Information security system and method for processing information security data
By employing edge-based log collection and cache snapshotting, the system addresses the inefficiency of over-sampling in CDN systems by focusing on relevant security data, reducing processing volume and costs while enhancing precision.
Patent Information
- Application Number
- CN202210983071.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-16
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-08-16
AI Technical Summary
Traditional information security data acquisition methods have excessive collection, resulting in low processing efficiency.
By deploying the log acquisition module and cached data acquisition module at the edge nodes and cache nodes of the content distribution network, information security data is obtained, and data analysis and processing modules are used to summarize, merge and associate, reducing the processing amount of original data.
It realizes full coverage collection of information security data, reduces the processing volume of CDN raw data, saves resources, and reduces the construction cost and operational overhead of the information security system.
Smart Images

Figure CN115333843B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of emerging information technologies, and more particularly, to an information security system and a method for processing information security data. Background Art
[0002] In traditional IDC / ISP information security management systems, the implementation process of information security data collection methods (hereinafter referred to as the information security data collection method based on optical splitting and DPI) is as follows: 1. Deploy a traffic splitting device on the network egress device side of each CDN service node to obtain all CDN service data packets; 2. Through deep packet inspection DPI, retrieve and filter out information security basic data from the split all-service traffic, and then report it to the CDN information security system control center.
[0003] Since in the CDN all-service traffic, the vast majority of the traffic is user service traffic such as CDN-accelerated video streams, files, and pictures, in order to filter and obtain information security basic data from it, it is necessary to perform optical splitting and deep packet inspection on all-service traffic. Since the ratio of all-service traffic data to basic information security data is 1000:3 or even lower, the traditional information security data collection method has serious over-collection, low processing efficiency, and low input-output ratio.
[0004] In response to the above problems, no effective solution has been proposed yet. Summary of the Invention
[0005] Embodiments of this application provide an information security system and a method for processing information security data to at least solve the technical problem that the traditional information security data collection method has over-collection, resulting in low processing efficiency.
[0006] According to one aspect of the embodiments of this application, an information security system is provided, including: a log collection module, a cache data collection module, a data analysis and processing module, and a control module. Among them, the log collection module is deployed on the edge nodes of the content delivery network and is used to obtain information security data from the logs of the edge nodes; the cache data collection module is set on the cache nodes of the content delivery network and is used to take a snapshot of the cache data on the cache nodes at any time and obtain information security data from the cache data; the data analysis and processing module is used to forward the information security data obtained by the log collection module and the cache data collection module to the control module, and forward the interception instructions sent by the control module to the log collection module and the cache data collection module, where the interception instructions are used to intercept target type data in the information security data; the control module is at least used to send interception instructions to the data analysis and processing module.
[0007] Optionally, when the log collection module obtains information security data from the logs of the edge nodes, it is implemented in the following manner: obtaining the service logs from the edge nodes through the network file transfer protocol; converting the information in the service logs into the target format, and filtering the service logs converted into the target format to obtain the information security data.
[0008] Optionally, the log collection module is also used to support the following data merging methods: merging by timestamp, merging by source IP address, merging by domain name, and merging by the IP address of the edge node.
[0009] Optionally, when the log collection module receives the interception instruction issued by the data analysis and processing module, it distributes the interception instruction to the edge nodes. The log collection module supports the following interception methods: interception by the IP address of the edge node, interception by domain name, interception by request URL, and interception by source IP address.
[0010] Optionally, the cache data collection module supports taking snapshots in one of the following ways: supporting a global full-volume data snapshot, supporting an incremental data snapshot based on querying any time period, supporting a user-based data snapshot, supporting a domain name-based data snapshot, supporting a source IP address-based data snapshot, and supporting an edge node IP address-based data snapshot.
[0011] Optionally, the cache data collection module is also used to support the following data filtering methods: filtering by timestamp, filtering by source IP address, filtering by domain name, and filtering by the IP address of the edge node.
