Reconfigurable network security computing method and device, computer equipment and storage medium

By introducing SDN and NFV technologies into network security devices, a reconfigurable network security architecture and controller are established, which solves the problem that traditional devices are difficult to deal with changing threats, and achieves flexible security policy management and efficient network security guarantees.

CN120165884APending Publication Date: 2025-06-17SHENZHEN EWARE INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311720165.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-14
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

Traditional cybersecurity devices are difficult to respond and adjust in a timely manner when facing changing cyber threats and attacks.

Method used

By establishing a reconfigurable network security architecture based on SDN and NFV, a reconfigurable network security controller is set up, and dynamic security policy management is carried out to achieve flexible adjustment and optimization of network protocols and security policies.

Benefits of technology

It realizes timely response and adjustment in the face of changing cyber threats and attacks, ensures the security and stability of the network environment, improves computing efficiency and flexibility, and reduces energy consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165884A_ABST
    Figure CN120165884A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network security, and relates to a reconfigurable network security calculation method and device, computer equipment and a storage medium, and the method comprises the steps: building a reconfigurable network security architecture based on an SDN and an NFV; setting a reconfigurable network security controller based on the reconfigurable network security architecture; performing dynamic security policy management according to the reconfigurable network security controller; and performing reconfigurable network security service according to the dynamic security policy management. Through the optimization of the software level, the reconfigurable computing can more effectively utilize computing resources, and the computing efficiency is improved; software support enables reconfigurable computing to adapt to different application scenes and requirements, and flexibility of the reconfigurable computing is enhanced. By optimizing software, reconfigurable calculation can reduce energy consumption while completing a calculation task, and the trend of green calculation is met; in the face of continuously changing network threats and attacks, timely response and adjustment can be carried out, and the network environment is ensured to be safe and stable.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technologies, and in particular, to a reconfigurable network security computing method, apparatus, computer device, and storage medium. Background Art

[0002] In traditional network security devices, fixed hardware circuits are usually adopted to support network protocols and security policies. This makes it difficult for the devices to respond and adjust in a timely manner when facing constantly changing network threats and attacks. Summary of the Invention

[0003] An object of embodiments of the present invention is to provide a reconfigurable network security computing method, apparatus, computer device, and storage medium to solve the problem that in the prior art, traditional network security devices are difficult to respond and adjust in a timely manner when facing constantly changing network threats and attacks.

[0004] To solve the above technical problems, the present invention provides a reconfigurable network security computing method, which adopts the following technical solutions:

[0005] Based on SDN and NFV, establish a reconfigurable network security architecture;

[0006] Based on the reconfigurable network security architecture, set up a reconfigurable network security controller;

[0007] According to the reconfigurable network security controller, perform dynamic security policy management;

[0008] According to the dynamic security policy management, provide reconfigurable network security services.

[0009] Preferably, the step of establishing a reconfigurable network security architecture based on SDN and NFV specifically includes:

[0010] Obtain the security requirements and objectives of the network;

[0011] According to the security requirements and objectives, based on SDN and NFV, implement the separation of the network control plane and the data plane;

[0012] Establish a reconfigurable network security overall architecture, where the reconfigurable network security overall architecture includes a control layer, a data layer, and a service management layer. The control layer is responsible for the control and management of network traffic, the data layer is responsible for the transmission and processing of data, and the service management layer is responsible for the operation and management of network services.

[0013] Preferably, the step of setting up a reconfigurable network security controller based on the reconfigurable network security architecture specifically includes:

[0014] Establish a virtualization engine for virtualizing network functions;

[0015] Design an open API and integrate the open API with third-party security solutions;

[0016] Set up a visualization interface for intuitive display and control of network security.

[0017] Preferably, the step of performing dynamic security policy management according to the reconfigurable network security controller specifically includes:

[0018] Through the reconfigurable network security controller, analyze network traffic and threat situations in real time;

[0019] Dynamically adjust network security configurations according to preset security policies;

[0020] Perform machine learning by the reconfigurable network security controller to analyze network traffic and threats;

[0021] Implement security policies on each endpoint;

[0022] Dynamically adjust network resource allocation by the reconfigurable network security controller according to changes in network load.

[0023] Preferably, the step of performing reconfigurable network security services according to dynamic security policy management specifically includes:

[0024] Select a security mode according to dynamic security policy management;

[0025] Formulate dynamic security policies according to the security mode;

[0026] Use machine learning to identify and prevent network threats, and use automated tools to deploy and update security policies.

[0027] Preferably, the reconfigurable network security controller realizes the reconfiguration of the hardware circuit by modifying the configuration file of the FPGA.

[0028] Preferably, the step of the reconfigurable network security controller realizing the reconfiguration of the hardware circuit by modifying the configuration file of the FPGA specifically includes:

[0029] Open the FPGA development tool;

[0030] Create a new project and select the FPGA chip model and configuration file format;

[0031] Open the configuration file of the FPGA in the project, and the configuration file contains the logic design and connection information of the FPGA;

[0032] Modify the content in the configuration file as needed by adding, deleting, or modifying logic blocks, signal connections, and parameters;

[0033] After the modification is completed, save the configuration file and close the development tool;

[0034] Write the modified configuration file into the FPGA chip through a programmer or a downloader.

