Network server security partition configuration method and system
By building a parallel network architecture and dynamically selecting communication links, the problem of excessive firewall load on the network server under high traffic is solved, and efficient and secure traffic management and processing is achieved.
Patent Information
- Application Number
- CN202510669473.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-22
- Publication Date
- 2025-08-15
AI Technical Summary
In the prior art, when a network server faces a large amount of Web traffic and non-Web traffic access, the firewall is too high and has a large delay, resulting in a decrease in network communication efficiency and security.
The first and second network architectures are built in parallel, which are used to process web traffic and non-Web traffic, identify the request type through the pre-trained neural network model, and dynamically select the communication link based on the request identifier, and manage the intranet server in combination with load balancing and security level partition.
It improves the efficiency and security of network communication, reduces firewall load, ensures stability and business continuity under high traffic conditions, and enhances the management and protection capabilities of different types of traffic.
Smart Images

Figure CN120498790A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network server security partition configuration method and system. Background Art
[0002] With the continuous advancement of network technology, the security management of information intranets has become increasingly prominent. Currently, there is a lack of effective security device protection management between servers, other network devices, and office computer workstations, resulting in numerous security risks for information intranets.
[0003] Intranet security can be enhanced by setting up a firewall or intrusion detection system. These systems are typically deployed at the network perimeter to monitor and block potentially malicious traffic. These systems sit between servers and the external network, inspecting and filtering data packets entering and leaving the intranet.
[0004] However, when a large amount of web traffic and non-web traffic is accessed, the firewall load will be too high and the delay will be large. Summary of the Invention
[0005] The present invention provides a network server security partition configuration method and system, which are used to solve the problem of excessive firewall load and large delay caused by a large amount of Web traffic and non-Web traffic access.
[0006] In a first aspect, the present invention provides a method for configuring secure partitions of a network server, comprising: Constructing a first network architecture in which a communication link is connected in sequence to a first edge switch, a first firewall, a WAF firewall, a first aggregation switch, and an intranet server; Constructing a second network architecture in which a communication link is connected in sequence to a second edge switch, a second firewall, a second aggregation switch, and an intranet server; receiving an access request and determining a type of the access request; If the type is web traffic, controlling the first network architecture to determine the IP address of the access request; If the type of the access request is non-Web traffic, controlling the second network architecture to determine the IP address of the access request; Obtain a request identifier for the IP address; If the request identifier is in the preset whitelist, the access request is sent to the first aggregation switch and / or the second aggregation switch to access the intranet server.
[0007] Optionally, obtaining the type of the access request includes: Obtaining a protocol feature of a preset byte of the access request; Classifying the protocol features based on a pre-trained neural network model and outputting a classification result; the classification result includes an access request type and an access request confidence level; If the access request confidence is lower than a preset threshold, an early warning message is generated and sent to the first firewall and WAF firewall, or the second firewall.
[0008] Optionally, if the access request confidence is lower than a preset threshold, a warning message is generated and sent to the first firewall and the WAF firewall, or behind the second firewall, and the method includes: According to the warning information, control the first firewall and the WAF firewall, or the second firewall to generate a plurality of virtual IP addresses and ports; When it is detected that the access request attacks the virtual IP address, the IP in the access request is recorded and the IP is added to a blacklist.
[0009] Optionally, after adding the IP to the blacklist, the method includes: Perform multi-dimensional data collection on the IP to obtain a data source; performing preprocessing on the data source to obtain standard data; extracting behavioral features from the standard data and constructing a threat profile based on the behavioral features; Extracting attack features from the threat profile and generating protection rules; The protection rules are input into the protection rule bases of the first firewall, the second firewall and the WAF firewall.
[0010] Optionally, the method further includes: Connecting the first firewall and the second firewall by setting a heartbeat line to synchronize the session state table and the protection rule base of the first firewall and the second firewall in real time; The load rate of the first firewall is obtained, and if the load rate is greater than a preset load rate, the second firewall is controlled to receive the access request of the first firewall.
[0011] Optionally, the first aggregation switch is connected to the second aggregation switch, and a first load balancer is deployed between the first aggregation switch and the second aggregation switch; The first border switch is connected to the second border switch; a second load balancer is deployed between the first border switch and the second border switch; The first load balancer and the second load balancer are used to dynamically adjust the distribution ratio of the Web traffic according to the real-time traffic load.
