address and the subnet gateway Media Access Control address where the first subnet is located;
[0015] if yes, it is determined that the first preset condition is met;
[0016] the northbound traffic data is imported into the first security subnet so that the first security subnet processes the address information to obtain first address information, and the first address information is transferred into the router;
[0017] judging whether the source Internet Protocol address and the destination Media Access Control address after passing through the first security subnet are respectively the first subnet Internet Protocol address and the subnet gateway Media Access Control address where the first security subnet is located;
[0018] if yes, it is determined that the second preset condition is met;
[0019] directing the northbound traffic data to the second security subnet so as to process the first address information to obtain second address information and to direct the second address information to the router;
[0020] directing the northbound traffic data to the second security subnet so as to process the first address information to obtain second address information and to direct the second address information to the router;
[0021] Preferably, when the current southbound traffic data is southbound traffic data, the preset condition comprises a third preset condition and a fourth preset condition, the third preset condition is that the destination Internet Protocol address is a destination Internet Protocol address of the first subnet and the destination Media Access Control address is a subnet gateway Media Access Control address of a subnet where the second subnet is located, and the fourth preset condition is that the destination Internet Protocol address is a destination Internet Protocol address of the first subnet and the destination Media Access Control address is a subnet gateway Media Access Control address of a subnet where the second security subnet is located.
[0022] obtaining a destination Internet Protocol address of the first subnet, a subnet gateway Media Access Control address of a subnet where the second subnet is located, and a subnet gateway Media Access Control address of a subnet where the second security subnet is located;
[0023] judging whether the destination Internet Protocol address and the destination Media Access Control address are respectively a destination Internet Protocol address of the first subnet and a subnet gateway Media Access Control address of a subnet where the second subnet is located;
[0024] if yes, it is determined that the third preset condition is met;
[0025] directing the southbound traffic data to the second security subnet so as to process the address information to obtain third address information and to direct the third address information to the router;
[0026] judging whether the destination Internet Protocol address and the destination Media Access Control address after passing through the second security subnet are respectively a destination Internet Protocol address of the first subnet and a subnet gateway Media Access Control address of a subnet where the second security subnet is located;
[0027] if yes, it is determined that the fourth preset condition is met;
[0028] directing the southbound traffic data to the first security subnet so as to process the third address information to obtain fourth address information and to direct the fourth address information to the router;
[0029] According to the southbound traffic data, an import order path of the second subnet, the second security subnet, the first security subnet and the first subnet is imported as the security service chain.
[0030] Preferably, the current southbound traffic data is the southbound traffic data, one single-arm mode exists in the two security network elements, the preset condition is that the destination Internet Protocol address is a destination Internet Protocol address of the first subnet and the destination Media Access Control address is a subnet gateway Media Access Control address where the second subnet is located, and the determining of the security service chain according to the address data corresponding to the policy routing and the single / double-arm mode of the security network element comprises the following steps.
[0031] Obtaining a destination Internet Protocol address of the first subnet and a subnet gateway Media Access Control address where the second subnet corresponding external network is located;
[0032] Judging whether the destination Internet Protocol address and the destination Media Access Control address are respectively a destination Internet Protocol address of the first subnet and a subnet gateway Media Access Control address where the second subnet is located;
[0033] If yes, it is determined that the preset condition is met;
[0034] The southbound traffic data is imported into a target security subnet corresponding to other security network elements except the security network element corresponding to the single-arm mode, so that the target security subnet processes the address information to obtain fifth address information, and the fifth address information is transferred to the router;
[0035] According to the southbound traffic data, an import order path of the second subnet, the target security subnet and the first subnet is imported as the security service chain.
[0036] Preferably, the interface information of the API interface of the security service chain at least includes network security service information and corresponding security network element information.
[0037] Preferably, the method further comprises the following steps.
[0038] Establishing a database corresponding to the security service chain, wherein the database at least stores basic information of the security service chain, basic information of the security network element, and corresponding acting security service chain and diversion subnet information and corresponding security service chain identity data, and the subnet information at least includes subnet data of the virtual machine, the external network and the security network element as a subnet.
[0039] To solve the above technical problems, the application further provides a processing device of a security network element, comprising:
[0040] an acquisition module, configured to acquire message data corresponding to current north-south traffic data, wherein the current north-south traffic data is data transmitted between a virtual machine and an external network;
[0041] an analysis module, configured to analyze the message data to obtain address data;
[0042] a determination module, configured to determine a security service chain according to the address data, security network element address data corresponding to the address data, and single / double-arm mode when the address data meets a preset condition of policy-based routing;
[0043] a transmission module, configured to transmit the current north-south traffic data to a target subnet according to the security service chain, wherein the target subnet is a subnet corresponding to the virtual machine or the external network.
[0044] To solve the above technical problem, the present application further provides a processing device of a security network element, comprising:
[0045] a memory, configured to store a computer program;
[0046] a processor, configured to execute the computer program to realize the steps of the processing method of the security network element.
[0047] To solve the above technical problem, the present application further provides a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program is executed by a processor to realize the steps of the processing method of the security network element.
[0048] The application provides a processing method of a security network element, which comprises the following steps: obtaining message data corresponding to current north-south traffic data, wherein the current north-south traffic data is data transmitted between a virtual machine and an external network; performing analysis and processing on the message data to obtain address data; when the address data meets preset conditions of a policy-based routing, determining a security service chain according to the address data, security network element address data corresponding to the policy-based routing and a single-arm mode; and transmitting the current north-south traffic data to a target subnet according to the security service chain, wherein the target subnet is a subnet corresponding to the virtual machine or the external network. The method uses the characteristics of the north-south traffic data passing through a router, analyzes the corresponding message data to obtain address data, uses the policy-based routing to introduce the north-south traffic into a determined security service chain when the address data meets the preset conditions of the policy-based routing, and determines the security service chain according to the address data, the security network element address data corresponding to the policy-based routing and the single-arm mode. The north-south traffic is forwarded to the external network after being processed by the security network element in the security service chain, or the traffic entering the cloud platform from the external network also passes through the security network element in the security service chain for processing, so that the arrangement order of the security network element is customized, the manual cost is saved, the processing and arrangement complexity of the security network element is reduced, and the transmission security of the data is improved.
[0049] In addition, the application further provides a processing device and medium of a security network element, which have the same beneficial effects as the processing method of the security network element. BRIEF DESCRIPTION OF DRAWINGS
[0050] In order to more clearly illustrate the embodiments of the application, the drawings required in the embodiments will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative effort.