[0035] To solve the above technical problems, the present invention also provides a reconfigurable network security computing device, which adopts the following technical solutions:

[0036] A building module, used to build a reconfigurable network security architecture based on SDN and NFV;

[0037] A setting module, used to set a reconfigurable network security controller based on the reconfigurable network security architecture;

[0038] A management module, used to perform dynamic security policy management according to the reconfigurable network security controller;

[0039] A service module, used to provide reconfigurable network security services according to dynamic security policy management.

[0040] To solve the above technical problems, the present invention also provides a computer device, which adopts the following technical solutions, including a memory and a processor. Computer-readable instructions are stored in the memory, and when the processor executes the computer-readable instructions, the steps of the above-mentioned reconfigurable network security computing method are implemented.

[0041] To solve the above technical problems, the present invention also provides a computer-readable storage medium, which adopts the following technical solutions. Computer-readable instructions are stored on the computer-readable storage medium, and when the computer-readable instructions are executed by a processor, the steps of the above-mentioned reconfigurable network security computing method are implemented.

[0042] Compared with the prior art, the present invention mainly has the following beneficial effects: By building a reconfigurable network security architecture based on SDN and NFV; then setting a reconfigurable network security controller based on the reconfigurable network security architecture; then performing dynamic security policy management according to the reconfigurable network security controller; and finally providing reconfigurable network security services according to dynamic security policy management; through software-level optimization, reconfigurable computing can more effectively utilize computing resources and improve computing efficiency; software support enables reconfigurable computing to adapt to different application scenarios and requirements, enhancing its flexibility; by optimizing software, reconfigurable computing can reduce energy consumption while completing computing tasks, meeting the trend of green computing; in the face of constantly changing network threats and attacks, it can respond and adjust in a timely manner to ensure the security and stability of the network environment. Description of the Drawings

[0043] To more clearly illustrate the solutions in the present invention, the following will give a brief introduction to the drawings required for the description of the embodiments of the present invention. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0044] Figure 1 is a flowchart of an embodiment of the reconfigurable network security computing method of the present invention;

[0045] Figure 2 is a schematic structural diagram of an embodiment of the reconfigurable network security computing device of the present invention;

[0046] Figure 3 is a schematic structural diagram of an embodiment of the computer device of the present invention. Detailed implementation manners

[0047] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs; the terms used in the description of the present application in the specification are only for the purpose of describing specific embodiments and are not intended to limit the present invention; the terms "including" and "having" and any variations thereof in the description and claims of the present invention and the above drawings are intended to cover non-exclusive inclusion. The terms "first", "second", etc. in the description and claims of the present invention or the above drawings are used to distinguish different objects and not to describe a specific order.

[0048] Referring to "embodiment" herein means that a specific feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the present invention. The phrase does not necessarily refer to the same embodiment at various positions in the specification, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0049] To enable those skilled in the art of the present technology to better understand the solutions of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings.

[0050] It should be noted that the reconfigurable network security computing method provided by the embodiments of the present invention is generally executed by a server / terminal device. Correspondingly, the reconfigurable network security computing device is generally disposed in the server / terminal device.

[0051] It should be understood that the numbers of terminal devices, networks, and servers are only illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers.

[0052] Example 1

[0053] Continue to refer to Figure 1 , which shows a flowchart of an embodiment of the reconfigurable network security computing method of the present invention. The reconfigurable network security computing method includes the following steps:

[0054] Step S1, based on SDN and NFV, establish a reconfigurable network security architecture.

[0055] In this embodiment, the electronic device (such as a server / terminal device) on which the reconfigurable network security computing method runs can receive a reconfigurable network security computing request through a wired connection method or a wireless connection method. It should be noted that the above wireless connection methods can include, but are not limited to, 3G / 4G / 5G connections, WiFi connections, Bluetooth connections, WiMAX connections, Zigbee connections, UWB (ultra wideband) connections, and other currently known or future-developed wireless connection methods.

[0056] Software Defined Network (SDN) is a new type of network innovation architecture and an implementation method of network virtualization. Its core technology, OpenFlow, separates the control plane and data plane of network devices, thereby realizing flexible control of network traffic, making the network more intelligent, and providing a good platform for the innovation of core networks and applications.

[0057] Network Functions Virtualization (abbreviated as NFV), a concept for network architecture, uses virtualization technology to divide the functions at the network node level into several functional blocks and implement them in software respectively, no longer limited to the hardware architecture.

[0058] In this embodiment, step S1, based on SDN and NFV, to establish a reconfigurable network security architecture may specifically further include the steps of:

[0059] S11. Obtain the security requirements and goals of the network.

[0060] In order to obtain the security requirements and goals of the network, it is necessary to identify possible threats, attacks, and vulnerabilities in the network, and determine the data, applications, and services that need to be protected.

[0061] Network security is a rapidly evolving field, with new threats and attack methods emerging continuously. Security tools can be used to regularly scan the network to find potential vulnerabilities. These tools can include firewalls, intrusion detection systems (IDS), and security information and event management (SIEM) systems, etc. It is also possible to continuously monitor network activities and analyze log files in order to detect abnormal behaviors in a timely manner. Log files contain clues about potential threats, such as unauthorized connections, abnormal traffic, or malware activities, etc. Additionally, strong authentication strategies can be implemented, such as two-factor authentication, strong password policies, and the use of multi-factor authentication, to enhance security.

