A cloud host network deployment method based on security linkage

By introducing a secure linkage VM deployment module and a network security recommendation training module in the virtualization management platform and SDN controller, the linkage training of cloud resources, security resources, and network resources is achieved using Portgroup identification, which solves the problem of not being able to perceive network load in the cloud network convergence scenario, and improves the overall utilization rate and service capabilities of the cloud network.

CN114416348BActive Publication Date: 2025-05-06GUANGXI PUBLIC INFORMATION IND CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202111594695.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-24
Publication Date
2025-05-06
Estimated Expiration
2041-12-24

AI Technical Summary

Technical Problem

In the cloud-network convergence scenario, the virtual management platform of the existing cloud resource pool center cannot sense the network load, resulting in the inability to select access to the optimal network when deploying the computing cloud host. Some networks are overloaded, affecting network services.

Method used

By adding a new secure linkage VM deployment module and a network security recommendation training module in the SDN controller to the virtualization management platform, using the Portgroup identifier to realize linkage training of cloud resources, security resources, and network resources, and selecting the network deployment method of cloud hosts.

Benefits of technology

The overall utilization and service capabilities of the cloud network are improved. Through intelligent model algorithm training, the balanced scheduling of cloud hosts and security resources is realized based on parameter factors such as security load, network load and network performance, and the balanced utilization rate of network resources is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114416348B_ABST
    Figure CN114416348B_ABST
Patent Text Reader

Abstract

The present invention discloses a cloud host network deployment method based on security linkage, comprising the following steps: ① First, a security linkage VM deployment module is added to the virtualization management platform, and a network security recommendation training module is added to the SDN controller; ② VDS matches the computing node attributes with the network according to the pushed information, and communicates with the controller to coordinate the virtualization management platform to realize the deployment and access of computing nodes and networks. The present invention realizes the linkage training of cloud resources, security resources, and network resources by adding Portgroup identifiers, selects the network deployment method of the cloud host, and improves the overall utilization rate and service capabilities of the cloud network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computers, and in particular to a cloud host network deployment method based on security linkage. Background Art

[0002] In the host overlay solution, VTEP, VXLAN GW, and VXLAN IP GW are all implemented through software installed on the server. When the traffic is large, vRouter will become a system bottleneck.

[0003] In a three-layer network, service flows usually select round-trip paths during operation. If the circuit quality is poor or interrupted, the line will be reselected. Based on the SLA guarantee and operation and maintenance requirements of 5G mobile bearer services, and combining the advantages and disadvantages of existing performance detection technologies, Huawei proposed an innovative iFIT (in-situ Flow Information Telemetry) solution. It is necessary to analyze the situation of poor service quality or interruption based on the end-to-end flow detection mode, and then convert it to a hop-by-hop detection mode to locate the circuit problem point and re-plan the route. For the re-planned route, it is necessary to add the performance data of the new service on the basis of the original service performance data, and predict the alternative path based on customer preferences and network performance to achieve efficient operation of the service flow and improve user perception.

[0004] The following Chinese patent documents related to cloud host network deployment methods are found:

[0005] 1. A mesh network deployment method and device, application (patent) number: CN201510131542.7, application date: 2015.03.25, proposes a mesh network deployment method and device. The method includes: the network deployment unit selects a wireless network location m where an AP has not been deployed according to the pre-planned wireless network location where the access point AP is to be deployed; arbitrarily selects an AP m from the APs that have not been deployed; determines the neighbor location list of location m according to the pre-planned neighbor relationship between each wireless network location; for any neighbor location of location m, determines whether the neighbor location has been deployed with an AP, and if so, instructs the network deployment personnel to touch AP m with the AP at the neighbor location, so that: the two APs learn each other's MAC address, and add each other's MAC address to their own neighbor AP list, and instructs the network deployment personnel to deploy AP m to location m after touching. The speed and accuracy of Mesh network deployment are improved.