[0051] Figure 1 A flowchart of the processing method of the security network element provided by the embodiments of the application;
[0052] Figure 2 A security service chain diagram of the north-south traffic data provided by the embodiments of the application;
[0053] Figure 3 A structure diagram of the processing device of the security network element provided by the embodiments of the application;
[0054] Figure 4 A structure diagram of another processing device of the security network element provided by the embodiments of the application. DETAILED DESCRIPTION
[0055] With reference to the accompanying drawings, the technical solutions in the embodiments of the present application will be described clearly and completely. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.
[0056] The core of the present application is to provide a security network element processing method, device and medium, provide a custom network element arrangement order, save labor cost, reduce the processing arrangement complexity of the security network element, and improve the transmission security of data.
[0057] In order to enable personnel in the technical field to better understand the present application scheme, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0058] For the physical hardware devices provided by the existing security device manufacturers for the network, planning and deployment need to be performed at the beginning of network planning, and configuration and debugging need to be performed one by one. Not only is the equipment procurement cost high, but there is also a problem of difficult unified management and configuration, and subsequent flexible adjustment cannot be performed according to demand iteration update. For a scene with high performance and super large bandwidth demand, hardware security devices can be directly used. However, for an ordinary cloud environment, the number of nodes is small, the operation business is small, and the scene does not require high latency and throughput. It is not suitable to purchase expensive and high-maintenance security devices. Considering the price and maintenance cost of hardware products, the security device manufacturers also provide software security devices. The security software product runs into the production environment and is configured for the network. External traffic is introduced into the security network element device, and after security software processing, the traffic is forwarded to the original traffic forwarding path, and then enters the cloud environment. The above method can greatly reduce the use cost of the security network element, and the maintenance method is more flexible and convenient. However, professional technical personnel are still required for configuration and management, and for the case of requiring multiple security network elements, the arrangement of the security network elements is still relatively complex.
[0059] The present application improves the shortcomings of the above two cases. Without providing physical hardware devices, only the configuration and management of the security network elements are completed automatically on the basis of software. Professional technical personnel or users can arrange the security network elements on the cloud platform management page. At this time, the security network elements are directly visualized as number processing. One number corresponds to one security network element. The arrangement of the current security network elements can be completed by adjusting or arranging the number information on the cloud platform management page.
[0060] Figure 1 A flowchart of a security network element processing method provided by the embodiments of the present application is shown in Figure 1 , and includes:
[0061] S11: Obtain message data corresponding to current north-south traffic data, wherein the current north-south traffic data is data transmitted between the virtual machine and the external network;
[0062] S12: Analyze the message data to obtain address data;
[0063] S13: When the address data meets a preset condition of policy routing, determine a security service chain according to the address data, security network element address data corresponding to the policy routing, and single-arm mode or double-arm mode;
[0064] S14: Transmit the current north-south traffic data to a target subnet according to the security service chain, wherein the target subnet is a subnet corresponding to the virtual machine or the external network.
[0065] It should be noted that the method provided by the present application can be applied in different cloud environments, such as openstack, k8s, and other cloud computing open source infrastructure projects, an environment using an open virtual network (Open Virtual Network, OVN) for control plane, and the execution subject of the embodiment is a virtual machine router. The OVN is a controller of an open vSwitch (Open vSwitch, OVS) virtual machine network device, used for managing the working behavior of the OVS. Based on the policy routing function of the OVN, the processing of the security network element described above can be realized. The north-south traffic is once introduced into the security network element, thereby realizing the effect of the security service chain. The policy routing is based on policy-based routing, and the traditional routing is based on routing decision and forwarding according to the destination Internet Protocol Address (Internet Protocol Address, IP address). The policy routing expands the reference range, and in addition to the destination IP address, other information in the network message is also referenced, such as the Media Access Control (Media Access Control, MAC) address, the source IP address, the port, etc. The message data corresponding to the current north-south traffic data is obtained, specifically, the current north-south traffic data includes southbound traffic data and northbound traffic data, and the corresponding southbound traffic data and / or northbound traffic data can be obtained, and the different data types correspond to different arrangement modes of the security network element.
[0066] The embodiment is only applicable to the north-south traffic data, and the east-west traffic data is the network traffic data in the cloud environment. The northbound traffic data is the traffic accessing the external network in the cloud environment, the matching IP address is the specified subnet, the destination MAC address is the gateway MAC of the specified subnet, the address used to determine the network device position is re-routed and forwarded to the first network element on the security service chain. The southbound traffic data, that is, the traffic flowing into the cloud environment from the external network, matches the destination IP of the specified service subnet and the destination MAC of the external network gateway MAC, and is re-routed and forwarded to the last network element on the security service chain. For the current north-south traffic data, it is the traffic data transmitted between the virtual machine and the external network.
[0067] The message data corresponding to the current north-south traffic data is obtained, whether it is the data of the virtual machine accessing the external network or the data of the external network responding to the virtual machine after the data of the virtual machine accessing the external network, or the data of the external network accessing the virtual machine. After the current north-south traffic data reaches the router, it is first routed normally. Before normal routing, the message data corresponding to the current north-south traffic data needs to be obtained, and the corresponding address data is obtained by parsing the message data. The address data is not limited here and can be IP address data, MAC address data, or a combination of the two data, etc. It can be set according to the actual situation.
[0068] The router first performs normal routing according to the address data. When the address data meets the preset condition of the policy-based routing, the security service chain is determined according to the address data, the security network element address data corresponding to the policy-based routing, and the single-arm or double-arm mode. The router connects two or more network devices and acts as a gateway between networks. The gateway is a device that realizes network interconnection above the network layer. It can be understood that there can be multiple routing modes corresponding to the policy-based routing, which means that there are multiple security network elements. The security network element in cloud computing is a network unit that provides security services for the network, such as a special virtual machine that provides firewall function, a virtual machine that provides network address translation (NAT), etc. The firewall is a technology that helps to build a relatively isolated protective barrier between the internal and external networks of a computer network by organically combining various software and hardware devices for security management and screening, to protect user data and information security. NAT is a network address translation that converts internal network addresses to external network addresses. As an embodiment, the number of routing modes of the policy-based routing is the same as the number of security network elements, and the number of security network elements is at least one.