[0012] Optionally, when the cache data collection module receives the interception instruction issued by the data analysis and processing module, it distributes the interception instruction to the cache nodes. The cache data collection module supports the following interception methods: intercepting the node corresponding to the domain name by domain name, intercepting the node corresponding to the URL by request URL, and intercepting the node corresponding to the source IP address.
[0013] Optionally, before forwarding the information security data to the control module, the data analysis and processing module is also used to: summarize the information security data in the target format; classify the summarized information security data according to data type and event type; associate the data in the information security data that belongs to the same domain name, the same customer name, and the same service request to obtain the target information security data.
[0014] Optionally, the data analysis and processing module forwards the interception instruction issued by the control module to the log collection module and the cache data collection module in the following manner: receiving the interception instruction issued by the control module; retrieving the target nodes involved in the interception instruction, where the target nodes include at least one of the following: edge nodes and cache nodes; forwarding the target nodes to the corresponding nodes of the log collection module and the cache data collection module.
[0015] Optionally, the data analysis and processing module is further configured to receive the feedback results of the log collection module and the cache data collection module, where the feedback result is the result of the target node executing the interception instruction, and the feedback result includes the remaining data after the target node executes the interception instruction.
[0016] According to another aspect of the embodiments of the present application, a method for processing information security data is further provided, including: obtaining information security data from the cache spaces of the edge nodes and cache nodes of the content delivery network; sending the information security data to the control center device; receiving the interception instruction issued by the control center device based on the information security data, where the interception instruction is used to intercept the target type data in the information security data; determining the target nodes involved in the interception instruction, where the target nodes include at least one of the following: cache nodes and edge nodes; notifying the target nodes to execute the interception instruction, and receiving the data after the target nodes execute the interception instruction.
[0017] Optionally, sending the information security data to the control center device includes: summarizing the information security data in the target format, associating the information security data belonging to the same domain name, the same customer name, and the same service request to obtain the target information security data; sending the target information security data to the control center device.
[0018] In the embodiments of the present application, by collecting the CDN logs of the edge nodes and the cache data of the cache nodes in the CDN system, the CDN information security data is obtained therefrom. After the cache data obtained from the cache and the information security data obtained from the CDN logs are integrated, a full coverage of the information security data of the CDN system can be formed. After the collection end collects the information security data, it is uniformly sent to the data analysis and processing module. The data analysis and processing module summarizes, merges, and associates the information security data, and then sends it to the control module of the CDN information security system, achieving the purpose of reducing the processing amount of the CDN original data, thus realizing the technical effect of saving resources, and further solving the technical problem that the traditional information security data collection method has excessive collection, resulting in low processing efficiency. Description of the Drawings
[0019] The accompanying drawings described herein are used to provide a further understanding of the present application, and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0020] Figure 1 is a schematic diagram of a method for collecting traditional information security data according to an embodiment of the present application;
[0021] Figure 2 is a structural diagram of an information security system according to an embodiment of the present application;
[0022] Figure 3a is a schematic diagram of a method for collecting information security data based on CDN caching and logs according to an embodiment of the present application;
[0023] Figure 3b is a schematic diagram of the functional structure of a log collection module according to an embodiment of the present application;
[0024] Figure 3c is a schematic diagram of the functional structure of a cached data collection module according to an embodiment of the present application;
[0025] Figure 3d is a schematic diagram of the functional structure of a data analysis and processing module according to an embodiment of the present application;
[0026] Figure 4 is a schematic diagram of a CDN information security data collection mode with a distributed architecture in a live network environment according to an embodiment of the present application;
[0027] Figure 5 is a flowchart of a method for processing information security data according to an embodiment of the present application. Detailed implementation manners
[0028] In order to enable those skilled in the art to better understand the solutions of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0029] It should be noted that the terms "first", "second", etc. in the specification, claims and above-mentioned drawings of this application are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0030] Since CDN uses global caching acceleration of content (such as a region or country, etc.) to achieve dynamic distribution, it makes it difficult to trace and locate, and it is difficult to monitor and handle abnormal information. The existing technical means of IDC / ISP information security management systems cannot cover CDN services.
