Network-level disaster recovery exercise method and apparatus, electronic device, and medium
By employing multi-domain wireless backup network connections and a persistent mode in network-level disaster recovery drills, combined with network traffic mirroring and AAA authentication technologies, the complexity and high cost of network-level disaster recovery drills were resolved, enabling efficient detection and low-impact switching of wireless disaster recovery networks.
Patent Information
- Application Number
- CN202211220737.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-08
- Publication Date
- 2026-02-10
- Estimated Expiration
- 2042-10-08
AI Technical Summary
In network-level disaster recovery drills, existing technologies require frequent establishment or disconnection of wired links and wireless network connections between end nodes and the main center, resulting in complex processes, high costs, and disruption to normal business operations, making it difficult to guarantee the effectiveness of the wireless disaster recovery network.
A multi-domain approach is used to establish a wireless backup network connection, with the primary domain having higher priority than the backup domain. The wireless network connection is maintained through a long-lived mode. Network traffic mirroring technology and AAA authentication are used to verify the access status of the target nodes and generate exercise data.
This reduced the complexity and cost of the drill process, minimized the impact on production operations, and improved the effectiveness and efficiency of disaster recovery network detection.
Smart Images

Figure CN115589610B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of disaster recovery technology, and in particular to a network-level disaster recovery drill method, apparatus, electronic equipment, and medium. Background Technology
[0002] Disaster recovery drills are a process of simulating a disaster scenario and conducting emergency drills to verify whether the disaster recovery plan of the disaster recovery system is reasonable and can achieve the disaster recovery effect expected at the beginning of the project.
[0003] During disaster recovery drills, the relevant technologies require frequent establishment or disconnection of wired and wireless links between end nodes and the main center, as well as the establishment of wireless network connections between end nodes and the backup center. This makes the drill process complex and requires excessive manpower and financial investment when there are many end nodes, while also significantly impacting daily production operations. On the other hand, if only some network points are selected, it is difficult to guarantee the effectiveness of the disaster recovery network.
[0004] Therefore, how to conduct large-scale network-level drills and ensure the effectiveness of wireless disaster recovery networks is an urgent problem to be solved. Summary of the Invention
[0005] To address the aforementioned issues, namely the complexity, high cost, and disruption to normal business operations associated with network disaster recovery drills, this application provides a network-level disaster recovery drill method, apparatus, electronic equipment, and medium.
[0006] To achieve the above objectives, this application provides the following technical solution:
[0007] According to one aspect of this application, a network-level disaster recovery drill method is provided, wherein a target node establishes a wireless backup network connection with a primary center and a backup center using a multi-domain method, the backup wireless network connection is in a persistent-live mode, and the domain name priority of the primary center is higher than that of the backup center, the method comprising:
[0008] In response to a disaster recovery drill request, disconnect the wireless backup network connection;
[0009] In response to the first terminal connection information of the main center, verify whether the target node has successfully accessed the wireless backup network based on the domain name of the main center. If not, obtain the second terminal connection information of the backup center.
[0010] Based on the second terminal connection information, verify whether the target node has successfully accessed the wireless backup network based on the domain name of the backup center, and generate exercise data based on the verification result of whether the target node has successfully accessed the wireless backup network based on the domain name of the backup center.
[0011] In one implementation, the second terminal connection information carries the Radius remote dialing authentication service transaction log.
[0012] The step of verifying whether the target node has successfully accessed the wireless backup network based on the domain name of the backup center, based on the second terminal connection information, includes:
[0013] Verify whether the AAA information in the Radius transaction log matches the AAA information of the target node;
[0014] If a match is found, then verify whether the login information corresponding to the AAA information of the target node indicates a successful login.
[0015] If the login is successful, it is determined that the target node has successfully accessed the wireless backup network based on the domain name of the backup center.
[0016] In one implementation, obtaining the second terminal connection information of the backup center includes:
[0017] The authentication network traffic of the backup center is obtained based on network traffic mirroring technology, and the connection information of the second terminal is obtained based on the authentication network traffic.
[0018] In one implementation, before verifying whether the AAA information in the Radius transaction log matches the AAA information of the target node, the method further includes:
[0019] The AAA information of the target node is collected in advance and stored in the database;
[0020] When verifying the AAA information in the Radius transaction log, the AAA information of the target node in the database is called for verification.