[0062] S12. Based on SDN and NFV, separate the network control and data planes according to security requirements and goals.

[0063] One of the main advantages of SDN is network management. It is responsible for parsing and managing network policies from applications or management interfaces. Through SDN, network resources can be centrally managed and optimized, improving network performance and flexibility.

[0064] NFV allows network functions to run in software form on general-purpose hardware, which realizes the virtualization of the data plane. Through the virtualization of network devices, the data plane can be separated from physical devices and run in virtual machines, and be uniformly managed and scheduled by SDN.

[0065] During the process of separating the control and data planes, it is necessary to ensure that the interfaces between the control plane and the data plane are independent of each other, that is, they communicate only through independent interfaces, to avoid the operations of the data plane affecting the decisions of the control plane.

[0066] Through SDN and NFV, more optimal network management and operation processes can be achieved. Through centralized SDN, the processes of network management and maintenance can be simplified. In addition, the virtualized data plane can be more easily upgraded, deployed, and expanded. This separation will greatly improve the flexibility and scalability of the network while reducing operating costs.

[0067] S13. Establish a reconfigurable network security overall architecture. The reconfigurable network security overall architecture includes a control layer, a data layer, and a service management layer. The control layer is responsible for the control and management of network traffic, the data layer is responsible for data transmission and processing, and the service management layer is responsible for the operation and management of network services.

[0068] The control layer is responsible for communication between policy decision-making and the data plane, the data layer is responsible for data processing, and the service management layer is responsible for actual network devices, connections, and management.

[0069] Step S2. Based on the reconfigurable network security architecture, set up a reconfigurable network security controller.

[0070] In this embodiment, step S2 of setting up the reconfigurable network security controller based on the reconfigurable network security architecture may further include the following steps:

[0071] S21. Based on the reconfigurable network security architecture, establish a virtualization engine for virtualizing network functions.

[0072] The virtualization engine refers to the core component for virtualization technology. It provides a software platform for creating, deploying, managing, and expanding virtual machines (VMs) and other virtualized objects. The virtualization engine may include a virtual machine monitor for managing the life cycle of virtual machines, as well as a set of tools and APIs for simplifying operations such as the creation, deployment, expansion, and recycling of virtual machines. Through the virtualization engine, users can easily utilize existing hardware resources, achieve more efficient resource allocation and utilization, and at the same time reduce the overall ownership cost of the infrastructure. The virtualization engine can also provide security and isolation to ensure that each virtual machine runs in its own environment, thereby reducing potential security risks.

[0073] First, determine which network functions the virtualization engine supports, how to manage these functions, and how to integrate with existing systems, etc. Second, according to the network functions to be supported, select tools, such as cloud platforms (such as Kubernetes, OpenStack, etc.) and network virtualization technologies (such as VMware NSX, AWS Network Virtualization, etc.). Then establish the virtualization engine architecture, which may include network function modules, management consoles, logging, and monitoring tools, etc. Finally, deploy the virtualization engine. Deploy the virtualization engine on a server or a terminal.

[0074] S22. On the basis of network function virtualization, design open APIs and integrate the open APIs with third-party security solutions.

[0075] It should be noted that for the designed and developed APIs, it is necessary to ensure that all requests are properly authenticated and authorized to prevent unauthorized access. In addition, use encryption methods to protect the transmitted data, such as HTTPS or TLS.

[0076] Set up a permission management system to ensure that only authorized users can access the designed open API. This can be achieved through methods such as API keys and access tokens. For malicious requests, some security mechanisms need to be configured to identify and block them. For example, blacklist and whitelist policies can be used to block known malicious IP addresses and malicious requests. To further enhance security, integrating third-party security solutions into the open API can be considered. For example, solutions from some cloud security service providers, such as DDoS protection, intrusion detection, and prevention, can be considered. These can provide an additional security layer to help protect the open API more effectively. When integrating third-party security solutions, it is necessary to ensure the security of data transmission between the open API and these solutions, and at the same time, the impact of these solutions on the performance of the open API also needs to be considered.

[0077] Unify and interact with the third-party security solution integrator in terms of the API's port number, protocol, data format, etc. Implement a communication interface with the third-party security solution in the open API to ensure the secure transmission of data and ensure that the open API is always in the best security state.

[0078] S23. Based on the open API, set up a reconfigurable network security controller.

[0079] Based on the open API, it can be known which software functions are supported. In some optional implementation manners of this embodiment, the open API also reserves some interfaces to facilitate expansion according to user needs. Then, according to the software functions to be supported, set up a reconfigurable network security controller.

[0080] A reconfigurable network security controller refers to a new type of network security device that uses reconfigurable computing technology and can dynamically adjust and optimize network protocols and network security policies without changing the hardware circuit structure.

[0081] In traditional network security devices, fixed hardware circuits are usually used to support network protocols and security policies. This makes it difficult for the device to respond and adjust in a timely manner when facing constantly changing network threats and attacks. The reconfigurable network security controller, however, by introducing reconfigurable computing technology, hands over the configuration right of the hardware circuit to the software program, and can dynamically change the behavior and function of the hardware circuit according to needs, thus achieving flexible adjustment and optimization of network protocols and security policies.