[0069] Specifically, each policy-based routing corresponds to the direction of the action of a security network element. Figure 2A security service chain diagram for north-south traffic data provided by an embodiment of the present application is shown in FIG. 1. As shown in FIG. 1, the black dashed line is a north-south traffic data forwarding path without introducing a security service chain. The router matches the destination IP address and forwards the message data to access the external network. Figure 2 The solid line in FIG. 1 is a traffic forwarding path after introducing the security service chain. The router matches the address information in the message and forwards the matched traffic data to the security network element virtual machine one by one. After the security network element processes the message, it is reforwarded to the router, which reforwards the traffic data to the external network according to the destination IP address. In the data transmission without introducing the security service chain, the security of the data cannot be guaranteed. The security service chain is introduced to ensure the security of data transmission, avoid data omission or interference, etc. Therefore, at least one security network element exists. Figure 2
[0070] The single-arm and double-arm mode is specific to each security network element, which can be bidirectional or unidirectional. The unidirectional mode supports direction selection. The single-arm and double-arm mode is the traffic forwarding direction of the network element. The single-arm is applied to one forwarding direction, and the double-arm is applied to both directions. In addition, the preset conditions corresponding to the policy routing are set according to the number of security network elements, that is, the number of preset conditions is the same as the number of security network elements. For example, there are two preset conditions, the first preset condition and the second preset condition. The first preset condition is set as the limit for entering the first security network element, and the second preset condition is set as the limit for entering the second security network element. The limits of the two preset conditions can be set according to the order of the security network elements, or the synchronous selection of the two security network elements can be selected, etc. This is not limited, and can be set according to the actual situation. When the address data does not meet the preset conditions of the policy routing, it can jump to the next interface according to the conventional routing, or it can find the corresponding next subnet through the Antenna in Package (AIP) broadcast mode, which is not limited.
[0071] According to the address data and the security network element address data and the single-arm and double-arm mode, the import order of the current security network element, that is, the security service chain, is determined. Figure 2 The security service chain is implemented through subnets 1-3 and an external network. A service function chain (SFC) is a network scenario in which a data flow usually needs to pass through multiple network service devices, such as an intrusion detection system (IDS) / intrusion prevention system (IPS), a firewall, a load balancing device (LB), and the like, before finally reaching a destination. The network devices that are passed through form a service chain. The LB device is a device that distributes loads to multiple operation units for execution. Figure 2 The subnets in the figure are used to determine network areas, thereby generating several separate network islands. Figure 2 Subnet 1 in the figure is a subnet that needs to direct north-south traffic to a security service chain. The subnet can access an external network through a router. Vif1 is a gateway interface of the subnet 1 on the router. Subnets 2 and 3 are security subnets that provide security services. Security network elements use addresses in the security subnets. Vif2 and vif3 are gateway interfaces of the security subnets on the router. Vif4 is a gateway interface of the external network on the router.
[0072] After the security service chain is determined, current north-south traffic data is transmitted to a target subnet. Specifically, when the current north-south traffic data is northbound traffic data, the target subnet is a subnet corresponding to the external network. When the current north-south traffic data is southbound traffic data, the target subnet is a subnet corresponding to the virtual machine.
[0073] The processing method of the safe network element provided by the embodiment of the application comprises the following steps: obtaining message data corresponding to current north-south traffic data, wherein the current north-south traffic data is data transmitted between a virtual machine and an external network; performing analysis and processing on the message data to obtain address data; when the address data satisfies a preset condition of a policy-based routing, determining a security service chain according to the address data, security network element address data corresponding to the policy-based routing, and a single-arm mode or a double-arm mode; and transmitting the current north-south traffic data to a target subnet according to the security service chain, wherein the target subnet is a subnet corresponding to the virtual machine or the external network. The method uses the characteristic that the north-south traffic data passes through a router, analyzes the corresponding message data to obtain address data, uses the policy-based routing to introduce the north-south traffic into a determined security service chain when the address data satisfies the preset condition of the policy-based routing, determines the security service chain according to the address data, the security network element address data corresponding to the policy-based routing, and the single-arm mode or the double-arm mode, and forwards the north-south traffic to the external network after processing by the security network element in the security service chain, or the traffic entering the cloud platform from the external network also passes through the processing of the security network element in the security service chain, so as to provide a custom network element arrangement order, save labor cost, reduce the processing and arrangement complexity of the security network element, and improve the transmission security of data.
[0074] On the basis of the above embodiment, as an embodiment, the address data at least comprises a destination IP address, a source IP address, a destination MAC address and a source MAC address, when the current north-south traffic data is northward traffic data, the number of the security network elements is two, and the two security network elements are both double-arm mode, the preset condition comprises a first preset condition and a second preset condition, the first preset condition is that the source IP address is a first subnet IP address and the destination MAC address is a subnet gateway MAC address of a first subnet, the second preset condition is that the source IP address is the first subnet IP address and the destination MAC address is a subnet gateway MAC address of a first security subnet, and the security service chain is determined according to the address data, the security network element address data corresponding to the policy-based routing, and the single-arm mode or the double-arm mode, comprising:
[0075] obtaining the first subnet IP address of the virtual machine corresponding to the first subnet, the subnet gateway MAC address of the first subnet and the subnet gateway MAC address of the first security subnet, wherein the security network element address data comprises address data corresponding to the first security subnet and the second security subnet;
[0076] determining whether the source IP address and the destination MAC address are respectively the first subnet IP address and the subnet gateway MAC address of the first subnet;
[0077] if yes, it is determined that the first preset condition is satisfied;
[0078] The northbound traffic data is imported into the first security subnet, so that the first security subnet processes the address data to obtain first address data, and the first address data is transferred to the router;
[0079] It is judged whether the source IP address and the destination MAC address after passing through the first security subnet are respectively the first subnet IP address and the subnet gateway MAC address where the first security subnet is located;
[0080] If yes, it is determined that the second preset condition is met;
[0081] The northbound traffic data is imported into the second security subnet, so that the second security subnet processes the first address data to obtain second address data, and the second address data is transferred to the router;
[0082] According to the import order path of the first subnet, the first security subnet, the second security subnet and the second subnet for the northbound traffic data, a security service chain is obtained.