[0021] In one implementation, before disconnecting the wireless backup network connection, the method further includes:
[0022] Obtain a pre-built exercise structure model, which includes a tree-structured first node, intermediate nodes, and end nodes;
[0023] Based on the exercise structure model, the target node and main center for disaster preparedness exercises are determined. The target node is one or more of the end nodes, and the main center is one or more of the head node and / or the intermediate nodes.
[0024] In one implementation, determining the target node and main center for disaster recovery drills based on the drill structure model includes:
[0025] The exercise structure model is displayed in a visualization interface, wherein the visualization interface is configured with visualization permissions;
[0026] The visualization interface receives selection information about the exercise structure model, and the target node and main center for disaster preparedness exercises are determined based on the selection information.
[0027] In one embodiment, the method further includes:
[0028] The visualization interface displays the verification process and results of verifying whether the target node has successfully accessed the wireless backup network based on the domain name of the backup center, using the connection information of the second terminal.
[0029] According to another aspect of this application, a network-level disaster recovery drill device is provided, wherein a target node establishes a wireless backup network connection with a primary center and a backup center using a multi-domain method. The backup wireless network connection is in a persistent-live mode, and the domain name priority of the primary center is higher than that of the backup center. The device includes:
[0030] The disconnect module is configured to disconnect the wireless backup network connection in response to a disaster recovery exercise request.
[0031] The first verification module is configured to respond to the first terminal connection information of the main center to verify whether the target node has successfully accessed the wireless backup network based on the domain name of the main center. If not, it obtains the second terminal connection information of the backup center.
[0032] The second verification module is configured to verify, based on the second terminal connection information, whether the target node has successfully accessed the wireless backup network based on the domain name of the backup center.
[0033] The data generation module is configured to generate exercise data based on the verification result of whether the target node has successfully accessed the wireless backup network based on the domain name of the backup center.
[0034] According to another aspect of this application, an electronic device is provided, comprising: a memory and a processor;
[0035] The memory stores computer-executed instructions;
[0036] The processor executes computer execution instructions stored in the memory, causing the electronic device to perform the network-level disaster recovery drill method.
[0037] According to another aspect of this application, a computer storage medium is provided, wherein computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the network-level disaster recovery drill method described above.
[0038] Understandably, the network-level disaster recovery drill method, apparatus, electronic device, and medium provided in this application establish a multi-domain wireless backup network connection between the target node and the primary / backup center. This wireless backup network connection is in a persistent-live mode. In response to a disaster recovery drill request, the wireless backup network connection is disconnected. In response to the first terminal connection information from the primary center, the system verifies whether the target node has successfully accessed the wireless backup network based on the primary center's domain name. If not, it obtains the second terminal connection information from the backup center. Based on the second terminal connection information, it verifies whether the target node has successfully accessed the wireless backup network based on the backup center's domain name, and generates drill data based on the verification result. Through this method, this application can effectively solve the problems of complex network disaster recovery drill processes, high costs, and disruption to normal business operations, improving the effectiveness of disaster recovery network detection processes. Attached Figure Description
[0039] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0040] Figure 1 This is one of the possible scenario diagrams provided for an embodiment of this application;
[0041] Figure 2 A flowchart illustrating a network-level disaster recovery drill method provided in an embodiment of this application;
[0042] Figure 3 A second schematic flowchart illustrating a network-level disaster recovery drill method provided in this application embodiment;
[0043] Figure 4 A flowchart illustrating another network-level disaster recovery drill method provided in this application embodiment;
[0044] Figure 5a This is an example diagram of terminal attributes in an embodiment of this application;
[0045] Figure 5b This is an example diagram of the organization and terminal management interface in the embodiments of this application;
[0046] Figure 5c This is an example diagram illustrating how the organization and terminal management interface operates on the terminal in this embodiment of the application;
[0047] Figure 5d This is a flowchart illustrating the configuration of the visual interface in an embodiment of this application.
[0048] Figure 5e This is an example diagram showing the data displayed in the visualization interface of this application embodiment;
[0049] Figure 6 A schematic diagram of the structure of a network-level disaster recovery drill device provided in an embodiment of this application;
[0050] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0051] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0052] In related technologies, when constructing a multi-data center disaster recovery network, some large and medium-sized data centers adopt a wireless approach, with the primary and backup centers constructing two or more levels of disaster recovery wireless access points through multiple domain names. When the wired line of the end node is interrupted, it will access the wireless access point of the primary center through the first domain name. After a disaster occurs in the primary center, the end node will access the wireless access point of the backup center through the second domain name, thereby realizing the switchover of the end node to the primary and backup centers through the wireless network.