[0012] Optionally, sending the access request to the first aggregation switch and / or the second aggregation switch to access the intranet server includes: Setting the security level of the intranet server; the security level includes the first security level, the second security level and the third security level; controlling the first aggregation switch to connect to the intranet servers having the first security level, the second security level, and the third security level; controlling the second aggregation switch to connect to the intranet server having the second security level and the third security level; If the access permission is level one, access the intranet server with a security level of the first security level through the first aggregation switch; If the access permission is level 2 or level 3, the intranet server with a security level of the second security level or the third security level is accessed through the first aggregation switch or the second aggregation switch.
[0013] In a second aspect, the present invention provides a network server security partition configuration system, comprising: a controller, a first network architecture, and a second network architecture; The controller is connected to the first network architecture and the second network architecture respectively; The communication link of the first network architecture is connected in sequence by the first edge switch, the first firewall, the WAF firewall, the first aggregation switch, and the intranet server; The communication link of the second network architecture is connected in sequence by the second edge switch, the second firewall, the second aggregation switch, and the intranet server; The first border switch and the second border switch are connected; The first firewall and the second firewall are connected; The first aggregation switch is connected to the second aggregation switch; The controller is configured to: receiving an access request and determining a type of the access request; If the type is web traffic, controlling the first network architecture to determine the IP address of the access request; If the type of the access request is non-Web traffic, controlling the second network architecture to determine the IP address of the access request; Obtain a request identifier for the IP address; If the request identifier is in the preset whitelist, the access request is sent to the first aggregation switch and / or the second aggregation switch to access the intranet server.
[0014] In a third aspect, the present invention provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the network server security partition configuration method as described in the first aspect is implemented.
[0015] In a fourth aspect, the present invention provides a non-transitory computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the network server security partition configuration method as described in the first aspect.
[0016] From the above technical solution, it can be seen that the present invention provides a network server security partition configuration method and system, the method comprising: constructing a first network architecture in which a communication link is connected in sequence by a first boundary switch, a first firewall, a WAF firewall, a first aggregation switch, and an intranet server; constructing a second network architecture in which a communication link is connected in sequence by a second boundary switch, a second firewall, a second aggregation switch, and an intranet server; receiving an access request and determining the type of the access request; if the type is Web traffic, controlling the first network architecture to determine the IP address of the access request; if the type of the access request is non-Web traffic, controlling the second network architecture to determine the IP address of the access request; obtaining a request identifier of the IP address; if the request identifier is in a preset whitelist, sending the access request to the first aggregation switch and / or the second aggregation switch to access the intranet server. The network server security partition configuration method and system provided by the present invention improves the efficiency and security of network communication by setting a first network architecture and a second network architecture in parallel, and dynamically selecting the optimal communication link based on the type of access request and the request type, so as to solve the problem of excessive firewall load and large delay when more Web traffic and non-Web traffic access. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0018] Figure 1 This is a flow chart of a method for configuring secure partitions in a network server according to an embodiment of the present invention; Figure 2 This is a schematic diagram of the structure of the first architecture and the second architecture provided by an embodiment of the present invention; Figure 3This is a schematic diagram of the structure of a network server security partition configuration system provided by an embodiment of the present invention; Figure 4 It is a structural diagram of an electronic device provided by an embodiment of the present invention.
[0019] Reference numerals: Among them, 110, first edge switch; 120, second edge switch; 130, first firewall; 140, second firewall; 150, WAF firewall; 160, first aggregation switch; 170, second aggregation switch; 180, intranet server; 191, first load balancer; 192, second load balancer; 210, heartbeat line; 610, processor; 620, communication interface; 630, memory; 640, communication bus. DETAILED DESCRIPTION
[0020] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0021] Figure 1 The present invention provides a flow chart of a method for configuring network server security partitions.
[0022] like Figure 1 As shown, the network server security partition configuration method provided by the embodiment of the present invention mainly includes the following steps: S101: Build a first network architecture in which a communication link is connected in sequence to a first edge switch 110, a first firewall 130, a WAF firewall 150, a first aggregation switch 160, and an intranet server 180.
[0023] S102 , constructing a second network architecture in which a communication link is sequentially connected to the second edge switch 120 , the second firewall 140 , the second aggregation switch 170 , and the intranet server 180 .
