Computer network security server virtualization processing method and related equipment
By combining data perception, camouflage, capture and identification modules with resource control measures, the problem of virus propagation in virtual servers is solved, and a computer network security server virtualization system with high security and efficient resource utilization is realized.
Patent Information
- Application Number
- CN202210918650.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-01
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2042-08-01
AI Technical Summary
In the prior art, virus files in virtual servers are easily spread at the virtual server level, making it difficult to effectively meet the security protection requirements of computer network security server virtualization processing systems.
The data perception module obtains input data and detects its type. The data camouflage module is used to filter redundant camouflaged data and store it in the file library. The data capture module detects abnormal files and stores them in a separate virtualization system of the cloud virtual platform. The data identification module performs virus identification. Combined with the resource call unit and the traffic restriction module, resource allocation is dynamically adjusted to isolate the spread of viruses.
It effectively isolates the spread of viruses at the virtual server level, improves the security of computer network security server virtualization system, and optimizes resource allocation to ensure high security and high efficiency of the system.
Smart Images

Figure CN115292694B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and in particular to a computer network security server virtualization processing method, system, active defense unit, computer equipment and readable storage medium. Background Art
[0002] Computer virtualization technology refers to operating system virtualization. A single node runs a unique operating system instance. By adding a virtualization platform to this operating system, the system can be divided into multiple independent and isolated containers, also known as virtual servers. Each virtual server is a virtual operating system, known as a virtual environment. In operating system virtualization technology, each node has only a unique system kernel, and no hardware devices are virtualized. In addition, multiple virtual environments share a file system in a template format.
[0003] However, in actual use, when there are virus files in the virtual server, the virus files can easily spread at the virtual server level, which cannot well meet the security protection processing needs of the computer network virtualization server virtualization processing system. Summary of the Invention
[0004] The embodiments of the present disclosure provide a computer network security server virtualization processing method, system, active defense unit, computer equipment and readable storage medium, which can isolate viruses from spreading in the virtual server application layer and meet the security protection requirements of the computer network security server virtualization processing system.
[0005] The present disclosure provides a computer network security server virtualization processing method, the method being applied to a computer network security server virtualization processing system, the computer network security server virtualization processing system comprising a main server platform, a cloud virtual platform, a virtual server, and an active defense unit; the virtual server comprising a target virtual server, the active defense unit comprising a data perception module, a data disguise module, a data capture module, and a data identification module. The method comprises: obtaining target input data through the data perception module and detecting the type of the target input data; inputting the target input data into a target virtual server application layer according to the type of the target input data through the data perception module so that the target virtual server application layer calls the target input data and generates dynamic operation data; filtering the dynamic operation data and the target input data through the data disguise module to obtain redundant disguise data, and storing the redundant disguise data in a file library; detecting abnormal files in the redundant disguise data in the file library through the data capture module, and storing the abnormal files in a separately divided virtualization system in the cloud virtual platform; and performing virus identification on the abnormal files in the virtualization system through the data identification module.
[0006] In some exemplary embodiments of the present disclosure, the computer network security server virtualization processing system further includes a resource invocation unit, which includes a traffic limiting module; and the active defense unit further includes a data monitoring module. The method further includes: monitoring the dynamic operation data in real time using the data monitoring module, obtaining monitoring results, and feeding the monitoring results back to the traffic limiting module; and determining a target output data threshold for the target virtual server using the traffic limiting module.
[0007] In some exemplary embodiments of the present disclosure, the method further includes: setting a basic capability threshold for the target virtual server according to the resource configuration information of the target virtual server through the cloud virtual platform, wherein the basic capability threshold includes a first basic capability threshold and a second basic capability threshold. Wherein, determining the target output data threshold of the target virtual server through the traffic restriction module includes: if the monitoring result is that the first basic capability threshold is in an active state and the second basic capability threshold is in an inactive state in the dynamic operation data, then determining the target output data threshold of the target virtual server to be the first basic capability threshold.
[0008] In some exemplary embodiments of the present disclosure, the method further includes: dynamically reporting the idle resources corresponding to the second part of the basic capacity threshold allocated to the target virtual server to release the idle resources to the remaining virtual servers other than the target virtual server.
[0009] In some exemplary embodiments of the present disclosure, the computer network security server virtualization processing system further includes an access control unit, which includes an application layer protection module and a core-layer firewall access control module. Acquiring target input data through the data perception module includes: receiving input data through the application layer protection module, verifying the input data, and determining that input data that passes the verification is the target input data; and invoking the active defense unit through the core-layer firewall access control module to input the target input data into the data perception module.
[0010] The disclosed embodiments also provide a computer network security server virtualization processing system, comprising a main server platform, a cloud virtualization platform, virtual servers, and an active defense unit. The virtual servers include target virtual servers, and the active defense unit includes a data perception module, a data camouflage module, a data capture module, and a data identification module.
[0011] Among them, the data perception module is used to obtain target input data and detect the type of the target input data; according to the type of the target input data, the target input data is input into the target virtual server application layer so that the target virtual server application layer calls the target input data and generates dynamic operation data. The data camouflage module is used to filter the dynamic operation data and the target input data, obtain redundant camouflage data, and store the redundant camouflage data in the file library. The data capture module is used to detect abnormal files in the redundant camouflage data in the file library, and store the abnormal files in a separately divided virtualization system in the cloud virtual platform. The data identification module is used to identify viruses on the abnormal files in the virtualization system.