[0053] This type of wireless network channel typically uses an on-demand dialing method. It only dials into the main center when the physical line at the end node is interrupted, and only establishes a network channel to the backup center after a disaster at the main center. Therefore, during routine operation and maintenance drills, if it is necessary to verify the availability of the wireless channel from the end node to the main center, the production wired link from the node to the main center needs to be interrupted. If it is necessary to verify the availability of the wireless channel from the end node to the backup center, both the production wired link to the main center and the backup wireless channel to the main center need to be interrupted.
[0054] In the aforementioned process, after the end nodes switch from wired to wireless disaster recovery networks, it is difficult to guarantee the effectiveness of the wireless disaster recovery link, and it affects the production operation of the main center. After the switchover and revert, business personnel still need to perform business transaction verification. In addition, large financial institutions currently have a large number of branches, with end nodes typically numbering in the tens of thousands. If wireless disaster recovery network operation and maintenance is to be carried out in the above manner, not only is the exercise process complex, but the required manpower and financial costs are also too high, and it will also have a significant impact on daily production operations.
[0055] In view of this, this application provides a network-level disaster recovery drill method, apparatus, and electronic device to address the aforementioned technical problems. It employs a persistent wireless network mode, ensuring the wireless network from the end node to the main center is always online. Through this persistent wireless channel mode, the system can monitor the status of the wireless channel from the end network node to the main center in real time, eliminating the need for additional wireless network drills from the end node to the main center. This reduces the workload of backup channel verification and effectively minimizes the impact of disaster recovery drills on production operations. Furthermore, when the wireless networks of the end node and the main center are disconnected, the system instructs the end node to switch to a lower-priority backup center domain name, initiates an access connection to the backup center, and generates drill data based on the connection status to detect the effectiveness of the disaster recovery network.
[0056] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions in the embodiments of this application will be described in more detail below with reference to the accompanying drawings. In the drawings, the same or similar reference numerals denote the same or similar components or components having the same or similar functions throughout. The described embodiments are some, but not all, embodiments of this application. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain this application, and should not be construed as limiting this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.
[0057] Figure 1 This is a possible scenario illustration provided for an embodiment of this application. It should be noted that the network-level disaster recovery drill method disclosed herein can be used in the financial technology field or any other field. The application field of the network-level disaster recovery drill method disclosed herein is not limited.
[0058] Taking disaster recovery drills in financial institutions as an example, such as Figure 1 As shown, the network includes a main center 110, provincial centers 120, city centers 130, terminals 140 at each level of network points, and a backup center (not shown). It can be understood that each center is a data center, and terminals 110 are interconnected with each center via wired or wireless networks, and can establish wireless network connections with backup centers. In some embodiments, the main center 110 is used to issue disaster recovery drill instructions to terminals 140, and terminals 140 are used to establish connections with the main center or backup center based on the instruction data provided by the main center 110. Optionally, during the disaster recovery drill, the main center undertakes the primary computing work, and the terminals undertake secondary computing work; or, the main center undertakes secondary computing work, and the terminals undertake primary computing work; or, the main center or terminals can each independently undertake computing work.
[0059] Among them, the data centers such as the General Center 110, Provincial Center 120, and City Center 130 can be independent physical servers, server clusters or distributed systems composed of multiple physical servers, or cloud servers that provide basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms.
[0060] Terminal 140 may include, but is not limited to, computers, smartphones, tablets, e-book readers, Moving Picture Experts Group audio layer III (MP3) players, Moving Picture Experts Group audio layer IV (MP4) players, portable computers, in-vehicle computers, wearable devices, desktop computers, set-top boxes, smart TVs, etc.
[0061] Optionally, the number of the aforementioned centers and terminals may be more or fewer, and this application embodiment does not limit this. In some embodiments, the aforementioned centers and terminals may also act as nodes in the blockchain system, synchronizing disaster recovery drill data with other nodes in the blockchain to improve the efficiency of disaster recovery drills and fault recovery efficiency.
[0062] The above provides a brief illustration of the scenario of this application. The following section describes its application... Figure 1 Taking the central control center 110 as an example, this application will explain in detail the network-level disaster recovery drill method provided in its embodiments. It is understood that in some embodiments, the network-level disaster recovery drill method can also be applied to other servers or terminal devices, and is not limited to its application in the central control center.
