A network security protection architecture, a communication method and device, and a communication equipment
By introducing a security management architecture that combines physical devices and virtualized network functions into 5G networks, the network can perform self-detection and handling, solving the problem of existing technologies being unable to identify network element anomalies and resist advanced threats, thus improving the network's security protection capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA MOBILE COMM LTD RES INST
- Filing Date
- 2021-05-17
- Publication Date
- 2026-04-14
AI Technical Summary
The existing 5G network security protection architecture cannot effectively identify abnormal processes and files in network elements, cannot resist advanced persistent threats, and cannot meet the differentiated security needs of vertical industries.
It adopts a network security protection architecture that includes physical devices, virtualized network functions, and a security management center, and achieves self-detection and handling through integrity measurement, anomaly detection, and security policy analysis.
It enhances the network's own security protection capabilities, possesses self-immunity and self-recovery characteristics, and can effectively cope with new security threats to 5G networks.
Smart Images

Figure CN115378618B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, specifically to a network security protection architecture, communication method and apparatus, and communication equipment. Background Technology
[0002] With the development of mobile internet, operators are using technologies such as Network Functions Virtualization (NFV), Software Defined Networking (SDN), and cloud computing to virtualize, cloudify, and SDN their networks. 5G adopts a service-oriented architecture and supports network slicing and edge computing, making it more suitable for deployment via virtualization and cloudification, enabling rapid and flexible deployment and improving operational efficiency. Currently, operators' network cloudification transformation projects are underway. Control plane network elements of the 5G Standalone (SA) core network, such as Network Exposure Function (NEF), Access and Mobility Management Function (AMF), Session Management Function (SMF), and Network Data Analytics Function (NWDAF), have already been deployed using NFV and can be flexibly scaled up or down according to service needs.
[0003] In this architecture, the control plane network elements of 5G SA are deployed on virtual machines. This exposes the 5G network to not only traditional security threats but also those related to new technologies like SDN / NFV, such as SDN controller distributed denial-of-service (DDoS) attacks, flow table tampering, exploitation of virtualization software vulnerabilities, and virtual machine escape. Furthermore, edge computing and slicing increase the exposure surface of the 5G network, allowing third-party applications (APPs) to launch attacks on the core network and enabling unauthorized access to slice management interfaces. The threat of quantum computing to traditional cryptographic algorithms and potential new attack methods also present new challenges for 5G.
[0004] At present, the boundary protection and security hardening of individual devices built by statically deployed security devices cannot fully meet the security requirements of 5G and have the following shortcomings: (1) Abnormal processes and abnormal files of network elements cannot be identified in a timely manner; (2) The detection method based on known features cannot resist new attacks such as advanced persistent threats (APT); (3) The support for the differentiated security needs of vertical industries is not good. Summary of the Invention
[0005] To address the existing technical problems, embodiments of the present invention provide a network security protection architecture, a communication method and apparatus, and a communication device.
[0006] To achieve the above objectives, the technical solution of this invention is implemented as follows:
[0007] In a first aspect, embodiments of the present invention provide a network security protection architecture, which includes: a first processing layer containing physical devices, a second processing layer containing multiple virtualized network functions, and a third processing layer;
[0008] The first processing layer also includes a security component for performing integrity measurement on the physical device and sending the integrity measurement result to the third processing layer;
[0009] Each virtualized network function in the second processing layer is used to perform anomaly detection and send the anomaly detection result to the third processing layer;
[0010] The third processing layer includes a security management center, which analyzes the integrity measurement results sent by the first processing layer and / or the anomaly detection results sent by the second processing layer, and determines the processing strategy based on the analysis results.
[0011] In the above scheme, the second processing layer includes: management and orchestration components;
[0012] The management and orchestration components include: a Network Functions Virtualization Orchestrator (NFVO), a Virtualized Network Function Manager (VNFM), a Virtualized Infrastructure Manager (VIM), and a Software Defined Network (SDN) controller, each with anomaly detection capabilities; wherein,
[0013] The SDN controller is used to send its own anomaly detection results to the VIM;
[0014] The VIM is used to send the anomaly detection results controlled by the SDN and / or its own anomaly detection results to the NFVO;
[0015] The VNFM is used to send its own anomaly detection results to the NFVO;
[0016] The NFVO is used to send at least one of the anomaly detection results sent by the VIM, the anomaly detection results sent by the VNFM, and its own anomaly detection results to the security management center.
[0017] In the above scheme, the second processing layer also includes a virtual layer with anomaly detection function;
[0018] The security component of the first processing layer is used to send the integrity measurement result to the virtual layer;
[0019] The virtual layer is used to send the integrity measurement result sent by the security component of the first processing layer and / or its own anomaly detection result to the VIM;
[0020] The VIM is also used to send the integrity measurement result and / or the anomaly detection result of the virtual layer to the NFVO;
[0021] The NFVO is also used to send the integrity measurement results and / or the anomaly detection results of the virtual layer to the security management center.
