Container-based network security implementation system and method

By designing a container-based network security implementation system in the Kubevirt environment, using security policy modules, control modules and proxy modules, the access control problem between virtual machines is solved, and more efficient virtual machine network security management is achieved.

CN115622748BActive Publication Date: 2025-05-23SUZHOU SICUI IND INTERNET TECH RES INST CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211171644.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-26
Publication Date
2025-05-23
Estimated Expiration
2042-09-26

AI Technical Summary

Technical Problem

In the Kubevirt environment, the existing Network Policy cannot effectively implement access control between virtual machines, resulting in a degradation of the security performance of virtual machines.

Method used

A container-based network security implementation system is designed, including security policy module, control module and proxy module. By listening to the security policy resources created by users, generating and applying security policies, binding them to virtual machine pods, and issuing security policies to linux bridges through proxy modules to achieve access control between virtual machines.

Benefits of technology

This system can ignore the differences between virtual machine systems, network types and network plug-ins, set network security policies for virtual machines, improve the security performance of virtual machines, and meet the network security management needs of running virtual machines in containers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115622748B_ABST
    Figure CN115622748B_ABST
Patent Text Reader

Abstract

The present invention particularly relates to a network security implementation system and method based on containers. In the network security implementation system and method based on containers, the security policy module monitors the security policy resources, and generates relevant security policies according to the resource information when monitoring the user to initiate a resource creation request; at the same time, a virtual machine is created through kubevirt, the virtual machine runs in the form of Pod, and the virtual machine is bound to the security policy; the control module interacts with the proxy module, is responsible for monitoring the virtual machine Pod, and calls the proxy module to perform corresponding operations when obtaining security policy related information; the proxy module is inside the virtual machine Pod, and sends security policies to the Linux bridge according to the instructions of the control module. The network security implementation system and method based on containers can ignore the differences in virtual machine systems, network types, and network plug-ins in the container, set network security policies for the virtual machine, and meet the network security management requirements of running virtual machines in containers.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of kubevirt virtual machine network security, and in particular to a network security implementation system and method based on a container. Background Art

[0002] Kubernetes is a portable and extensible open source platform. As the current mainstream container management platform, Kubernetes is used to manage containerized workloads and services, which can promote declarative configuration and automation. Moreover, Kubernetes has a large and rapidly growing ecosystem, and Kubernetes services, support and tools are widely available.

[0003] Kubevirt is a virtual machine management plugin for Kubernetes. Its purpose is to provide a common foundation for virtualization solutions based on Kubernetes. At its core, Kubevirt extends Kubernetes by adding additional virtualization resource types (especially VM types) through the Kubernetes custom resource definition API. By using this mechanism, the Kubernetes API can manage these VM resources together with all other resources provided by Kubernetes.

[0004] The virtual machine created under Kubevirt runs in the Kubernetes Pod. During the creation of the Kubernetes Pod where the virtual machine is located, cni (Container Network Interface) will pay attention to all resources related to network resource changes in Kubernetes. When the Pod is created, cni configures specific network information for the container, such as IP, MAC, etc., and then writes it back to the Kubernetes resources in the form of annotations. cni completes the creation of veth pairs on the physical machine where the Pod is located, one end of which is linked to the physical machine and the other end is in the network space of the container.

[0005] When creating a virtual machine container, a Linux bridge and a tap port will be created. Connect the veth pair port in the container to the Linux bridge, and then connect the newly created tap port to the Linux bridge. Then use the tap port as the network port to start the virtual machine to start the virtual machine, and complete the creation of the virtual machine.

[0006] Currently, Kubernetes can use Network Policy to implement access control between Pods. Network Policy is a Kubernetes resource that takes effect through processes such as definition, storage, and configuration. The specific process for implementing access control is as follows: create Network Policy resources through the Kubernetes client; calico's policy-controller listens to Network Policy resources, and writes them to calico's etcd database after obtaining them; calico will install an agent on each node, and calico-felix in the agent will obtain policy resources from the etcd database and call iptables to make corresponding configurations (refer to the attached Figure 1 ).

[0007] For security reasons, access control must also be implemented between virtual machines created under kubevirt. However, Network Policy is limited by fixed network plug-ins. In some scenarios, access control between virtual machines cannot be implemented through Network Policy, which greatly reduces the security performance of virtual machines.