[0024] Specifically, such as Figure 2As shown, in the first network architecture and the second network architecture, the first boundary switch 110 and the second boundary switch 120 serve as the entrances of the two network architectures, respectively, and are responsible for data transmission between the external network and the internal network. The first firewall 130 and the second firewall 140 are respectively set behind the entrances of the two network architectures, and are used to perform security detection and filtering on the data entering the internal network to prevent malicious attacks and unauthorized access. In the first network architecture, the WAF firewall 150 mainly performs security protection on the Web application layer, effectively resisting SQL injection and cross-site scripting Web attacks. The first aggregation switch 160 and the second aggregation switch 170 are respectively responsible for aggregating and forwarding data traffic from different sources to improve network transmission efficiency and stability. As the core part of the two network architectures, the intranet server 180 carries various business applications and data storage functions.
[0025] Furthermore, the first and second architectures of the present invention are connected in parallel, with the first boundary switch 110 and the second boundary switch 120 connected, the first firewall 130 and the second firewall 140 connected, and the first aggregation switch and the second aggregation switch 170 connected, forming a comprehensive security protection system. This parallel design of the first and second architectures not only improves network security and stability but also ensures service continuity by enabling data transmission through the other architecture in the event of a failure in one architecture. Furthermore, the connections between these components enhance system redundancy, making the overall network architecture more robust and reliable.
[0026] In some embodiments, a heartbeat line 210 is set to connect the first firewall 130 and the second firewall 140 to synchronize the session state tables and protection rule bases of the first firewall 130 and the second firewall 140 in real time.
[0027] The load rate of the first firewall 130 is obtained, and if the load rate is greater than a preset load rate, the second firewall 140 is controlled to receive the access request of the first firewall 130 .
[0028] First aggregation switch 160 is connected to second aggregation switch 170, and first edge switch 110 is connected to second edge switch 120. A first load balancer 191 is deployed between first aggregation switch 160 and second aggregation switch 170, and a second load balancer is deployed between first edge switch 110 and second edge switch 120. First load balancer 191 and second load balancer 192 are used to dynamically adjust the distribution ratio of web traffic based on real-time traffic load.
[0029] For example, when the load on the first border switch 110 is large, a portion of the traffic can be distributed to the second border switch 120 through the second load balancer 192 to balance the load of the two border switches and avoid network bottlenecks caused by overloading of a single border switch. Similarly, when the first firewall 130 detects abnormal traffic or attack behavior, it can quickly direct this portion of traffic to the second firewall 140 for further analysis and processing, thereby achieving rapid response and effective isolation of potential threats. In addition, the first load balancer 191 between the first aggregation switch 160 and the second aggregation switch 170 can also ensure the uniform distribution of data traffic, avoiding the impact of single point failures on the entire network architecture. Through flexible and efficient traffic distribution and load balancing strategies, not only the overall performance and security of the network are improved, but also a more stable and reliable network service experience is provided.
[0030] S103: Receive an access request and determine the type of the access request.
[0031] Access requests include those from internal users and those from external users. When a user initiates an access request, it first passes through the first edge switch 110 and / or the second edge switch 120, which then analyzes the protocol characteristics of the access request to determine the type of access request. For example, internal user access requests are generally non-web-based, while external user access requests are generally web-based.
[0032] The types of access requests include: S201: Acquire a protocol feature of a preset byte of an access request.
[0033] S202: Classify the protocol features based on the pre-trained neural network model and output the classification results; the classification results include the access request type and the access request confidence.
[0034] S203 : If the access request confidence is lower than a preset threshold, an early warning message is generated and sent to the first firewall 130 and the WAF firewall 150 , or the second firewall 140 .
[0035] The protocol features of the preset bytes are key fields in the network packet header of the access request, such as the source address, destination address, source port, destination port, and transport layer protocol type. These fields reflect the basic attributes of the access request and are an important basis for determining the type of access request. By extracting and analyzing the protocol features of the preset bytes, we can gain a preliminary understanding of the source, purpose, and protocol type of the access request, providing basic data for subsequent classification and judgment.
[0036] In this embodiment of the present invention, a pre-trained neural network model is used to classify the extracted protocol features. This neural network model can learn the differences and patterns between the protocol features of different types of access requests, thereby accurately classifying the types of access requests. The classification results include not only the type of access request but also the confidence level of the access request, that is, the degree to which the access request is deemed dangerous. The confidence level can help the system more accurately determine the true nature of the access request, reducing false positives and false negatives. When the confidence level of an access request falls below a preset threshold, it indicates that the access request may contain anomalies or uncertainties. At this point, the system generates an alert and sends it to the first firewall 130 and WAF firewall 150, or the second firewall 140, for further analysis and processing.