[0082] In specific implementation, the reconfigurable network security controller can adopt an FPGA (Field Programmable Gate Array)-based architecture. By integrating FPGA with components such as CPU, memory, and network interface, a network security processing platform is formed. When facing different network threats and attacks, the hardware circuit can be reconfigured by modifying the configuration file of FPGA, so as to quickly adapt to new network security requirements. The reconfigurable network security controller also has characteristics such as high reliability, high performance, and high security. Since FPGA has the ability of parallel computing, multiple security functions can be simultaneously run on a single chip, improving the processing capacity and efficiency of the device. In addition, since FPGA can be configured and reconfigured through software, the device can be upgraded and expanded without changing the hardware circuit, improving the maintainability and scalability of the device. The reconfigurable network security controller can effectively cope with changing network threats and attacks, and protect the security and stable operation of the network.

[0083] S24. Based on the reconfigurable network security controller, set up a visual interface for intuitively displaying and controlling network security.

[0084] Based on the reconfigurable network security controller, determine which network security metric information needs to be obtained and displayed, such as attack frequency, number of malware, network traffic, etc. At the same time, considering user requirements, determine the layout and interaction mode of the interface.

[0085] Select a visualization tool: Common visualization tools include Tableau, PowerBI, ECharts, etc.

[0086] Design the interface: According to the results of the requirements analysis, design the layout and appearance of the interface. Consider using graphics, charts, and data visualization to display network security information. At the same time, consider the interactivity of the interface, such as real-time update, data filtering, alarm prompt, etc.

[0087] In some optional implementation manners of this embodiment, the developed visual interface can also be integrated into the existing network security system and integrated with the existing security devices and services. Deploy the interface to ensure that it can work properly and provide necessary control functions, such as permission management, data export, etc.

[0088] Step S3. Perform dynamic security policy management according to the reconfigurable network security controller.

[0089] Dynamic security policy management is a systematic method that focuses on how to formulate and implement secure policies in a changing environment. Specifically, dynamic security policy management has the following core elements:

[0090] First, real-time monitoring: Dynamic security policy management emphasizes the collection and analysis of real-time data and information. It continuously monitors changes in the internal and external environments of the organization to ensure timely identification of new security risks.

[0091] Second, dynamic adjustment: In the face of a constantly changing threat environment, dynamic security policy management requires that security policies are not static but can be adjusted according to environmental changes to adapt to new challenges.

[0092] Third, cross-departmental collaboration is possible: Dynamic security policy management emphasizes the shared responsibility for security across all departments. It requires collaboration among different departments to ensure an overall response when facing complex threats.

[0093] Fourth, risk management can be carried out: Dynamic security policy management attaches importance to risk management. It not only focuses on known threats but also actively addresses unknown threats, identifying, assessing, and reducing security risks through risk management tools and methods.

[0094] The benefits of dynamic security policy management are obvious. It provides a continuous, comprehensive, and flexible way to protect the organization and keep it secure in a constantly changing environment.

[0095] In this embodiment, in step S3, dynamic security policy management based on the reconfigurable network security controller may specifically further include the following steps:

[0096] S31. Analyze network traffic and threat situations in real time through the reconfigurable network security controller.

[0097] Device deployment: Deploy the reconfigurable network security controller at appropriate locations in the network, such as servers or terminals with deployment requirements, according to security policies and device performance.

[0098] Real-time monitoring: Use the reconfigurable network security controller to monitor network traffic in real time, collect and analyze various data, including but not limited to network packet content, session information, application usage, etc.

[0099] Threat detection: Detect threats such as malware, ransomware, DDoS attacks, etc. in real time through built-in or integrated advanced threat detection engines.

[0100] Traffic analysis: Through packet flow analysis, better understand network activities and identify potential security issues, such as illegal access, resource abuse, etc.

[0101] User behavior analysis: Through the analysis of user behavior, identify abnormal activities, such as unauthorized access, password theft, etc.

[0102] Threat intelligence sharing: Share and integrate threat intelligence from different sources in real time to enhance threat recognition capabilities.

[0103] Response plan: Trigger pre-set response plans in a timely manner based on real-time analysis results to minimize potential losses.

[0104] Automation and manual intervention: Achieve automated responses in most cases, but be able to quickly perform manual intervention when necessary to address specific threats.

[0105] Regular audits and updates: Regularly review the effectiveness of security measures and update security policies and threat models to adapt to the changing cyber threat environment. Through the above steps, the reconfigurable network security controller can protect the network while reducing operating costs and risks.

[0106] S32. Dynamically adjust network security configurations according to pre-set security policies.

[0107] The pre-set security policies include security goals, security standards, security measures, etc. Regularly evaluate the current network security configurations to check whether they meet the requirements of the security policies. This may require regular security audits and risk assessments. Once it is found that the existing configurations do not meet the security policies, it is necessary to determine the parts that need to be adjusted. This may include firewall rules, access control lists, intrusion detection system settings, etc. According to the security policies and evaluation results, implement new network security configurations. This may require modifying existing configuration files or creating new configuration files. Test the new configurations to ensure that they can correctly perform the expected security functions without introducing new security risks. Record the new configurations and conduct audits. Finally, it is necessary to regularly review the network security configurations to ensure that they still comply with the pre-set security policies. This may require regular security audits and risk assessments, as well as updating and modifying the configurations.