[0031] The CDN information security management system built by CDN service operators should have functions such as basic data management, information security management, access log management, and service status monitoring to meet the information security management needs of CDN service operators and management departments.
[0032] The main functional requirements of the CDN information security management system are as follows:
[0033] 1) Basic data management
[0034] Local management of basic data: includes business unit information, customer information, node information, accelerated domain name service information, etc.
[0035] Reporting and verification of basic data: After proofreading and verifying basic data such as business unit information and customer information, the updated information will be automatically reported to the information management system (the updated data will be reported to the information management system within 10 minutes after the basic data is updated).
[0036] Query of basic data: It can respond to the basic data query instructions issued by the superior management department, retrieve the local records and report the relevant information.
[0037] 2) Monitoring of active resources: Conduct full-scale monitoring of the data links that provide public information services in the CDN network, and form service status monitoring records and report them to the superior management department daily.
[0038] 3) Information security management: The system can accept the abnormal website list and abnormal information monitoring / filtering instructions issued by the superior management department, generate corresponding abnormal network and information monitoring / filtering records (locally) for the effective instructions, and report them to the superior management department in real time or regularly (not exceeding 2 hours).
[0039] 4) Access log management: Based on the successful access behavior of external access users to the Internet content accelerated by CDN, the system completely records and statistically analyzes the access information to form an access log. When meeting the conditions of the query instructions issued by the information security system, report according to the requirements (the relevant access log should be effectively queryable within 2 hours after the user access behavior occurs).
[0040] Figure 1 It is a schematic diagram of a method for collecting traditional information security data according to an embodiment of the present application. As Figure 1 shown, the traditional method is a bandwidth coverage method. An optical splitter is deployed on the network export side of each CDN service node. Among them, the CDN service node at least includes a CDN cache relay node and a CDN edge node to obtain all CDN service data, including service traffic data, information security data, etc. Through deep packet inspection (DPI), retrieve and filter out the information security basic data (hereinafter referred to as information security data) from the shunted all-service traffic, and then report it to the CDN information security system. Among them, the information security data only accounts for 0.3% of the all data. The CDN information security system uniformly stores the information security data. After format translation, it is reported to the CDN information security supervision system. The CDN information security system receives the blocking / detection instructions issued by the superior management department. The information security system extracts the urls or domain names and keywords that need to be blocked / monitored, translates the instructions, queries the involved CDN nodes, and issues a blocking policy to the corresponding egress switch. After the egress switch of the involved CDN node executes the instruction, it returns the execution result to the information security system. However, the disadvantage of the traditional method is that in the all-service traffic, a large amount is service traffic such as video streams, files, and pictures. To filter and obtain the information security data from it, it is necessary to perform optical splitting and deep packet inspection on the all-service traffic, and the input-output ratio is not high.
[0041] According to the requirements of information management, when building the supporting information security for a multi-node, large-capacity (the whole network distribution capacity exceeds Tbps or even 10 Tbps) CDN system, the construction cost of using traditional information security data collection means will increase sharply with the growth of the scale and number of nodes of the CDN system. How to effectively reduce the overall construction cost of the CDN information security system while meeting the CDN compliance supervision requirements is a practical problem in the operation of CDN service providers. To solve the above problems, the embodiments of the present application provide corresponding solutions, which are described in detail below.
[0042] Figure 2 It is a structural diagram of an information security system according to an embodiment of the present application. As Figure 2As shown in the figure, the system includes: a log collection module 202, a cached data collection module 204, a data analysis and processing module 206, and a control module 208. Among them, the log collection module is deployed on the edge nodes of the content delivery network and is used to obtain information security data from the logs of the edge nodes; the cached data collection module is set on the cache nodes of the content delivery network and is used to take a snapshot of the cached data on the cache nodes at any time and obtain information security data from the cached data; the data analysis and processing module is used to forward the information security data obtained by the log collection module and the cached data collection module to the control module, and forward the interception instructions issued by the control module to the log collection module and the cached data collection module, where the interception instructions are used to intercept the target type data in the information security data; the control module is at least used to send interception instructions to the data analysis and processing module.
