A tunnel drainage method, device and storage medium based on security policies

By configuring security policies on the CPE device and matching the policy information of network traffic, and cache and detecting data link layer information, the data loss problem under the routing and drainage method is solved, and the complete forwarding of network traffic is achieved.

CN115632819BActive Publication Date: 2025-07-25BEIJING SHANGYUAN XINAN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211171652.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-26
Publication Date
2025-07-25
Estimated Expiration
2042-09-26

AI Technical Summary

Technical Problem

In the prior art, when traffic is drained through routing, data link layer information cannot be cached, resulting in data link layer information being lost when traffic returns, and subsequent forwarding processes cannot be continued.

Method used

Configure security policies on the CPE device, obtain policy information of network traffic and match it with the security policy. After the matching is successful, the network traffic is marked and the data link layer information is cached, and the traffic is directed to the cloud security resource pool for security detection. After the detection is passed, return to the CPE device and restore the data link layer information to continue the forwarding process.

Benefits of technology

The problem of the inability to cache data link layer information in the prior art is solved, and the complete forwarding process of network traffic is realized.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115632819B_ABST
    Figure CN115632819B_ABST
Patent Text Reader

Abstract

The present invention relates to a tunnel drainage method, device and storage medium based on security policies, which are applied in the field of traffic transmission technology. The method includes: configuring security policies on a CPE device, obtaining policy information of network traffic and matching it with the security policies. After successful matching, marking the network traffic and caching the data link layer information, leading the network traffic to a security resource pool in the cloud for security detection, and then returning it to the CPE device. The CPE device reads the identifier of the network traffic and restores the original data link layer information of the network traffic to continue the subsequent forwarding process. Through the above solution, the problem in the prior art that the data link layer information cannot be cached by the routing drainage method, resulting in the inability to continue the subsequent forwarding process, is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of traffic transmission, and in particular to a tunnel drainage method, device and storage medium based on security policies. Background Art

[0002] Network security devices are essential products for enterprises to ensure the security of their own network environments. Due to the variety of network security devices, if an enterprise adds a new type of security device, it needs to modify the current networking method, which increases the enterprise cost and the number of failure points. Therefore, it is necessary to divert traffic to the cloud security resource pool through tunnels for security protection.

[0003] The existing drainage method is achieved through routing. However, the routing method cannot cache the data link layer information of the traffic, resulting in the loss of data link layer information when the traffic returns and the inability to continue the subsequent forwarding process. Summary of the Invention

[0004] In view of this, the purpose of the present invention is to provide a tunnel drainage method, device and storage medium based on security policies to solve the problem in the prior art that when traffic is diverted through routing, the data link layer information of the traffic cannot be cached, resulting in the loss of data link layer information when the traffic returns and the inability to continue the subsequent forwarding process.

[0005] According to the first aspect of the embodiments of the present invention, a tunnel drainage method based on security policies is provided, including:

[0006] Configuring security policies for network traffic when passing through the CPE device in the network topology;

[0007] When network traffic passes through the CPE device, obtaining the policy information of the network traffic, matching the policy information of the network traffic with the security policy. If the match is successful, marking the network traffic and caching the data link layer information of the network traffic on the CPE device at the same time;

[0008] Diverting the network traffic to the security resource pool in the cloud through the first tunnel for security detection;

[0009] After the security detection is passed, sending the network information back to the CPE device through the second tunnel. The CPE device reads the mark and restores the data link layer information of the network traffic to continue the subsequent forwarding process.

[0010] Preferably,

[0011] The configuration of the security policy for network traffic when passing through includes:

[0012] Configuring the traffic ingress interface, traffic source address, traffic destination address and service type of the network traffic.

[0013] Preferably,

[0014] Obtaining the policy information of network traffic and matching the policy information of network traffic with the security policy includes:

[0015] Obtaining the traffic ingress interface, traffic source address, traffic destination address, and service type of the network traffic;

[0016] Judging whether the traffic ingress interface, traffic source address, traffic destination address, and service type match the pre-configured traffic ingress interface, traffic source address, traffic destination address, and service type;

[0017] If all the above conditions can be matched, the matching is successful.

[0018] Preferably,

[0019] When matching the traffic ingress interface, traffic source address, traffic destination address, and service type, it is a sequential match.

[0020] Preferably,

[0021] When matching the policy information of network traffic with the security policy, only the first packet of the network traffic is matched. After the matching is completed, the subsequent packets of the same flow are no longer matched.