[0022] In the above scheme, the second processing layer includes: a virtualized network function and an operation and maintenance component, each with anomaly detection capabilities;
[0023] The virtualized network function is used to send its own anomaly detection results to the operation and maintenance component;
[0024] The operation and maintenance component is used to send the behavior detection results of the virtualized network function and / or its own behavior detection results to the security management center.
[0025] In the above scheme, the security management center is also used to send processing policies related to virtualization network functions to the operation and maintenance component.
[0026] In the above scheme, the second processing layer further includes a security device for recording security logs and sending the security logs to the third processing layer.
[0027] In the above scheme, the second processing layer includes: a virtualized security device and a security control component, which are respectively equipped with the functions of recording security logs and reporting security logs;
[0028] The virtualized security device is used to send security logs to the security control component;
[0029] The security control component is used to send the security logs of the virtualized security device to the security management center.
[0030] In the above scheme, the second processing layer further includes a physical security device for recording security logs and sending the security logs to the security control component;
[0031] The security control component is also used to send the security logs of the physical security device to the security management center.
[0032] In the above scheme, the security management center is also used to send security policy-related processing policies to the security control component.
[0033] In the above scheme, the security control component is further configured to convert the processing policy into a security policy and send the security policy to the corresponding virtualized security device and / or physical security device.
[0034] In the above scheme, the second processing layer includes: a virtualized network function with anomaly detection capability, the virtualized network function including a virtualized network exposure function (NEF), the virtualized NEF supporting the calling of the interface of the security control component to realize communication between the virtualized NEF and the security control component;
[0035] The second processing layer further includes: management and orchestration components; the management and orchestration components include: NFVO, VNFM, and SDN controllers;
[0036] The virtualization NEF is used to receive security service requests and send the security service requests to the security control component by calling the interface of the security control component;
[0037] The security control component is further configured to determine the security function corresponding to the security service request, and to coordinate with at least one of the NFVO, the VNFM, and the SDN controller to provide the security service corresponding to the security function.
[0038] Secondly, embodiments of the present invention also provide a communication method, the communication method comprising:
[0039] Obtain security service requests through virtualized network open functions, and determine the security functions and security policies corresponding to the security service requests;
[0040] Identify the virtual security devices and / or physical security devices corresponding to the security functions and security policies;
[0041] The security service corresponding to the security service request is provided in collaboration with the NFVO and / or SDN controller, as well as the virtual security device and / or physical security device corresponding to the security function.
[0042] In the above scheme, the collaborative NFVO and / or SDN controller, as well as the virtual security device and / or physical security device corresponding to the security function, provide the security service corresponding to the security service request, including:
[0043] Send routing information to the SDN controller, the routing information being used by the SDN controller to issue corresponding flow tables;
[0044] Send the security policy corresponding to the security function to the virtual security device and / or physical security device corresponding to the security function.
[0045] In the above scheme, if it is determined that there is no virtual security device and / or physical security device corresponding to the security function, or that the capabilities of the virtual security device and / or physical security device corresponding to the security function are insufficient to provide the security service, the method further includes:
[0046] The NFVO can request a new virtual security device corresponding to the security function, or expand the capacity of the existing virtual security device corresponding to the security function.
[0047] Thirdly, embodiments of the present invention also provide a communication device, the device comprising a first determining unit, a second determining unit, and a processing unit; wherein,
[0048] The first determining unit is configured to obtain a security service request through the virtualized network open function, and determine the security function and security policy corresponding to the security service request;
[0049] The second determining unit is used to determine the virtual security device and / or physical security device corresponding to the security function and security policy;
[0050] The processing unit is used to coordinate with the NFVO and / or SDN controller, as well as the virtual security device and / or physical security device corresponding to the security function, to provide the security service corresponding to the security service request.
[0051] Fourthly, embodiments of the present invention also provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in the second aspect of the present invention.
[0052] Fifthly, embodiments of the present invention also provide a communication device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the method described in the second aspect of the present invention.
[0053] The network security protection architecture, communication method and apparatus, and communication equipment provided in this invention include: a first processing layer containing physical devices, a second processing layer containing various virtualized network functions, and a third processing layer; the first processing layer further includes a security component for performing integrity measurements on the physical devices and sending the integrity measurement results to the third processing layer; each virtualized network function in the second processing layer is used for anomaly detection and sending the anomaly detection results to the third processing layer; the third processing layer includes a security management center for analyzing the integrity measurement results sent by the first processing layer and / or the anomaly detection results sent by the second processing layer, and determining a processing strategy based on the analysis results. By employing the technical solution of this invention, through a second processing layer with anomaly detection and reporting functions, and a first processing layer with integrity measurement, the third processing layer with a security management center can obtain the anomaly detection results from the second processing layer and the integrity measurement results from the first processing layer, achieving network self-detection and handling, comprehensively improving the network's self-security protection and security service capabilities, and possessing self-immunity and self-recovery characteristics. Attached Figure Description
[0054] Figure 1 This is a schematic diagram of a network security protection architecture according to an embodiment of the present invention;
[0055] Figure 2 This is a schematic diagram of another network security protection architecture according to an embodiment of the present invention;
[0056] Figure 3 This is a schematic diagram illustrating the interaction of various components in the network security protection architecture according to an embodiment of the present invention;
[0057] Figure 4 This is a flowchart illustrating the communication method according to an embodiment of the present invention;
[0058] Figure 5 This is a schematic diagram of the interaction flow of the communication method according to an embodiment of the present invention;
[0059] Figure 6This is a schematic diagram of the hardware composition structure of a communication device according to an embodiment of the present invention. Detailed Implementation
[0060] The present invention will now be described in further detail with reference to the accompanying drawings and specific embodiments.