[0012] In some exemplary embodiments of the present disclosure, the system also includes a resource calling unit, which includes a traffic limiting module; the active defense unit also includes a data monitoring module; wherein the data monitoring module is used to monitor the dynamic operation data in real time, obtain monitoring results, and feed back the monitoring results to the traffic limiting module; the traffic limiting module is used to determine the target output data threshold of the target virtual server.
[0013] In some exemplary embodiments of the present disclosure, the cloud virtual platform is used to set a basic capability threshold for the target virtual server according to resource configuration information of the target virtual server, and the basic capability threshold includes a first basic capability threshold and a second basic capability threshold.
[0014] The traffic limiting module is also used to determine that the target output data threshold of the target virtual server is the first part of the basic capacity threshold if the monitoring result is that in the dynamic operation data, the first part of the basic capacity threshold is in an active state and the second part of the basic capacity threshold is in an inactive state.
[0015] In some exemplary embodiments of the present disclosure, the traffic limiting module is also used to dynamically report the idle resources corresponding to the second part of the basic capacity threshold allocated to the target virtual server to release the idle resources to the remaining virtual servers other than the target virtual server.
[0016] In some exemplary embodiments of the present disclosure, the computer network security server virtualization processing system also includes an access control unit, which includes an application layer protection module and a core-based firewall access control module; the data perception module is also used to receive input data through the application layer protection module, and verify the input data to determine that the input data that passes the verification is the target input data; call the active defense unit through the core-based firewall access control module, and input the target input data into the data perception module.
[0017] The embodiment of the present disclosure also provides an active defense unit, including: a data perception module, a data camouflage module, a data capture module and a data identification module.
[0018] Among them, the data perception module is used to obtain target input data and detect the type of the target input data; according to the type of the target input data, the target input data is input into the target virtual server application layer so that the target virtual server application layer calls the target input data to generate dynamic operation data. The data camouflage module is used to filter the dynamic operation data and the target input data, obtain redundant camouflage data, and store the redundant camouflage data in the file library. The data capture module is used to detect abnormal files in the redundant camouflage data in the file library, and store the abnormal files in a separately divided virtualization system in the cloud virtual platform. The data identification module is used to identify viruses on the abnormal files in the virtualization system.
[0019] An embodiment of the present disclosure further provides a computer device comprising a processor, a memory, and an input / output interface; the processor is connected to the memory and the input / output interface, respectively, wherein the input / output interface is used to receive and output data, the memory is used to store a computer program, and the processor is used to call the computer program so that the computer device including the processor executes the computer network security server virtualization processing method in any embodiment of the present disclosure.
[0020] An embodiment of the present disclosure further provides a computer-readable storage medium storing a computer program, which is suitable for being loaded and executed by a processor, so that a computer device having the processor executes the computer network security server virtualization processing method in any embodiment of the present disclosure.
[0021] The present disclosure also provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the method provided in any of the various optional embodiments of the present disclosure.
[0022] Some embodiments of the present disclosure provide a computer network security server virtualization processing method, which obtains redundant disguised data through a data disguise module, detects abnormal files in the disguised redundant module through a data capture module, stores the abnormal files in a separately divided virtualization system, and uses a data identification module to perform virus identification. Therefore, it is possible to filter the input data and perform virus identification, isolate the virus files, and prevent the spread of viruses at the virtual server level, thereby playing a role of active defense and improving the security of the computer network security server virtualization system. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the embodiments of the present disclosure or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0024] Figure 1 This is a flowchart of a computer network security server virtualization processing method provided by an embodiment of the present disclosure;
[0025] Figure 2 This is a block diagram of a computer network security server virtualization processing system provided by an embodiment of the present disclosure;
[0026] Figure 3 is a block diagram of an active defense unit provided by an embodiment of the present disclosure;
[0027] Figure 4 is a block diagram of a resource calling unit provided by an embodiment of the present disclosure;
[0028] Figure 5 is a block diagram of an access control unit provided by an embodiment of the present disclosure;
[0029] Figure 6 It is a structural diagram of a computer device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION
[0030] The following will be combined with the accompanying drawings in the embodiments of the present disclosure to clearly and completely describe the technical solutions in the embodiments of the present disclosure. Obviously, the embodiments described are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present disclosure.
[0031] In the following description of various exemplary embodiments of the present disclosure, reference is made to the accompanying drawings, which form a part of this disclosure and in which are shown by way of illustration various exemplary structures that may implement various aspects of the present disclosure. It should be understood that other specific arrangements of components, structures, exemplary devices, systems, and steps may be utilized, and structural and functional modifications may be made without departing from the scope of the present disclosure.
[0032] The flowcharts shown in the accompanying drawings are for illustrative purposes only and do not necessarily include all contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps may be decomposed, while others may be combined or partially combined. Therefore, the actual execution order may vary depending on the actual situation.
[0033] like Figure 1 As shown, the embodiment of the present disclosure provides a computer network security server virtualization processing method, which is applied to a computer network security server virtualization processing system. Figure 2 , shows a block diagram of a computer network security server virtualization processing system according to an embodiment of the present disclosure. The computer network security server virtualization processing system may include: a main server platform 20, a cloud virtual platform 21, a virtual server 22, and an active defense unit 23. Among them, the virtual server 22 includes a target virtual server, and the target virtual server may be any virtual server in the virtual server 22. Figure 3As described above, the active defense unit 23 may further include a data perception module 231 , a data camouflage module 232 , a data monitoring module 233 , a data capture module 234 and a data identification module 235 .
