Micro-isolation method, apparatus and related device

By receiving and comparing the topology and log information of network elements, and using the micro-segmentation security management platform for traffic control, the problem of normal processes in virtual networks being tampered with is solved, achieving micro-segmentation without the need for host agents and ensuring network security.

CN115733627BActive Publication Date: 2025-12-09CHINA MOBILE COMM LTD RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110986758.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-08-26
Publication Date
2025-12-09
Estimated Expiration
2041-08-26

AI Technical Summary

Technical Problem

During micro-segmentation, the normal processes of the virtual network are at high risk of being tampered with by the host agent. Existing technologies require the installation of host agent software on the virtual machine to obtain the highest privileges to access topology information, which poses a security risk.

Method used

By receiving topology and log information from network elements, and comparing them using a micro-segmentation security management platform, it is determined whether to perform isolation operations, avoiding the need to install host agents on virtual machines and directly controlling traffic at the network layer.

Benefits of technology

It enables micro-segmentation without installing a host agent on the virtual machine, avoiding the risk of normal virtual network processes being tampered with, and without affecting the performance and resources of the host and virtual machine.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115733627B_ABST
    Figure CN115733627B_ABST
Patent Text Reader

Abstract

The application provides a micro-isolation method, device and related equipment, wherein the method comprises receiving first information, comparing the received first information with reference information to obtain a comparison result, and determining whether to perform an isolation operation on traffic of a target flow direction according to the comparison result. In the embodiment of the application, the first device receives the first information, then compares the received first information with the reference information to obtain a comparison result, and finally determines whether to perform an isolation operation on traffic of a target flow direction according to the comparison result. In this way, the micro-isolation of the target flow direction traffic can be realized without installing a host agent on a virtual machine. Thus, the situation that the normal process of a virtual network is tampered with by a host agent due to the fact that the host agent needs to obtain the highest authority to obtain the topology information of a network element from the virtual machine is avoided, and the problem that the normal process of a virtual network is tampered with in the micro-isolation process is solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of network security, and in particular to a micro-isolation method and device and related equipment. BACKGROUND

[0002] In order to solve the east-west isolation of data centers, the industry has proposed a micro-isolation solution. Micro-isolation is a network isolation technology with finer granularity, which can meet the needs of east-west traffic isolation in traditional environments, virtualization environments, hybrid cloud environments, and container environments, and is mainly used to prevent attackers from moving east-west after entering the data center network.

[0003] Currently, micro-isolation can be implemented using a host agent. A host agent software is installed on each virtual machine, and the host agent needs to obtain the highest privilege to obtain the topology information of the network element from the virtual machine, which has the risk of tampering with the normal process of the virtual network by the host agent. That is, there is a problem of tampering with the normal process of the virtual network in the micro-isolation process. SUMMARY

[0004] The embodiments of the present application provide a micro-isolation method, device and related equipment, which solve the problem of tampering with the normal process of the virtual network in the micro-isolation process.

[0005] To achieve the above-mentioned purpose, in a first aspect, the embodiments of the present application provide a micro-isolation method applied to a first device, comprising:

[0006] Receiving first information, the first information comprising at least one of the following: first topology information of a network element, second topology information of a second device corresponding to the network element, and log information of the network element;

[0007] Comparing the first information with reference information to obtain a comparison result;

[0008] According to the comparison result, determining whether to perform an isolation operation on traffic of a target flow direction.

[0009] In a second aspect, the embodiments of the present application provide a micro-isolation method applied to a first network element, the first network element comprising an OSS, an OMC and an NFVO, comprising:

[0010] Sending second information to a first device, the second information comprising at least one of the following: first topology information of the first network element, second topology information of a second device corresponding to the first network element, and log information of the first network element.

[0011] In a third aspect, the embodiments of the present application provide a micro-isolation method applied to a third device, comprising:

[0012] receive a third sub-subscription request sent by the first device, the third sub-subscription request being used to request to acquire the log information;

[0013] send the log information to the first device.