[0061] This invention provides a network security protection architecture. Figure 1 This is a schematic diagram of a network security protection architecture according to an embodiment of the present invention; as shown below. Figure 1 As shown, the network security protection architecture includes: a first processing layer containing physical devices, a second processing layer containing various virtualized network functions, and a third processing layer;
[0062] The first processing layer also includes a security component for performing integrity measurement on the physical device and sending the integrity measurement result to the third processing layer;
[0063] Each virtualized network function in the second processing layer is used to perform anomaly detection and send the anomaly detection result to the third processing layer;
[0064] The third processing layer includes a security management center, which analyzes the integrity measurement results sent by the first processing layer and / or the anomaly detection results sent by the second processing layer, and determines the processing strategy based on the analysis results.
[0065] In this embodiment, the first processing layer can also be called the trusted integrity measurement layer, the second processing layer can also be called the security detection and control layer, and the third processing layer can also be called the security analysis and orchestration layer.
[0066] In this embodiment, the first processing layer may be a physical server containing a security component, as well as physical devices such as switches and routers. The physical server can be responsible for providing computing, storage, and network resources for the 5G network. The security component in the first processing layer is a type of security protection hardware. For example, the security component may be a Hardware Security Module (HSM), which performs integrity measurements on the physical server's hardware, firmware, host operating system (HOS, which can be considered the operating system of the physical machine), guest operating system (Guest OS, which can be considered the operating system of a virtual machine), applications, etc., and sends the integrity measurement results to the third processing layer to ensure the integrity of the server and its VNFs, Operation and Maintenance Centers (OMCs), and other applications.
[0067] In this embodiment, the second processing layer is mainly responsible for anomaly detection, which includes anomaly behavior detection, anomaly file detection, and so on.
[0068] In some alternative embodiments, the second processing layer includes: management and orchestration components;
[0069] The management and orchestration components include: NFVO, VNFM, VIM, and SDN controllers, each with anomaly detection capabilities; wherein...
[0070] The SDN controller is used to send its own anomaly detection results to the VIM;
[0071] The VIM is used to send the anomaly detection results controlled by the SDN and / or its own anomaly detection results to the NFVO;
[0072] The VNFM is used to send its own anomaly detection results to the NFVO;
[0073] The NFVO is used to send at least one of the anomaly detection results sent by the VIM, the anomaly detection results sent by the VNFM, and its own anomaly detection results to the security management center.
[0074] In this embodiment, each component in the management and orchestration component has anomaly detection and reporting functions. Each component performs anomaly detection on itself and sends the anomaly detection results to the third processing layer. For example... Figure 2 As shown, the management and orchestration components include: NFVO, VNFM, VIM, and SDN controller. The connection relationships between NFVO, VNFM, VIM, and SDN controller are as follows: Figure 2 As shown, based on this connection relationship, the SDN controller sends its own anomaly detection results to the VIM; the VIM sends the anomaly detection results of the SDN controller and / or its own anomaly detection results to the NFVO; the VNFM sends its own anomaly detection results to the NFVO; and the NFVO sends at least one of the anomaly detection results sent by the VIM, the VNFM, and its own anomaly detection results to the security management center of the third processing layer.
[0075] In some alternative embodiments, the second processing layer further includes a virtual layer with anomaly detection functionality;
[0076] The security component of the first processing layer is used to send the integrity measurement result to the virtual layer;
[0077] The virtual layer is used to send the integrity measurement result sent by the security component of the first processing layer and / or its own anomaly detection result to the VIM;
[0078] The VIM is also used to send the integrity measurement result and / or the anomaly detection result of the virtual layer to the NFVO;
[0079] The NFVO is also used to send the integrity measurement results and / or the anomaly detection results of the virtual layer to the security management center.
[0080] In some alternative embodiments, the second processing layer includes: a virtualized network function and an operation and maintenance component, each having anomaly detection capabilities;
[0081] The virtualized network function is used to send its own anomaly detection results to the operation and maintenance component;
[0082] The operation and maintenance component is used to send the behavior detection results of the virtualized network function and / or its own behavior detection results to the security management center.
[0083] In this embodiment, the virtualized network function can specifically be the network function of a virtualized core network element. For example, the virtualized network function can specifically be a virtualized network exposure function (vNEF), a virtualized access and mobility management function (vAMF), a virtualized network data analytics function (vNWDAF), etc. Of course, this embodiment is not limited to the virtualized network functions exemplified above; other virtualized network functions are also within the protection scope of this invention.
[0084] For example, the operation and maintenance component may be an OMC.
[0085] In some alternative embodiments, the security management center is also configured to send processing policies related to virtualized network functions to the operation and maintenance component.