[0006] 2. A cloud load balancing optimization method and system, application (patent) number: CN201910977767.2 application date: 2019.10.15, discloses a cloud load balancing optimization method and system, by configuring the parameters in the cloud node, virtual switch and cloud host respectively, the cloud node network card queue, the cloud node polling thread, the virtual switch DPDK port queue, the virtual switch vhost port queue, the cloud host network card queue, the cloud host load balancing service process one-to-one correspondence is realized, so that the data packet can be directly shared between the kernel layer of the cloud node and the cloud host load balancing service process, and the polling thread is bound to the cpu and the active polling mechanism of the polling thread eliminates the lock and cpu context switching. Compared with the prior art, the technical solution of the present invention solves the problems of long IO path of traditional cloud load balancing network, data copy, lock overhead, CPU context switching and other inefficiencies, and at the same time enables the cloud load balancing to have flexible flow control, hot migration, elastic scaling and other characteristics. High-performance cloud load balancing is achieved.

[0007] 3. Method, device, equipment and storage medium for evaluating cloud host resources, application (patent) number: CN201910885428.1, application date: 2019.09.19, involving the field of cloud services, providing a method, device, equipment and storage medium for evaluating cloud host resources, the method comprising: analyzing target project information, resource types and resource usage of multiple cloud hosts through a resource monitoring model obtained through training, so as to obtain a cloud host to be evaluated and the resources to be evaluated of the cloud host to be evaluated, obtaining first sampling data and second sampling data of the resources to be evaluated, obtaining prediction information based on the first sampling data and the second sampling data, obtaining evaluation information based on the first sampling data, the second sampling data and the prediction information, and generating an optimization configuration strategy corresponding to the evaluation information based on the evaluation information. By adopting this solution, the resource utilization rate of the cloud host can be improved.

[0008] Although the above literature has optimized the cloud host to a certain extent, in the cloud-network integration scenario, the virtual management platform of the existing cloud resource pool center cannot perceive the network load. When deploying computing cloud hosts, it can only rely on manual experience and cannot choose to access the optimal network, resulting in overload of some network VTEP / vFWs, affecting network services.

[0009] Therefore, the present invention proposes a cloud host network deployment method based on security linkage, which realizes the linkage training of cloud resources, security resources, and network resources by adding Portgroup identifiers, selects the network deployment method of the cloud host, and improves the overall utilization and service capabilities of the cloud network. Summary of the invention

[0010] In view of the above problems, the present invention proposes a cloud host network deployment method based on security linkage, which realizes the linkage training of cloud resources, security resources, and network resources by adding Portgroup identifiers, selects the network deployment method of the cloud host, and improves the overall utilization and service capabilities of the cloud network.

[0011] To achieve the above object, the present invention provides the following technical solutions:

[0012] A cloud host network deployment method based on security linkage includes the following steps:

[0013] ① First, add a new security linkage VM deployment module in the virtualization management platform and a new network security recommendation training module in the SDN controller;

[0014] ② Based on the pushed information, VDS matches the computing node attributes with the network, communicates with the controller, and collaborates with the virtualization management platform to realize the deployment and access of computing nodes and networks.

[0015] It should be further explained that the deployment of the security linkage VM deployment module includes the following steps:

[0016] Step 1: Add the cloud resource cluster management center, bind VDS, and build a link;

[0017] Step 2: Discover the network location of the physical server host through LLDP;

[0018] Step 3: GBP binds the port group PortGroup to LogicSwitch;

[0019] Step 4: The SDN controller pushes the PortGroup information to the VDS of the cloud resource cluster management center;

[0020] Step 5: Notify the SDN controller when the VM is deployed or online, and configure the physical network.

[0021] Step 6: The SDN controller front-end displays the VM and its topology information.

[0022] It should be further explained that the network security recommendation training module carries the priorities of network resources and security resources from the SDN controller to the virtualization management platform through the PortGroup attribute.