[0043] In the embodiment of the present application, for example, it can be implemented through Figure 3a the schematic diagram of the information security data collection method based on CDN cache and log shown in the figure. The CDN log collection module is deployed on each edge node of the CDN content, supports distribution, and obtains the original service logs from the CDN nodes through adapting to the log API interface of the CDN system or through network file transfer protocols such as ftp, ftps, rsync, and nfs, and then performs format translation and filtering to obtain the original information security data.
[0044] The cached data collection module is a supplement to the information of the log collection module. The cached data collection module is deployed on the first-level cache and second-level cache nodes of the CDN system, supports distribution, and through adapting to the cache class API interface of the CDN system, the cached data collection module can take a snapshot of the basic information on the CDN system cache nodes at a certain moment and obtain information security data from it. Although the business data (such as video streams, pictures, files, etc.) in the cache is updated very frequently, the change of information security data (such as domain names, urls, ips, etc.) is much less frequent. Snapshots at fixed intervals (such as 30 seconds) can basically keep the information of the information security system synchronized with the CDN live network. By adjusting the collection frequency and interval of the collection module, the balance can also be maintained between the real-time performance of information security data collection and the additional system overhead of the collection module.
[0045] After the above two modules respectively obtain the original information security data, they process the data into information security data in the target format and report it to the information security data analysis and processing module; the information security data analysis and processing module is in a centralized deployment mode, responsible for data aggregation, merging, and association, and then reports the data to the CDN information security system control center through the API method. This control center is equivalent to the control module in the embodiment of the present application. The latter further performs subsequent operation processing (such as data reporting, warning of bad information, issuing domain name blocking instructions, etc.).
[0046] In the above information security system, when the log collection module obtains information security data from the logs of edge nodes, it is implemented in the following manner: obtaining service logs from edge nodes through the network file transfer protocol; converting the information in the service logs into a target format, and filtering the service logs converted into the target format to obtain information security data.
[0047] In the above information security system, the log collection module is also used to support the following data merging methods: merging by timestamp, merging by source IP address, merging by domain name, and merging by the IP address of the edge node.
[0048] In the above information security system, when the log collection module receives an interception instruction issued by the data analysis and processing module, it distributes the interception instruction to the edge node. The log collection module supports the following interception methods: interception by the IP address of the edge node, interception by domain name, interception by request URL, and interception by source IP address.
[0049] In the embodiment of the present application, the log collection module can be as Figure 3b shown in the schematic diagram. In Figure 3b the CDN log collection module mainly implements the following functions: log reading, format translation, data filtering and merging, and executing the blocking and disposal instruction, which can also be called the interception instruction.
[0050] 1) Log reading
[0051] Support directly reading the content items in the CDN original service log file through the API log interface adapted to the CDN system;
[0052] Support obtaining the CDN original service log file from the CDN edge node through network file transfer protocols such as ftp, ftps, rsync, and nfs.
[0053] 2) Format translation: If the original log file is obtained through the network file transfer protocol, it is necessary to further translate the format of the log file and filter and screen out the entries containing CDN information security basic information from it.
[0054] In the actual CDN integration scenario, the original CDN service log formats of each CDN operator are different. Through format translation, the information in the log file is uniformly arranged into the following format:
[0055] Log field Field meaning $remote_addr Client IP $remote_user Username of HTTP Auth $time_local Access time $request_method Access type GET $scheme Application protocol $http_host Accessed domain name $uri Requested URI $querystring Request parameters $server_protocol HTTP protocol version $status Return status code $bodybytessent Bytes sent in the body $http_referer Request source referrer $httpuseragent Client information $content_type Content type $requestcontentlength Content size of the client's request to the server $cache_hit Whether CDN cache hit $source_code Origin server return status code $is_dynamic Whether it is a dynamic request $cache_control Cache control header information $request_time Request processing time consumption $edgeserverip CDN edge node IP
[0056] 3) Data filtering and merging: For each user access record in the above information, an information security data message containing preset requirements will be generated. The preset requirements are to meet the requirements of the superior management department. However, there are a large number of duplicate messages among them. Exceptions to be considered include: abnormal user clients that send a large number of duplicate requests and repeat accesses at different times; repeated information transmission caused by network jitter between internal nodes of the CDN; access failure requests when the CDN system is under abnormal network attacks; other worthless information, etc., such as other information that is irrelevant or worthless to the CDN information security data. In addition, in the current log data, in addition to the basic information security data, there is also a large amount of auxiliary information that is not related to information security and needs to be filtered.