[0037] The confidence of the access request can be obtained through a neural network model. For example, the access request can be judged from multiple angles, reasonable weights can be set, and then the confidence can be calculated.
[0038] Specifically, four influencing factors are set, namely protocol compliance score, behavior deviation, threat intelligence matching degree and model prediction probability. The confidence calculation formula is: ; in, Indicates execution degree, The weight of the protocol compliance score, Indicates the protocol compliance score, Indicates behavioral deviation, The weight of the behavior deviation, Indicates the threat intelligence matching degree, Indicates the score of threat intelligence matching degree, represents the model prediction probability, Represents the weight of the model's predicted probability.
[0039] The weight of the protocol compliance score is set to 0.3, the weight of the behavior deviation is set to 0.4, the weight of the threat intelligence matching is set to 0.2, and the weight of the model prediction probability is set to 0.1. After the neural network model analysis, the protocol compliance score is 80%, the behavior deviation is 90%, the threat intelligence matching is 70%, and the model prediction probability is 95%. .
[0040] Based on the confidence calculation results, the access request can be judged whether there is a threat, thereby improving the security of the network server.
[0041] In some embodiments, if the access request confidence is lower than a preset threshold, an early warning message is generated and sent to the first firewall 130 and the WAF firewall 150, or the second firewall 140. The network server security partition configuration method includes: S301. According to the warning information, the first firewall 130 and the WAF firewall 150, or the second firewall 140, are controlled to generate a number of virtual IP addresses and ports.
[0042] S302: When it is detected that an access request attacks a virtual IP address, the IP in the access request is recorded and the IP is added to a blacklist.
[0043] When the confidence level of an access request falls below a preset threshold, it indicates that the request is likely to be illegal. Therefore, by setting up a virtual IP as bait, we can lure low-confidence access requests to the virtual IP instead of the actual server resources. Once an attack is detected, we can quickly respond by recording the attacker's IP address and adding it to a blacklist, effectively preventing further access to the real server.
[0044] In addition, after adding the IP to the blacklist, the IP may be analyzed. In some embodiments, after adding the IP to the blacklist, the network server security partition configuration method includes: S401: Perform multi-dimensional data collection on the IP to obtain a data source.
[0045] S402: Preprocess the data source to obtain standard data.
[0046] S403: Extract behavioral features from standard data and construct a threat profile based on the behavioral features.
[0047] S404: Extract attack features from the threat profile and generate protection rules.
[0048] S405 : Input the protection rules into the protection rule bases of the first firewall 130 , the second firewall 140 , and the WAF firewall 150 .
[0049] Specifically, when performing multi-dimensional data collection on an IP, information such as the IP's access records, access frequency, access time, access content type, etc. over the past period of time can be collected to form a comprehensive data source.
[0050] The preprocessing step involves cleaning, deduplication, and formatting the data source to ensure data consistency and accuracy.
[0051] When constructing a threat profile, we comprehensively consider the IP's behavioral characteristics, such as access patterns and the frequency of abnormal behavior, to depict the potential threat level of the IP. Through in-depth analysis of the threat profile, we can extract specific attack characteristics, such as specific request patterns and abnormal packet structures. These behavioral and attack characteristics are then used to generate targeted protection rules.
[0052] The generated protection rules are then fed into the protection rule bases of the first firewall 130, the second firewall 140, and the WAF firewall 150, enhancing the defense capabilities of these security devices. When future access requests arrive, the firewalls will be able to quickly identify and block potential attacks based on these rules, effectively protecting the security of the network server.
[0053] S104: If the type is Web traffic, control the first network architecture to determine the IP address of the access request.
[0054] S105: If the type of the access request is non-Web traffic, control the second network architecture to determine the IP address of the access request.