[0083] Specifically, for the northbound traffic data, the message of accessing the external network issued by the virtual machine reaches the router, the number of security network elements is limited to two and both are in the double-arm mode, that is, the two security network elements support bidirectional flow diversion. The preset conditions include a first preset condition for importing the first security subnet and a second preset condition for importing the second security subnet. In step S13, the security service chain is determined according to the security network element address data corresponding to the address data and the single / double-arm mode, the first subnet IP address of the first subnet and the subnet gateway MAC address where the first subnet is located are obtained, and the subnet gateway MAC address where the first security subnet is located. As shown in Figure 2 The first subnet in the above is subnet 1 corresponding to the virtual machine, the first security subnet is subnet 2, and the second security subnet is subnet 3. The security network element address data can be the same as the type of the address data parsed according to the message data, or can be different, which is not limited here. As a preferred embodiment, the two types of address data are the same, and at least the corresponding source IP address, destination IP address, source MAC address and destination MAC address.
[0084] When the source IP address and the destination MAC address are respectively the first subnet IP address and the subnet gateway MAC address where the first subnet is located, it is determined that the first preset condition is met, the northbound traffic data can be imported into the first security subnet, and the first security subnet performs security processing on the address data to obtain first address data. The process of security processing is not limited, which can be updating each corresponding address data and the current address data of the first security subnet to obtain the first address data. The gateway is a device for realizing network interconnection above the network layer.
[0085] As an embodiment, the processing process of the first address data specifically includes:
[0086] obtaining a MAC address of the first security subnet and a subnet gateway MAC address where the first security subnet is located;
[0087] updating the source MAC address to the MAC address of the first security subnet;
[0088] updating the destination MAC address to the subnet gateway MAC address where the first security subnet is located.
[0089] Specifically, the source MAC address of the address data corresponding to the packet data is updated to the MAC address of the first security subnet, and the destination MAC address is updated to the subnet gateway MAC address where the first security subnet is located. The source IP address and the destination IP address of the address data corresponding to the packet data are not changed. After the first security subnet is processed, the traffic forwarded from the corresponding network element A is matched in the router, that is, the source IP address and the destination MAC address after passing through the first security subnet are the first subnet IP address and the subnet gateway MAC address where the first security subnet is located, respectively, and it is determined that the second preset condition is met. The northbound traffic data can be imported into the second security subnet, and the processing principle of the above security subnet is the same, which will not be described here.
[0090] As an embodiment, the processing process of the second address data specifically includes:
[0091] obtaining a source IP address of the second security subnet;
[0092] updating the destination IP address of the first address data to the source IP address of the second security subnet.
[0093] Specifically, the destination IP address of the first address data is updated to the source IP address of the second security subnet. The remaining address data is not changed. The packet of the traffic data leaving the network element B of the second security subnet and reaching the router is not processed additionally, and is directly forwarded to the external network by the conventional routing.
[0094] According to the import order path of the northbound traffic data into the first subnet, the first security subnet, the second security subnet and the second subnet as the current security service chain.
[0095] As another embodiment, when the current southbound traffic data is the southbound traffic data, the preset condition includes a third preset condition and a fourth preset condition, the third preset condition is that the destination IP address is the destination IP address of the first subnet and the destination MAC address is the subnet gateway MAC address where the second subnet is located, and the fourth preset condition is that the destination IP address is the destination IP address of the first subnet and the destination MAC address is the subnet gateway MAC address where the second security subnet is located. According to the address data corresponding to the policy routing of the security network element address data and the single / dual-arm mode, the security service chain is determined, including:
[0096] obtain a destination IP address of the first subnet, a subnet gateway MAC address of the external network corresponding to the second subnet, and a subnet gateway MAC address of the second security subnet;
[0097] determine whether the destination IP address and the destination MAC address are respectively the destination IP address of the first subnet and the subnet gateway MAC address of the second subnet;
[0098] if yes, determine that the third preset condition is met;
[0099] import the southbound traffic data into the second security subnet so that the second security subnet processes the address data to obtain third address data, and transfer the third address data to the router;
[0100] determine whether the destination IP address and the destination MAC address after passing through the second security subnet are respectively the destination IP address of the first subnet and the subnet gateway MAC address of the second security subnet;
[0101] if yes, determine that the fourth preset condition is met;
[0102] import the southbound traffic data into the first security subnet so that the first security subnet processes the third address information to obtain fourth address data, and transfer the fourth address data to the router;
[0103] the import order path of the second subnet, the second security subnet, the first security subnet and the first subnet according to the southbound traffic data is taken as a security service chain.
[0104] Specifically, the current southbound traffic data can be the traffic data of the message data of the external network responding after the northbound traffic data in the above embodiment is forwarded to the external network and enters the cloud platform, or can be the traffic data of the external network directly accessing the virtual machine, which is not limited here and can be set according to actual conditions. It should be noted that the first security subnet and the second security subnet in the embodiment follow the nomenclature in the above embodiment, and can also be different, and are re-sequenced according to the embodiment, which is not limited here.
[0105] According to the above embodiment, the number of security network elements is limited to two, and both are in a double-arm mode. The preset conditions include the third preset condition for importing the second security subnet and the first preset condition for importing the first security subnet. In step S13, the security service chain is determined according to the security network element address data corresponding to the address data and the policy routing and the single / double-arm mode, the destination IP address of the first subnet, the subnet gateway MAC address of the second subnet, and the subnet gateway MAC address of the second security subnet are obtained.
[0106] When the destination IP address and the destination MAC address are the destination IP address of the first subnet and the MAC address of the subnet gateway of the second subnet respectively, it is determined that the third preset condition is met, the southbound traffic data is imported into the second security subnet, and the second security subnet performs security processing to obtain third address data. The processing principle is the same as that of the above embodiment, and will not be described here.
[0107] According to the import order path of the southbound traffic data into the second subnet, the second security subnet, the first security subnet and the first subnet as the current security service chain.
[0108] As an embodiment, the processing process of the third address data specifically includes:
[0109] updating the source MAC address to the MAC address of the second security subnet;
[0110] updating the destination MAC address to the MAC address of the subnet gateway of the second security subnet;
[0111] Specifically, the source MAC address of the address data corresponding to the message data is updated to the MAC address of the second security subnet, and the destination MAC address is updated to the MAC address of the subnet gateway of the second security subnet. The source IP address and the destination IP address of the address data corresponding to the message data are not changed. After the second security subnet is processed, the traffic forwarded from the corresponding network element B is matched in the router, and it is determined that the third preset condition is met, and the southbound traffic data is imported into the first security subnet. The process can refer to the security subnet processing process in the above embodiment, and will not be described here.
[0112] As an embodiment, the processing process of the fourth address data specifically includes:
[0113] obtaining the destination IP address of the first subnet;
[0114] updating the destination IP address of the third address data to the destination IP address of the first subnet.