[0008] Based on this, the present invention proposes a container-based network security implementation system and method. Summary of the invention

[0009] In order to overcome the deficiencies of the prior art, the present invention provides a simple and efficient container-based network security implementation system and method.

[0010] The present invention is achieved through the following technical solutions:

[0011] A container-based network security implementation system, characterized by: comprising a security policy module, a control module and an agent module;

[0012] The security policy module monitors the security policy resources and generates relevant security policies according to the resource information when monitoring the user to initiate a resource creation request;

[0013] At the same time, a virtual machine is created through kubevirt, which runs as a Pod and is bound to the security policy.

[0014] The control module interacts with the proxy module, is responsible for monitoring the virtual machine Pod, and calls the proxy module to perform corresponding operations when obtaining security policy related information;

[0015] The proxy module is inside the virtual machine Pod and sends security policies to the Linux bridge according to the instructions of the control module.

[0016] The container-based network security implementation method of the present invention is characterized by comprising the following steps:

[0017] Step S01: Create a kubernetes custom resource through the kubernetes client and use it as a security policy resource to configure security policies for the virtual machine;

[0018] Step S02: Set a default security policy and create corresponding security policy resources. All virtual machines have access rights to the default security policy.

[0019] Step S03: while configuring security policies other than the default security policy, create security policy resources and configure resource information;

[0020] Step S04: specifying entry and exit rules in the security policy resource information;

[0021] The entry rules specify a list of rules that the virtual machine is allowed to enter, and the rules allow messages whose Ethernet type, IP protocol, source address, destination address and port are within the specified range to enter the virtual machine;

[0022] The egress rule specifies a list of egress rules allowed by the virtual machine, and the rules allow messages whose Ethernet type, IP protocol, source address, destination address and port are within the specified range to be sent from the virtual machine;

[0023] Step S05: After the configuration of security policy resource information is completed, a request to create a custom resource is initiated through the Kubernetes client to the API Server (Kubernetes' important management API layer). After receiving the request, the API Server writes the custom resource information into the Kubernetes etcd.

[0024] Step S06: The security policy module monitors the custom resources, and when a user initiates a request to create a resource, generates a relevant security policy based on the resource information;

[0025] Step S07: Create a virtual machine in the Node through kubevirt, select one of the security policies and the network card where the security policy takes effect, and create a virtual machine Pod;

[0026] Step S08: cni completes the creation of a veth pair on the physical machine where the virtual machine Pod is located, one end of which is linked to the physical machine and the other end is in the network space of the container;

[0027] Step S09: while creating the container of the virtual machine, create a linux bridge and a tap type port;

[0028] Connect the veth pair port in the container to the Linux bridge, and then connect the newly created tap port to the Linux bridge. Then use the tap port as the network port to start the virtual machine to complete the creation of the virtual machine Pod.

[0029] In the step S07, when creating the virtual machine Pod, the selected security policy and network card information are written into the virtual machine Pod in the form of annotations, and the virtual machine is bound to the security policy.

[0030] In step S07, the control module monitors the security policy and network card information in the virtual machine Pod, and after obtaining the security policy and the network card information, calls the proxy module to issue the security policy.

[0031] In the step S08, the cni is not limited to a fixed network plug-in.

[0032] In step S09, the proxy module sends the bound security policy to the linux bridge in the virtual machine Pod. One end of the linux bridge is connected to the veth pair port and the other end is connected to the tap port. If the virtual machine has multiple network cards, multiple linux bridges are connected.

[0033] When the virtual machine Pod receives or sends messages, they will pass through the Linux bridge. The security policy on the Linux bridge filters the messages to implement access control of the virtual machines under kubevirt.

[0034] The beneficial effects of the present invention are as follows: the container-based network security implementation system and method can ignore the differences in virtual machine systems, network types, and network plug-ins in the container, set network security policies for the virtual machines, and meet the network security management requirements of running virtual machines in containers. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0036] Attached Figure 1 A diagram of the access control architecture for Network Policy to implement Pods.

[0037] Attached Figure 2 This is a schematic diagram of a container-based network security implementation method of the present invention.

[0038] Attached Figure 3 The figure is a schematic diagram of the container-based network security system architecture of the present invention.