[0063] Please refer to Figure 2 , Figure 2 This is a flowchart illustrating a network-level disaster recovery exercise method provided in an embodiment of this application. A wireless network connection is established between the target node and the main center. The wireless network connection is in a persistent live mode, and the domain name priority of the main center is higher than that of the backup center. The method includes steps S201-S203.
[0064] It is understandable that the target node in this embodiment corresponds to Figure 1 The terminal in the process, i.e., the end node.
[0065] Understandably, the long-lived mode, or L2TP (Layer 2 Tunneling Protocol) link long-lived mode, is a mode in which IPSEC (Internet Protocol Security) sessions are not established under normal wired network conditions.
[0066] Understandably, in this embodiment, the domain name priority of the primary center is higher than that of the backup center in the wireless backup network. The target node prioritizes establishing a wireless backup network connection with the primary center. That is, under normal circumstances, the wireless backup network accessed by the target node in long-lived mode is the network accessed based on the access point of the primary center.
[0067] In this embodiment, after the end node accesses the main center via a wireless network (e.g., 3G / 4G / 5G network), it maintains a continuous connection, meaning the end node and the main center are always in a connected state and can transmit network data at any time. Simultaneously, since the wired network from the end node to the main center is also connected, service traffic prioritizes the wired network and is not transmitted over the wireless network. Therefore, the persistent live mode ensures uninterrupted service traffic, achieving both the availability of the wireless disaster recovery network and reducing the uncertainty of temporary disaster recovery network activation, thus shortening the switchover time.
[0068] With this long-lived wireless channel mode, the main center can monitor the status of the wireless channel from the end network node to the main center in real time, eliminating the need to conduct wireless network drills from the end node to the main center. This reduces the workload of backup channel verification and avoids the impact of disaster recovery drills on production operations.
[0069] Step S201: In response to the disaster recovery exercise request, disconnect the wireless backup network connection.
[0070] In this embodiment, when a network-level disaster recovery exercise is required, the user can initiate a disaster recovery exercise request to the main center. Optionally, the disaster recovery exercise request can carry the domain names of the main center and the backup center to improve the network connection efficiency during the disaster recovery exercise.
[0071] In one implementation, the main center is equipped with an enable switch that automatically disconnects the wireless network connection between the target node and the main center upon receiving a disaster recovery exercise request. In other implementations, the main center can also disconnect the wireless network connection between the two nodes by sending a disconnect instruction to the target node.
[0072] In some embodiments, the method is applied to a server independent of the main center and the end nodes, and can issue network disconnection instructions to the target node and the main center simultaneously or selectively to disconnect the network connection between the target node and the main center.
[0073] During actual drills, the system can instruct target nodes to connect to the backup center, for example, by sending an instruction message to the backup center.
[0074] Step S202: In response to the first terminal connection information of the main center, verify whether the target node has successfully accessed the wireless backup network based on the domain name of the main center. If not, obtain the second terminal connection information of the backup center.
[0075] In one implementation, a site priority setting is configured for the endpoint node domain names, prioritizing the primary center domain name over the backup center domain name. When the primary center is unavailable, the endpoint node will first attempt to connect to the primary center using its domain name. If multiple reconnections fail, the endpoint node will automatically switch to the lower-priority backup center domain name, initiate an access connection to the backup center, and, after AAA server authentication, establish a wireless connection with the backup center if the username and password match successfully. (Specific details can be combined with...) Figure 3 As shown, after the exercise begins, the main center domain name is probed first. The probe process can be performed once every 10 seconds, and can be performed three times. If the main center domain name can be detected, the latest Radius transaction log of the main center is obtained, and it is determined whether the Radius transaction log matches the AAA username and password. If the match is successful, it means that the connection to the main center network has been successfully established. If it fails, the matching can continue every 10 seconds.
[0076] In this embodiment, the effectiveness of the primary center's wireless network is verified before the backup center's disaster recovery network is verified. This avoids interference with the disaster recovery network verification when the backup center's wireless network is accessible, thereby improving the accuracy of the disaster recovery drill.
[0077] Step S203: Verify whether the target node has successfully accessed the wireless backup network based on the domain name of the backup center, based on the second terminal connection information.
[0078] In this embodiment, after the target node is unable to connect to the main center, it establishes a wireless network connection with the backup center. For example, the target node makes a remote dial-up call to detect the backup center's domain name XXX.COM.CN and generates second terminal connection information.