[0034] The computer network security server virtualization processing system of the embodiment of the present disclosure establishes a main server platform 20 through hardware components. The main server platform 20 is the core of the entire system and controls and coordinates other components in the system, such as the cloud virtual platform 21, the virtual server 22, and the active defense unit 23.
[0035] A cloud virtual platform 21 is built based on the main server platform 20 , and the cloud virtual platform 21 is used to perform resource allocation and data exchange for the virtual server 22 .
[0036] According to business needs, multiple virtual servers 22 can be established, and the virtual servers 22 are used to provide service support. Figure 2 The computer network security server virtualization processing system of the embodiment of the present disclosure may further include a configuration management module 26 for obtaining configuration information of the virtual server 22, initializing the configuration of the virtual server 22, and setting the IP address, time, serial port, and other processing data of the virtual server 22. Each virtual server 22 can be independently configured with application software and environment deployment, that is, each virtual server 22 is a standalone server.
[0037] Furthermore, the virtual servers 22 are classified into different levels according to their performance indicators, usage types, and security levels.
[0038] The performance indicators of the server may include throughput TPS (Transactions Per Second), QPS (Query Per Second), RPS (Requests Per Second), RT (Response Time), etc.
[0039] Server usage types are divided into four categories according to application levels: entry-level servers, workgroup-level servers, department-level servers, and enterprise-level servers; according to purpose, they are divided into two categories: general-purpose servers and dedicated servers; they can also be divided according to chassis structure, processor architecture, etc., which will not be repeated here.
[0040] The security level of the server is divided according to the security protection level of the information system, specifically: Level 1: User autonomous protection level; Level 2: System audit protection level; Level 3: Security mark protection level; Level 4: Structured protection level; Level 5: Access verification protection level.
[0041] By classifying the virtual servers 22 according to the above content, the basic attributes of each virtual server 22 can be determined, providing data accumulation and application for the access control unit 25, the active defense unit 23, etc.
[0042] The computer network security server virtualization processing system of the embodiment of the present disclosure is constructed based on the above content and is applicable to the computer network security server virtualization processing method of the embodiment of the present disclosure.
[0043] like Figure 1 As shown, the computer network security server virtualization processing method of the embodiment of the present disclosure includes the following steps: S110 to S150.
[0044] S110: Obtain target input data through the data perception module and detect the type of the target input data.
[0045] The target input data is a type of input data that can be sent to the virtual server application layer after being screened by the data sensing module 231. The system obtains the input data by relying on the access control unit 25 in the system.
[0046] As mentioned above, the computer network security server virtualization processing system of the embodiment of the present disclosure further includes an access control unit 25, such as Figure 5 As shown, the access control unit 25 includes an application layer protection module 251 and a core base layer firewall access control module 252.
[0047] Obtaining the target input data through the data perception module 231 in S110 may include: receiving the input data through the application layer protection module 251, and verifying the input data to determine that the input data that passes the verification is the target input data; calling the active defense unit 23 through the core base firewall access control module 252, and inputting the target input data into the data perception module 231 of the active defense unit 23.
[0048] The input data, also known as access data, is used by the access control unit 25 of the present embodiment to receive and assess the access data. The application layer protection module 251 receives and verifies the input data, determining whether the input data meets the requirements for entering the virtual server application layer of the cloud virtual platform 21, i.e., the target input data. The core base firewall access control module 252, using the target input data, invokes the active defense unit 23 and inputs the target input data into the data perception module 231.
[0049] In the embodiment of the present disclosure, after receiving the target input data, the data perception module 231 detects the type of the target input data.
[0050] Specifically, the type of target input data detected by the data perception module 231 may include one or more of system files, text, data files, response files, static files, parameters, execution command files, etc., among which system files may include Windows, UNIX, iOS and Android, etc., and there is no special limitation here.
[0051] S120: The target input data is input to the target virtual server application layer through the data perception module 231 according to the type of the target input data, so that the target virtual server application layer calls the target input data to generate dynamic operation data.
[0052] After detecting the type of target input data, the target input data is input into the virtual server application layer corresponding to the type according to the type. That is, different types of target input data are input into the virtual server 22 that matches the type. The virtual server 22 that receives the specific type of target input data is called the target virtual server, and the application layer of the target virtual server is called the target virtual server application layer. For example, the virtual server 22 that receives system files can be called the first target virtual server, and the system files are input into the first target virtual server application layer; the virtual server 22 that receives text can be called the second target virtual server, and the text is input into the second target virtual server application layer; the virtual server 22 that receives response files can be called the third target virtual server, and the response files are input into the third target virtual server application layer; the virtual server 22 that receives static files can be called the fourth target virtual server, and the static files are input into the fourth target virtual server application layer.
[0053] Of course, the target virtual server does not necessarily receive only one type of target input data, but can also receive any multiple types at the same time. For example, the first target virtual server can receive two types of target input data, system files and static files, at the same time. This can be set according to the level of virtual server division, and no special limitation is made here.
[0054] After the target input data is input into the target virtual server application layer, the target virtual server application layer calls the target input data to generate dynamic operation data.