[0115] Specifically, the destination IP address of the first address data is updated to the source address of the first security subnet, and the remaining address data is not changed. The message of the traffic data leaving the network element A of the first security subnet and reaching the router is not processed additionally, and is directly forwarded to the virtual machine by the conventional routing.
[0116] As a preferred embodiment, the whole process of the virtual machine accessing the external network is shown in Table 1, which is a traffic import strategy routing table. As shown in Table 1, the specific process is as follows:
[0117] 1. The message of the virtual machine VM accessing the external network reaches the router. The router first performs regular routing according to the destination IP, and then matches whether the source IP address is an IP address within the subnet 1 network segment and whether the destination MAC is the MAC of vif1. If the matching is successful, the next hop destination address of the message is set as the IP address of the security network element A and is forwarded.
[0118] 2. After the message reaches the security network element, the data in the message is first processed for security, and then is forwarded out to the router. The security network element does not change the destination IP and the source IP of the message, but only changes the source MAC and the destination MAC of the message. At this time, the source MAC of the message is the MAC of the security network element, and the destination MAC is the MAC of the gateway of the subnet where the security network element is located.
[0119] 3. The traffic forwarded from the network element A is matched in the router whether the source IP address is an IP address within the subnet 1 network segment and whether the destination MAC is the MAC of vif2. If the matching is successful, the next hop destination address of the message is set as the IP address of the security network element B and is forwarded.
[0120] 4. The message of the traffic leaving the network element B and reaching the router is not processed additionally, but is forwarded to the external network by regular routing.
[0121] 5. After the message of the response of the external network enters the cloud platform, it first reaches the router. The policy routing matches that the destination IP address of the message is the IP of the specified subnet and the destination MAC is the gateway vif4 of the external network, and then the message is re-routed, the next hop destination of the message is set as the security network element B, and is forwarded to the security network element virtual machine.
[0122] 6. After the message reaches the security network element B, the data in the message is processed for security, and then the source MAC and the destination MAC of the message are modified and are forwarded out to the router. At this time, the destination MAC of the message is the MAC of the gateway vif3 of the subnet B.
[0123] 7. After the message reaches the router, the policy routing matches that the destination IP address is the address of the subnet 1 and the destination MAC is the gateway vif3 of the subnet B, and then the message is re-routed, the next hop destination of the message is set as the security network element B, and is forwarded to the security network element A.
[0124] 8. After the message leaving the network element A reaches the router, it is not processed additionally, but is routed to the virtual machine VM according to the destination IP. Thus, the whole traffic forwarding process is completed.
[0125] Table 1 traffic import policy routing table
[0126]
[0127] The priority in Table 1 means that the priority of the policy routing is greater than the priority of the regular routing. The policy routing determines the order of the traffic through the network elements. In the embodiment, the policy routing can be adjusted according to the order of the network elements configured by the user to realize the order of the network elements arranged by the user. If the network element A and the network element B are adjusted, the new policy routing is shown in Table 2, which is the policy routing table after the order of the network elements is adjusted:
[0128] Table 2: Policy routing table after the order of the network elements is adjusted
[0129]
[0130] As an embodiment, the current northbound traffic data is the northbound traffic data, there is a single-arm mode in the two security network elements, the preset condition is that the destination IP address is the destination IP address of the first subnet and the destination MAC address is the subnet gateway MAC address of the second subnet, the security service chain is determined according to the address data, the address data of the security network element corresponding to the policy routing and the single-double-arm mode, and the security service chain comprises the following steps:
[0131] obtaining the destination IP address of the first subnet and the subnet gateway MAC address of the external network where the second subnet is located;
[0132] determining whether the destination IP address and the destination MAC address are respectively the destination IP address of the first subnet and the subnet gateway MAC address of the second subnet;
[0133] if yes, it is determined that the preset condition is met;
[0134] the northbound traffic data is imported into the target security subnet corresponding to the other security network element except the security network element corresponding to the single-arm mode, so that the target security subnet processes the address data to obtain fifth address data, and the fifth address data is transferred to the router;
[0135] the import order path of the northbound traffic data into the second subnet, the target security subnet and the first subnet is taken as the security service chain.
[0136] Specifically, since there is a single-arm mode in one security network element, the security network element does not need to be considered in the process of forming the security service chain. The single-double-arm mode is mainly considered for the security of data transmission. If both security network elements participate in the security service chain process of the backhaul when the northbound traffic data flows through the backhaul, the data transmission efficiency can be improved in the process of the southbound traffic data due to the single-arm mode of one security network element, and resources are saved under the condition of ensuring the security of data transmission. The same as the above embodiment, another security network element except the security network element provided with the single-arm mode is determined to be imported, which is not described herein and can be referred to the content of the above embodiment.
[0137] It can be understood that the single-arm mode of the network element is based on the policy routing mentioned above, and the policy routing can be adjusted according to the single-arm mode of the network element configured by the user, so as to realize the expected direction of the network element. In combination with the above embodiment, if the network element A is adjusted to the single-arm mode and acts on the northbound traffic data, the new policy routing is shown in Table 3, which is a policy routing table in the single-arm mode of the network element:
[0138] Table 3: Policy routing table in single-arm mode of network element
[0139]
[0140] According to the import order path of the northbound traffic data into the second subnet, the target security subnet and the first subnet as the current security service chain.
[0141] The embodiment of the application is directed to the single-arm mode, the address data of the security network element and the address data determining the security service chain of the traffic data. In different conditions, different embodiments are correspondingly realized, the function of the north-south security service chain is realized, the network element order arrangement and the single-arm mode setting of the network element are supported. The cloud platform can be allowed to access a plurality of third-party security network elements, the security of the north-south traffic data is guaranteed, and a plurality of functions of the security network element order arrangement and the single-arm mode configuration of the network element are provided, the flexibility and the ease of use of the security service chain are greatly improved, and the needs of customers in the security service arrangement are met.
[0142] On the basis of the above embodiment, the interface information of the API interface of the security service chain at least includes network security service information and corresponding security network element information.
[0143] Specifically, Figure 2 The corresponding gateway interface vif1-3 in the network element is in the form of a neutron plug-in, which provides an application program interface (API) of the security service chain to the outside, and then converts the configuration item to be issued to the OVN, and the interface information provided by the network element at least includes network security service information and security network element information.
