Security system, method for building a cloud platform, and server
By embedding the security module into the infrastructure service layer of the cloud platform, the problem of complex traffic paths of security products in the cloud platform is solved, and the effect of reducing construction costs and improving business stability is achieved.
Patent Information
- Application Number
- CN202111222374.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-20
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2041-10-20
AI Technical Summary
In the prior art, external security products with side-mounted security products are complex when used in cloud platforms, resulting in reduced business stability, high construction costs and incomplete security capabilities.
Embed the security module into the infrastructure service layer of the cloud platform and divided into series, bypass and proxy client classes to avoid modification of the physical structure, reduce additional traffic and network equipment consumption, and design and improve the security modules by yourself.
It reduces the impact of the business stability of the cloud platform, reduces construction costs, and improves the comprehensiveness of security functions and business stability.
Smart Images

Figure CN113886020B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computers, and in particular, to a security system, a method for building a cloud platform, and a server. Background Art
[0002] With the popularization of cloud computing, more and more enterprises have migrated their office systems and office networks to the cloud platform. While users put forward usage requirements for the cloud platform, they also put forward requirements for the security of the cloud platform.
[0003] Currently, in the construction of the cloud platform, the cloud platform usually uses mature security products to achieve the security protection of the cloud platform. These security products can be integrated into the cloud platform in a side-hung and external-connected manner to meet the security requirements of the cloud platform.
[0004] However, the complexity of the traffic path of the side-hung and external-connected security products during use is usually relatively high, which easily leads to a reduction in the business stability of the cloud platform. Summary of the Invention
[0005] This application provides a security system, a method for building a cloud platform, and a server to solve the problem that the complexity of the traffic path of the side-hung and external-connected security products during use is usually relatively high, which easily leads to a reduction in the business stability of the cloud platform.
[0006] In a first aspect, this application provides a security system, including: a cloud platform running in the system kernel of a first server, where the cloud platform includes an infrastructure service layer and a security module;
[0007] The system kernel of the first server is used to run the cloud platform and mount the security module;
[0008] The cloud platform is used to embed the security module mounted on the system kernel into the infrastructure service layer.
[0009] Optionally, the security module includes a series-connected type security module, and the system further includes: other functional modules;
[0010] The other functional modules run in the infrastructure service layer;
[0011] The security module and the other functional modules are connected in series in signal transmission, so that the data traffic in the cloud platform enters the other functional modules after passing through the security module.
[0012] Optionally, the security module includes a bypass type security module, and the system includes: a security management area;
[0013] The security management area is communicatively connected to the infrastructure service layer;
[0014] The security module is located in the security management area, and the data traffic that needs to be processed using the security module will be sent to the security module in the security management area.
[0015] Optionally, the security module includes a client - type security module, and the system includes: a first virtual machine running in the system kernel of a first server;
[0016] The first virtual machine is independent of and communicatively connected to the cloud platform;
[0017] The security module is built into the first virtual machine to simulate the operating state of the security module set on the client.
[0018] Optionally, the system further includes: a management module;
[0019] The management module runs in the cloud platform and is used to manage each security module in the cloud platform.
[0020] Optionally, the management module further includes: a background management interface;
[0021] Each security module in the cloud platform and the functions of each security module are displayed in the background management interface.
[0022] In a second aspect, the present application provides a method for building a cloud platform, including:
[0023] In response to a target selection instruction, select at least one target security module in the background management interface;
[0024] In response to a creation instruction, build a user cloud platform on the target physical machine or target virtual machine indicated by the creation instruction. The target security module runs in the infrastructure service layer of the user cloud platform, and the target physical machine or target virtual machine is a physical machine or virtual machine in the security system.
[0025] Optionally, before building a user cloud platform on the target physical machine or target virtual machine indicated by the creation instruction, the method further includes:
[0026] In response to a function selection instruction, select at least one current security function of a target security module in the background management interface of the cloud platform.