[0086] In some alternative embodiments, the second processing layer further includes a security device for recording security logs and sending the security logs to the third processing layer.
[0087] In this embodiment, on the one hand, the second processing layer is responsible for anomaly detection or abnormal behavior detection and reporting; on the other hand, the second processing layer is also responsible for recording security logs and reporting security logs, etc.
[0088] In some optional embodiments, the second processing layer includes: a virtualized security device and a security control component, each having the function of recording security logs and reporting security logs;
[0089] The virtualized security device is used to send security logs to the security control component;
[0090] The security control component is used to send the security logs of the virtualized security device to the security management center.
[0091] For example, the virtualized security device may include a virtual firewall (vFW), a virtualized intrusion prevention system (vIPS), a virtualized web application protection system (vWAF), etc. Of course, this embodiment is not limited to the virtualized security devices exemplified above, and other virtualized security devices may also be within the protection scope of this embodiment.
[0092] In some alternative embodiments, the second processing layer further includes a physical security device for recording security logs and sending the security logs to the security control component;
[0093] The security control component is also used to send the security logs of the physical security device to the security management center.
[0094] For example, the physical security device may include firewalls, IPS, WAF, anti-DDoS, etc. Of course, this embodiment is not limited to the physical security devices exemplified above, and other physical security devices may also be within the protection scope of this embodiment.
[0095] In some alternative embodiments, the security management center is also used to send security policy-related processing policies to the security control component.
[0096] In this embodiment, the security management center supports analysis based on security logs reported by the security control component (also known as the security controller) from virtualized security devices and / or physical security devices, anomaly detection results reported by the operation and maintenance component (such as the OMC) from itself and each virtualized network function, anomaly detection results reported by the NFVO from each component in the management and orchestration component (NFVO, VNFM, VIM, and SDN controller), anomaly detection results from the virtual layer, and integrity measurement results from the first processing layer. It provides early warnings of security threats, gives security policies or handling policies (or processing policies), and distributes them to the security control component and / or operation and maintenance component (such as the OMC). Optionally, the security management center sends security policies or handling policies (or processing policies) related to the configuration of virtualized network functions to the operation and maintenance component (such as the OMC).
[0097] In some optional embodiments, the security control component is further configured to convert the processing policy into a security policy and send the security policy to the corresponding virtualized security device and / or physical security device.
[0098] In some optional embodiments, the second processing layer includes: a virtualized network function with anomaly detection capabilities, the virtualized network function including a virtualized network open function (vNEF), the virtualized NEF supporting the invocation of the interface of the security control component to realize communication between the virtualized NEF and the security control component;
[0099] The second processing layer further includes: management and orchestration components; the management and orchestration components include: NFVO, VNFM, and SDN controllers;
[0100] The virtualization NEF is used to receive security service requests and send the security service requests to the security control component by calling the interface of the security control component;
[0101] The security control component is further configured to determine the security function corresponding to the security service request, and to coordinate with at least one of the NFVO, the VNFM, and the SDN controller to provide the security service corresponding to the security function.
[0102] Optionally, the security controller may also apply for a new virtual security device or expand the capacity of the current virtual security device when there is no virtual security device and / or physical security device corresponding to the security function, or when there is a virtual security device and / or physical security device corresponding to the security function but the virtual security device and / or physical security device cannot provide the security service corresponding to the security function.
[0103] Specifically, in combination Figure 2As shown, the first processing layer includes physical servers with HSMs (i.e., security components) and physical devices (i.e., hardware infrastructure) such as switches and routers. For example, the physical servers are responsible for providing computing, storage, and network resources for the 5G network. The physical servers have built-in HSMs that perform integrity measurements on the physical server's hardware, firmware, Host OS, Guest OS, applications, etc., and upload these integrity measurement values to the security management center of the third processing layer via the virtual layer, VIM, and NFVO to ensure the integrity of the server and its applications such as VNFs and OMCs.
[0104] The second processing layer includes a virtualization layer, management and orchestration components, 5GC network functions, security resource pools (i.e., virtualized security appliances), physical security appliances, security controllers, and OMC, etc.; the management and orchestration components include NFVO, VNFM, VIM, and SDN controllers; 5GC network functions include virtualized network functions such as vNEF, vAMF, and vNWDAF, mainly responsible for abnormal behavior detection and reporting, security log recording and reporting, centralized management of security policies, etc. Specifically:
[0105] -5GC Network Functions: These include virtualized network functions such as vAMF, vNEF, and vNWDAF, which support the detection of their own abnormal behavior and report the anomaly detection results to the OMC. For example, since vNWDAF has the ability to collect and analyze data from 5G network functions and the OMC, such as collecting data from vAMF and vSMF to analyze whether there are DDoS attacks from the UE, vNWDAF supports the OMC in ordering security attack data and can send security attack data to the OMC according to the OMC's order.
[0106] -OMC: Supports its own anomaly detection and reports its own anomaly detection results, as well as the anomaly detection results of virtualized network functions received and network security events received from vNWDAF, to the security management center.