[0055] The first network architecture is equipped with a WAF firewall 150, while the second network architecture is equipped with only a second firewall 140. Therefore, when the access request type is Web traffic, the WAF firewall 150 can perform a more detailed security check on the access request, including Web-specific threats such as SQL injection and cross-site scripting attacks, thereby ensuring the security of the Web service. When the access request type is non-Web traffic, since non-Web traffic generally does not involve complex Web interactions and is mostly access requests from internal users, only basic security checks need to be performed through the second firewall 140. This ensures security and improves processing efficiency. The first and second architectures flexibly select the most appropriate network architecture for processing based on different types of access requests, thereby achieving effective management and security protection of different types of traffic.
[0056] S106: Obtain a request identifier for the IP address.
[0057] S107 : If the request identifier is in the preset whitelist, the access request is sent to the first aggregation switch 160 and / or the second aggregation switch 170 to access the intranet server 180 .
[0058] Specifically, when receiving an access request from web or non-web traffic, it is necessary to obtain the request identifier of the IP address in the access request. For example, the request packet is parsed. Within the packet, a specific field or information is searched for that uniquely identifies the access request, i.e., the request identifier. The request identifier may be a sequence number, timestamp, session ID, or other identifier that ensures the uniqueness of the request.
[0059] When the request identifier is found, it will be checked whether the request identifier exists in the preset whitelist. Among them, the preset whitelist is a pre-set set of trusted request identifiers. The access requests corresponding to the trusted request identifiers are considered safe and do not need to go through a complicated security check process. If the request identifier is indeed in the whitelist, then the access request will be forwarded to the first aggregation switch 160 and / or the second aggregation switch 170. The first aggregation switch 160 and / or the second aggregation switch 170 is the gateway of the intranet server 180, responsible for routing the access request to the corresponding intranet server 180. In this way, trusted access requests can be quickly identified and processed, thereby improving the overall processing efficiency. At the same time, since the request identifiers in the whitelist are strictly screened and verified, the security of the intranet server 180 can also be guaranteed to a certain extent.
[0060] In some embodiments, sending the access request to the first aggregation switch 160 and / or the second aggregation switch 170 to access the intranet server 180 includes: Set the security level of the intranet server 180.
[0061] The security levels include the first security level, the second security level and the third security level; The first aggregation switch 160 is controlled to connect to the intranet server 180 with the first security level, the second security level, and the third security level.
[0062] The second aggregation switch 170 is controlled to connect to the intranet server 180 with the second security level and the third security level.
[0063] If the access permission is level one, the intranet server 180 with a security level of the first security level is accessed through the first aggregation switch 160 .
[0064] If the access permission is level 2 or level 3, the intranet server 180 with a security level of the second security level or the third security level is accessed through the first aggregation switch 160 or the second aggregation switch 170 .
[0065] Specifically, by partitioning the intranet server 180 and setting corresponding access control policies based on different security levels, the security of the intranet server 180 can be further improved. The first security level is the highest security level, corresponding to the intranet server 180 storing the most sensitive and important data. Only users or devices with the highest access rights are allowed to access it through the first aggregation switch 160. The second security level is the next highest security level, corresponding to the intranet server 180 storing relatively sensitive data. Users or devices with second or third level access rights are allowed to access it through the first aggregation switch 160 or the second aggregation switch 170. The third security level is the lowest security level, corresponding to the intranet server 180 storing general data. Users or devices with any access rights are allowed to access it through the first aggregation switch 160 or the second aggregation switch 170. This configuration ensures that intranet servers 180 of different security levels are appropriately protected, avoiding the risk of data leakage or unauthorized access. It also improves the management efficiency and flexibility of the intranet server 180.
[0066] For example, within a number of intranet servers 180, they are divided into three areas: an office area with a relatively low security level, an isolation area with a medium security level, and a server area with the highest security level. The isolation area serves as a buffer between non-secure and secure systems, addressing the issue of external networks being unable to access internal network services behind a firewall. Web servers, mail servers, and other systems are deployed in the isolation area. The office area houses servers used by company employees for daily work and generally has access to the isolation area. The core area houses servers that store important corporate data, documents, and other information.
[0067] Based on the same general inventive concept, the present invention also protects a network server security partition configuration system. The network server security partition configuration system provided by the present invention is described below. The network server security partition configuration system described below and the network server security partition configuration method described above can be referenced to each other.
[0068] Among them, such as Figure 3 As shown, the network server security partition configuration system includes: a controller, a first network architecture and a second network architecture.
[0069] The controller is connected to the first network architecture and the second network architecture respectively.
[0070] The communication link of the first network architecture is the first edge switch 110, the first firewall 130, the WAF firewall 150, the first aggregation switch 160, and the intranet server 180 connected in sequence.