[0023] It should be further explained that the training model parameters of the network security recommendation training module include VTEP load rate, vFW utilization rate, network delay, packet loss rate and VDS load rate.

[0024] It should be further explained that the network security recommendation training module predicts the network and security performance of the virtual machine before deployment, and then performs difference analysis training after actual deployment.

[0025] It should be further explained that the training model of the network security recommendation training module uses the LightGBM algorithm for prediction:

[0026] f m (x) = f m-1 (x)+T(x;θ m )

[0027] Among them, x is the prediction sample, T(x; θ m ) represents a decision tree, θ m Indicates decision tree parameters, including VTEP load rate, vFW utilization rate, network delay, packet loss rate, and VDS load rate. m is the number of trees. f m (x) is the sample prediction value;

[0028] The training difference function is expressed as: L(y i ,f m (x i ))=0.5(y i -f m (x i )) 2

[0029] Among them, y i is the true value of the i-th sample, f m (x i ) is the predicted value of the i-th sample;

[0030] Calculate the recommendation weight:

[0031] i=1,2,3,4,5

[0032] Among them, w i is the parameter weight, x i is the sample value of the training parameter defined above, μ i is the mean value corresponding to each of the five parameter samples, σ i is the standard deviation corresponding to each parameter sample; the larger the y value, the greater the degree of recommendation.

[0033] Explanation of terms involved in this application:

[0034] VDS is the abbreviation of Virus Detection System, which is a general term for equipment-based products that can perform computer virus detection on data in network transmission based on bypass access. VDS network security equipment adds a whole network warning line to the traditional host collaborative anti-virus mechanism, which can enhance the timeliness and accuracy of large-scale network virus prevention and provide a global monitoring view of the current status of network viruses for large-scale networks. The other is the VDS independent agent system. In short, it is a virtual independent server management system that adds a management interface for agents / large enterprises to directly manage their domain names, users, and sites on the basis of the Easyweb2.0 virtual host management platform. It is a low-cost, highly reliable, powerful, simple to use, and easy to maintain virtual independent server management system.

[0035] VDS uses full-virtualization technology, which provides a completely independent virtual server environment, which is equivalent to a real physical machine. Various types of operating systems can be run on VDS at the same time. Typical technology platforms include VMware, Hyper-V, etc.

[0036] VM: Virtual Machine, a virtual machine (Virtual Machine) refers to a complete computer system with complete hardware system functions that is simulated by software and runs in a completely isolated environment. All the work that can be done in a physical computer can be done in a virtual machine. When creating a virtual machine in a computer, part of the hard disk and memory capacity of the physical machine needs to be used as the hard disk and memory capacity of the virtual machine. Each virtual machine has an independent CMOS, hard disk and operating system, and the virtual machine can be operated like a physical machine.

[0037] LLDP refers to Link Layer Discovery Protocol. Link Layer Discovery Protocol (LLDP) is a data link layer protocol.

[0038] Network devices can send LLDPDU (Link Layer Discovery Protocol Data Unit) in the local network to notify other devices of their own status. It is a protocol that enables devices in the network to discover each other, notify each other of their status, and exchange information.

[0039] GBP, group-based policy, provides a declarative architecture based on user intent. In this mode, users face the application architecture itself, rather than the various network elements in Neutron. When using it, users define various "groups" and then define the network characteristics between "groups", including security, performance, network services, etc.

[0040] There are many projects that implement GBP, such as OpenStack's GBP, OpenDaylight's GBP and Cisco's ACI. In addition to driving Neutron, OpenStack's GBP can also be integrated with OpenDaylight GBP and Cisco's ACI.

[0041] Port-group means port group. The port-group command is to add the ports to be operated in the same way into a group, and then operate in this group. Of course, like virtual LAN, port-group can also be numbered, and there is no upper limit to the number of ports that can be numbered.