[0027] In a third aspect, the present application provides a device for building a cloud platform, including:
[0028] A selection module, configured to select at least one target security module in the background management interface of the cloud platform system in response to a target selection instruction;
[0029] A creation module, configured to, in response to a creation instruction, set up a user cloud platform on a target physical machine or a target virtual machine indicated by the creation instruction, where a target security module runs in an infrastructure service layer of the user cloud platform, and the target physical machine or the target virtual machine is a physical machine or a virtual machine in the security system.
[0030] Optionally, the creation module is further configured to:
[0031] In response to a function selection instruction, select at least one current security function of a target security module in a background management interface of the cloud platform.
[0032] In a fourth aspect, the present application provides a server, including: a memory and a processor;
[0033] The memory is used to store program instructions; the processor is used to call the program instructions in the memory to execute the security system in the first aspect and any possible design of the first aspect.
[0034] The security system, cloud platform setup method, and server provided by the present application include a cloud platform running in a system kernel of a first server. The cloud platform includes an infrastructure service layer. For each security module, the security system can first mount the security module to the system kernel of the first server. Subsequently, the cloud platform running in the system kernel of the first server embeds the security module into the infrastructure service layer. One or more security modules can be embedded in the infrastructure service layer. The security modules embedded in the infrastructure service layer can be divided into three categories: series type, bypass type, and proxy client type, which avoids modifying the physical structure or logical structure of the cloud platform, reduces the additional traffic generated after mounting the security module, reduces the performance consumption of additional network devices such as switches, and avoids installing additional proxy ends, thereby reducing the impact on service stability. The present application can also improve the security module through self-design, reduce the cost of cloud platform security construction, and avoid the problem of incomplete security functions caused by separately purchasing security functions. Description of the Drawings
[0035] To more clearly illustrate the technical solutions in the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0036] Figure 1 It is a schematic diagram of an application scenario of a security system provided by an embodiment of the present application;
[0037] Figure 2Schematic structural diagram of a security system provided by an embodiment of the present application;
[0038] Figure 3 Schematic structural diagram of a security system provided by an embodiment of the present application;
[0039] Figure 4 Flowchart of a cloud platform construction method provided by an embodiment of the present application;
[0040] Figure 5 Schematic structural diagram of a cloud platform construction device provided by an embodiment of the present application;
[0041] Figure 6 Schematic hardware structure diagram of a server provided by an embodiment of the present application. Detailed implementation manners
[0042] To make the objectives, technical solutions and advantages of the present application clearer, the technical solutions in the present application will be clearly and completely described below with reference to the accompanying drawings in the present application. Apparently, the described embodiments are some but not all of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.
[0043] The terms "first", "second", "third", "fourth", etc. in the specification and claims of the present application and the above accompanying drawings are used to distinguish similar objects and do not necessarily need to describe a specific order or sequence. It should be understood that such data used may be interchanged under appropriate circumstances. For example, without departing from the scope of this article, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information.
[0044] Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".
[0045] Furthermore, as used in this article, the singular forms "a", "an" and "the" are also intended to include the plural forms unless the context indicates otherwise.
[0046] It should be further understood that the terms "comprising", "including" indicate the presence of features, steps, operations, elements, components, items, types, and / or groups, but do not exclude the presence, appearance or addition of one or more other features, steps, operations, elements, components, items, types, and / or groups.
[0047] The terms "or" and "and / or" as used herein are to be interpreted as inclusive, or mean any one or any combination. Thus, "A, B, or C" or "A, B, and / or C" means "any one of the following: A; B; C; A and B; A and C; B and C; A, B, and C." An exception to this definition occurs only when a combination of elements, functions, steps, or operations are inherently mutually exclusive in some manner.