[0055] The so-called dynamic operation data is actually part or all of the target input data. When part of the target input data is called, the part of the target input data is dynamic operation data. When all the target input data is called, all the target input data is dynamic operation data.
[0056] S130: Filter the dynamic operation data and the target input data through the data disguise module 232 to obtain redundant disguise data, and store the redundant disguise data in the file library.
[0057] Redundant disguised data refers to data exhibiting abnormalities, obtained by filtering the collected dynamic operation data and target input data through the data disguise module 232. Specifically, the data disguise module classifies the dynamic operation data and target input data, determining their readability based on virus signatures and internal program logic, and classifying the dynamic operation data and target input data as potentially containing harmful viruses. Abnormalities can manifest as frequent read and write operations on data files and logs, or database logins using brute force authentication.
[0058] The file library refers to the file library established by the data disguise module 232 in the virtual server 22. This file library can store the target input data obtained by the data perception module 231. In other words, in S120, the target input data is input into the target virtual server application layer, and this target input data is stored in the file library established by the data disguise module 232 in the virtual server 22. After the redundant disguise data is obtained, this redundant disguise data is also stored in the file library.
[0059] In addition, the data monitoring module 233 monitors the dynamic operation data in real time to monitor the system in real time.
[0060] S140 : Detect abnormal files in the redundant disguised data in the file library through the data capture module 234 , and store the abnormal files in a virtualization system separately divided in the cloud virtual platform 21 .
[0061] After the redundant disguised data is stored in the file library, the data capture module 234 detects the redundant disguised data and obtains abnormal files in the redundant disguised data. The abnormal files may be files that cause the redundant disguised data to be abnormal, such as files that cause the redundant disguised data to appear as frequent read and write operations on data files, logs, etc., or database permission brute force logins.
[0062] In order to facilitate the subsequent identification of these abnormal files, a virtualization system can be separately divided in the cloud virtual platform 21, and these abnormal files can be stored separately in the separately divided virtualization system to distinguish them from normal data in the file library.
[0063] S150: Perform virus identification on abnormal files in the virtualization system through the data identification module 235.
[0064] After storing abnormal files separately in the virtualization system, the data identification module 235 is called to identify these abnormal files. The data identification module 235 includes a virus database, which is located in the main server receipt of the main server platform 20. Specifically, by identifying dangerous functions, SQL (Structure Query Language) injection, weak passwords, XSS (Cross Site Scripting), etc. in abnormal files, harmful viruses with different logics can be further identified. Among them, different logical viruses may include: trapdoors, which are secret entrances into the program that gain access rights without going through the normal security access process and can be abused by attackers to pose a threat; logic bombs, which are a piece of code embedded in a legitimate program. When executing a harmful program, they will explode and spread under certain conditions; Trojans, which are a piece of code hidden in useful software with certain practical functions. When the Trojan virus is running, it acts as a springboard and acts as a hacker's agent. Bacteria, which do not execute programs that obviously damage computer systems, reproduce themselves and occupy resources. A worm is a virus program that can replicate itself through a network, perform any number of destructive or destructive activities, and maintain copies of the activity in a computer. Of course, it can also be other logical viruses, which are not specifically limited here.
[0065] After storing the abnormal files in a separately divided virtualization system in the cloud virtual platform 21 and identifying the viruses, the method of the embodiment of the present disclosure may further include: observing the files in the virtual server 22 for a certain period of time. When the virtual server 22 is running, if the file library has not changed and the target input data has not undergone abnormal operations after being called, the file library will be added to the file whitelist, and the monitoring of the virtual server 22 will be stopped, so that the virtual server 22 can be restored to normal use.
[0066] In summary, since harmful viruses are stored in a separate virtualization system in the target virtual server and isolated from other virtual servers 22, these harmful viruses will not spread at the level of the virtual server 22, playing an active defense role and improving the security of the computer network security server virtualization system of the embodiment of the present disclosure.
[0067] In some embodiments of the present disclosure, the method may further include: detecting and killing viruses. After the virus is identified, the virus may be detected and killed to eliminate the virus and further improve the security of the system.
[0068] In related technologies, multiple virtual servers in a cloud virtual platform lack the ability to share data resources (data resources can be data traffic in the system), which often results in virtual servers that require more data resources not getting enough resources, while virtual servers that require fewer data resources have excess data resources, making it impossible to evenly distribute data resources in the system and unable to meet the security protection processing needs of computer network security server virtualization systems.
[0069] As mentioned above, in the embodiment of the present disclosure, the computer network security server virtualization processing system may further include a resource calling unit 24, which is used to allocate data resources (which may be data traffic) of the system. The resource calling unit 24 may include a traffic limiting module 241.
[0070] The computer network security server virtualization processing method of the embodiment of the present disclosure further includes: monitoring the dynamic operation data in real time by the data monitoring module 233, obtaining monitoring results, and feeding the monitoring results back to the flow limiting module 241. The flow limiting module 241 determines the target output data threshold of the target virtual server.
[0071] Among them, after the dynamic operation data is generated in S120, the data monitoring module 233 monitors the dynamic operation data, for example, it can monitor the data transmission flow of the application layer of the target virtual server to obtain the corresponding monitoring results. And the monitoring results are fed back to the flow limiting module 241 in the resource calling unit 24. In some embodiments, the flow limiting module 241 can count the throughput TPS, QPS, RPS, RT and other information of the virtual server 22, and can also count the usage type, security level classification and other information of the virtual server 22. Combined with the monitoring results of the data transmission flow of each virtual server 22, the target output data threshold of the target virtual server is determined to adjust the transmission flow of the target virtual server.