[0042] SDN controllers are applications in software-defined networking (SDN) that are responsible for traffic control to ensure an intelligent network. SDN controllers are based on protocols such as OpenFlow, which allow servers to tell switches where to send packets.

[0043] OpenFlow is a network communication protocol that belongs to the data link layer and can control the forwarding plane of switches or routers on the Internet, thereby changing the network path taken by network data packets.

[0044] Compared with the prior art, the present invention has the following beneficial effects:

[0045] (1) The present invention uses intelligent model algorithm training to train parameter factors such as security load, network load and network performance, and adds Portgroup identification to achieve linkage decision-making of cloud resources, security resources and network resources;

[0046] (2) The present invention identifies PortGroup on the network side by adding a new HostName attribute to identify the host location of the optimal network recommended by the VM selection, and the cloud resource manager deploys the cloud host and automatically binds the PortGroup. According to the newly added PortGroup attribute, the idle network device port can be selected for access, thereby improving the balanced scheduling capability of the cloud host and security in the entire cloud-network fusion resource pool;

[0047] (3) The present invention pushes the security network load information to the cloud resource manager. After iterative training, the cloud manager selects the physical host that carries the cloud host online and recommends the host location of the optimal security network, thereby achieving balanced utilization of network resources in an automatic and intelligent manner. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1 A schematic diagram of the deployment process of a security linkage VM deployment module is provided for an embodiment of the present application;

[0049] Figure 2 An architecture diagram of a safety training recommendation system is proposed for an embodiment of the present application;

[0050] Figure 3 A schematic diagram showing the difference between the traditional deployment method and the network deployment method of the present application. DETAILED DESCRIPTION

[0051] The technical solutions in the embodiments of the present invention will be described clearly and completely below in conjunction with the accompanying drawings in the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0052] An embodiment of the present invention provides a cloud host network deployment method based on security linkage, comprising the following steps:

[0053] ① First, add a new security linkage VM deployment module in the virtualization management platform and a new network security recommendation training module in the SDN controller;

[0054] ② Based on the pushed information, VDS matches the computing node attributes with the network, communicates with the controller, and collaborates with the virtualization management platform to realize the deployment and access of computing nodes and networks.

[0055] See also Figure 1 The deployment of the security linkage VM deployment module includes the following steps:

[0056] Step 1: Add the cloud resource cluster management center, bind VDS, and build a link;

[0057] Step 2: Discover the network location of the physical server host through LLDP;

[0058] Step 3: GBP binds the port group PortGroup to LogicSwitch;

[0059] Step 4: The SDN controller pushes the PortGroup information to the VDS of the cloud resource cluster management center;

[0060] Step 5: Notify the SDN controller when the VM is deployed or online, and configure the physical network.

[0061] Step 6: The SDN controller front-end displays the VM and its topology information.

[0062] The network security recommendation training module carries the priorities of network resources and security resources from the SDN controller to the virtualization management platform through the PortGroup attribute.

[0063] Taking the deployment of a virtual machine in a private cloud as an example, VMware's SDN controller and vFW are used in the resource pool, and VTEP load rate, vFW utilization rate, network latency, packet loss rate, and VDS load rate are selected as training parameters of the recommendation model.

[0064] A safety training recommendation system is proposed, and its architecture is shown in Figure 2 The optimal network deployment of the cloud host is recommended and trained as a nonlinear programming model, and the VTEP load rate, vFW utilization rate, network latency, packet loss rate, and VDS load rate are used as training model parameters; after predicting the network and security performance of the virtual machine before deployment, the difference analysis training is carried out after the actual deployment.

[0065] Use the LightGBM algorithm for prediction:

[0066] f m (x) = f m-1 (x)+T(x;θ m )

[0067] Among them, x is the prediction sample, T(x; θ m ) represents a decision tree, θ m Indicates decision tree parameters, including VTEP load rate, vFW utilization rate, network delay, packet loss rate, and VDS load rate. m is the number of trees. f m (x) is the sample prediction value;

[0068] The training difference function is expressed as: L(y i ,f m (x i ))=0.5(y i -f m (x i )) 2

[0069] Among them, y i is the true value of the i-th sample, f m (x i ) is the predicted value of the i-th sample.