[0048] With the rise in popularity of cloud computing, more and more enterprises are migrating their office systems and networks to cloud platforms. While users are demanding cloud platforms, they are also demanding their security. Currently, cloud platforms typically implement security protection by using mature security products. These products can be integrated into the cloud platform through an external, side-by-side approach to meet the platform's security needs. For example, security products can be connected in series within the network, traffic can be diverted to security products through switches, traffic can be directed to security products through port mirroring, or security capabilities can be achieved through the installation of agents. However, these approaches present challenges such as complex traffic paths, difficulty troubleshooting, high deployment costs, and incomplete security capabilities.
[0049] To address the above issues, this application proposes a security system that integrates security capabilities into the cloud platform as native capabilities, reducing the complexity and cost of additional construction, alleviating the complexity of troubleshooting, and comprehensively improving the security of the cloud platform and its underlying business systems.
[0050] Currently, cloud platform construction is mainly divided into three layers: Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). In this application, the cloud platform system will be deployed as a software system in the IaaS layer and provide services to the PaaS and SaaS layers.
[0051] When the cloud platform system provides services to users, the underlying virtual machines use KVM technology and the containers use Docker technology. Security capabilities, integrated into the cloud platform as native capabilities, can be embedded into the virtual machines and containers. Consequently, when the cloud platform utilizes security capabilities, it no longer requires external security products.
[0052] The following specific embodiments are used to describe the technical solution of the present application in detail. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments.
[0053] Figure 1A schematic diagram of an application scenario of a security system provided by an embodiment of the present application is shown. As shown in the figure, the first cloud platform can be installed on a physical machine or a virtual machine. All the security functions that have been designed can be embedded in the first cloud platform. For example, these security functions may include a security integrated operation and maintenance management system, a VPN system, a WEB application security protection system (WAF), a host monitoring and auditing system (EDR), an intrusion detection system (IPS), an intrusion prevention system (IDS), a baseline inspection management system, a security device and policy management system, a security operation and maintenance auditing system (bastion host), a log collection and analysis system (log audit), a load balancing system, an application traffic management system, an abnormal traffic management and anti-denial of service system (DDoS), a network security attack and defense drill platform, a digital certificate authentication management system, a data security management system, a database encryption and reinforcement system, a database auditing system, a database firewall system, a data leakage prevention system, a document security management system, a Trojan monitoring system, a virus filtering gateway system, a unified user identity authentication management system, a network security access system, a network traffic analysis and auditing system, a network management system, a web page anti-tampering system, a vulnerability scanning and management system, a firewall system, a big data situation awareness system, etc.
[0054] The first cloud platform may include a management module. The management module can manage one or more physical machines and / or virtual machines in one or more computer rooms. For example, as shown in the figure, the first cloud platform can be connected to physical machines 11, 12, 21, and 22 in computer rooms 1 and 2. These physical machines or virtual machines can communicate with the first cloud platform through communication ports. User cloud platforms can be built in these physical machines or virtual machines. The security functions in these user cloud platforms can be partially or fully mirrored from the security functions of the first cloud platform to the user cloud platform according to the actual needs of the user. When a new security function is designed, the security function can also be added to the first cloud platform. The user cloud platform can also embed the security function into the user cloud platform through mirroring.
[0055] Figure 2A structural diagram of a security system provided by an embodiment of the present application is shown. The security system 10 may include a cloud platform 11 running in the system kernel of the first server. In addition, the security system 10 may also include a user cloud platform running in the system kernel of other servers. The first service and other servers may be physical machines or virtual machines. The cloud platform 11 includes an infrastructure service layer 111, platform services, and software services. Each security function may correspond to a security module 112. For each security module 112, the security system may first hang the security module 112 in the system kernel of the first server. Thereafter, the cloud platform 11 running in the system kernel of the first server embeds the security module 112 into the infrastructure service layer 111. Therefore, one or more security modules 112 may be embedded in the infrastructure service layer 111.
[0056] In the existing technology, security products can be divided into inline, bypass, and proxy client types. Each type of security product typically requires a different method for externalizing it to the cloud platform. For example, inline security products need to be logically connected to the cloud platform's network to promptly prevent security attacks against the cloud platform when they are discovered. Alternatively, bypass security products need to be logically deployed in a bypass fashion within the cloud platform's network, allowing network traffic or data to be sent to the security product for analysis. Furthermore, proxy client security products require the installation of a proxy client within a virtual machine or container to implement relevant security capabilities.