[0057] For the above reasons, it is necessary to further filter and merge the data to remove duplicates. The CDN log collection module needs to support the following functions: support merging by timestamp; support merging by source IP; support merging by domain name; support merging by node IP.
[0058] After the data filtering and merging are completed, it can be further reduced to the following format and the duplicate records are removed:
[0059]
[0060]
[0061] 4) Execute the blocking instruction or interception instruction: After receiving the blocking instruction issued by the CDN information security system, notify the edge node to execute as required, which is achieved by calling the CDN cache class API. Specifically, the log collection module can support blocking by edge node IP; support blocking by domain name; support blocking by url and support blocking by source ip.
[0062] In the above information security system, the cache data collection module supports taking snapshots in one of the following ways: support global full - volume data snapshots; support incremental data snapshots based on querying any time period; support user - based data snapshots; support domain - name - based data snapshots; support source - IP - address - based data snapshots and support edge - node - IP - address - based data snapshots.
[0063] In the above information security system, the cache data collection module is also used to support the following data filtering methods: filtering by timestamp; filtering by source IP address; filtering by domain name and filtering by edge - node IP address.
[0064] In the above information security system, when the cache data collection module receives an interception instruction issued by the data analysis and processing module, it distributes the interception instruction to the cache nodes. The cache data collection module supports the following interception methods: intercepting the nodes corresponding to a domain name by domain name, intercepting the nodes corresponding to a request URL by request URL, and intercepting the nodes corresponding to the source IP address.
[0065] In the embodiment of the present application, since there is a synchronization time difference between the cache information and the information already stored in the CDN service log, directly collecting the cache node data can be used as an effective supplement to the CDN service log information. By adapting to the cache class API interface of the CDN system, the cache data collection module can perform snapshot collection on the cache data on the CDN system cache nodes at a certain moment, and obtain information security data therefrom.
[0066] The cache data collection module can also be called the cache information collection module. The cache information collection module can be as Figure 3c shown in the schematic diagram, as Figure 3c shown, the main functions of the cache data collection module are as follows: snapshot collection, data filtering, and executing the blocking disposal instruction (also called the interception instruction).
[0067] 1) Snapshot collection: By adapting to the cache class API interface of the CDN system, take snapshots of the content items related to information security data in the CDN cache nodes and CDN edge nodes, and then collect the information security data in the cache. The cache information collection module supports the following snapshot methods: supporting global full-volume data snapshots; supporting incremental data snapshots based on querying a certain time period; supporting user-based data snapshots; supporting domain name-based data snapshots; supporting source IP-based data snapshots; supporting edge node IP-based data snapshots.
[0068] 2) Data filtering: For multiple snapshots of the cache nodes, there will be a large amount of duplicate data, and data filtering and deduplication are required. The cache information collection module supports the following filtering methods: supporting filtering by timestamp; supporting user-based data filtering; supporting source IP-based data filtering; supporting domain name-based data filtering; supporting edge node IP-based data filtering.
[0069] 3) Executing the blocking instruction: After receiving the blocking instruction issued by the superior, notify the cache node to execute as required, and implement it by calling the CDN cache class API. Specifically, the cache data collection module supports the following methods to execute the blocking instruction: supporting single-node domain name-based blocking, supporting single-node URL-based blocking, supporting single-node source IP-based blocking, supporting global domain name-based blocking, querying all the transit nodes and edge nodes involved in the domain name, and issuing the blocking instruction.
[0070] In the above information security system, before forwarding the information security data to the control module, the data analysis and processing module is further configured to: summarize the information security data in a target format; classify the summarized information security data according to data types and event types; associate the data in the information security data that belongs to the same domain name, the same customer name, and the same service request to obtain target information security data.