[0070] Calculate the recommendation weight:

[0071] i=1,2,3,4,5

[0072] Among them, w i is the parameter weight, x i is the sample value of the training parameter defined above, μ i is the mean value corresponding to each of the five parameter samples, σ i is the standard deviation corresponding to each parameter sample; the larger the y value, the greater the degree of recommendation.

[0073] like Figure 3 As shown, the difference between the traditional cloud host network deployment method and the cloud host network deployment method of the present application is (the left side is the traditional method, and the right side within the dotted line is the method introduced in the present application):

[0074] 1. Define a deployment process for linking an intelligent training model with a cloud host. The SDN controller carries the priority of network resources and security resources to the cloud resource management platform through the PortGroup attribute, thus realizing the linkage decision-making of cloud resources, security resources, and network resources.

[0075] 2. Newly defined network-side identifier PortGroup adds a new security recommendation priority attribute Security priority, which pushes the security network load information to the cloud resource manager. After iterative training, the cloud manager selects the physical host that carries the cloud host online and recommends the host location of the optimal security network, achieving balanced utilization of network resources in an automatic and intelligent manner.

Claims

1. A cloud host network deployment method based on security linkage, characterized in that: The following steps are involved: ① First, add a new security linkage VM deployment module in the virtualization management platform and a new network security recommendation training module in the SDN controller; The deployment of the security linkage VM deployment module includes the following steps: Step 1: Add the cloud resource cluster management center, bind VDS, and build a link; Step 2: Discover the network location of the physical server host through LLDP; Step 3: GBP binds the port group PortGroup to LogicSwitch; Step 4: The SDN controller pushes the PortGroup information to the VDS of the cloud resource cluster management center; Step 5: Notify the SDN controller when the VM is deployed or online, and configure the physical network. Step 6: The SDN controller front-end displays the VM and its topology information; The network security recommendation training module carries the priorities of network resources and security resources from the SDN controller to the virtualization management platform through the PortGroup attribute; The network security recommendation training module predicts the network and security performance of the virtual machine before deployment and performs difference analysis training with the actual deployment; The training model parameters of the network security recommendation training module include VTEP load rate, vFW utilization rate, network delay, packet loss rate and VDS load rate; The training model of the network security recommendation training module uses the LightGBM algorithm for prediction: f m (x)=f m-1 (x)+T(x;θ m ) Among them, x is the prediction sample, T(x; θ m ) represents a decision tree, θ m Indicates decision tree parameters, including VTEP load rate, vFW utilization rate, network delay, packet loss rate, and VDS load rate. m is the number of trees. f m (x) is the sample prediction value; The training difference function is expressed as: L(y i ,f m (x i ))=0.5(y i -f m (x i )) 2 Among them, y i is the true value of the i-th sample, f m (x i ) is the predicted value of the i-th sample; Calculate the recommendation weight: i=1,2,3,4,5 Among them, w i is the parameter weight, x i is the sample value of the training parameter defined above, μ i is the mean value corresponding to each of the five parameter samples, σ i is the standard deviation corresponding to each parameter sample; the larger the y value, the greater the recommendation degree; ② Based on the pushed information, VDS matches the computing node attributes with the network, communicates with the controller, and collaborates with the virtualization management platform to realize the deployment and access of computing nodes and networks.

Citation Information

Patent Citations

  • Mesh network deployment method and mesh network deployment device

    CN104703193A

  • Cloud load balancing optimization method and system

    CN110636139A

  • Method, device and equipment for evaluating cloud host resources and storage medium

    CN110806954A

  • Virtual computing resource dynamic management system of cloud computing service platform

    CN102681899A

  • Dynamic resource allocation method and device

    CN103051564A