[0039] Attached Figure 4 This is a schematic diagram of the mutual access effect between vm1 and vm2 of the present invention. DETAILED DESCRIPTION

[0040] In order to enable those skilled in the art to better understand the technical solutions in the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

[0041] On the edge cloud platform, when the virtual machines created by kubevirt use the Network Policy in kubernetes to manage the virtual machines securely, the following problems exist: the virtual machine control granularity is not fine enough, it is limited by fixed network plug-ins, and the complex security policies in the node host are not conducive to operation and maintenance.

[0042] The container-based network security implementation system method includes a security policy module, a control module and an agent module;

[0043] The security policy module monitors the security policy resources and generates relevant security policies according to the resource information when monitoring the user to initiate a resource creation request;

[0044] At the same time, a virtual machine is created through kubevirt, which runs as a Pod and is bound to the security policy.

[0045] The control module interacts with the proxy module, is responsible for monitoring the virtual machine Pod, and calls the proxy module to perform corresponding operations when obtaining security policy related information;

[0046] The proxy module is inside the virtual machine Pod and sends security policies to the Linux bridge according to the instructions of the control module.

[0047] The container-based network security implementation method comprises the following steps:

[0048] Step S01: Create a kubernetes custom resource through the kubernetes client and use it as a security policy resource to configure security policies for the virtual machine;

[0049] Step S02: Set a default security policy and create corresponding security policy resources. All virtual machines have access rights to the default security policy.

[0050] Step S03: while configuring security policies other than the default security policy, create security policy resources and configure resource information;

[0051] Step S04: specifying entry and exit rules in the security policy resource information;

[0052] The entry rules specify a list of rules that the virtual machine is allowed to enter, and the rules allow messages whose Ethernet type, IP protocol, source address, destination address and port are within the specified range to enter the virtual machine;

[0053] The egress rule specifies a list of egress rules allowed by the virtual machine, and the rules allow messages whose Ethernet type, IP protocol, source address, destination address and port are within the specified range to be sent from the virtual machine;

[0054] Step S05: After the configuration of security policy resource information is completed, a request to create a custom resource is initiated through the Kubernetes client to the API Server (Kubernetes' important management API layer). After receiving the request, the API Server writes the custom resource information into the Kubernetes etcd.

[0055] Step S06: The security policy module monitors the custom resources, and when a user initiates a request to create a resource, generates a relevant security policy based on the resource information;

[0056] Step S07: Create a virtual machine in the Node through kubevirt, select one of the security policies and the network card where the security policy takes effect, and create a virtual machine Pod;

[0057] Step S08: cni completes the creation of a veth pair on the physical machine where the virtual machine Pod is located, one end of which is linked to the physical machine and the other end is in the network space of the container;

[0058] Step S09: while creating the container of the virtual machine, create a linux bridge and a tap type port;

[0059] Connect the veth pair port in the container to the Linux bridge, and then connect the newly created tap port to the Linux bridge. Then use the tap port as the network port to start the virtual machine to start the virtual machine and complete the creation of the virtual machine Pod.

[0060] In the step S07, when creating the virtual machine Pod, the selected security policy and network card information are written into the virtual machine Pod in the form of annotations, and the virtual machine is bound to the security policy.

[0061] In step S07, the control module monitors the security policy and network card information in the virtual machine Pod, and after obtaining the security policy and the network card information, calls the proxy module to issue the security policy.

[0062] In the step S08, the cni is not limited to a fixed network plug-in.

[0063] In step S09, the proxy module sends the bound security policy to the linux bridge in the virtual machine Pod. One end of the linux bridge is connected to the veth pair port and the other end is connected to the tap port. If the virtual machine has multiple network cards, multiple linux bridges are connected.

[0064] When the virtual machine Pod receives or sends messages, they will pass through the Linux bridge. The security policy on the Linux bridge filters the messages to implement access control of the virtual machines under kubevirt.

[0065] Attached Figure 4 This is a diagram showing the effect of vm1 and vm2 accessing each other. In the figure, an egress rule is added to vm1's Linux bridge to allow vm1 to access vm2, and an ingress rule is added to vm2's Linux bridge to allow vm1 to access vm2; vm1 has the right to access vm2, but due to the lack of an egress rule, vm2's packets to vm1 are discarded, and it has no right to access vm1.