[0071] In the above information security system, the data analysis and processing module forwards the interception instructions issued by the control module to the log collection module and the cache data collection module in the following manner: receive the interception instructions issued by the control module; retrieve the target nodes involved in the interception instructions, where the target nodes include at least one of the following: edge nodes and cache nodes; forward the target nodes to the corresponding nodes of the log collection module and the cache data collection module.
[0072] In the above information security system, the data analysis and processing module is further configured to receive the feedback results of the log collection module and the cache data collection module, where the feedback results are the results of the target nodes executing the interception instructions, and the feedback results include the remaining data after the target nodes execute the interception instructions.
[0073] In the embodiments of the present application, the main functions of the data analysis and processing module are: summarization, merging, and association of information security basic data, receiving blocking instructions, retrieving the involved nodes, and issuing instructions accordingly. Specifically, this module can be as Figure 3d shown in the schematic diagram, and the functions of the data analysis and processing module are explained through Figure 3d the following.
[0074] 1) Data summarization: Summarize the information security data collected by each CDN log collection module and cache information collection module in a unified format and store it in the database.
[0075] 2) Data merging: Tag and classify the information security data according to data types and event types.
[0076] 3) Data association: Associate the information security data from different nodes according to domain names, customer names, and service requests, which is convenient for the CDN information security system control center to verify, monitor, and manage the information security data.
[0077] 4) Receive and issue blocking instructions: Receive the blocking instructions issued by the CDN information security management system, retrieve the nodes involved in the blocking instructions, notify each node to execute the blocking instructions respectively, and receive the feedback of the execution results of each node.
[0078] In the embodiments of the present application, by collecting CDN logs of the edge nodes of the CDN system and cache data of the cache nodes, and then performing data analysis and processing, CDN information security data is obtained therefrom. In the CDN service system, the information security data will be distributed in the CDN service logs and CDN caches. The embodiments of the present application are divided into a data collection end and a data processing end. Among them, the information security basic data collection end is further divided into a CDN log collection module and a cache data collection module according to the location and mechanism of the collection points, so as to achieve real-time coverage of the information security data of the CDN system.
[0079] The CDN log collection module deployed on each CDN edge node side is responsible for collecting CDN service logs on the edge nodes, and performing format translation and filtering to obtain the information security data on the edge node. In addition to the CDN service logs, there will be hot data in the cache of the CDN system that has not been written into the logs. Therefore, the cache data collection module deployed on the first-level and second-level cache nodes of the CDN system is responsible for interacting with the CDN system cache in real time to collect the information security data in the cache. After integrating the information security data obtained from the cache with the information security data obtained from the CDN logs, a full coverage of the information security data of the CDN system can be formed. After the collection end collects the information security basic data, it is uniformly sent to the information security data analysis and processing module, and the latter summarizes, merges, and correlates the information security data, and then sends it to the CDN information security system control center.
[0080] Compared with the traditional information security data collection methods based on optical splitting and DPI, the amount of original data (CDN service logs) to be processed in the embodiments of the present application is reduced by more than 99% compared with the traditional methods (full-service traffic, including videos, large files, pictures, etc.). The principle is that the volume of CDN logs generated per unit time is about 1% of the CDN full-service traffic. The traditional methods need to filter, screen, and process the full-service traffic, while the present application only needs to filter, screen, and process the CDN service logs. After shielding a large amount of service traffic, the processing volume of the overall information security system for the original data of the CDN service platform can be greatly reduced.
[0081] In terms of the construction cost of the information security system, the present application (log coverage mode) has less overhead on system resources and hardware resources than the traditional information security methods. Each information security server hardware can process the information security data filtering of 100G - 200G (depending on different user application types) of CDN service traffic, thus greatly saving the construction cost of the CDN information security platform at the collection end. The comparison of the construction costs is as follows:
[0082]
[0083] In addition, when implementing the information security blocking instruction, the present application can accurately locate the involved server. Compared with the traditional method that can only be accurate to the involved physical computer room, the present application is more friendly to the current network operation of the CDN platform.