[0072] In the embodiment of the present disclosure, the cloud virtual platform 21 sets a basic capability threshold for the target virtual server according to the resource configuration information of the target virtual server. The basic capability threshold includes a first basic capability threshold and a second basic capability threshold.
[0073] Among them, the resource configuration information can be information such as the memory, CPU (Central Processing Unit), hard disk, network configuration, software configuration, environment variables, etc. of the target virtual server, which is not limited to this. Based on the above information, the cloud virtual platform 21 sets a basic capability threshold for the target virtual server. The basic capability threshold refers to the boundary value of the data flow required when the target virtual server is running, which can be a range from a lower limit value to an upper limit value. The first part of the basic capability threshold can be a range from the lower limit value to a specific value in the range, and the second part of the basic capability threshold can be a range from the specific value to the upper limit value.
[0074] The target output data threshold of the target virtual server is determined by the traffic limiting module 241, including: if the monitoring result is that in the dynamic operation data, the first part of the basic capacity threshold is in an active state and the second part of the basic capacity threshold is in an inactive state, then the target output data threshold of the target virtual server is determined to be the first part of the basic capacity threshold.
[0075] The first part of the basic capacity threshold is in an active state, and the second part of the basic capacity threshold is in an inactive state. This means that when the target virtual server is running, the data traffic at the first part of the basic capacity threshold is used multiple times, while the data traffic at the second part of the basic capacity threshold is not used. In other words, the data traffic at the second part of the basic capacity threshold is idle. For the target virtual server, the data traffic required is the data traffic at the first part of the basic capacity threshold. Therefore, the target output data threshold of the first part of the basic capacity threshold can be determined.
[0076] The idle resources corresponding to the second part of the basic capacity threshold allocated to the target virtual server are dynamically reported to release the idle resources to the remaining virtual servers 22 other than the target virtual server.
[0077] The idle resources refer to idle data traffic, such as the data traffic within the second basic capacity threshold described above, so the data traffic within the second basic capacity threshold can be reallocated to other adapted virtual servers 22 .
[0078] For example, according to the resource configuration information, the basic capacity threshold set for the target virtual server is 1 to 7, the first part of the basic capacity threshold is 1 to 3, and the second part of the basic capacity threshold is 4 to 7. When the target virtual server is running, the target virtual server uses the first part of the basic capacity threshold 1 to 3 multiple times, while the second part of the basic capacity threshold 4 to 7 is not used and cannot be active. The target output data threshold of the target virtual server is determined to be the first part of the basic capacity threshold 1 to 3. This can ensure that the data traffic (data resources) allocation of the target virtual server is more reasonable, and the excess resources (data traffic in the second part of the basic capacity threshold 4 to 7) can be allocated to other virtual servers 22.
[0079] In other embodiments, the basic capacity threshold may further include a third portion of basic capacity thresholds. For example, in the aforementioned basic capacity thresholds 1 to 7, the first portion of basic capacity thresholds may be 1 to 2, the second portion of basic capacity thresholds may be 3 to 5, and the third portion of basic capacity thresholds may be 6 to 7. This further refines the basic capacity thresholds, thereby enabling more accurate allocation of data traffic. Of course, the basic capacity threshold may further include a fourth and fifth portion, and so on. The basic capacity thresholds may be divided according to actual circumstances and are not specifically limited here.
[0080] Therefore, by adjusting the target data output threshold of the target virtual server, the data traffic in the entire system is evenly distributed, thereby improving the utilization efficiency of the data traffic.
[0081] It should be noted that by setting the target output data threshold, not only the upper and lower limits of the output data can be controlled, but also the upper and lower limits of the input data can be controlled simultaneously because the output data threshold can constrain the input data.
[0082] The traffic limiting module 241 in the embodiment of the present disclosure can not only adjust the data traffic of the virtual server 22, but also implement the call to the network interface, thereby meeting the high security and high durability of the virtual server 22 test.
[0083] In addition, by setting the target output data threshold and adjusting the traffic of the target virtual server, the spread of viruses at the virtual server level can be further isolated.
[0084] In the embodiment of the present disclosure, after adjusting the target output data threshold of the target virtual server, the configuration management module 26 can reconfigure the hardware resources of the target virtual server according to the target data threshold, for example, resetting the IP address, time and serial port processing data of the target virtual server.
[0085] In this embodiment of the present disclosure, Figure 4As shown, the resource calling unit 24 may further include an intranet transmission module 242 and an extranet transmission module 243. The output ends of the intranet transmission module 242 and the extranet transmission module 243 are respectively connected to the flow limiting module 241 of the active defense unit 23. In addition, the intranet transmission module 242 is connected to the cloud virtual platform 21 through the main server platform 20, and the output end of the extranet transmission module 243 is also connected to the main server platform 20. The intranet transmission module 242 and the extranet transmission module 243 are used for data transmission and acquisition of data resources, and for data communication between the virtual server 22 and the main server platform 20. That is, the intranet transmission module 242 transmits data to the internal network and the one-way network card, and the extranet transmission module 243 transmits data to the external network end on the external network side, so that the intranet and extranet data are transmitted securely.