[0057] The security modules 112 embedded in the infrastructure service layer 111 can also be divided into three categories.
[0058] In one example, the in-line security module 112 can be in-lined within the infrastructure service layer 111 or the cloud platform 11. For example, when the infrastructure service layer 111 includes other functional modules, the security module 112 can be in-lined with the other functional modules in terms of signal transmission, so that data traffic in the cloud platform enters the other functional modules after passing through the security module 112. In another example, the security module 112 can be in-lined with the infrastructure service layer 111 in terms of signal transmission, so that data traffic enters the infrastructure service layer 111 after passing through the security module 112. In another example, the in-line security module 112 can be implemented using the underlying virtual network card of the cloud platform 11. For example, the security module 112 can be in-lined in front of the application server using a firewall. The cloud platform 11 for the application server will activate a virtual firewall and add a new virtual network card. This virtual network card connects only to the application server and the firewall. The application server's data traffic first passes through the firewall, which then sends the traffic to the application server via this virtual network card.
[0059] In another example, for the bypass security module 112, a security management area can be set in the infrastructure service layer 111 or the cloud platform 11. The security management area can be set in the cloud platform 11 and communicated with the infrastructure service layer 111. Alternatively, the security management area can be set in the infrastructure service layer 111 and communicated with other functional modules. The security module 112 is located in the security management area. The data traffic that needs to be processed by the security module 112 will be sent to the security management area and processed by the security module 112. Alternatively, the cloud platform 111 can start a virtual machine or container separately according to actual conditions. The virtual machine or container can be divided into a separate security management area through a virtual network card. The relevant data traffic can be sent to the corresponding security management area within the virtual machine, container or virtual network. Among them, the data traffic can be log data, attack data, management data, etc.
[0060] In another example, for the client-side security module 112, a first virtual machine can be run within the system kernel of the first server. The first virtual machine is independent of and communicatively connected to the cloud platform. The security module 112 is embedded within the first virtual machine to simulate the operational state of the security module 112 deployed on the client. Alternatively, the proxy-client-side security module 112 can implement built-in security capabilities through the underlying KVM or Docker environment, eliminating the need for deploying a proxy client.
[0061] The security system provided by the present application includes a cloud platform running in the system kernel of a first server. The cloud platform includes an infrastructure service layer. For each security module, the security system can first hang the security module in the system kernel of the first server. Thereafter, the cloud platform running in the system kernel of the first server embeds the security module into the infrastructure service layer. One or more security modules can be embedded in the infrastructure service layer. The security modules embedded in the infrastructure service layer can be divided into three categories: series connection, bypass connection and proxy client connection. For series connection security modules, the security module can be connected in series in the infrastructure service layer or the cloud platform. For bypass connection security modules, a security management area can be set up in the infrastructure service layer or the cloud platform. The security module is located in the security management area. For client connection security modules, a first virtual machine can be run in the system kernel of the first server. The security module is built into the first virtual machine. In this application, by embedding the security module into the infrastructure service layer, modifications to the physical or logical structure of the cloud platform are avoided, reducing the additional traffic generated after mounting the security module, reducing the performance consumption of additional switches and other network devices, and avoiding the installation of additional agents, thereby reducing the impact on business stability. This application can also reduce the cost of cloud platform security construction by independently designing and improving the security module, and avoid the problem of incomplete security functions caused by purchasing security functions separately.
[0062] Figure 3 FIG1 shows a schematic diagram of the structure of a security system provided by an embodiment of the present application. Figure 1 and Figure 2 Based on the embodiment shown, Figure 3 As shown, the cloud platform 11 of the security system 10 may further include a management module 113 .