[0079] In one implementation, to improve the accuracy and efficiency of obtaining the second terminal connection information, this embodiment employs network traffic mirroring technology. Specifically, obtaining the second terminal connection information of the backup center in step S202 may include the following steps:
[0080] The authentication network traffic of the backup center is obtained based on network traffic mirroring technology, and the connection information of the second terminal is obtained based on the authentication network traffic.
[0081] In one implementation, the success of the target node in connecting to the backup center is determined by verifying the Radius transaction log. Specifically, the second terminal connection information carries the Radius transaction log of the remote dialing authentication service. Step S203, verifying whether the target node has successfully connected to the wireless backup network, may include the following steps:
[0082] Verify whether the AAA information in the Radius transaction log matches the AAA information of the target node;
[0083] If a match is found, then verify whether the login information corresponding to the AAA information of the target node indicates a successful login.
[0084] If the login is successful, it is determined that the target node has successfully accessed the wireless backup network based on the domain name of the backup center.
[0085] Understandably, RADIUS (Remote Authentication Dial In User Service), defined by RFC2865 and RFC2866, is the most widely used AAA protocol. AAA (Authentication, Authorization, Accounting) is a management framework, a security management mechanism for access control in network security, providing authentication, authorization, and accounting services. Therefore, it can be implemented using various protocols. In practical applications, users most commonly use Remote Authentication Dial In User Service (RADIUS) to implement AAA.
[0086] For example, after starting the network disaster recovery drill, the main center shuts down the end node accounts on the AAA server and clears the session connections on the LNS (Look N Stop, firewall) device to simulate a failure of the main center's wireless access point. This causes the wireless network connection from each end node to the main center to be disconnected, and the end nodes can no longer dial the main center's wireless access point. At this time, since the end nodes have not disconnected the wired network link of the main center, the business traffic will take priority through the wired network and will not be transmitted on the wireless network. Therefore, the actual business is still running in the main center and will not affect normal production operations.
[0087] Meanwhile, at the backup center, network traffic mirroring technology is used to mirror the AAA authentication traffic (i.e., AAA information) of the end nodes accessing the wireless network on the LNS device. The mirrored traffic is then used to determine whether the end nodes successfully connected to the head office disaster recovery center during the exercise. The AAA information can be AAA authentication request and response messages, including the AAA username, password, and login information. The results of obtaining the AAA authentication request and response messages using traffic mirroring technology can be combined to determine whether wireless network authentication was successfully used.
[0088] In this embodiment, by extracting the Radius transaction log, the AAA information corresponding to the target node can be quickly retrieved. Furthermore, before verifying whether the AAA information in the Radius transaction log matches the AAA information of the target node, the following steps may also be included:
[0089] The AAA information of the target node is collected in advance and stored in the database;
[0090] When verifying the AAA information in the Radius transaction log, the AAA information of the target node in the database is called for verification.
[0091] The Radius transaction log can be the latest Radius transaction log with the current timestamp.
[0092] In one implementation, the system constructs a training structure model. This model employs a tree structure to manage the organizational structure, and the AAA information of each target node is also collected and managed uniformly in the form of an organizational structure, stored in a database to improve the efficiency of AAA information management and retrieval. It is understood that the centers and target nodes in this embodiment's application scenario constitute a tree structure.
[0093] Step S204: Generate exercise data based on the verification result of whether the target node has successfully accessed the wireless backup network based on the domain name of the backup center.
[0094] Compared to network-level drills in related technologies, which involve disconnecting the production wired lines of end nodes and verifying the switchover and revert by manual execution of business cases by the business department, this approach requires covering every node to ensure the effectiveness of all end node switches and reverts. This process is complex, labor-intensive, and can easily impact daily production operations, making it difficult to guarantee the effectiveness of the disaster recovery network. This embodiment uses the operator's 3G / 4G / 5G wireless network as the disaster recovery network. By leveraging the long-lived mode of the wireless network channel, it achieves seamless verification between end nodes and the primary / backup center. This effectively solves the problems of not being able to guarantee the effectiveness of the wireless disaster recovery link after a wired switch to a wireless disaster recovery network, excessive cost, and the inability to maintain normal production operations during end node drills. Furthermore, it combines traffic mirroring, information collection, and AAA authentication technologies to analyze the switching status of dial-in users, effectively improving drill efficiency.
[0095] Further, step S204 generates exercise data based on the verification result of whether the target node successfully accesses the wireless backup network based on the domain name of the backup center. Specifically, exercise data is generated based on the verification result of whether the target node successfully accesses the wireless backup network based on the domain name of the backup center and / or the verification result of whether the target node successfully accesses the wireless backup network based on the domain name of the primary center.