[0086] In the embodiment of the present disclosure, Figure 2 As shown, the computer network security server virtualization processing system further includes a power protection module 27 for adjusting and adapting the power of hardware resources in the system.
[0087] The method in the embodiment of the present disclosure can isolate the virus in a separate virtual server 22, so that the system maintains effective protection and improves the security of the system. At the same time, through dynamic adjustment, it can balance resource consumption of the entire system and make resource allocation and utilization more efficient.
[0088] like Figure 2 As shown, the embodiment of the present disclosure also provides a computer network security server virtualization processing system, including a main server platform 20, a cloud virtual platform 21, a virtual server 22, and an active defense unit 23. The virtual server 22 includes a target virtual server; the active defense unit 23 includes: a data perception module 231, a data disguise module 232, a data capture module 234, and a data identification module 235.
[0089] The data sensing module 231 is used to obtain target input data and detect the type of the target input data; according to the type of the target input data, the target input data is input to the target virtual server application layer so that the target virtual server application layer calls the target input data and generates dynamic operation data;
[0090] The data disguise module 232 is used to filter the dynamic operation data and the target input data to obtain redundant disguised data, and store the redundant disguised data in a file library.
[0091] The data capture module 234 is used to detect abnormal files in the redundant disguised data in the file library, and store the abnormal files in a virtualization system separately divided in the cloud virtual platform 21.
[0092] The data identification module 235 is used to identify viruses in abnormal files in the virtualization system.
[0093] Since harmful viruses are stored in a separate virtualization system in the target virtual server and isolated from other virtual servers 22, these harmful viruses will not spread at the level of the virtual server 22, playing an active defense role and improving the security of the computer network security server virtualization system of the embodiment of the present disclosure.
[0094] In some embodiments of the present disclosure, the system also includes a resource calling unit 24, which includes a traffic limiting module 241; the active defense unit 23 also includes a data monitoring module 233; wherein the data monitoring module 233 is used to monitor dynamic operation data in real time, obtain monitoring results, and feed back the monitoring results to the traffic limiting module 241; the traffic limiting module 241 is used to determine the target output data threshold of the target virtual server.
[0095] In some embodiments of the present disclosure, the cloud virtual platform 21 is used to set a basic capability threshold for the target virtual server according to the resource configuration information of the target virtual server, and the basic capability threshold includes a first basic capability threshold and a second basic capability threshold.
[0096] The traffic limiting module 241 is also used to determine the target output data threshold of the target virtual server as the first basic capacity threshold if the monitoring result shows that in the dynamic operation data, the first basic capacity threshold is in an active state and the second basic capacity threshold is in an inactive state.
[0097] In some embodiments of the present disclosure, the traffic limiting module 241 is further configured to dynamically report the idle resources corresponding to the second part of the basic capacity threshold allocated to the target virtual server, so as to release the idle resources to the remaining virtual servers 22 other than the target virtual server.
[0098] By adjusting the target data output threshold of the target virtual server, the data flow distribution in the entire system is balanced, and the efficiency of data flow utilization is improved.
[0099] In some embodiments of the present disclosure, the computer network security server virtualization processing system further includes an access control unit 25 , which includes an application layer protection module 251 and a core base firewall access control module 252 .
[0100] The data perception module 231 is also used to receive input data through the application layer protection module 251, and verify the input data to determine that the input data that passes the verification is the target input data; call the active defense unit 23 through the core base firewall access control module 252 to input the target input data into the data perception module 231.
[0101] like Figure 3 As shown, the embodiment of the present disclosure also provides an active defense unit 23, which is applied to a computer network security server virtualization processing system. The computer network security server virtualization processing system includes a main server platform 20, a cloud virtual platform 21 and a virtual server 22; the virtual server 22 includes a target virtual server; the active defense unit 23 includes: a data perception module 231, a data camouflage module 232, a data capture module 234 and a data identification module 235.
[0102] Among them, the data perception module 231 is used to obtain target input data and detect the type of target input data; according to the type of target input data, the target input data is input to the target virtual server application layer so that the target virtual server application layer calls the target input data to generate dynamic operation data.
[0103] The data disguise module 232 is used to filter the dynamic operation data and the target input data to obtain redundant disguised data, and store the redundant disguised data in a file library.
[0104] The data capture module 234 is used to detect abnormal files in the redundant disguised data in the file library, and store the abnormal files in a virtualization system separately divided in the cloud virtual platform 21.
[0105] The data identification module 235 is used to identify viruses in abnormal files in the virtualization system.
[0106] Since harmful viruses are stored in a separate virtualization system in the target virtual server and isolated from other virtual servers 22, these harmful viruses will not spread at the level of the virtual server 22, playing an active defense role and improving the security of the computer network security server virtualization system of the embodiment of the present disclosure.
[0107] For other contents of the embodiments of the present disclosure, reference can be made to the description of the other embodiments mentioned above.
[0108] See also Figure 6 , Figure 6 This is a schematic diagram of the structure of a computer device provided by an embodiment of the present disclosure. Figure 6 As shown, the computer device in the embodiment of the present disclosure may include: Figure 6As shown, the computer device in the embodiment of the present disclosure may include: one or more processors 601, a memory 602 and an input / output interface 603. The processor 601 is connected to the memory 602 and the input / output interface 603 respectively. Figure 6 As shown, the processor 601, memory 602, and input / output interface 603 are connected via a bus 604. The memory 602 is used to store computer programs, which include program instructions. The input / output interface 603 is used to receive and output data, such as for data exchange between a host machine and a computer device, or for data exchange between virtual machines in a host machine. The processor 601 is used to execute the program instructions stored in the memory 602.