[0063] The management module 113 can be run in the cloud platform 11. The management module 113 is used to manage the various security modules in the cloud platform. The management module 113 can also be used to manage Figure 1 Multiple physical machines and / or virtual machines are shown connected to the first server via ports.
[0064] The management module 113 may also include a background management interface. The background management interface displays the various security modules in the cloud platform and the functions of each security module. The background management interface may also display the various physical machines and / or virtual machines connected to the first server through ports, as well as the customer cloud platforms,
[0065] The security system provided in this application includes a management module. This management module can run in a cloud platform. This management module is used to manage the various security modules in the cloud platform. This management module can also be used to manage multiple physical machines and / or virtual machines connected to the first server via ports. In this application, by using this management module, management of other physical machines and / or virtual machines is achieved, and a customer cloud platform is created, as well as management of security modules in the customer cloud platform.
[0066] Figure 4 A flow chart of a cloud platform construction method provided by an embodiment of the present application is shown. Figures 1 to 3 Based on the examples, Figure 4 As shown, with the first server as the execution subject, the method of this embodiment may include the following steps:
[0067] S101 : In response to a target selection instruction, select at least one target security module in a background management interface.
[0068] In this embodiment, the cloud platform in the system kernel of the first server includes a backend management interface. A user can view the security modules in the cloud platform by viewing the backend management interface. The user can select at least one target security module from the at least one security module included in the cloud platform by checking or clicking. The cloud platform's security modules may also include default security modules. If the user does not select to delete these default security modules, these default security modules will become the target security modules.
[0069] In one example, the security functions of each security module are also displayed in the background management interface. In response to a function selection instruction, at least one current security function of a target security module is selected in the background management interface of the cloud platform.
[0070] In this example, the user can view the security functions of each security module in the cloud platform by viewing this background management interface. After selecting a security module, the user can continue to select at least one security function of this security module. Each security module may include default security functions. When the user does not additionally delete these default security functions, these default security functions will become the target security functions.
[0071] S102. In response to a creation instruction, a user cloud platform is built on the target physical machine or target virtual machine indicated by the creation instruction. The target security module runs in the infrastructure service layer of the user cloud platform, and the target physical machine or target virtual machine is a physical machine or virtual machine in the security system.
[0072] In this embodiment, the background management interface also includes a creation button. The user can trigger the creation instruction by clicking this creation button. Before executing this creation instruction, the first server can obtain the target physical machine or target virtual machine. The user cloud platform will be built on this target physical machine or target virtual machine. The target security module runs in the infrastructure service layer of the user cloud platform.
[0073] In one example, the target security functions of the target security module run in the infrastructure service layer of the user cloud platform.
[0074] For the cloud platform building method provided in this application, the cloud platform in the system kernel of the first server. This cloud platform includes a background management interface. The user can view the security modules in the cloud platform by viewing this background management interface. In response to a target selection instruction, at least one target security module is selected in the background management interface. The background management interface also includes a creation button. The user can trigger the creation instruction by clicking this creation button. In response to the creation instruction, a user cloud platform is built on the target physical machine or target virtual machine indicated by the creation instruction. The target security module runs in the infrastructure service layer of the user cloud platform, and the target physical machine or target virtual machine is a physical machine or virtual machine in the security system. In this application, by using the background management interface, the rapid creation of the user cloud platform is realized, and in each user cloud platform, the security module is embedded in the infrastructure service layer of the cloud platform, reducing the extra traffic generated after mounting the security module and improving the service stability of the cloud platform.
[0075] Figure 5 The structural schematic diagram of a cloud platform building device provided by an embodiment of this application is shown, as Figure 5As shown, the cloud platform construction device 20 of this embodiment is used to implement the operations corresponding to the server in any of the above method embodiments. The cloud platform construction device 20 of this embodiment includes:
[0076] The selection module 21 is configured to select at least one target security module in the background management interface of the cloud platform system in response to a target selection instruction.