[0107] - Security Resource Pool: Includes virtualized security devices. These virtualized security devices and the virtualized network functions within the 5GC network function can be deployed on the same infrastructure. Virtual resources can be uniformly managed and orchestrated by the Management and Orchestration (MANO) component, and can be managed by the security controller through the northbound interface, enabling unified configuration of security policies, device registration, and unified reporting of security events.
[0108] - Security Controller: Provides unified management of virtualized security devices and physical security devices (such as firewalls and anti-DDoS devices deployed at the boundary of 5G networks and Internet connections) in the security resource pool. For example, management may include configuring security policies, tracking device operational status, and collecting security logs. The security controller supports reporting security logs from both virtualized and physical security devices to the security management platform and supports requesting MANO to create new virtualized security devices and scale them up or down. Furthermore, the security controller's northbound interface is open and supports exposing security capabilities via vNEF.
[0109] - Management and orchestration: This includes NFVO, VNFM, VIM, and SDN controllers, all of which support the detection of their own abnormal behavior. VIM supports reporting its own and the virtual layer's reported anomaly detection results to NFVO; VNFM supports reporting its own anomaly detection results to NFVO; NFVO supports reporting its own anomaly detection results, as well as the anomaly detection results received from VIM, the integrity measurement results of the first processing layer, the anomaly detection results of the virtual layer and VIM itself, and the anomaly detection results received from VNFM, to the security management center.
[0110] The third processing layer, including the security management center, supports analysis based on security logs from virtualized security devices and / or physical security devices reported by the security controller, anomaly detection results from the OMC (Original Network Controller) and its network elements, anomaly detection results from NFVO (Network Functions Object Controller) for each component in management and orchestration, integrity measurement results from the first processing layer, and anomaly detection results from the virtualization layer. It provides early warnings of security threats, proposes handling strategies, and distributes them to the security controller / OMC (only handling strategies related to virtualized network function configuration are distributed to the OMC). Additionally, it analyzes and presents the overall network security posture.
[0111] In some alternative embodiments, the security management center can be deployed hierarchically and / or in a distributed manner. For example, a primary security management center can be as follows: Figure 1 or Figure 2 As shown, in order to reduce the workload of the primary security management center, the secondary security management center can be deployed in the third processing layer, such as in the OMC and / or VIM. The OMC and VIM are used to analyze the anomaly detection results of virtualized network elements and virtual layers, respectively, and to issue network element configurations and virtual layer configuration policies to virtualized network functions and virtual layers, etc. The primary security management center can perform threat analysis based on the analysis results of the secondary security management center and the anomaly detection results, trusted integrity measurement results, security logs, etc. reported by NFVO and VNFM, and give the response strategy.
[0112] Figure 3This is a schematic diagram illustrating the interaction of various components in the network security protection architecture of this invention; as shown below. Figure 3 As shown, the network self-detection and handling process may include:
[0113] Step 1: The HSM of hardware facilities (such as servers) performs integrity measurements on hardware, firmware, OS, virtualization software, Guest OS, etc.
[0114] Step 2: The server sends the integrity metric value (i.e., the integrity metric result) to the virtual layer.
[0115] Step 3: The virtual layer, 5GC network function, OMC, security controller, SDN controller, VIM, VNFM, and NFVO perform their own anomaly (or abnormal behavior) detection, such as detecting abnormal processes, abnormal accounts, privilege escalation, malware, information tampering, and non-compliant security configurations.
[0116] Step 4: The virtual layer reports its own anomaly detection results and trusted integrity metric values to the VIM; the VIM reports its own anomaly detection results, the virtual layer's anomaly detection results, and trusted integrity metric values to the NFVO; the VNFM reports its own anomaly detection results to the NFVO; the 5GC network function reports its anomaly detection results, and the NWDAF reports security attacks (i.e., anomaly detection results) to the OMC; the virtualized security device (i.e., each virtual device in the security resource pool) / physical security device reports security logs (or security events) to the security controller.
[0117] Step 5: The security controller reports the attack events and its own anomaly detection results, the OMC reports its own anomaly detection results and received anomaly detection results / security attacks, etc., and the NFVO reports its own anomaly detection results and received anomaly detection results, as well as integrity metrics, to the security management center.
[0118] Step 6: The intelligent analysis function of the security management center can use technologies such as artificial intelligence (AI) and big data to perform intelligent threat analysis on the received anomaly detection results, integrity metrics, security logs (security events), and security attacks to identify potential or actual security threats.
[0119] Step 7: The intelligent analysis function sends the analysis results to the intelligent processing function.
[0120] Step 8: The intelligent handling function provides a handling strategy (or disposal strategy) and sends the security-related handling strategy (or disposal strategy) to the security controller, and sends the virtualization network function security configuration-related handling strategy (or disposal strategy) to the OMC.
[0121] Step 9: The security controller resolves the handling policy (or disposal policy) into the corresponding security policy of the security device (e.g., ...). Figure 3 The parsing and handling strategy shown in step 9a is used to coordinate with NFVO and SDN controllers to instantiate / expand virtualized security devices and to direct traffic to relevant security devices. Figure 3 The NFVO instantiation virtualization security function shown in step 9b will only be implemented when the security device resources are insufficient. Figure 3 The SDN controller routing configuration shown in step 9c is performed when the security control component (i.e., the security controller) collaborates with the NFVO and the SDN controller to implement security services.