[0108] S33. The reconfigurable network security controller performs machine learning to analyze network traffic and threats.

[0109] Data collection: First, a large amount of network traffic and threat data needs to be collected. This can be collected through network devices, security devices, and other sensors. This data can include various types of network traffic, threat types, attack behaviors, and other relevant information.

[0110] Data preprocessing: Clean and organize the collected data to prepare it for machine learning. This can include removing duplicate data, filling in missing values, converting data types, etc.

[0111] Feature engineering: Use machine learning algorithms to perform feature engineering on the data to extract useful features about network traffic and threats. This may include methods such as time series analysis, classification, clustering, and deep learning.

[0112] Model training: Use appropriate machine learning algorithms, such as supervised learning or unsupervised learning, to model the training data. Existing algorithms that can be selected include support vector machines, neural networks, decision trees, and random forests, etc.

[0113] Model evaluation: Use some metrics (such as accuracy, recall, F1 score, etc.) to evaluate the performance of the model. Methods such as cross-validation and test set evaluation can be used to improve the accuracy of the evaluation.

[0114] Threat detection: Apply the trained model to actual network traffic and threat data to detect potential network threats. This can be achieved by real-time monitoring of network traffic or periodic analysis of historical data.

[0115] Real-time response: Once a threat is detected, the attack patterns and behaviors predicted by the model can be used to take corresponding response measures in a timely manner, such as isolating the affected network area, updating security policies, etc. Through the above steps, a reconfigurable network security controller and machine learning technology can be used to analyze network traffic and threats. This method can improve network security performance, reduce false positives and false negatives, and improve the detection and response speed.

[0116] S34. Implement security policies on each endpoint.

[0117] An endpoint refers to a network node, which is set on a server or a terminal, etc.

[0118] Understand the endpoint environment: First, it is necessary to understand the endpoint environment, including the location, quantity, type (physical or virtual) of the endpoints, and how they interact with the network and the system.

[0119] Develop security policies: According to the endpoint environment, develop appropriate security policies. This may include access control, data encryption, authentication, intrusion detection / prevention, etc.

[0120] Implement security technologies: Use various security technologies to protect the endpoints, such as firewalls, intrusion detection systems (IDS / IPS), antivirus software, security gateways, etc. Ensure that all new and existing endpoints are equipped with appropriate security measures.

[0121] Regular auditing and updating: Regularly conduct security audits on the endpoints to ensure that the policies and technologies are implemented well. At the same time, regularly update the policies and technologies to address new threats and vulnerabilities.

[0122] Implement remote management: Use remote management tools to perform security configuration and management without actually accessing the endpoints. This helps reduce the risk of physical access and improve efficiency.

[0123] Regular assessment and adjustment: Regularly assess the implementation of endpoint security policies and adjust the policies and technologies as needed.

[0124] By following these steps, appropriate security policies can be implemented on each endpoint to protect the network and data from potential attacks.

[0125] S35. Dynamically adjust network resource allocation by a reconfigurable network security controller according to changes in network load.

[0126] Load monitoring and feedback: First, a system needs to be designed to monitor network load in real time. This may include monitoring network traffic, node status, user behavior, etc. This data can be collected through various sensors and data analysis tools. Once the data is collected, algorithms are needed to analyze this data to determine the current load condition.

[0127] Resource prediction and optimization: Based on the observation of the current load, the trend of future load needs to be predicted. This can be done through the use of machine learning models such as time series analysis or prediction algorithms for resource prediction and optimization. In this way, the best way to allocate network resources can be determined.

[0128] Security controller adjustment: Once the load prediction information is obtained, the reconfigurable network security controller can dynamically adjust network resource allocation according to this information. For example, if it is predicted that the future load will increase, the controller can increase firewall rules or add additional security devices to handle higher traffic. If it is predicted that the load will decrease, the controller can reduce resource allocation to optimize network performance.

[0129] Resilient policy: To make the system more resilient, a resilient policy can be implemented. This policy allows the network security controller to quickly adapt and reallocate resources when the network load suddenly increases or decreases.

[0130] Feedback and learning: To further improve the self - adaptability of the system, a feedback mechanism should be implemented, which can learn and improve the resource allocation strategy based on the results after each adjustment. For example, if the increased firewall rules do not reduce the load, different rules should be considered next time.

[0131] Security audit and monitoring: Throughout the process, regular security audits and monitoring are required to ensure that the network security controller does not introduce new security risks when adjusting resource allocation. Through the above steps and strategies, a reconfigurable network security controller system that can dynamically adjust network resource allocation according to changes in network load can be constructed. This will help improve network performance while ensuring network security.

[0132] Step S4: Perform reconfigurable network security services according to dynamic security policy management.

[0133] In this embodiment, step S4: Performing reconfigurable network security services according to dynamic security policy management may specifically further include the steps of:

[0134] S41: Select a security mode according to dynamic security policy management.