[0022] Preferably,

[0023] When configuring the security policy for network traffic to pass through, the effective time of the security policy is also configured;

[0024] When obtaining the policy information of network traffic, the passing time of the network traffic is also obtained;

[0025] When matching the policy information of network traffic with the security policy, it is also judged whether the passing time of the network traffic is within the effective time of the pre-configured security policy. If so, the network traffic is drained to the security resource pool in the cloud through the first tunnel.

[0026] According to the second aspect of the embodiments of the present invention, a tunnel drainage device based on a security policy is provided, including:

[0027] A security policy configuration module: used to configure the security policy for network traffic to pass through in the CPE device of the network topology;

[0028] A security policy matching module: used to obtain the policy information of network traffic when the network traffic passes through the CPE device, match the policy information of network traffic with the security policy. If the matching is successful, the network traffic is marked, and at the same time, the data link layer information of the network traffic is cached on the CPE device;

[0029] Drainage module: used to drain the network traffic to the secure resource pool in the cloud through the first tunnel and perform security detection;

[0030] Information restoration module: used to send the network information back to the CPE device through the second tunnel after the security detection is passed. The CPE device reads the tag and restores the data link layer information of the network traffic to continue the subsequent forwarding process.

[0031] According to the third aspect of the embodiments of the present invention, a storage medium is provided. The storage medium stores a computer program, and when the computer program is executed by a processor, it implements each step in a tunnel drainage method based on a security policy as described above.

[0032] The technical solutions provided by the embodiments of the present invention may include the following beneficial effects:

[0033] In this application, by configuring a security policy on the CPE device, obtaining the policy information of the network traffic and matching it with the security policy. After successful matching, the network traffic is marked and the data link layer information is cached. After the network traffic is led to the secure resource pool in the cloud for security detection, it is then returned to the CPE device. The CPE device reads the identifier of the network traffic and restores the original data link layer information of the network traffic to continue the subsequent forwarding process. Through the above solution, the problem in the prior art that the data link layer information cannot be cached by the routing drainage method, resulting in the inability to continue the subsequent forwarding process, is solved.

[0034] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] The drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present invention and used together with the specification to explain the principles of the present invention.

[0036] Figure 1 is a flowchart showing a tunnel drainage method based on a security policy according to an exemplary embodiment;

[0037] Figure 2 is a system diagram showing a tunnel drainage device based on a security policy according to another exemplary embodiment;

[0038] In the drawings: 1 - Security policy configuration module, 2 - Security policy matching module, 3 - Drainage module, 4 - Information restoration module. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0039] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present invention as detailed in the appended claims.

[0040] Embodiment 1

[0041] Figure 1 is a schematic flow chart of a tunnel drainage method based on a security policy shown according to an exemplary embodiment, as Figure 1 shown, including:

[0042] S1, Configure a security policy when network traffic passes through the CPE device in the network topology;

[0043] S2, When network traffic passes through the CPE device, obtain the policy information of the network traffic, match the policy information of the network traffic with the security policy. If the match is successful, mark the network traffic, and at the same time cache the data link layer information of the network traffic on the CPE device;

[0044] S3, Drain the network traffic to the security resource pool in the cloud through the first tunnel and perform security detection;

[0045] S4, After the security detection passes, send the network information back to the CPE device through the second tunnel. The CPE device reads the mark and restores the data link layer information of the network traffic to continue the subsequent forwarding process;

[0046] It can be understood that in this application, by configuring a security policy on the CPE device, obtaining the policy information of the network traffic and matching it with the security policy, after the match is successful, marking the network traffic and caching the data link layer information, leading the network traffic to the security resource pool in the cloud for security detection and then returning to the CPE device. The CPE device reads the identifier of the network traffic and restores the original data link layer information of the network traffic to continue the subsequent forwarding process. Through the above solution, the problem in the prior art that the data link layer information cannot be cached by the routing drainage method, resulting in the inability to continue the subsequent forwarding process, is solved;

[0047] It should be noted that the CPE device (Customer Premise Equipment) is a customer-premises device. The main function of the CPE is to receive WIFI signals, while the main function of a wireless router is to transmit WIFI signals. A wireless CPE is a WIFI signal receiver. Its main function is to receive WIFI signals and then transmit network signals to a computer through an Ethernet cable and can be used independently. The device mode of the wireless CPE is relatively simple. By default, it can receive various WIFI signals, with a "foolish" usage mode. A wireless router, on the other hand, is equivalent to a WIFI signal transmitter. Its main function is to transmit WIFI signals, and devices such as mobile phones, tablets, and wireless network cards can receive its WIFI signals and then connect to the Internet.