[0144] Correspondingly, the network security service information can be designed as follows:
[0145] 1. Network security service creation
[0146] url: / v2.0 / network_securities method: POST
[0147] Table 4: Parameter list of network security service creation
[0148] Parameter Name Parameter Type Whether Mandatory Parameter Description project_id string Yes Project ID name string No Security service name description string No Security service description subnets list No List of protected subnet IDs router_id string Yes Router ID, vpc default router elements list No List of security network element enable_shield bool Yes Whether to enable east-west traffic shielding ip_version string Yes IP version
[0149] 2. Enumerate network security services
[0150] url: / v2.0 / network_securities method: GET
[0151] 3. View network security service details
[0152] url: / v2.0 / network_securities / {network_security_id} method: GET
[0153] 4. Modify network security service
[0154] url: / v2.0 / network_securities / {network_security_id} method: PUT
[0155] Table 5. Parameter list for network security service modification
[0156]
[0157]
[0158] 5. Delete network security service
[0159] url: / v2.0 / network_securities / {network_security_id} method: DELETE
[0160] Correspondingly, the security network element information can be designed as follows:
[0161] 1. Security network element addition
[0162] url: / v2.0 / network_securities / {network_security_id} / add_elements
[0163] Method: PUT
[0164] This interface is a batch operation interface, and the parameter is a network element object list. The following is the parameter of a single network element, and Table 6 is the parameter list for security network element addition, as shown in Table 6:
[0165] Table 6. Parameter list for security network element addition
[0166]
[0167] 2. Security network element removal
[0168] url: / v2.0 / network_securities / {network_security_id} / remove_elements
[0169] Method: PUT
[0170] This interface is a batch operation interface, and the parameter is a list of network element objects. The parameters of a single network element are as follows, and the parameter list for removing a security network element is shown in Table 7:
[0171] Table 7 Parameter list for removing a security network element
[0172] Parameter Name Parameter Type Whether Mandatory Parameter Description compute_id string Yes Security network element virtual machine ID subnet_id string Yes Security network element virtual machine port ID address string Yes Security network element IP address
[0173] 3. Security network element update
[0174] url: / v2.0 / network_securities / {network_security_id} / update_element
[0175] Method: PUT
[0176] Table 8 is the parameter list for updating a security network element, as shown in Table 8:
[0177] Table 8 Parameter list for updating a security network element
[0178]
[0179] 4. Corresponding security service subnet addition
[0180] url: / v2.0 / network_securities / {network_security_id} / add_subnets
[0181] Method: PUT
[0182] Table 9 is the parameter list for adding a security service subnet, as shown in Table 9:
[0183] Table 9 Parameter list for adding a security service subnet
[0184] Parameter Name Parameter Type Mandatory Parameter Description subnets list Yes List of subnet IDs
[0185] 5. Corresponding security service subnet deletion
[0186] url: / v2.0 / network_securities / {network_security_id} / remove_subnets
[0187] Method: PUT
[0188] Table 10 is a parameter list of security service subnet deletion, see Table 10:
[0189] Table 10 is a parameter list of security service subnet deletion
[0190] Parameter Name Parameter Type Mandatory Parameter Description subnets list Yes List of subnet IDs
[0191] It can be understood that the API interface of the user is set according to the corresponding cloud environment, and the corresponding different can be set according to the actual situation.
[0192] The interface information of the API interface of the security service chain provided by the embodiment of the application at least includes network security service information and corresponding security network element information, and the configuration flexibility of the configuration environment is improved.
[0193] On the basis of the above embodiment, a database corresponding to the security service chain is established, wherein the database at least stores basic information of the security service chain, basic information of the security network element, and subnet information of the corresponding security service chain and the security service chain ID data, and the subnet information at least includes subnet data of the virtual machine, the external network and the security network element as the subnet.
[0194] Specifically, a database structure is designed for the security service chain, which is used to store the information of the security service chain and can be used to verify the consistency with the underlying ovn data and data repair. The database at least adds three tables, one table stores the basic information of the security service chain (icos_network_securities), one table stores the basic information of the security network element and the corresponding security service chain (icos_network_security_elements), and the other table stores the subnet information of the corresponding security service chain ID data (icos_network_security_subnets). Specifically as follows:
[0195] Table 11 is an icos_network_securities information table, see Table 11, which stores the basic information of the security service chain:
[0196] Table 11 icos_network_securities information table
[0197] Column Name Type Whether Can Be Null Whether Primary Key Default Value Remarks id varchar(36) NO PRI Null router_id verchar(36) NO NULL Associated router id name varchar(255) YES NULL Name description varchar(1024) YES NULL Description project_id verchar(36) NO NULL Project id enable_shield bool NO True Shield east-west traffic standard_attr_id biginteger NO NULL Inject security network element subnet ip_version integer NO 4 IP version
[0198] Table 12 is an icos_network_security_elements information table, see Table 12, which stores the basic information of the security network element and the corresponding security service chain:
[0199] Table 12 icos_network_security_elements information table
[0200] Column Name Type Whether Can Be Null Whether Primary Key Default Value Remarks ns_id varchar(36) NO PRI NULL compute_id varchar(36) NO PRI NULL subnet_id varchar(36) NO PRI NULL address string NO NULL index int NO 1 model string NO NULL Single / double arm mode direction string YES NULL Action direction
[0201] Table 13 is the icos_network_security_elements information table, see Table 13, the subnetwork information and the corresponding security service chain ID data of the diversion are stored:
[0202] Table 13 is the icos_network_security_elements information table
[0203] Column Name Type Whether Can Be Null Whether Primary Key Default Value Remarks ns_id varchar(36) No PRI NULL subnet_id varchar(36) No PRI NULL
[0204] The database provided by the embodiment of the application needs to be supported by the database whether the configuration information is modified or the software logic is modified, and the data recorded in the database prevents the loss of configuration information.
[0205] The above detailed description of the processing method of the security network element corresponds to each embodiment, and on this basis, the application further discloses a processing device of a security network element corresponding to the above method. Figure 3 A structure diagram of a processing device of a security network element provided by the embodiment of the application is shown in FIG. 1. Figure 3 As shown in the figure, the processing device of the security network element comprises:
[0206] The acquisition module 11 is configured to acquire message data corresponding to current north-south traffic data, wherein the current north-south traffic data is data transmitted between a virtual machine and an external network.
[0207] The analysis module 12 is configured to analyze and process the message data to obtain address data.