[0077] The creation module 22 is used to build a user cloud platform on the target physical machine or target virtual machine indicated by the creation instruction in response to the creation instruction. The target security module runs in the infrastructure service layer of the user cloud platform, and the target physical machine or target virtual machine is a physical machine or virtual machine in the security system.
[0078] In one example, the creation module 22 is further configured to:
[0079] In response to the function selection instruction, at least one current security function of a target security module is selected in the background management interface of the cloud platform.
[0080] The cloud platform building device 20 provided in the embodiment of the present application can execute the above method embodiment. Its specific implementation principles and technical effects can be found in the above method embodiment, and this embodiment will not be repeated here.
[0081] Figure 6 FIG1 shows a hardware structure diagram of a server provided in an embodiment of the present application. Figure 6 As shown, the server 30 is used to implement the operations corresponding to the server in any of the above method embodiments. The server 30 of this embodiment may include: a memory 31 , a processor 32 and a communication interface 34 .
[0082] Memory 31 is used to store computer programs. Memory 31 may include high-speed random access memory (RAM) or non-volatile memory (NVM), such as at least one disk memory. It may also be a USB flash drive, a mobile hard drive, a read-only memory, a magnetic disk, or an optical disk.
[0083] The processor 32, which is engaged with the server, is used to run the cloud platform. For specific details, reference can be made to the relevant descriptions in the foregoing method embodiments. The processor 32 may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the invention can be directly embodied as being executed and completed by a hardware processor, or can be executed and completed by a combination of hardware and software modules in the processor.
[0084] Optionally, the memory 31 can be either independent or integrated with the processor 32.
[0085] When the memory 31 is a device independent of the processor 32, the server 30 may further include a bus 33. The bus 33 is used to connect the memory 31 and the processor 32. The bus 33 may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience in representation, the buses in the drawings of this application are not limited to only one bus or one type of bus.
[0086] The communication interface 34 can be connected to the processor 31 through the bus 33. This communication interface can achieve communication with other servers, thereby realizing the background management of the cloud platform.
[0087] The server provided in this embodiment can be used to execute the above security system, and its implementation manner and technical effects are similar, so they will not be elaborated here in this embodiment.
[0088] This application also provides a computer-readable storage medium. A computer program is stored in the computer-readable storage medium. When the computer program is executed by a processor, it is used to implement the methods provided by the above various embodiments.
[0089] Among them, the computer-readable storage medium can be a computer storage medium or a communication medium. The communication medium includes any medium that facilitates the transfer of a computer program from one place to another. The computer storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer. For example, the computer-readable storage medium is coupled to the processor, so that the processor can read information from the computer-readable storage medium and write information to the computer-readable storage medium. Of course, the computer-readable storage medium can also be a component of the processor. The processor and the computer-readable storage medium can be located in an Application Specific Integrated Circuits (ASIC). In addition, the ASIC can be located in a user device. Of course, the processor and the computer-readable storage medium can also exist as discrete components in a communication device.
[0090] Specifically, the computer-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random-Access Memory (SRAM), Electrically-Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read Only Memory (EPROM), Programmable read-only memory (PROM), Read-Only Memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disk. The storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0091] This application also provides a computer program product. The computer program product includes a computer program stored in a computer-readable storage medium. At least one processor of the device can read the computer program from the computer-readable storage medium, and the execution of the computer program by at least one processor enables the device to implement the methods provided by the above various embodiments.
[0092] This embodiment of the application also provides a chip. The chip includes a memory and a processor. The memory is used to store a computer program, and the processor is used to call and run the computer program from the memory, so that the device installed with the chip executes the methods in the above various possible embodiments.
[0093] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of modules is only a logical function division. In actual implementation, there may be other division methods, such as multiple modules can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or modules, which can be electrical, mechanical or other forms.
[0094] The modules may be physically separate, for example, installed in different locations on a single device, or installed on different devices, or distributed across multiple network units, or distributed across multiple processors. The modules may also be integrated, for example, installed in the same device, or integrated into a set of codes. The modules may exist in the form of hardware, or in the form of software, or may be implemented in the form of software plus hardware. The present application may select some or all of the modules according to actual needs to achieve the purpose of the present embodiment.