[0122] Step 10: The security controller configures the security policy on the corresponding security devices to achieve secure traffic handling. The OMC then distributes the security policy configuration to the corresponding virtualized network functions to achieve secure configuration.
[0123] In this embodiment, vNEF has the ability to call the northbound interface of the security controller.
[0124] By adopting the technical solution of this invention, through a second processing layer with anomaly detection and reporting functions and a first processing layer with integrity measurement, the third processing layer with a security management center can obtain the anomaly detection results of the second processing layer and the integrity measurement results of the first processing layer, thereby realizing the network's self-detection and handling, comprehensively improving the network's own security protection capabilities and security service capabilities, and possessing the characteristics of self-immunity and self-recovery.
[0125] Based on the above network security protection architecture, this embodiment of the invention also provides a communication method that is applied to a security control component (such as a security controller). Figure 4 This is a flowchart illustrating the communication method according to an embodiment of the present invention; as shown below. Figure 4 As shown, the method includes:
[0126] Step 101: Obtain a security service request through the virtualized network open function, and determine the security function and security policy corresponding to the security service request;
[0127] Step 102: Determine the virtual security devices and / or physical security devices corresponding to the security functions and security policies;
[0128] Step 103: Collaborate with the NFVO and / or SDN controller, as well as the virtual security device and / or physical security device corresponding to the security function, to provide the security service corresponding to the security service request.
[0129] In this embodiment, based on the foregoing Figure 1 and Figure 2The network security protection architecture shown has the ability to call the northbound interface of the security control component (i.e., the security controller), and the security control component (i.e., the security controller) can work with the NFVO and / or SDN controller to provide security services.
[0130] In some optional embodiments, the coordinating NFVO and / or SDN controller, as well as the virtual security device and / or physical security device corresponding to the security function, provide the security service corresponding to the security service request, including: sending routing information to the SDN controller, the routing information being used by the SDN controller to issue corresponding flow tables; and sending the security policy corresponding to the security function to the virtual security device and / or physical security device corresponding to the security function.
[0131] In some optional embodiments, if it is determined that there is no virtual security device and / or physical security device corresponding to the security function, or the capacity of the virtual security device and / or physical security device corresponding to the security function is insufficient to provide the security service, the method further includes: applying for a new virtual security device corresponding to the security function from the NFVO, or expanding the capacity of the current virtual security device corresponding to the security function.
[0132] The security service implementation process of this invention will be described below with reference to specific examples.
[0133] Figure 5 This is a schematic diagram of the interaction flow of the communication method according to an embodiment of the present invention, such as... Figure 5 As shown, the method includes:
[0134] Step 201: The Application Function (AF) sends a security service request to vNEF.
[0135] Step 202: vNEF authenticates and authorizes the AF, checking if the AF has permission to request security services. If authentication and authorization are successful, proceed to step 203; otherwise, vNEF returns a failure message to the AF and ends the process.
[0136] Step 203: NEF forwards the security service request to the security controller.
[0137] Step 204: The security controller parses the security request, specifically including parsing the security functions, security policies, protected IP addresses and ports, protocols, required bandwidth, etc., required by the security service, and checking whether there are corresponding security devices that meet the security functions required by the security service, including virtualized security devices and / or physical security devices.
[0138] Step 205a: If there is no corresponding virtualized security appliance and / or physical security appliance, or if there is a corresponding virtualized security appliance and / or physical security appliance but it cannot provide sufficient processing capacity to handle AF traffic, the security controller, in coordination with the NFVO, requests the instantiation of a new virtualized security appliance or expands the capacity of the existing virtualized security appliance. If the current virtualized security appliance and / or physical security appliance meets the requirements for providing security services, this step is skipped.
[0139] Step 205b: The security controller, in coordination with the router, obtains the network topology, selects the appropriate security device based on the network topology and the operating status of the security devices, and sends the traffic redirection request (network topology and routing request) to the SDN controller. The SDN controller redirects the traffic requiring protection to the appropriate security device by issuing flow tables to the switches.
[0140] Step 206: The security controller issues security policies to the corresponding security devices. The security devices then provide security services to the AF.
[0141] This invention also provides a communication device, which includes a first determining unit, a second determining unit, and a processing unit; wherein,
[0142] The first determining unit is configured to obtain a security service request through the virtualized network open function, and determine the security function and security policy corresponding to the security service request;
[0143] The second determining unit is used to determine the virtual security device and / or physical security device corresponding to the security function and security policy;
[0144] The processing unit is used to coordinate with the NFVO and / or SDN controller, as well as the virtual security device and / or physical security device corresponding to the security function, to provide the security service corresponding to the security service request.
[0145] In some optional embodiments of the present invention, the processing unit is configured to send routing information to the SDN controller, the routing information being used by the SDN controller to issue corresponding flow tables;
[0146] Send the security policy corresponding to the security function to the virtual security device and / or physical security device corresponding to the security function.