[0084] In the production environment of the existing network CDN system, as Figure 4 shown in the schematic diagram of the CDN information security data collection mode in the existing network environment of the distributed architecture. Figure 4 Taking Shanghai and Zhejiang as examples, the overall CDN system is a multi-level architecture (transfer nodes, edge nodes), and is usually distributed. The CDN nodes are located in multiple physical computer rooms, and the CDN nodes communicate with each other through the Internet. In addition, with the business development needs of CDN operators, the CDN system is basically a fusion architecture, that is, the self-built platform needs to be integrated with the platforms of other CDN operators, and they are mutually adapted and coordinated in terms of main functions (content distribution, content preheating, etc.), billing, and information security, and the overall business distribution is realized for customers. Under the fusion architecture, the physical architectures, system implementation methods, log formats, etc. of each CDN operator will be different.
[0085] In the process of implementing information security coverage, it is first necessary to deploy a CDN log collection module on the side of each CDN edge node. For CDN platforms with different manufacturers and heterogeneous physical architectures, the CDN logs can be obtained by customizing this module, through the log API, or through network file transfer protocols allowed to be opened by each platform, such as ftp, ftps, rsync, nfs, etc.
[0086] The original CDN logs from different sources may still have inconsistent data formats. Therefore, the CDN log collection module also needs to translate the information security data from different sources into a unified data format, and then further report it to the CDN information security management system, and the latter stores the data uniformly.
[0087] The CDN log collection module supports distributed deployment. The relationship between this module and its associated CDN nodes (edge nodes or transfer nodes) can be 1:1 or 1:N, and it supports 1 module to collect the logs of multiple CDN nodes (the same standard) at the same time. In this mode, the overall CDN information security system can be infinitely expanded as the business distribution ability of the CDN business system expands, without the ability limitation in information security management.
[0088] The cache data collection module is deployed 1:1 with each transfer node, without geographical restrictions and without increasing the load of the network egress device traffic.
[0089] When receiving the abnormal website blocking instruction, the information security log analysis module first receives the instruction forwarded from the CDN information security control center. After retrieving all the involved nodes, the instruction is separately sent to the CDN log collection module and the cache data collection module, which are the final execution terminals. This mode can further issue the abnormal website disposal instruction to the CDN service system through the API interface adapted to the CDN service system, thus accelerating the disposal speed, removing unnecessary manual review and configuration links, and improving the disposal speed.
[0090] Figure 5 It is a flowchart of a method for processing information security data according to an embodiment of the present application, as Figure 5 shown, the method includes:
[0091] Step S502, obtaining information security data from the cache spaces of the edge nodes and cache nodes of the content delivery network;
[0092] Step S504, sending the information security data to the control center device;
[0093] Step S506, receiving the interception instruction issued by the control center device according to the information security data, where the interception instruction is used to intercept the target type data in the information security data;
[0094] Step S508, determining the target nodes involved in the interception instruction, where the target nodes include at least one of the following: cache nodes and edge nodes;
[0095] Step S510, notifying the target nodes to execute the interception instruction and receiving the data after the target nodes execute the interception instruction.
[0096] In step S504 of the above method for processing information security data, sending the information security data to the control center device specifically includes the following steps: After summarizing the information security data in the target format, associating the information security data belonging to the same domain name, the same customer name, and the same service request to obtain the target information security data; sending the target information security data to the control center device.
[0097] It should be noted that Figure 5 the method for processing information security data shown can be applied to Figure 2 the information security system shown, so the relevant explanations in the above information security system also apply to this method for processing information security data, and will not be repeated here.
[0098] The serial numbers of the embodiments of the present application above are only for description and do not represent the advantages or disadvantages of the embodiments.
[0099] In the above embodiments of the present application, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0100] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.
[0101] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0102] In addition, in each embodiment of the present application, the functional units can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0103] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs and other various media that can store program codes.
[0104] The above are only the preferred embodiments of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.