[0109] Among them, the processor 601 can perform the following operations: obtain target input data through the data perception module 231 and detect the type of the target input data; input the target input data to the target virtual server application layer according to the type of the target input data through the data perception module 231, so that the target virtual server application layer calls the target input data to generate dynamic operation data; filter the dynamic operation data and target input data through the data disguise module 232 to obtain redundant disguise data, and store the redundant disguise data in the file library; detect abnormal files in the redundant disguise data in the file library through the data capture module 234, and store the abnormal files in a separately divided virtualization system in the cloud virtual platform; perform virus identification on abnormal files in the virtualization system through the data identification module 235.
[0110] In some feasible implementations, the processor 601 may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor, or the processor may be any conventional processor, etc.
[0111] The memory 602 may include a read-only memory and a random access memory, and provides instructions and data to the processor 601 and the input / output interface 603. A portion of the memory 602 may also include a non-volatile random access memory. For example, the memory 602 may also store device type information.
[0112] In a specific implementation, the computer device can execute the implementation methods provided by the various steps in any of the above method embodiments through its built-in functional modules. For details, please refer to the implementation methods provided by the various steps in the figure shown in the above method embodiments, which will not be repeated here.
[0113] The embodiments of the present disclosure provide a computer device including a processor, an input / output interface, and a memory. The processor obtains a computer program in the memory to execute the steps of the method shown in any of the above embodiments.
[0114] The embodiments of the present disclosure also provide a computer-readable storage medium, which stores a computer program, and the computer program is suitable for being loaded by the processor and executing the computer network security server virtualization processing method provided in each step of any of the above embodiments. For details, please refer to the implementation method provided in each step of any of the above embodiments, which will not be repeated here. In addition, the description of the beneficial effects of adopting the same method will not be repeated. For technical details not disclosed in the computer-readable storage medium embodiments involved in the present disclosure, please refer to the description of the method embodiments of the present disclosure. As an example, the computer program can be deployed to be executed on one computer device, or on multiple computer devices located in one location, or on multiple computer devices distributed in multiple locations and interconnected by a communication network.
[0115] The computer-readable storage medium may be the computer network security server virtualization processing system provided by any of the aforementioned embodiments or the internal storage unit of the computer device, such as the hard disk or memory of the computer device. The computer-readable storage medium may also be an external storage device of the computer device, such as a plug-in hard disk, a smart memory card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device. Furthermore, the computer-readable storage medium may also include both the internal storage unit of the computer device and an external storage device. The computer-readable storage medium is used to store the computer program and other programs and data required by the computer device. The computer-readable storage medium may also be used to temporarily store data that has been output or is to be output.
[0116] The present disclosure also provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the method provided in any of the optional embodiments described above.
[0117] The terms "first", "second", etc. in the description, claims, and drawings of the embodiments of the present disclosure are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "including" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, apparatus, product, or device that includes a series of steps or units is not limited to the listed steps or modules, but may optionally include steps or modules that are not listed, or may optionally include other steps and units inherent to these processes, methods, apparatuses, products, or devices.
[0118] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in this description according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this disclosure.
[0119] The methods and related devices provided by the embodiments of the present disclosure are described with reference to the method flow charts and / or structural diagrams provided by the embodiments of the present disclosure. Specifically, each process and / or block in the method flow charts and / or structural diagrams, as well as the combination of processes and / or blocks in the flow charts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable application display device to generate a machine, so that the instructions executed by the processor of the computer or other programmable application display device generate instructions for implementing the process. Figure 1 Schematic diagram of one or more processes and / or structures Figure 1 These computer program instructions can also be stored in a computer readable memory that can guide a computer or other programmable application display device to work in a specific way, so that the instructions stored in the computer readable memory produce a product including the instruction device, which implements the function specified in the process. Figure 1 Schematic diagram of one or more processes and / or structures Figure 1 These computer program instructions can also be loaded onto a computer or other programmable application display device, so that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide the functions for implementing the process. Figure 1 The flow or flows and / or structures illustrate the steps of the functions specified in one block or multiple blocks.
[0120] The above disclosure is merely a preferred embodiment of the present disclosure and certainly cannot be used to limit the scope of the present disclosure. Therefore, equivalent changes made according to the claims of the present disclosure are still within the scope of the present disclosure.
Claims
1. A computer network security server virtualization processing method, characterized in that: The method is applied to a computer network security server virtualization processing system, which includes a main server platform, a cloud virtual platform, a virtual server, and an active defense unit; The virtual server includes a target virtual server, and the active defense unit includes a data perception module, a data camouflage module, a data capture module, and a data identification module; The method comprises: Acquire target input data through the data perception module and detect the type of the target input data, where the type of the target input data includes one or more of a system file, text, data file, response file, static file, parameter, and execution command file; Inputting the target input data to a target virtual server application layer corresponding to the type of the target input data through the data perception module, so that the target virtual server application layer calls the target input data to generate dynamic operation data; filtering the dynamic running data and the target input data by the data disguise module to obtain data showing abnormalities to obtain redundant disguised data, and storing the redundant disguised data and the target input data in a file library established by the data disguise module in the target virtual server; Detecting abnormal files in the redundant disguised data in the file library through the data capture module, and storing the abnormal files in a separately divided virtualization system in the cloud virtual platform to isolate them from other virtual servers; Performing virus identification on the abnormal files in the virtualization system by the data identification module; The files in the target virtual server are observed for a certain period of time. When the target virtual server is running, if the file library has not changed and the target input data has not undergone abnormal operation after being called, the file library will be added to the file whitelist, and the monitoring of the target virtual server will be stopped, so that the target virtual server can be restored to normal use.