[0048] Preferably,

[0049] The security policies when the configured network traffic passes through include:

[0050] Configuring the traffic incoming interface, traffic source address, traffic destination address, and service type of the network traffic;

[0051] It can be understood that in order to identify and distinguish each network traffic, it is necessary to perform matching verification of network traffic, including the traffic incoming interface, traffic source address, traffic destination address, and service type. It should be noted that in the prior art, when using routing for tunnel drainage, the routing cannot identify the service type, while the CPE device can achieve the identification of the service type.

[0052] Preferably,

[0053] Obtaining the policy information of the network traffic and matching the policy information of the network traffic with the security policy includes:

[0054] Obtaining the traffic incoming interface, traffic source address, traffic destination address, and service type of the network traffic;

[0055] Judging whether the traffic incoming interface, traffic source address, traffic destination address, and service type match the pre-configured traffic incoming interface, traffic source address, traffic destination address, and service type;

[0056] If all the above conditions can be matched, the matching is successful;

[0057] It can be understood that after presetting the security policy for the network traffic to be diverted, when network traffic passes through the CPE device, the CPE device obtains the traffic ingress interface, traffic source address, traffic destination address, and service type of the network traffic. After obtaining them, it matches them with the traffic ingress interface, traffic source address, traffic destination address, and service type in the preset security policy. If all of them can be matched, the data link layer information of the network traffic is cached, and then the corresponding tunnel processing function is called for diversion processing.

[0058] Preferably,

[0059] When matching the traffic ingress interface, traffic source address, traffic destination address, and service type, it is a sequential match;

[0060] It can be understood that when performing security policy matching, it is a sequential match, that is, the order of matching the traffic ingress interface, traffic source address, traffic destination address, and service type is fixed. For example, first match the traffic ingress interface, and then match the traffic source address, and perform the matching in the preset order.

[0061] Preferably,

[0062] When matching the policy information of the network traffic with the security policy, only the first packet of the network traffic is matched. After the matching is completed, the subsequent packets of the same flow are no longer matched;

[0063] It can be understood that in order to reduce the time for security policy matching, since the packets of the same flow, that is, the policy information of the network traffic is the same, then when matching, only the first packet needs to be matched, and it is not necessary to match all the packets.

[0064] Preferably,

[0065] When configuring the security policy for the passing of network traffic, the effective time of the security policy is also configured;

[0066] When obtaining the policy information of the network traffic, the passing time of the network traffic is also obtained;

[0067] When matching the policy information of the network traffic with the security policy, it is also judged whether the passing time of the network traffic is within the effective time of the pre-configured security policy. If so, the network traffic is diverted to the secure resource pool in the cloud through the first tunnel;

[0068] It can be understood that the user can also set the effective time of the policy. That is, after the policy information is matched, the effective time still needs to be verified. For example, if the effective time of the policy is set from 5 o'clock to 8 o'clock, even if the traffic ingress interface, traffic source address, traffic destination address, and service type can all be matched, but the traffic passes at 4 o'clock, the tunnel drainage function will not be started for drainage either.

[0069] Embodiment 2

[0070] This embodiment also discloses a system schematic diagram of a tunnel drainage device based on a security policy, as shown in the appendix Figure 2 shown, including:

[0071] Security policy configuration module 1: used to configure the security policy when network traffic passes through the CPE device in the network topology structure;

[0072] Security policy matching module 2: used to obtain the policy information of network traffic when the network traffic passes through the CPE device, match the policy information of the network traffic with the security policy, if the match is successful, mark the network traffic, and at the same time cache the data link layer information of the network traffic on the CPE device;

[0073] Drainage module 3: used to drain the network traffic to the security resource pool in the cloud through the first tunnel and perform security detection;

[0074] Information restoration module 4: used to send the network information back to the CPE device through the second tunnel after the security detection passes, the CPE device reads the mark, and restores the data link layer information of the network traffic to continue the subsequent forwarding process;

[0075] It can be understood that this embodiment also discloses a tunnel drainage device based on a security policy. The security policy configuration module 1 configures the security policy when network traffic passes through the CPE device in the network topology structure; the security policy matching module 2 obtains the policy information of network traffic when the network traffic passes through the CPE device, matches the policy information of the network traffic with the security policy, if the match is successful, marks the network traffic, and at the same time caches the data link layer information of the network traffic on the CPE device; the drainage module 3 drains the network traffic to the security resource pool in the cloud through the first tunnel and performs security detection; the information restoration module 4 is used to send the network information back to the CPE device through the second tunnel after the security detection passes, the CPE device reads the mark, and restores the data link layer information of the network traffic to continue the subsequent forwarding process; through the above solution, the problem in the prior art that the data link layer information cannot be cached by the routing drainage method, resulting in the inability to continue the subsequent forwarding process, is solved.