[0014] In a fourth aspect, an embodiment of the present application provides a micro-isolation device, comprising:

[0015] a first transceiver, configured to receive first information, the first information comprising at least one of the following: first topology information of a network element, second topology information of a second device, log information of the network element, the second device corresponding to the network element;

[0016] a first processor, configured to compare the first information with reference information to obtain a comparison result;

[0017] determine whether to perform an isolation operation on traffic of a target flow direction according to the comparison result.

[0018] In a fifth aspect, an embodiment of the present application provides a micro-isolation device, comprising:

[0019] a second transceiver, configured to send second information to a first device, the second information comprising at least one of the following: first topology information of a first network element, second topology information of a second device corresponding to the first network element, log information of the first network element.

[0020] In a sixth aspect, an embodiment of the present application provides a micro-isolation device, comprising:

[0021] a third transceiver, configured to receive a third sub-subscription request sent by a first device, the third sub-subscription request being used to request to acquire log information;

[0022] send the log information to the first device.

[0023] In a seventh aspect, an embodiment of the present application provides a communication device, comprising a transceiver, a memory, a processor, and a program stored in the memory and capable of running on the processor; the processor is configured to read the program in the memory to implement steps in the micro-isolation method according to the first aspect; or steps in the micro-isolation method according to the second aspect; or steps in the micro-isolation method according to the third aspect.

[0024] In an eighth aspect, an embodiment of the present application provides a readable storage medium, configured to store a program, the program being executed by a processor to implement steps in the micro-isolation method according to the first aspect; or steps in the micro-isolation method according to the second aspect; or steps in the micro-isolation method according to the third aspect.

[0025] In the embodiments of the present application, the first device receives the first information, then compares the received first information with the reference information to obtain a comparison result, and finally determines whether to perform the isolation operation on the traffic of the target flow direction according to the comparison result. In this way, the micro-isolation of the traffic of the target flow direction can be implemented without installing the host agent on the virtual machine. Thus, the situation that the normal process of the virtual network is tampered by the host agent due to the fact that the host agent needs to obtain the highest permission to obtain the topology information of the network element from the virtual machine is avoided, and the problem that the normal process of the virtual network is tampered in the micro-isolation process is solved. BRIEF DESCRIPTION OF DRAWINGS

[0026] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings of the specification are described as follows. Obviously, the following drawings are only embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of the listed drawings.

[0027] Figure 1 is a structural schematic diagram of a network system to which the embodiments of the present application can be applied;

[0028] Figure 2 is one of the flow schematic diagrams of the micro-isolation method provided by the embodiments of the present application;

[0029] Figure 3 is the second flow schematic diagram of the micro-isolation method provided by the embodiments of the present application;

[0030] Figure 4 is the third flow schematic diagram of the micro-isolation method provided by the embodiments of the present application;

[0031] Figure 5 is the fourth flow schematic diagram of the micro-isolation method provided by the embodiments of the present application;

[0032] Figure 6 is the fifth flow schematic diagram of the micro-isolation method provided by the embodiments of the present application;

[0033] Figure 7 is the sixth flow schematic diagram of the micro-isolation method provided by the embodiments of the present application;

[0034] Figure 8 is a structural schematic diagram of the micro-isolation management platform provided by the embodiments of the present application;

[0035] Figure 9 is one of the structural schematic diagrams of the micro-isolation device provided by the embodiments of the present application;

[0036] Figure 10 is the second structural schematic diagram of the micro-isolation device provided by the embodiments of the present application;

[0037] Figure 11Figure 3 is a structural schematic diagram of a micro-isolation device according to an embodiment of the present application;

[0038] Figure 12 Figure 4 is a structural schematic diagram of a communication device according to an embodiment of the present application. DETAILED DESCRIPTION

[0039] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work are within the scope of protection of the present application.

[0040] The terms "first", "second", and the like in the embodiments of the present application are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to include only those steps or units clearly listed, but can include other steps or units that are not clearly listed or inherent to the process, method, product or device. In addition, "and / or" is used in the present application to represent at least one of the connected objects, for example, A and / or B and / or C represents 7 cases including A alone, B alone, C alone, A and B both exist, B and C both exist, A and C both exist, and A, B and C all exist.