[0096] Please refer to Figure 4 , Figure 4 This is a flowchart illustrating another network-level disaster recovery drill method provided in this application embodiment. Based on the above embodiment, this embodiment adds a drill structure model and a visualization interface to further improve drill efficiency. Specifically, in addition to steps S201-S204 of the above embodiment, steps S401 and S402 are included before step S201.
[0097] Step S401: Obtain a pre-built exercise structure model, which includes a first node, intermediate nodes, and end nodes in a tree structure.
[0098] As can be understood, in this embodiment, the first node is the main center, the intermediate nodes are the provincial center or the city center, and in other embodiments, other centers may also be included. The end node is the target node or the terminal in the application scenario of this embodiment.
[0099] In one feasible approach, the exercise structure model is first constructed to define and divide organizational levels, combined with... Figure 1 As shown, this model reflects the hierarchical structure of an organization.
[0100] In the exercise structure model, attributes can be abstracted for organizations and terminals. Specifically, attributes of organizations and terminals can be defined to establish relationships between organizations and between organizations and terminals. For example, organization attributes include: name, number, parent group, and geographic location information; terminal attributes include: name, type, alias, geographic location, and whether it is enabled. Terminal attributes include, for instance... Figure 5a As shown.
[0101] Furthermore, the organization and terminal management interface can be visualized, using a tree structure to manage the organizational structure. It provides functions such as manually adding, editing, deleting, and batch importing / exporting information from multiple nodes at the same or different levels. Figure 5b As shown. Furthermore, terminal management supports the definition of terminal information under different organizational nodes, including functions for adding, deleting, modifying, querying, and batch importing / exporting node information from multiple nodes at the same or different levels, such as... Figure 5c As shown.
[0102] The above methods enable centralized management of AAA information for multiple sites, ultimately achieving nationwide network terminal wireless disaster recovery network to site verification and adaptation management. It can also be used as basic information to build a visual view.
[0103] Step S402: Based on the exercise structure model, determine the target node and main center for the disaster preparedness exercise. The target node is one or more of the end nodes, and the main center is one or more of the head node and / or the intermediate nodes.
[0104] In this embodiment, due to the division of the exercise structure model, the end nodes that need to be exercised and the corresponding main centers can be quickly determined, thereby improving the efficiency of disaster recovery network exercises.
[0105] In one implementation, step S402, which determines the target node and main center for the disaster recovery exercise based on the exercise structure model, may include the following steps:
[0106] The exercise structure model is displayed in a visualization interface, wherein the visualization interface is configured with visualization permissions;
[0107] The visualization interface receives selection information about the exercise structure model, and the target node and main center for disaster preparedness exercises are determined based on the selection information.
[0108] During actual drills, management users can select the corresponding drill nodes in real time through a visual interface and switch between nodes flexibly to improve the convenience and operability of the drills.
[0109] In this embodiment, during visualization, visualization permissions are set. For example, different centers' drill processes correspond to visualization views with different permissions. These views have specific permissions, ensuring view isolation between different users and preventing them from seeing each other, effectively protecting data security at each center. In one example, combined with... Figure 5d As shown, in the initial stage of the exercise, first define the name of the visualization interface view (if multiple centers need to be exercised, the view names corresponding to these multiple centers can be defined), then select the view permissions. When the management user has the view permissions, they can select the exercise organization scope under this view based on the centrally maintained organization information (exercise structure model), and select the Radius login service. Finally, the organization can be grouped and displayed in a table, the layout can be displayed, and the verification pass strategy can be defined.
[0110] Furthermore, during the construction of the visual interface, it can be based on data such as organizational information, AAA (user) information, and AAA login logs. The organizational and AAA information are maintained using the aforementioned organizational and terminal management description methods. The Radius login logs can be generated by bypassing the collection of business traffic and decoding it to produce Radius (remote network access authentication) transaction logs. These logs contain information such as the AAA username and whether the login was successful.
[0111] In one implementation, the following steps may also be included:
[0112] The visualization interface displays the verification process and results of verifying whether the target node has successfully accessed the wireless backup network based on the domain name of the backup center, using the connection information of the second terminal.
[0113] In this embodiment, the verification process of each target node accessing the backup center or the primary center is monitored through a visual interface. For example, its dialing status to the backup center or the primary center is displayed. Figure 5e As shown, it can be understood that the stations and outlets in the figure correspond to the target nodes in this embodiment.