[0095] When each module is implemented as an integrated module in the form of a software function module, it can be stored in a computer-readable storage medium. The above-mentioned software function module is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) or a processor to perform some steps of the methods of each embodiment of the present application.
[0096] It should be understood that, although the various steps in the flowcharts of the above embodiments are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they may be performed in other orders. Moreover, at least a portion of the steps in the figure may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily performed at the same time, but may be performed at different times, and their execution order is not necessarily sequential, but may be performed in turn or alternately with other steps or at least a portion of sub-steps or stages of other steps.
[0097] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some or all of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A security system, characterized in that, The system includes: a cloud platform running in the system kernel of a first server, the cloud platform including an infrastructure service layer and a security module; The system kernel of the first server is used to run the cloud platform and mount the security module; The cloud platform is used to embed the security module mounted to the system kernel into the infrastructure service layer; The security module includes at least one of a series-connected type security module, a bypass type security module, and a client type security module, wherein: The series-connected type security module is connected in series with other functional modules in the infrastructure service layer in terms of signal transmission, so that the data traffic in the cloud platform first passes through the security module and then enters other functional modules; The bypass type security module is located in a security management area communicatively connected to the infrastructure service layer, and the data traffic that needs to be processed using the security module will be sent to the security module in the security management area; The client type security module is built into a first virtual machine that is independent of and communicatively connected to the cloud platform to simulate the operating state of the client type security module when it is set on the client side.
2. The system according to any one of claims 1, characterized in that The system further includes: a management module; The management module runs in the cloud platform and is used to manage each of the security modules in the cloud platform.
3. The system according to claim 2, wherein The management module further includes: a background management interface; Each security module in the cloud platform and the functions of each security module are displayed in the background management interface.
4. A method for building a cloud platform, characterized in that, Applied to the security system according to any one of claims 1-3 above, the method includes: In response to a target selection instruction, select at least one target security module in the background management interface; In response to a creation instruction, build a user cloud platform on the target physical machine or target virtual machine indicated by the creation instruction, and the target security module runs in the infrastructure service layer of the user cloud platform, and the target physical machine or target virtual machine is a physical machine or virtual machine in the security system.
5. The method according to claim 4, characterized in that Before building the user cloud platform on the target physical machine or target virtual machine indicated by the creation instruction, the method further includes: In response to a function selection instruction, select at least one current security function of a target security module in the background management interface of the cloud platform.
6. A cloud platform building device, characterized in that The device includes: A selection module, configured to select at least one target security module in the background management interface of the cloud platform system in response to a target selection instruction; the security module includes at least one of a series-connected type security module, a bypass type security module, and a client type security module, wherein: the series-connected type security module is connected in series with other functional modules in the infrastructure service layer in terms of signal transmission, so that the data traffic in the cloud platform first passes through the security module and then enters other functional modules; the bypass type security module is located in a security management area communicatively connected to the infrastructure service layer, and the data traffic that needs to be processed by the security module will be sent to the security module in the security management area; the client type security module is built into a first virtual machine that is independent of and communicatively connected to the cloud platform to simulate the operating state of the client type security module set on the client. A creation module, configured to build a user cloud platform on a target physical machine or a target virtual machine indicated by the creation instruction in response to a creation instruction, and the target security module runs in the infrastructure service layer of the user cloud platform, and the target physical machine or the target virtual machine is a physical machine or a virtual machine in the security system.
7. A server, characterized in that, The server includes: a memory, a processor; The memory is used to store a computer program; the processor is configured to implement the security system according to any one of claims 1-3 based on the computer program stored in the memory.
8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the security system according to any one of claims 1-3 above.
Citation Information
Patent Citations
Cloud security protection system and flow cleaning method
CN106790091A
Heterogeneous hybrid cloud computing system
CN107979620A