[0147] In some optional embodiments of the present invention, the processing unit is further configured to, if it is determined that there is no virtual security device and / or physical security device corresponding to the security function, or the capability of the virtual security device and / or physical security device corresponding to the security function is insufficient to provide the security service, apply from the NFVO for a new virtual security device corresponding to the security function, or expand the capacity of the current virtual security device corresponding to the security function.
[0148] In this embodiment of the invention, the communication device is applied in a communication equipment, which may be a security control component or a security controller as described in the preceding embodiments. The alarm unit 54, control unit 56, working mode monitoring unit 57, and application processing unit 58 in the terminal can all be implemented by a central processing unit (CPU), digital signal processor (DSP), microcontroller unit (MCU), or field-programmable gate array (FPGA) in the terminal in practical applications. The first power supply unit 51 and the second power supply unit 52 in the terminal can both be implemented by a battery in the terminal in practical applications. The power monitoring unit 53 in the terminal can be implemented by a voltage sensor in practical applications. The communication unit 55 in the terminal can be implemented by a communication module (including: basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and transceiver antenna in practical applications.
[0149] It should be noted that the communication device provided in the above embodiments is only illustrated by the division of the above program modules during communication processing. In practical applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. In addition, the communication device and communication method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process can be found in the method embodiments, which will not be repeated here.
[0150] This invention also provides a communication device, which may be the security control component or security controller described in the foregoing embodiments. Figure 6 This is a schematic diagram of the hardware composition structure of the communication device according to an embodiment of the present invention, such as... Figure 6 As shown, the communication device includes a memory 12, a processor 11, and a computer program stored in the memory 12 and executable on the processor 11. When the processor 11 executes the computer program, it implements the steps of the communication method described in this embodiment of the invention.
[0151] Optionally, the communication device may also include one or more network interfaces 13. It is understood that the various components in the communication device can be coupled together via a bus system 14. It is understood that the bus system 14 is used to implement communication between these components. In addition to a data bus, the bus system 14 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 6 The general will label all buses as Bus System 14.
[0152] It is understood that memory 12 can be volatile memory or non-volatile memory, or both. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), ferromagnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM); magnetic surface memory can be disk storage or magnetic tape storage. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM).The memory 12 described in the embodiments of the present invention is intended to include, but is not limited to, these and any other suitable types of memory.
[0153] The methods disclosed in the above embodiments of the present invention can be applied to or implemented by the processor 11. The processor 11 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in the processor 11 or by instructions in the form of software. The processor 11 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 11 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of the present invention can be directly manifested as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in the memory 12. The processor 11 reads the information in the memory 12 and completes the steps of the aforementioned method in combination with its hardware.
[0154] In an exemplary embodiment, the communication device may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to perform the aforementioned method.
[0155] In an exemplary embodiment, the present invention also provides a computer-readable storage medium, such as a memory 12 including a computer program, which can be executed by a processor 11 of a communication device to perform the steps described in the foregoing method. The computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM; or it may be various devices including one or any combination of the above-mentioned memories.
[0156] This invention also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the communication method described in this invention.
[0157] The methods disclosed in the several method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments.
[0158] The features disclosed in the several product embodiments provided in this application can be arbitrarily combined without conflict to obtain new product embodiments.
[0159] The features disclosed in the several method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method or device embodiments.
[0160] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or units can be electrical, mechanical, or other forms.
[0161] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected to achieve the purpose of this embodiment according to actual needs.
[0162] In addition, in the various embodiments of the present invention, each functional unit can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.
[0163] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0164] Alternatively, if the integrated units of this invention are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this invention, or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROM, RAM, magnetic disks, or optical disks.
[0165] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A network security protection system, characterized in that, The network security protection system includes: a first processing layer containing physical devices, a second processing layer containing various virtualized network functions, and a third processing layer; The first processing layer further includes a security component for performing integrity measurement on the physical device and sending the integrity measurement result to the second processing layer and / or the third processing layer; Each virtualized network function in the second processing layer is used for anomaly detection and sending the anomaly detection results to the third processing layer; the second processing layer includes a security device for recording security logs and sending the security logs to the third processing layer; the second processing layer further includes: a virtualized security device and / or a physical security device respectively having the function of recording security logs, and a security control component for reporting security logs; the virtualized security device is used to send security logs to the security control component; the physical security device is used to send security logs to the security control component; the security control component is used to send the security logs of the virtualized security device and / or the security logs of the physical security device to the security management center; The third processing layer includes the security management center, which is used to analyze the integrity measurement results sent by the first processing layer and / or the anomaly detection results sent by the second processing layer, and determine the processing strategy based on the analysis results; it is also used to send the security policy-related processing strategies to the security control component.