[0114] It is understood that the interfaces and visual interfaces mentioned in various places in this embodiment may be the same interface or different interfaces, and this application does not make any special limitation on this.
[0115] This application also provides a network-level disaster recovery drill device, in which a wireless backup network connection is established between the target node and the primary center and the backup center using a multi-domain method. The backup wireless network connection is in a persistent-live mode, and the domain name priority of the primary center is higher than that of the backup center. Figure 6 As shown, the device includes:
[0116] Disconnect module 61, which is configured to disconnect the wireless backup network connection in response to a disaster recovery exercise request;
[0117] The first verification module 62 is configured to verify, in response to the first terminal connection information of the main center, whether the target node has successfully accessed the wireless backup network based on the domain name of the main center; if not, it obtains the second terminal connection information of the backup center.
[0118] The second verification module 63 is configured to verify, based on the second terminal connection information, whether the target node has successfully accessed the wireless backup network based on the domain name of the backup center.
[0119] The data generation module 64 is configured to generate exercise data based on the verification result of whether the target node has successfully accessed the wireless backup network based on the domain name of the backup center.
[0120] In one embodiment, the second terminal connection information carries the Radius remote dialing authentication service transaction log, and the second verification module 63 includes:
[0121] The first verification unit is configured to verify whether the AAA information in the Radius transaction log matches the AAA information of the target node;
[0122] The second verification unit is configured to verify, when a match is found, whether the login information corresponding to the AAA information of the target node indicates successful login.
[0123] The determination unit is configured to determine that, upon successful login, the target node has successfully accessed the wireless backup network based on the domain name of the backup center.
[0124] In one implementation, the first verification module includes:
[0125] The information acquisition unit is configured to acquire the authentication network traffic of the backup center based on network traffic mirroring technology, and acquire the connection information of the second terminal based on the authentication network traffic.
[0126] In one embodiment, the device further includes:
[0127] The acquisition module is configured to pre-acquire the AAA information of the target node and store the AAA information of the target node in the database;
[0128] The module is configured to call the AAA information of the target node in the database for verification when verifying the AAA information in the Radius transaction log.
[0129] In one embodiment, the device further includes:
[0130] The model acquisition module is configured to acquire a pre-built exercise structure model, which includes a tree-structured first node, middle nodes, and end nodes.
[0131] The determination module is configured to determine the target node and main center for disaster preparedness drills based on the drill structure model. The target node is one or more of the end nodes, and the main center is one or more of the head node and / or the intermediate nodes.
[0132] In one implementation, the determining module includes:
[0133] The display unit is configured to display the exercise structure model on a visualization interface, wherein the visualization interface has visualization permissions.
[0134] The receiving and determining unit is configured to receive selection information about the exercise structure model based on the visualization interface, and determine the target node and main center for disaster preparedness exercise based on the selection information.
[0135] In one embodiment, the device further includes:
[0136] The display module is configured to display on a visual interface the verification process and the verification result of verifying whether the target node has successfully accessed the wireless backup network based on the domain name of the backup center, based on the connection information of the second terminal.
[0137] This application also provides an electronic device, such as... Figure 7 As shown, it includes: a memory 71 and a processor 72;
[0138] The memory 71 stores computer-executed instructions;
[0139] The processor 72 executes the computer execution instructions stored in the memory 71, causing the electronic device to perform the network-level disaster recovery drill method.
[0140] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the network-level disaster recovery drill method.
[0141] This application also provides a computer program product, which includes computer program code. When the computer program code is run on a computer, it causes the computer to execute the network-level disaster recovery drill method.
[0142] This application also provides a chip, including a memory and a processor. The memory is used to store a computer program, and the processor is used to call and run the computer program from the memory to execute the network-level disaster recovery drill method.
[0143] Those skilled in the art will understand that all or some of the steps, systems, and apparatuses disclosed above, and their functional modules / units, can be implemented as software, firmware, hardware, or suitable combinations thereof. In hardware implementations, the division between functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed collaboratively by several physical components. Some or all physical components may be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit (ASIC). Such software can be distributed on a computer-readable medium, which may include computer storage media (or non-transitory media) and communication media (or transient media).
[0144] As is known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer.
[0145] Furthermore, as is known to those skilled in the art, communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.