[0135] Security modes include access control, identity authentication, data encryption, intrusion detection and prevention, etc. A mode that can meet the requirements of the dynamic security policy and is compatible with the existing infrastructure can be selected. When selecting a security mode, ensure that the selected security mode can adapt to the network security environment, including hardware, software, and network infrastructure. When selecting a security mode, it is necessary to balance the relationship between security and performance. Once a security mode is selected, it needs to be implemented and monitored for its operation. Regularly evaluate the performance and security of the security mode and make adjustments as needed. In addition, an appropriate emergency response plan can be established to address potential security threats and vulnerabilities.

[0136] S42: Develop a dynamic security policy according to the security mode.

[0137] From the current security mode, the current network environment, user behavior, network traffic patterns, etc. can be obtained. Based on the security mode, various security policies can be defined. Security policies include access control, data protection, authentication, vulnerability management, etc. These policies should clearly state under what circumstances specific behaviors are allowed or blocked.

[0138] Dynamic security means that the policy should change according to changes in the environment. For example, if user behavior changes, or the network traffic pattern changes, then the security policy should also be adjusted accordingly. This can be achieved by using real-time monitoring and alerts.

[0139] Existing artificial intelligence (AI) and machine learning (ML) technologies in the art can be used to help develop more intelligent and dynamic security policies. These technologies can automatically adjust policies based on historical data and real-time data to address new threats and challenges.

[0140] After implementing the dynamic security policy, it is necessary to conduct comprehensive testing and verification. Ensure that the security policy can correctly identify and respond to various threat situations and issue alerts in a timely manner.

[0141] Continuous monitoring and updating: Network security is an ongoing process, so it is necessary to regularly monitor the security policy to ensure that it remains effective and can address new threats. Update the security policy as needed. By following these steps, a dynamic security policy can be developed according to the security mode and ensure that applications and systems are always in the best security state.

[0142] S43. Use machine learning to identify and prevent network threats, and use automated tools to deploy and update security policies.

[0143] Threat identification and classification: First, establish a machine learning model for identifying and classifying network threats. This may include malware, phishing emails, DDoS attacks, etc. Collect sufficient training data, including known malicious and non-malicious traffic, and then use this data to train your model. You can use supervised learning (such as decision trees, support vector machines, or neural networks) or unsupervised learning (such as clustering) methods in the existing technology.

[0144] Build automated tools: Using automated tools can greatly improve efficiency and accuracy. You can use automated tools in the existing technology according to actual needs to automatically detect network traffic and compare it with security policies. If a threat is detected, the tool should be able to trigger appropriate responses, such as sending warning notifications or even automatically performing security measures (such as isolating or deleting malicious files).

[0145] Security policy update: Use the machine learning model to predict future threat trends and automatically update security policies based on these trends. For example, if the model predicts that a new threat pattern is emerging, then the security policy can be automatically updated to adapt to this new threat.

[0146] Continuous monitoring and optimization: Continuously monitor network traffic and regularly evaluate the performance of the machine learning model. If the model performs poorly, you may need to adjust the model or collect more training data. In addition, security policies need to be reviewed regularly to ensure that they are still effective and can cope with new threats. Generally speaking, using machine learning and automated tools can help you more effectively identify and prevent network threats while deploying and updating security policies. This method can improve efficiency, reduce human errors, and ensure that your network environment is always in the best security state.

[0147] In some optional implementation manners of this embodiment, the reconfigurable network security controller realizes the reconfiguration of the hardware circuit by modifying the configuration file of the FPGA, specifically including the steps:

[0148] Open the FPGA development tool;

[0149] Create a new project and select the FPGA chip model and configuration file format;

[0150] Open the configuration file of the FPGA in the project. The configuration file contains the logical design and connection information of the FPGA;

[0151] Modify the content in the configuration file by adding, deleting, or modifying logic blocks, signal connections, and parameters as needed;

[0152] After the modification is completed, save the configuration file and close the development tool;

[0153] Write the modified configuration file into the FPGA chip through a programmer or a downloader.

[0154] FPGA development tools include Xilinx ISE or Vivado, etc. The configuration file of an FPGA is usually a text file. Usually, the configuration file of the FPGA needs to be converted into a binary format, and then the data is transmitted to the FPGA chip through the corresponding interface. After the FPGA chip is powered on, the FPGA will reconfigure the hardware circuit according to the new configuration file. It should be noted that modifying the configuration file of the FPGA requires careful operation. Incorrect modification may cause the FPGA to malfunction or result in unpredictable errors. Therefore, it is best to back up the original configuration file before making modifications and conduct sufficient testing and verification after the modification is completed.

[0155] Implementing this embodiment has the following beneficial effects:

[0156] By establishing a reconfigurable network security architecture based on SDN and NFV; then setting up a reconfigurable network security controller based on the reconfigurable network security architecture; then performing dynamic security policy management according to the reconfigurable network security controller; and finally providing reconfigurable network security services according to the dynamic security policy management; through software-level optimization, reconfigurable computing can more effectively utilize computing resources and improve computing efficiency; software support enables reconfigurable computing to adapt to different application scenarios and requirements, enhancing its flexibility; by optimizing the software, reconfigurable computing can reduce energy consumption while completing computing tasks, conforming to the trend of green computing; in the face of constantly changing network threats and attacks, it can respond and adjust in a timely manner to ensure the security and stability of the network environment.