[0208] The determination module 13 is configured to determine a security service chain according to the address data and the single-arm mode or the double-arm mode when the address data meets a preset condition of policy routing.
[0209] The transmission module 14 is configured to transmit the current north-south traffic data to a target subnetwork according to the security service chain, wherein the target subnetwork is a subnetwork corresponding to the virtual machine or the external network.
[0210] Since the embodiments of the device part correspond to the above-mentioned embodiments, the embodiments of the device part are described with reference to the above-mentioned embodiments of the method part, and will not be described here.
[0211] For the processing device of the security network element provided by the application, please refer to the above-mentioned method embodiments, and the application will not be described here, which has the same beneficial effects as the above-mentioned processing method of the security network element.
[0212] Figure 4 Another structural diagram of a processing apparatus of a secure network element provided by an embodiment of the present application is shown in FIG. 3, which includes: Figure 4
[0213] a memory 21 configured to store a computer program;
[0214] a processor 22 configured to implement the steps of the processing method of the secure network element when executing the computer program.
[0215] The processing apparatus of the secure network element provided by the embodiment can include but is not limited to a tablet computer, a notebook computer, or a desktop computer, etc.
[0216] The processor 22 can include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 22 can be implemented in at least one of a hardware form of a Digital Signal Processor (DSP), a Field-Programmable Gate Array (FPGA), a Programmable Logic Array (PLA). The processor 22 can also include a main processor and a coprocessor. The main processor is a processor for processing data in an awake state, also known as a Central Processing Unit (CPU). The coprocessor is a low-power processor for processing data in a standby state. In some embodiments, the processor 22 can be integrated with a Graphics Processing Unit (GPU) for rendering and drawing the content to be displayed by the display screen. In some embodiments, the processor 22 can also include an Artificial Intelligence (AI) processor for processing machine learning-related computing operations.
[0217] The memory 21 can include one or more computer-readable storage media. The memory 21 can also include high-speed random access memory and non-volatile, computer-readable storage media such as one or more magnetic disk storage devices, flash memory devices. In this embodiment, the memory 21 is used to store at least the following computer program 211, wherein the computer program is loaded and executed by the processor 22 and can implement the related steps of the processing method of the secure network element disclosed in any of the preceding embodiments. In addition, the resources stored in the memory 21 can also include an operating system 212 and data 213, etc., and the storage mode can be temporary storage or permanent storage. The operating system 212 can include Windows, Unix, Linux, etc. The data 213 can include but is not limited to data related to the processing method of the secure network element, etc.
[0218] In some embodiments, the processing device of the secure network element can further include a display screen 23, an input / output interface 24, a communication interface 25, a power supply 26, and a communication bus 27.
[0219] Those skilled in the art can understand that the structure shown in the above embodiments does not constitute a limitation on the processing device of the secure network element, and can include more or fewer components than those shown in the figure. Figure 4
[0220] The processor 22 implements the processing method of the secure network element provided in any of the preceding embodiments by invoking the instructions stored in the memory 21.
[0221] For the processing device of the secure network element provided by the present application, please refer to the above method embodiments, and the present application will not be repeated here, which has the same beneficial effects as the processing method of the secure network element described above.
[0222] Further, the present application also provides a computer-readable storage medium, and the computer-readable storage medium stores a computer program, and the computer program is executed by the processor 22 to implement the steps of the processing method of the secure network element.
[0223] It can be understood that if the method in the above embodiment is implemented in the form of a software function unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the part of the prior art that contributes to the present application or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and performs all or part of the steps of the method described in each embodiment of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (Read-Only Memory, ROM), a random access memory (Random Access Memory, RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0224] For the computer readable storage medium provided by the present application, please refer to the above method embodiment. The present application will not be repeated here, and has the same beneficial effects as the processing method of the above-mentioned security network element.
[0225] The processing method of the security network element, the processing device of the security network element and the medium provided by the present application are described in detail above. The embodiments in the specification are described in a progressive manner, and each embodiment mainly describes the differences from other embodiments. The same and similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and the related parts can be referred to the method part. It should be pointed out that for ordinary skilled in the art, without departing from the principle of the present application, the present application can be improved and modified. These improvements and modifications also fall within the protection scope of the claims of the present application.
[0226] It should be further noted that in the present specification, the relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between the entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or equipment including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or equipment. Without more limitation, the element defined by the sentence "including a…" does not exclude the presence of other identical elements in the process, method, article or equipment including the element.
Claims
1. A method for handling a secure network element, characterized by, The method comprises: obtaining packet data corresponding to current north-south traffic data, wherein the current north-south traffic data is data transmitted between a virtual machine and an external network; performing analysis processing on the packet data to obtain address data; when the address data satisfies a preset condition of a policy-based routing, determining a security service chain according to the address data, security network element address data corresponding to the policy-based routing, and a single / dual-arm mode; transmitting the current north-south traffic data to a target subnet according to the security service chain, wherein the target subnet is a subnet corresponding to the virtual machine or the external network; correspondingly, the address data at least includes a destination Internet Protocol address, a source Internet Protocol address, a destination Media Access Control address, and a source Media Access Control address; when the current north-south traffic data is northbound traffic data, the number of security network elements is two, and the two security network elements are both in a dual-arm mode of the single / dual-arm mode, the preset condition includes a first preset condition and a second preset condition, and the determining of the security service chain according to the address data, the security network element address data corresponding to the policy-based routing, and the single / dual-arm mode comprises: determining whether the source Internet Protocol address and the destination Media Access Control address satisfy the first preset condition; if yes, importing the northbound traffic data into a first security subnet so that the first security subnet processes address information to obtain first address information, and transferring the first address information to a router; wherein the security network element address data includes address data corresponding to the first security subnet and a second security subnet; determining whether the source Internet Protocol address and the destination Media Access Control address after passing through the first security subnet satisfy the second preset condition; if yes, importing the northbound traffic data into the second security subnet so that the second security subnet processes the first address information to obtain second address information, and transferring the second address information to the router; taking a path of import order of the first subnet, the first security subnet, the second security subnet, and a second subnet according to the northbound traffic data as the security service chain.
2. The method according to claim 1, c h a r a c t e r i z e d b y The number of routing modes of the policy-based routing is the same as the number of the security network elements, and the number of the security network elements is at least one.