Claims
1. An information security system, characterized in that, Including: A log collection module, a cache data collection module, a data analysis and processing module, and a control module. Among them, The log collection module is deployed on the edge nodes of the content delivery network and is used to obtain information security data from the logs of the edge nodes; The cache data collection module is set on the cache nodes of the content delivery network and is used to take a snapshot of the cache data on the cache nodes at any time and obtain information security data from the cache data; The data analysis and processing module is used to forward the information security data obtained by the log collection module and the cache data collection module to the control module, and forward the interception instructions issued by the control module to the log collection module and the cache data collection module. Among them, the interception instructions are used to intercept the target type data in the information security data; The control module is at least used to send the interception instructions to the data analysis and processing module; Among them, before the data analysis and processing module forwards the information security data to the control module, the data analysis and processing module is also used to: summarize the information security data in a target format; classify the summarized information security data according to data types and event types; associate the data in the information security data that belongs to the same domain name, the same customer name, and the same business request to obtain target information security data.
2. The system according to claim 1, wherein When the log collection module obtains information security data from the logs of the edge nodes, it is implemented in the following ways: Obtain business logs from the edge nodes through the network file transfer protocol; Convert the information in the business logs into a target format, and filter the business logs converted into the target format to obtain the information security data.
3. The system according to claim 2, wherein The log collection module is also used to support the following data merging methods: merging by timestamp, merging by source IP address, merging by domain name, and merging by the IP address of the edge node.
4. The system according to claim 3, wherein When the log collection module receives the interception instructions issued by the data analysis and processing module, it distributes the interception instructions to the edge nodes. The log collection module supports the following interception methods: interception by the IP address of the edge node, interception by the domain name, interception by the request URL, and interception by the source IP address.
5. The system according to claim 1, wherein The cache data collection module supports one of the following methods for taking snapshots: supporting a global full-volume data snapshot, supporting an incremental data snapshot based on querying any time period, supporting a user-based data snapshot, supporting a domain name-based data snapshot, supporting a source IP address-based data snapshot, and supporting an edge node IP address-based data snapshot.
6. The system according to claim 1, wherein The cache data collection module is also used to support the following data filtering methods: filtering by timestamp, filtering by source IP address, filtering by domain name, and filtering by the IP address of the edge node.
7. The system according to claim 6, wherein When the cache data collection module receives the interception instruction sent by the data analysis and processing module, it distributes the interception instruction to the cache nodes. The cache data collection module supports the following interception methods: intercepting the nodes corresponding to a domain name by the domain name, intercepting the nodes corresponding to a request URL by the request URL, and intercepting the nodes corresponding to the source IP address.
8. The system according to claim 1, characterized in that The data analysis and processing module forwards the interception instruction sent by the control module to the log collection module and the cache data collection module in the following manner: Receiving the interception instruction sent by the control module; Retrieving the target nodes involved in the interception instruction, where the target nodes include at least one of the following: the edge nodes and the cache nodes; Forwarding the target nodes to the corresponding nodes of the log collection module and the cache data collection module.
9. The system according to claim 8, wherein The data analysis and processing module is further configured to receive the feedback results of the log collection module and the cache data collection module, where the feedback result is the result of the target nodes executing the interception instruction, and the feedback result includes the remaining data after the target nodes execute the interception instruction.
10. A method for processing information security data, characterized in that, Including: Obtaining information security data from the cache spaces of the edge nodes and cache nodes of the content delivery network; Sending the information security data to the control center device; Receiving the interception instruction sent by the control center device based on the information security data, where the interception instruction is used to intercept the target type data in the information security data; Determining the target nodes involved in the interception instruction, where the target nodes include at least one of the following: the cache nodes and the edge nodes; Informing the target nodes to execute the interception instruction and receiving the data after the target nodes execute the interception instruction; Among them, sending the information security data to the control center device includes: after summarizing the information security data in a target format, correlating the information security data belonging to the same domain name, the same customer name, and the same service request to obtain target information security data; sending the target information security data to the control center device.
Citation Information
Patent Citations
CDN monitoring system and method
CN107707414A
Web crawler interception method and device, electronic equipment and readable storage medium
CN114036360A