2. The method according to claim 1, wherein The computer network security server virtualization processing system further includes a resource calling unit, and the resource calling unit includes a flow limiting module; The active defense unit also includes a data monitoring module; The method further comprises: The dynamic operation data is monitored in real time by the data monitoring module to obtain monitoring results, and the monitoring results are fed back to the flow restriction module; The target output data threshold of the target virtual server is determined by the traffic limiting module.
3. The method according to claim 2, wherein Also includes: Setting a basic capability threshold for the target virtual server by the cloud virtual platform according to resource configuration information of the target virtual server, wherein the basic capability threshold includes a first basic capability threshold and a second basic capability threshold; The process of determining the target output data threshold of the target virtual server by the traffic limiting module includes: If the monitoring result shows that in the dynamic operation data, the first part of the basic capability threshold is in an active state and the second part of the basic capability threshold is in an inactive state, then the target output data threshold of the target virtual server is determined to be the first part of the basic capability threshold.
4. The method according to claim 3, wherein Also includes: The idle resources corresponding to the second part of the basic capacity threshold allocated to the target virtual server are dynamically reported to release the idle resources to the remaining virtual servers other than the target virtual server.
5. The method according to claim 1, wherein The computer network security server virtualization processing system further includes an access control unit, which includes an application layer protection module and a core base layer firewall access control module; Wherein, obtaining target input data through the data perception module includes: receiving input data through the application layer protection module, and verifying the input data to determine that the input data that passes the verification is the target input data; The active defense unit is called through the core base firewall access control module to input the target input data into the data perception module.
6. A computer network security server virtualization processing system, characterized in that: include: Main server platform, cloud virtual platform, virtual server and active defense unit; among them, The virtual server includes: a target virtual server; The active defense unit includes: a data perception module, configured to obtain target input data and detect a type of the target input data; based on the type of the target input data, input the target input data into a target virtual server application layer corresponding to the type of the target input data, so that the target virtual server application layer calls the target input data to generate dynamic operation data; the type of the target input data includes one or more of a system file, text, a data file, a response file, a static file, a parameter, and an execution command file; a data disguise module, configured to filter the dynamic operation data and the target input data to obtain data exhibiting abnormalities to obtain redundant disguised data, and store the redundant disguised data and the target input data in a file library established by the data disguise module in the target virtual server; a data capture module, configured to detect abnormal files in the redundant disguised data in the file library, and store the abnormal files in a separately divided virtualization system in the cloud virtual platform to isolate them from other virtual servers; and A data identification module is used to identify viruses on the abnormal files in the virtualization system; observe the files in the target virtual server for a certain period of time, and when the target virtual server is running, if the file library has not changed and the target input data has not undergone abnormal operations after being called, then the file library will be added to the file whitelist, the monitoring of the target virtual server will be stopped, and the target virtual server will be restored to normal use.
7. The system according to claim 6, characterized in that It also includes a resource calling unit, which includes a flow restriction module; the active defense unit also includes a data monitoring module; wherein, The data monitoring module is used to monitor the dynamic operation data in real time, obtain monitoring results, and feed the monitoring results back to the flow restriction module; The traffic limiting module is used to determine a target output data threshold of the target virtual server.
8. An active defense device, characterized in that: include: A data perception module, configured to obtain target input data and detect the type of the target input data; inputting the target input data into a target virtual server application layer corresponding to the target input data type, so that the target virtual server application layer calls the target input data to generate dynamic operation data, wherein the target input data type includes one or more of a system file, a text file, a data file, a response file, a static file, a parameter, and an execution command file; a data disguise module, configured to filter the dynamic operation data and the target input data to obtain data exhibiting abnormalities to obtain redundant disguised data, and store the redundant disguised data and the target input data in a file library established by the data disguise module in the target virtual server; a data capture module, configured to detect abnormal files in the redundant disguised data in the file library, and store the abnormal files in a separately divided virtualization system in the cloud virtual platform to isolate them from other virtual servers; as well as A data identification module is used to identify viruses on the abnormal files in the virtualization system; observe the files in the target virtual server for a certain period of time, and when the target virtual server is running, if the file library has not changed and the target input data has not undergone abnormal operations after being called, then the file library will be added to the file whitelist, the monitoring of the target virtual server will be stopped, and the target virtual server will be restored to normal use.
9. A computer device, characterized in that: Includes processor, memory, input and output interfaces; The processor is connected to the memory and the input / output interface respectively, wherein the input / output interface is used to receive and output data, the memory is used to store a computer program, and the processor is used to call the computer program so that the computer device executes the method according to any one of claims 1 to 5.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which is suitable for being loaded and executed by a processor, so that a computer device having the processor executes the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Activity-based virtual machine availability in a networked computing environment
CN103259742A