3. The method according to claim 2, c h a r a c t e r i z e d b y The first preset condition is that the source Internet Protocol address is a first subnet Internet Protocol address and the destination Media Access Control address is a subnet gateway Media Access Control address of a subnet where the first subnet is located, and the second preset condition is that the source Internet Protocol address is the first subnet Internet Protocol address and the destination Media Access Control address is a subnet gateway Media Access Control address of a subnet where the first security subnet is located. obtaining the first subnet Internet Protocol address of the virtual machine corresponding to the first subnet, the subnet gateway Media Access Control address of the subnet where the first subnet is located, and the subnet gateway Media Access Control address of the first security subnet; determining whether the source Internet protocol address and the destination media access control address are respectively the first subnet Internet protocol address and a subnet gateway media access control address of a subnet where the first subnet is located after the first security subnet; if yes, determining that the first preset condition is met; determining whether the source Internet protocol address and the destination media access control address are respectively the first subnet Internet protocol address and a subnet gateway media access control address of a subnet where the first security subnet is located after the first security subnet; if yes, determining that the second preset condition is met.
4. The method according to claim 3, c h a r a c t e r i z e d b y When the current north-south traffic data is southbound traffic data, the preset condition includes a third preset condition and a fourth preset condition, the third preset condition is that the destination Internet protocol address is a destination Internet protocol address of the first subnet and the destination media access control address is a subnet gateway media access control address of a subnet where the second subnet is located, and the fourth preset condition is that the destination Internet protocol address is a destination Internet protocol address of the first subnet and the destination media access control address is a subnet gateway media access control address of a subnet where the second security subnet is located, and the determining the security service chain according to the address data and the security network element address data and the single-arm mode corresponding to the policy routing includes: obtaining a destination Internet protocol address of the first subnet, a subnet gateway media access control address of a subnet where the external network corresponding to the second subnet is located, and a subnet gateway media access control address of a subnet where the second security subnet is located; determining whether the destination Internet protocol address and the destination media access control address are respectively the destination Internet protocol address of the first subnet and the subnet gateway media access control address of the subnet where the second subnet is located; if yes, determining that the third preset condition is met; directing the southbound traffic data to the second security subnet so that the second security subnet processes the address information to obtain third address information, and directing the third address information to the router; determining whether the destination Internet protocol address and the destination media access control address are respectively the destination Internet protocol address of the first subnet and the subnet gateway media access control address of the subnet where the second security subnet is located after the second security subnet; if yes, determining that the fourth preset condition is met; directing the southbound traffic data to the first security subnet so that the first security subnet processes the third address information to obtain fourth address information, and directing the fourth address information to the router; directing the second subnet, the second security subnet, the first security subnet and the first subnet according to an import order path of the southbound traffic data as the security service chain.
5. The method according to claim 3, c h a r a c t e r i z e d b y The current north-south traffic data is southbound traffic data, and one of the two security network elements is in a single-arm mode, the preset condition is that the destination Internet Protocol address is a destination Internet Protocol address of the first subnet and the destination Media Access Control address is a subnet gateway Media Access Control address of a subnet where the second subnet is located, and the determining of the security service chain according to the address data, the security network element address data corresponding to the policy-based routing, and the single / dual-arm mode comprises: obtaining a destination Internet Protocol address of the first subnet and a subnet gateway Media Access Control address of a subnet where the second subnet is located; determining whether the destination Internet Protocol address and the destination Media Access Control address are respectively a destination Internet Protocol address of the first subnet and a subnet gateway Media Access Control address of a subnet where the second subnet is located; if yes, determining that the preset condition is met; directing the southbound traffic data to a target security subnet corresponding to a security network element other than the security network element corresponding to the single-arm mode, so that the target security subnet processes the address information to obtain fifth address information, and transferring the fifth address information to the router; taking a path of an order of directing the second subnet, the target security subnet and the first subnet as the security service chain according to the southbound traffic data.
6. The method according to any one of claims 1 to 5, wherein the method further comprises: Interface information of an application program interface of the security service chain at least comprises network security service information and corresponding security network element information.
7. The method according to claim 6, c h a r a c t e r i z e d b y Further comprising: establishing a database corresponding to the security service chain, wherein the database at least stores basic information of the security service chain, basic information of the security network element, and corresponding role of the security service chain and diversion of subnet information and corresponding security service chain identity data, and the subnet information at least comprises subnet data of the virtual machine, the external network and the security network element as subnets.
8. A processing device of a secure network element, characterized by Comprising: an obtaining module, configured to obtain message data corresponding to current north-south traffic data, wherein the current north-south traffic data is data transmitted between a virtual machine and an external network; an analyzing module, configured to analyze and process the message data to obtain address data; a determining module, configured to, when the address data meets a preset condition of a policy-based routing, determine a security service chain according to the address data, security network element address data corresponding to the policy-based routing, and single / dual-arm mode; a transmitting module, configured to transmit the current north-south traffic data to a target subnet according to the security service chain, wherein the target subnet is a subnet corresponding to the virtual machine or the external network; Correspondingly, the address data at least comprises a destination Internet Protocol address, a source Internet Protocol address, a destination Media Access Control address and a source Media Access Control address, when the current north-south traffic data is northbound traffic data, the number of the security network elements is two, and the two security network elements are both in a dual-arm mode of the single / dual-arm mode, the preset condition comprises a first preset condition and a second preset condition, and the determining of the security service chain according to the address data, the security network element address data corresponding to the policy-based routing, and the single / dual-arm mode comprises: determining whether the source internet protocol address and the destination media access control address satisfy a first preset condition; if yes, importing the northbound traffic data into a first security subnet so that the first security subnet processes address information to obtain first address information, and transferring the first address information to a router; wherein the security network element address data comprises address data corresponding to the first security subnet and a second security subnet; determining whether the source internet protocol address and the destination media access control address satisfy a second preset condition after passing through the first security subnet; if yes, importing the northbound traffic data into a second security subnet so that the second security subnet processes the first address information to obtain second address information, and transferring the second address information to the router; a path of importation orders of the first subnet, the first security subnet, the second security subnet and the second subnet according to the northbound traffic data is taken as the security service chain.
9. A processing device of a secure network element, characterized by comprise: a memory for storing a computer program; a processor for executing the computer program to implement the steps of the processing method of the security network element according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, the computer readable storage medium stores a computer program, and the computer program is executed by the processor to implement the steps of the processing method of the security network element according to any one of claims 1 to 7.
Citation Information
Patent Citations
Security defense method and system in cloud environment and computer readable storage medium
CN109889533A
Flow data control method and device and medium
CN115242788A