2. The network security protection system according to claim 1, characterized in that, The second processing layer also includes: management and orchestration components; The management and orchestration components include: a Network Function Virtualization Orchestrator (NFVO) with anomaly detection capabilities, a Virtual Network Function Manager (VNFM), a Virtual Infrastructure Manager (VIM), and a Software-Defined Networking (SDN) controller; wherein... The SDN controller is used to send its own anomaly detection results to the VIM; The VIM is used to send the anomaly detection results controlled by the SDN and / or its own anomaly detection results to the NFVO; The VNFM is used to send its own anomaly detection results to the NFVO; The NFVO is used to send at least one of the anomaly detection results sent by the VIM, the anomaly detection results sent by the VNFM, and its own anomaly detection results to the security management center.
3. The network security protection system according to claim 2, characterized in that, The second processing layer also includes a virtual layer with anomaly detection functionality; The security component of the first processing layer is used to send the integrity measurement result to the virtual layer; The virtual layer is used to send the integrity measurement result sent by the security component of the first processing layer and / or its own anomaly detection result to the VIM; The VIM is also used to send the integrity measurement result and / or the anomaly detection result of the virtual layer to the NFVO; The NFVO is also used to send the integrity measurement results and / or the anomaly detection results of the virtual layer to the security management center.
4. The network security protection system according to claim 1, characterized in that, The second processing layer includes: a virtualized network function and an operation and maintenance component, each with anomaly detection capabilities; The virtualized network function is used to send its own anomaly detection results to the operation and maintenance component; The operation and maintenance component is used to send the behavior detection results of the virtualized network function and / or its own behavior detection results to the security management center.
5. The network security protection system according to claim 4, characterized in that, The security management center is also used to send processing policies related to virtualized network functions to the operation and maintenance component.
6. The network security protection system according to claim 1, characterized in that, The security control component is further configured to convert the processing policy into a security policy and send the security policy to the corresponding virtualized security device and / or physical security device.
7. The network security protection system according to claim 1, characterized in that, The second processing layer includes: a virtualized network function with anomaly detection capability, the virtualized network function including a virtualized network open function (NEF), the virtualized NEF supporting the invocation of the interface of the security control component to realize communication between the virtualized NEF and the security control component; The second processing layer further includes: management and orchestration components; the management and orchestration components include: NFVO, VNFM, and SDN controllers; The virtualization NEF is used to receive security service requests and send the security service requests to the security control component by calling the interface of the security control component; The security control component is further configured to determine the security function corresponding to the security service request, and to coordinate with at least one of the NFVO, the VNFM, and the SDN controller to provide the security service corresponding to the security function.
8. A communication method, characterized in that, The method is applied to a security control component, which is deployed in the second processing layer of the network security protection system according to any one of claims 1 to 7, and the communication method includes: Security service requests are obtained through the virtualization network open function, and the corresponding security functions and security policies are determined. The security policy is determined by the security control component through a processing policy sent by the security management center, which is deployed as the third processing layer in the network security protection system. The processing policy is obtained by the security management center based on the integrity measurement results for physical devices sent by the first processing layer in the network security protection system, and / or the anomaly detection results for anomaly detection of each virtualization network function sent by the second processing layer. Identify the virtual security devices and / or physical security devices corresponding to the security functions and security policies; The system coordinates with the NFVO and / or the software-defined network (SDN) controller, as well as the virtual security devices and / or physical security devices corresponding to the security functions, to provide the security services corresponding to the security service requests.
9. The method according to claim 8, characterized in that, The collaborative NFVO and / or SDN controller, along with the virtual security device and / or physical security device corresponding to the security function, provide the security services corresponding to the security service request, including: Send routing information to the SDN controller, the routing information being used by the SDN controller to issue corresponding flow tables; Send the security policy corresponding to the security function to the virtual security device and / or physical security device corresponding to the security function.
10. The method according to claim 8, characterized in that, If it is determined that there is no virtual security device and / or physical security device corresponding to the security function, or that the capabilities of the virtual security device and / or physical security device corresponding to the security function are insufficient to provide the security service, the method further includes: The NFVO can request a new virtual security device corresponding to the security function, or expand the capacity of the existing virtual security device corresponding to the security function.
11. A communication device, characterized in that, The device is applied to a security control component, which is deployed in the second processing layer of the network security protection system according to any one of claims 1 to 7. The device includes a first determining unit, a second determining unit, and a processing unit; wherein... The first determining unit is configured to obtain a security service request through the virtualized network open function, and determine the security function and security policy corresponding to the security service request; wherein, the security policy is determined by the security control component through the processing policy sent by the security management center, the security management center is deployed in the third processing layer of the network security protection system, and the processing policy is obtained by the security management center based on the integrity measurement result of the physical device integrity measurement sent by the first processing layer of the network security protection system, and / or the anomaly detection result of the anomaly detection of each virtualized network function sent by the second processing layer; The second determining unit is used to determine the virtual security device and / or physical security device corresponding to the security function and security policy; The processing unit is used to coordinate with the orchestrator NFVO and / or the software-defined network SDN controller, as well as the virtual security device and / or physical security device corresponding to the security function, to provide the security service corresponding to the security service request.
12. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the steps of the method according to any one of claims 8 to 10.
13. A communication device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 8 to 10.
Citation Information
Patent Citations
Safety management method and device based on NFV (Network Function Virtualization)
CN105847237A
Network security service system and method
CN112671772A