[0157] The present invention can be used in numerous general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on. The present invention can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present invention can also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.

[0158] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through computer-readable instructions. These computer-readable instructions can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, an optical disk, a read-only memory (ROM), etc., or a random access memory (RAM), etc.

[0159] It should be understood that although the steps in the flowchart of the accompanying drawings are shown in sequence according to the indication of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit and can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the accompanying drawings can include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same moment but can be executed at different moments. Their execution order is not necessarily sequential but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.

[0160] Example 2

[0161] For further reference Figure 2 and as an implementation of the method shown above Figure 1 , the present invention provides an embodiment of a reconfigurable network security computing device. This device embodiment corresponds to the method embodiment shown Figure 1 and can be specifically applied to various electronic devices.

[0162] Such asFigure 2 As shown in Figure 2 , the reconfigurable network security computing device 50 in this embodiment includes: an establishment module 51, a setting module 52, a management module 53, and a service module 54. Among them:

[0163] The establishment module 51 is used to establish a reconfigurable network security architecture based on SDN and NFV;

[0164] The setting module 52 is used to set a reconfigurable network security controller based on the reconfigurable network security architecture;

[0165] The management module 53 is used to perform dynamic security policy management according to the reconfigurable network security controller;

[0166] The service module 54 is used to provide reconfigurable network security services according to the dynamic security policy management.

[0167] Implementing this embodiment has the beneficial effects that:

[0168] By establishing a reconfigurable network security architecture based on SDN and NFV; then setting a reconfigurable network security controller based on the reconfigurable network security architecture; then performing dynamic security policy management according to the reconfigurable network security controller; and finally providing reconfigurable network security services according to the dynamic security policy management; through software-level optimization, reconfigurable computing can more effectively utilize computing resources and improve computing efficiency; software support enables reconfigurable computing to adapt to different application scenarios and requirements, enhancing its flexibility; by optimizing software, reconfigurable computing can reduce energy consumption while completing computing tasks, meeting the trend of green computing; when facing constantly changing network threats and attacks, it can respond and adjust in a timely manner to ensure the security and stability of the network environment.

[0169] Example 3

[0170] To solve the above technical problems, the embodiment of the present invention also provides a computer device. Specifically, please refer to Figure 3 , Figure 3 which is the basic structural block diagram of the computer device in this embodiment.

[0171] The above computer device 6 includes a memory 61, a processor 62, and a network interface 63 that are communicatively connected to each other via a system bus. It should be noted that only the computer device 6 with components such as the memory 61, the processor 62, and the network interface 63 is shown in the figure. However, it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively. Among them, those skilled in the art of the present technology can understand that the computer device here is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0172] The above computer device can be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The above computer device can perform human-computer interaction with the user through means such as a keyboard, a mouse, a remote control, a touchpad, or a voice control device.

[0173] The above memory 61 includes at least one type of readable storage medium. The above readable storage medium includes flash memory, hard disks, multimedia cards, card-type memories (such as SD or DX memories, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memories, magnetic disks, optical disks, etc. In some embodiments, the above memory 61 can be an internal storage unit of the above computer device 6, such as the hard disk or memory of the computer device 6. In other embodiments, the above memory 61 can also be an external storage device of the above computer device 6, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device 6. Of course, the above memory 61 can also include both the internal storage unit of the above computer device 6 and its external storage device. In this embodiment, the above memory 61 is generally used to store the operating system and various application software installed on the above computer device 6, such as computer-readable instructions for a reconfigurable network security calculation method. In addition, the above memory 61 can also be used to temporarily store various data that have been output or will be output.

[0174] In some embodiments, the above-mentioned processor 62 may be a Central Processing Unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chips. The processor 62 is generally used to control the overall operation of the above-mentioned computer device 6. In this embodiment, the processor 62 is used to run the computer-readable instructions stored in the above-mentioned memory 61 or process data, such as running the computer-readable instructions of the above-mentioned reconfigurable network security computing method.

[0175] The above-mentioned network interface 63 may include a wireless network interface or a wired network interface, and this network interface 63 is generally used to establish a communication connection between the above-mentioned computer device 6 and other electronic devices.

[0176] Implementing this embodiment has the following beneficial effects:

[0177] By establishing a reconfigurable network security architecture based on SDN and NFV; then setting up a reconfigurable network security controller based on the reconfigurable network security architecture; then performing dynamic security policy management according to the reconfigurable network security controller; and finally providing reconfigurable network security services according to the dynamic security policy management; through software-level optimization, reconfigurable computing can more effectively utilize computing resources and improve computing efficiency; software support enables reconfigurable computing to adapt to different application scenarios and requirements, enhancing its flexibility; by optimizing the software, reconfigurable computing can reduce energy consumption while completing computing tasks, meeting the trend of green computing; in the face of constantly changing network threats and attacks, it can respond and adjust in a timely manner to ensure the security and stability of the network environment.

[0178] Example 4

[0179] The present invention also provides another implementation manner, that is, to provide a computer-readable storage medium storing computer-readable instructions that can be executed by at least one processor, so that at least one processor executes the steps of the reconfigurable network security computing method as described above.