[0076] Embodiment 3

[0077] This embodiment also discloses a storage medium storing a computer program, which, when executed by a processor, implements each step in a tunneling drainage method based on a security policy as described above.

[0078] It can be understood that the same or similar parts in the above embodiments can be referred to each other, and the content not described in detail in some embodiments can be found in the same or similar content in other embodiments.

[0079] It should be noted that in the description of the present invention, the terms "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or implying relative importance. In addition, in the description of the present invention, unless otherwise specified, the meaning of "a plurality of" refers to at least two.

[0080] Any process or method description shown in the flowchart or described in other ways herein can be understood as representing a module, segment, or part of code including one or more executable instructions for implementing a specific logical function or process. The scope of the preferred embodiments of the present invention includes additional implementations, where the functions can be executed in a substantially simultaneous manner or in the reverse order according to the functions involved, rather than in the order shown or discussed. This should be understood by those skilled in the technical field to which the embodiments of the present invention belong.

[0081] It should be understood that each part of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following well-known technologies in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.

[0082] Those of ordinary skill in the art in this technical field can understand that all or part of the steps carried by the methods in the above embodiments can be completed by instructing relevant hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiments.

[0083] In addition, in each embodiment of the present invention, each functional unit may be integrated into a processing module, may exist separately as individual physical units, or two or more units may be integrated into one module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. When the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.

[0084] The above-mentioned storage medium may be a read-only memory, a magnetic disk or an optical disc, etc.

[0085] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.

[0086] Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.

Claims

1. A tunnel drainage method based on security policies, characterized in that, Including: Configuring a security policy when network traffic passes through a CPE device in a network topology; When network traffic passes through the CPE device, obtaining the policy information of the network traffic, matching the policy information of the network traffic with the security policy. If the match is successful, mark the network traffic, and at the same time cache the data link layer information of the network traffic on the CPE device; Draining the network traffic to a security resource pool in the cloud through a first tunnel and performing security detection; After the security detection passes, sending the network information back to the CPE device through a second tunnel. The CPE device reads the mark and restores the data link layer information of the network traffic to continue the subsequent forwarding process.

2. The method according to claim 1, characterized in that: The configuring of the security policy when network traffic passes through includes: Configuring the traffic ingress interface, traffic source address, traffic destination address, and service type of the network traffic.

3. The method according to claim 2, characterized in that: Obtaining the policy information of the network traffic and matching the policy information of the network traffic with the security policy includes: Obtaining the traffic ingress interface, traffic source address, traffic destination address, and service type of the network traffic; Judging whether the traffic ingress interface, traffic source address, traffic destination address, and service type match the pre-configured traffic ingress interface, traffic source address, traffic destination address, and service type; If all the above conditions can be matched, the match is successful.

4. The method according to claim 3, characterized in that: When matching the traffic ingress interface, traffic source address, traffic destination address, and service type, it is sequential matching.

5. The method according to claim 4, characterized in that: When matching the policy information of the network traffic with the security policy, only the first packet of the network traffic is matched. After the match is completed, the subsequent packets of the same flow are no longer matched.

6. The method according to claim 2, characterized in that: When configuring the security policy when network traffic passes through, the effective time of the security policy is also configured; When obtaining the policy information of the network traffic, the passing time of the network traffic is also obtained; When matching the policy information of the network traffic with the security policy, it is also judged whether the passing time of the network traffic is within the effective time of the pre-configured security policy. If so, the network traffic is drained to the security resource pool in the cloud through the first tunnel.

7. A tunnel diversion device based on a security policy, characterized in that, The device includes: A security policy configuration module: used to configure a security policy when network traffic passes through a CPE device in a network topology; A security policy matching module: used to obtain the policy information of the network traffic when network traffic passes through the CPE device, match the policy information of the network traffic with the security policy. If the match is successful, mark the network traffic, and at the same time cache the data link layer information of the network traffic on the CPE device; A drainage module: used to drain the network traffic to a security resource pool in the cloud through a first tunnel and perform security detection; Information restoration module: After passing the security detection, it is used to send network information back to the CPE device through the second tunnel. The CPE device reads the tag and restores the data link layer information of the network traffic to continue the subsequent forwarding process.

8. A storage medium, characterized in that, The storage medium stores a computer program, and when the computer program is executed by a processor, it implements each step in a tunnel drainage method based on a security policy as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Method and system for CPE (Customer Premises Equipment) to realize Internet surfing through two WAN (Wide Area Network) ports

    CN105721298A

  • Network transmission method, device and system for mobile network services

    CN109151916A