[0066] Compared with the existing technology, the container-based network security implementation system and method has the following characteristics:

[0067] (1) In the kubevirt scenario, it supports network security management in containers, supports custom security policy resources, and deploys security policies inside containers to support access control between virtual machines, meeting the network security management requirements in containers.

[0068] (2) Security policies are deployed inside the container, and the differences between virtual machine systems can be ignored during network security management, thus meeting the network security management needs of virtual machines in different systems.

[0069] (3) It reduces the complexity of security policies in the node host and ignores the differences in network types and network plug-ins, providing network security management for all virtual machines.

[0070] The embodiment described above is only one specific implementation of the present invention. Common changes and substitutions made by those skilled in the art within the scope of the technical solution of the present invention should be included in the protection scope of the present invention.

Claims

1. A container-based network security implementation method, Features: The steps include: Step S01: Create a kubernetes custom resource through the kubernetes client and use it as a security policy resource to configure security policies for the virtual machine; Step S02: Set a default security policy and create corresponding security policy resources. All virtual machines have access rights to the default security policy. Step S03: while configuring security policies other than the default security policy, create security policy resources and configure resource information; Step S04: specifying entry and exit rules in the security policy resource information; Step S05: After the security policy resource information is configured, a request to create a custom resource is initiated to the API Server through the Kubernetes client. After receiving the request, the API Server writes the custom resource information into the etcd of Kubernetes. Step S06: The security policy module monitors the custom resources, and when a user initiates a request to create a resource, generates a relevant security policy based on the resource information; Step S07: Create a virtual machine in the Node through kubevirt, select one of the security policies and the network card where the security policy takes effect, and create a virtual machine Pod; Step S08: cni completes the creation of a veth pair on the physical machine where the virtual machine Pod is located, one end of which is linked to the physical machine and the other end is in the network space of the container; Step S09: while creating the container of the virtual machine, create a linux bridge and a tap type port; Connect the veth pair port in the container to the Linux bridge, and then connect the newly created tap port to the Linux bridge. Then use the tap port as the network port to start the virtual machine to start the virtual machine and complete the creation of the virtual machine Pod.

2. The method for implementing network security based on a container according to claim 1, Features: The entry rules specify the list of rules that the virtual machine is allowed to enter. The rules allow packets with Ethernet type, IP protocol, source address, destination address and port within the specified range to enter the virtual machine; The egress rule specifies a list of egress rules allowed by the virtual machine, and the rules allow messages whose Ethernet type, IP protocol, source address, destination address and port are within the specified range to be sent from the virtual machine.

3. The method for implementing network security based on a container according to claim 1, Features: In the step S07, when creating the virtual machine Pod, the selected security policy and network card information are written into the virtual machine Pod in the form of annotations, and the virtual machine is bound to the security policy.

4. The method for implementing network security based on a container according to claim 3, Features: In step S07, the control module monitors the security policy and network card information in the virtual machine Pod, and after obtaining the security policy and the network card information, calls the proxy module to issue the security policy.

5. The method for implementing network security based on a container according to claim 1, Features: In the step S08, the cni is not limited to a fixed network plug-in.

6. The container-based network security implementation method according to claim 1 or 4, Features: In step S09, the proxy module sends the bound security policy to the linux bridge in the virtual machine Pod. One end of the linux bridge is connected to the veth pair port and the other end is connected to the tap port. If the virtual machine has multiple network cards, multiple linux bridges are connected.

7. The method for implementing network security based on a container according to claim 6, Features: When the virtual machine Pod receives or sends messages, they all pass through the Linux bridge. The security policy on the Linux bridge filters the messages to implement access control of the virtual machines under kubevirt.

8. A network security implementation system based on containers, Features: Used to implement the method described in any one of claims 1 to 7, comprising a security policy module, a control module and an agent module; The security policy module monitors the security policy resources and generates relevant security policies according to the resource information when monitoring the user to initiate a resource creation request; At the same time, a virtual machine is created through kubevirt, which runs as a Pod and is bound to the security policy. The control module interacts with the proxy module, is responsible for monitoring the virtual machine Pod, and calls the proxy module to perform corresponding operations when obtaining security policy related information; The proxy module is inside the virtual machine Pod and sends security policies to the Linux bridge according to the instructions of the control module.

Citation Information

Patent Citations

  • Multi-cluster network security policy management and control method and system

    CN112615856A

  • User demand-oriented security function service network system and implementation method thereof

    CN112822192A