[0146] In the description of the embodiments of this application, the term "and / or" merely indicates a relationship describing the associated objects, meaning that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the term "at least one" indicates any combination of at least two of a plurality of options, for example, including at least one of A, B, and C, which can represent any one or more elements selected from a set including communication between A, B, and C. Furthermore, the term "multiple" means two or more, unless otherwise precisely specified.
[0147] In the description of the embodiments of this application, the terms "first," "second," "third," "fourth," etc. (if present) are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0148] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
Claims
1. A network-level disaster recovery drill method, characterized in that, The target node establishes a wireless backup network connection with the primary center and the backup center using a multi-domain method. This wireless backup network connection is in a persistent-live mode, and the domain name priority of the primary center is higher than that of the backup center. The method includes: In response to a disaster recovery drill request, the wireless backup network connection between the target node and the main center is disconnected; In response to the first terminal connection information of the main center, verify whether the target node has successfully accessed the wireless backup network based on the domain name of the main center. If the target node has not successfully accessed the wireless backup network based on the domain name of the main center, obtain the second terminal connection information of the backup center. Based on the second terminal connection information, verify whether the target node has successfully accessed the wireless backup network based on the domain name of the backup center, and generate exercise data based on the verification result of whether the target node has successfully accessed the wireless backup network based on the domain name of the backup center; The step of obtaining the second terminal connection information of the backup center includes: The authentication network traffic of the backup center is obtained based on network traffic mirroring technology, and the connection information of the second terminal is obtained based on the authentication network traffic.
2. The method according to claim 1, characterized in that, The second terminal connection information carries the Radius remote dialing authentication service transaction log. The step of verifying whether the target node has successfully accessed the wireless backup network based on the domain name of the backup center, based on the second terminal connection information, includes: Verify whether the AAA information in the Radius transaction log matches the AAA information of the target node; If a match is found, then verify whether the login information corresponding to the AAA information of the target node indicates a successful login. If the login is successful, it is determined that the target node has successfully accessed the wireless backup network based on the domain name of the backup center.
3. The method according to claim 2, characterized in that, Before verifying whether the AAA information in the Radius transaction log matches the AAA information of the target node, the process also includes: The AAA information of the target node is collected in advance and stored in the database; When verifying the AAA information in the Radius transaction log, the AAA information of the target node in the database is called for verification.
4. The method according to claim 1, characterized in that, Before disconnecting the wireless backup network connection between the target node and the main center, the process also includes: Obtain a pre-built exercise structure model, which includes a tree-structured first node, intermediate nodes, and end nodes; Based on the exercise structure model, the target node and main center for disaster preparedness exercises are determined. The target node is one or more of the end nodes, and the main center is one or more of the head node and / or the intermediate nodes.
5. The method according to claim 4, characterized in that, The process of determining the target nodes and main center for disaster recovery drills based on the drill structure model includes: The exercise structure model is displayed in a visualization interface, wherein the visualization interface is configured with visualization permissions; The visualization interface receives selection information about the exercise structure model, and the target node and main center for disaster preparedness exercises are determined based on the selection information.
6. The method according to claim 1 or 5, characterized in that, Also includes: The visualization interface displays the verification process and results of verifying whether the target node has successfully accessed the wireless backup network based on the domain name of the backup center, using the connection information of the second terminal.
7. A network-level disaster recovery drill device, characterized in that, The target node establishes a wireless backup network connection with the primary center and the backup center using a multi-domain method. This wireless backup network connection is in a persistent-live mode, and the domain name priority of the primary center is higher than that of the backup center. The device includes: The disconnect module is configured to disconnect the wireless backup network connection between the target node and the main center in response to a disaster recovery exercise request. The first verification module is configured to respond to the first terminal connection information of the main center to verify whether the target node has successfully accessed the wireless backup network based on the domain name of the main center. If the target node has not successfully accessed the wireless backup network based on the domain name of the main center, it obtains the second terminal connection information of the backup center. The second verification module is configured to verify, based on the second terminal connection information, whether the target node has successfully accessed the wireless backup network based on the domain name of the backup center. The data generation module is configured to generate exercise data based on the verification result of whether the target node has successfully accessed the wireless backup network based on the domain name of the backup center; The first verification module is further configured to obtain the authentication network traffic of the backup center based on network traffic mirroring technology, and obtain the second terminal connection information based on the authentication network traffic.
8. An electronic device, characterized in that, include: Memory and processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the electronic device to perform the network-level disaster recovery drill method according to any one of claims 1-6.
9. A computer storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the network-level disaster recovery drill method as described in any one of claims 1-6.