[0071] The communication link of the second network architecture is that the second edge switch 120, the second firewall 140, the second aggregation switch 170, and the intranet server 180 are connected in sequence.
[0072] The first edge switch 110 and the second edge switch 120 are connected.
[0073] The first firewall 130 and the second firewall 140 are connected.
[0074] The first aggregation switch 160 is connected to the second aggregation switch 170 .
[0075] The controller is configured as: An access request is received and the type of the access request is determined.
[0076] If the type is web traffic, controlling the first network architecture to determine the IP address of the access request; If the type of the access request is non-Web traffic, controlling the second network architecture to determine an IP address of the access request; Get the request identifier for the IP address.
[0077] If the request identifier is in the preset whitelist, the access request is sent to the first aggregation switch 160 and / or the second aggregation switch 170 to access the intranet server 180 .
[0078] Figure 4 It is a structural diagram of an electronic device provided by an embodiment of the present invention.
[0079] like Figure 4 As shown, the electronic device may include: a processor 610, a communications interface 620, a memory 630, and a communication bus 640, wherein the processor 610, the communications interface 620, and the memory 630 communicate with each other via the communication bus 640. The processor 610 may call logic instructions in the memory 630 to execute a method for configuring network server security partitions, which includes: establishing a first network architecture in which a communication link is sequentially connected to a first edge switch 110, a first firewall 130, a WAF firewall 150, a first aggregation switch 160, and an intranet server 180.
[0080] The communication link is constructed as a second network architecture in which the second edge switch 120, the second firewall 140, the second aggregation switch 170, and the intranet server 180 are connected in sequence.
[0081] An access request is received and the type of the access request is determined.
[0082] If the type is Web traffic, the first network architecture is controlled to determine the IP address of the access request.
[0083] If the type of the access request is non-Web traffic, the second network architecture is controlled to determine an IP address of the access request.
[0084] Get the request identifier for the IP address.
[0085] If the request identifier is in the preset whitelist, the access request is sent to the first aggregation switch 160 and / or the second aggregation switch 170 to access the intranet server 180 .
[0086] Furthermore, the logic instructions in the aforementioned memory 630 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0087] On the other hand, the present invention also provides a computer program product, which includes a computer program, which can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the network server security partition configuration method provided by the above methods, which includes: constructing a first network architecture in which a communication link is connected in sequence to a first boundary switch 110, a first firewall 130, a WAF firewall 150, a first aggregation switch 160, and an intranet server 180.
[0088] The communication link is constructed as a second network architecture in which the second edge switch 120, the second firewall 140, the second aggregation switch 170, and the intranet server 180 are connected in sequence.
[0089] An access request is received and the type of the access request is determined.
[0090] If the type is Web traffic, the first network architecture is controlled to determine the IP address of the access request.
[0091] If the type of the access request is non-Web traffic, the second network architecture is controlled to determine an IP address of the access request.
[0092] Get the request identifier for the IP address.
[0093] If the request identifier is in the preset whitelist, the access request is sent to the first aggregation switch 160 and / or the second aggregation switch 170 to access the intranet server 180 .
[0094] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, it is implemented to execute the network server security partition configuration method provided by the above methods. The method includes: constructing a first network architecture in which a communication link is connected in sequence to a first boundary switch 110, a first firewall 130, a WAF firewall 150, a first aggregation switch 160, and an intranet server 180.
[0095] The communication link is constructed as a second network architecture in which the second edge switch 120, the second firewall 140, the second aggregation switch 170, and the intranet server 180 are connected in sequence.
[0096] An access request is received and the type of the access request is determined.
[0097] If the type is Web traffic, the first network architecture is controlled to determine the IP address of the access request.
[0098] If the type of the access request is non-Web traffic, the second network architecture is controlled to determine an IP address of the access request.
[0099] Get the request identifier for the IP address.
[0100] If the request identifier is in the preset whitelist, the access request is sent to the first aggregation switch 160 and / or the second aggregation switch 170 to access the intranet server 180 .
[0101] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.
[0102] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods described in each embodiment or certain portions of the embodiments.