[0180] Implementing this embodiment has the following beneficial effects:

[0181] By establishing a reconfigurable network security architecture based on SDN and NFV; then setting up a reconfigurable network security controller based on the reconfigurable network security architecture; then performing dynamic security policy management according to the reconfigurable network security controller; and finally providing reconfigurable network security services according to the dynamic security policy management; through software-level optimization, reconfigurable computing can make more effective use of computing resources and improve computing efficiency; software support enables reconfigurable computing to adapt to different application scenarios and requirements, enhancing its flexibility; by optimizing the software, reconfigurable computing can reduce energy consumption while completing computing tasks, conforming to the trend of green computing; in the face of constantly changing network threats and attacks, it can respond and adjust in a timely manner to ensure the security and stability of the network environment.

[0182] Through the description of the above embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, in essence, or the part that makes a contribution to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc) and includes several instructions for causing a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods of various embodiments of the present invention.

[0183] Obviously, the above-described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. The accompanying drawings show preferred embodiments of the present invention, but do not limit the patent scope of the present invention. The present invention can be implemented in many different forms. On the contrary, the purpose of providing these embodiments is to make the understanding of the disclosed content of the present invention more thorough and comprehensive. Although the present invention has been described in detail with reference to the foregoing embodiments, for those skilled in the art, they can still modify the technical solutions described in the foregoing specific embodiments, or perform equivalent replacements on some of the technical features. Any equivalent structure directly or indirectly using the content of the specification and drawings of the present invention in other related technical fields is equally within the scope of the patent protection of the present invention.

Claims

1. A reconfigurable network security computing method, characterized in that, It includes the following steps: Based on SDN and NFV, establish a reconfigurable network security architecture; Based on the reconfigurable network security architecture, set up a reconfigurable network security controller; According to the reconfigurable network security controller, conduct dynamic security policy management; According to the dynamic security policy management, provide reconfigurable network security services.

2. The reconfigurable network security computing method according to claim 1, characterized in that, The step of establishing a reconfigurable network security architecture based on SDN and NFV specifically includes: Obtain the security requirements and goals of the network; According to the security requirements and goals, based on SDN and NFV, separate the network control and data planes; Establish a reconfigurable network security overall architecture, which includes a control layer, a data layer, and a service management layer. The control layer is responsible for the control and management of network traffic, the data layer is responsible for data transmission and processing, and the service management layer is responsible for the operation and management of network services.

3. The reconfigurable network security computing method according to claim 1, characterized in that, The step of setting up a reconfigurable network security controller based on the reconfigurable network security architecture specifically includes: Establish a virtualization engine for virtualizing network functions; Design open APIs, and integrate the open APIs with third-party security solutions; Set up a visualization interface for intuitively displaying and controlling network security.

4. The reconfigurable network security computing method according to claim 1, characterized in that, The step of conducting dynamic security policy management according to the reconfigurable network security controller specifically includes: Through the reconfigurable network security controller, analyze network traffic and threat situations in real time; According to preset security policies, dynamically adjust network security configurations; Let the reconfigurable network security controller perform machine learning to analyze network traffic and threats; Implement security policies on each endpoint; According to changes in network loads, the reconfigurable network security controller dynamically adjusts network resource allocation.

5. The reconfigurable network security computing method according to claim 1, characterized in that, The step of providing reconfigurable network security services according to the dynamic security policy management specifically includes: According to the dynamic security policy management, select a security mode; According to the security mode, formulate dynamic security policies; Use machine learning to identify and prevent network threats, and use automated tools to deploy and update security policies.

6. The reconfigurable network security computing method according to any one of claims 1 to 5, characterized in that, The reconfigurable network security controller realizes the reconfiguration of the hardware circuit by modifying the configuration file of the FPGA.

7. The reconfigurable network security computing method according to claim 6, characterized in that, The step of the reconfigurable network security controller realizing the reconfiguration of the hardware circuit by modifying the configuration file of the FPGA specifically includes: Open the FPGA development tool; Create a new project, and select the FPGA chip model and configuration file format; Open the configuration file of the FPGA in the project, and the configuration file contains the logical design and connection information of the FPGA; According to needs, modify the content in the configuration file by adding, deleting, or modifying logic blocks, signal connections, and parameters; After the modification is completed, save the configuration file and close the development tool; Write the modified configuration file into the FPGA chip through a programmer or a downloader.

8. A reconfigurable network security computing device, characterized in that It includes: An establishment module for establishing a reconfigurable network security architecture based on SDN and NFV; A setting module for setting up a reconfigurable network security controller based on the reconfigurable network security architecture; A management module, configured to perform dynamic security policy management according to the reconfigurable network security controller; A service module, configured to perform reconfigurable network security services according to the dynamic security policy management.

9. A computer device, comprising a memory and a processor, wherein computer-readable instructions are stored in the memory, and when the processor executes the computer-readable instructions, the steps of the reconfigurable network security computing method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium, characterized in that Computer-readable instructions are stored on the computer-readable storage medium, and when the computer-readable instructions are executed by a processor, the steps of the reconfigurable network security calculation method according to any one of claims 1 to 7 are implemented.