[0103] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A method for configuring network server security partitions, characterized in that: include: Constructing a first network architecture in which a communication link is connected in sequence to a first edge switch, a first firewall, a WAF firewall, a first aggregation switch, and an intranet server; Constructing a second network architecture in which a communication link is connected in sequence to a second edge switch, a second firewall, a second aggregation switch, and an intranet server; receiving an access request and determining a type of the access request; If the type is web traffic, controlling the first network architecture to determine the IP address of the access request; If the type of the access request is non-Web traffic, controlling the second network architecture to determine the IP address of the access request; Obtain a request identifier for the IP address; If the request identifier is in the preset whitelist, the access request is sent to the first aggregation switch and / or the second aggregation switch to access the intranet server.
2. The network server security partition configuration method according to claim 1, characterized in that: The acquiring of the type of the access request includes: Obtaining a protocol feature of a preset byte of the access request; Classifying the protocol features based on a pre-trained neural network model and outputting a classification result; the classification result includes an access request type and an access request confidence level; If the access request confidence is lower than a preset threshold, an early warning message is generated and sent to the first firewall and WAF firewall, or the second firewall.
3. The network server security partition configuration method according to claim 2, characterized in that: If the access request confidence is lower than a preset threshold, an early warning message is generated and sent to the first firewall and the WAF firewall, or behind the second firewall. The method includes: According to the warning information, control the first firewall and the WAF firewall, or the second firewall to generate a plurality of virtual IP addresses and ports; When it is detected that the access request attacks the virtual IP address, the IP in the access request is recorded and the IP is added to a blacklist.
4. The network server security partition configuration method according to claim 3, characterized in that: After adding the IP to the blacklist, the method includes: Perform multi-dimensional data collection on the IP to obtain a data source; performing preprocessing on the data source to obtain standard data; extracting behavioral features from the standard data and constructing a threat profile based on the behavioral features; Extracting attack features from the threat profile and generating protection rules; The protection rules are input into the protection rule bases of the first firewall, the second firewall and the WAF firewall.
5. The network server security partition configuration method according to claim 4, characterized in that: The method further comprises: Connecting the first firewall and the second firewall by setting a heartbeat line to synchronize the session state table and the protection rule base of the first firewall and the second firewall in real time; The load rate of the first firewall is obtained, and if the load rate is greater than a preset load rate, the second firewall is controlled to receive the access request of the first firewall.
6. The network server security partition configuration method according to claim 1, characterized in that: The first aggregation switch is connected to the second aggregation switch, and a first load balancer is deployed between the first aggregation switch and the second aggregation switch; The first border switch is connected to the second border switch; a second load balancer is deployed between the first border switch and the second border switch; The first load balancer and the second load balancer are used to dynamically adjust the distribution ratio of the Web traffic according to the real-time traffic load.
7. The network server security partition configuration method according to claim 1, characterized in that: The step of sending the access request to the first aggregation switch and / or the second aggregation switch to access the intranet server includes: Setting the security level of the intranet server; the security level includes the first security level, the second security level and the third security level; controlling the first aggregation switch to connect to the intranet servers having the first security level, the second security level, and the third security level; controlling the second aggregation switch to connect to the intranet server having the second security level and the third security level; If the access permission is level one, access the intranet server with a security level of the first security level through the first aggregation switch; If the access permission is level 2 or level 3, the intranet server with a security level of the second security level or the third security level is accessed through the first aggregation switch or the second aggregation switch.
8. A network server security partition configuration system, characterized in that: include: a controller, a first network fabric, and a second network fabric; The controller is connected to the first network architecture and the second network architecture respectively; The communication link of the first network architecture is connected in sequence by the first edge switch, the first firewall, the WAF firewall, the first aggregation switch, and the intranet server; The communication link of the second network architecture is connected in sequence by the second edge switch, the second firewall, the second aggregation switch, and the intranet server; The first border switch and the second border switch are connected; The first firewall and the second firewall are connected; The first aggregation switch is connected to the second aggregation switch; The controller is configured to: receiving an access request and determining a type of the access request; If the type is web traffic, controlling the first network architecture to determine the IP address of the access request; If the type of the access request is non-Web traffic, controlling the second network architecture to determine the IP address of the access request; Obtain a request identifier for the IP address; If the request identifier is in the preset whitelist, the access request is sent to the first aggregation switch and / or the second aggregation switch to access the intranet server.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the network server security partition configuration method according to any one of claims 1 to 8 is implemented.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the network server security partition configuration method according to any one of claims 1 to 8 is implemented.