[0041] Referring to Figure 1 , Figure 1 Figure 1 is a structural diagram of a network system to which the embodiments of the present application can be applied. The network system to which the embodiments of the present application can be applied includes a first device 11, a first network element 12 and a third device 13.

[0042] The first device 11 can be a micro-isolation security management platform, and the third device 12 can be a log server. The first network element 12 includes an operation and maintenance center (OMC), a network function virtualization orchestrator (NFVO) and a receiving operation support system (OSS).

[0043] The first device 11 can communicate with the OMC, the NFVO, the OSS, and the third device 13. Specifically, the communication between the first device 11 and the OMC, the NFVO, and the OSS can be implemented by adding interfaces between the first device 11 and the OMC, the NFVO, the OSS, and the third device 13. The first device 11 can obtain the topology information and the log information of the network element from the OSS, the NFVO, and the OMC. The third device 13 can communicate with the network function virtualization (NFV) infrastructure to obtain the log information of the network element.

[0044] The present application combines the characteristics of the cloud-based telecommunications network and proposes a micro-isolation method. The micro-isolation method can utilize the topology information and the log information on the existing OSS, NFVO, and OMC to monitor and isolate the target traffic in the cloud-based telecommunications network data center. The micro-isolation method does not require a host agent or a security virtual machine, does not need to modify the network, and does not affect the performance and resources of the host and the virtual machine. The following will be described in detail.

[0045] Referring to Figure 2 , Figure 2 is one of the flow diagrams of the micro-isolation method provided by the embodiments of the present application. Figure 2 The micro-isolation method shown in the figure can be executed by a micro-isolation security management platform 11. The micro-isolation security management platform 11 can be a first device.

[0046] As shown in Figure 2 , the micro-isolation method can include the following steps:

[0047] Step 201, receiving first information, the first information including at least one of the following: first topology information of a network element, second topology information of a second device, log information of the network element, the second device corresponding to the network element;

[0048] In step 201, the network element can include all network elements in the monitored virtual network, and the first topology information can include at least one of the following: a source Internet Protocol (IP) address, a destination IP address, a source port, a destination port, a communication protocol, and the name of a virtual machine corresponding to each network element. According to the source IP address, the destination IP address, the source port, and the destination port of the network element, the first device can determine the port opening status of each network element in the network element, and other network elements that can communicate with each network element.

[0049] The above-mentioned second device can include at least one of a virtual machine and a host, each network element can have one or more virtual machines corresponding thereto, and each virtual machine can implement a specific function of the network element, such as a receiving function, a data storage function, and a forwarding function. The second topology information can include at least one of the following: the correspondence between the network element and the virtual machine, the correspondence between the virtual machine and the host, the name of the virtual machine, and the name of the host.

[0050] The log information can include at least one of the following: a communication time between network elements, a source port corresponding to the communication time, a destination port, a source IP address, a destination IP address, and a communication protocol. The log information records the source port, the destination port, the communication protocol, the communication peer address (the source IP address and the destination IP address), and the communication time of the communication between the network elements, and the communication time corresponds to the source port, the destination port, the communication protocol, and the communication peer address.

[0051] The first device 11 can receive first information sent by the network element, and the first topology information, the second topology information, and the log information in the first information can be sent to the first device 11 by the OMC, the NFVO, and the OSS in the network element. The log information in the first information can also be sent to the first device 11 by the third device 13, which can obtain the log information from the OMC in the network element.

[0052] Step 202, comparing the first information with reference information to obtain a comparison result;

[0053] The first device compares the received first information with the reference information, which can directly compare the first information and the reference information one by one, such as comparing whether the network connection relationship in the first information is the same as the network connection relationship in the reference information, comparing whether the port opening situation of the network element in the first information is the same as the port opening situation of the network element in the reference information, and the like. If the contents of the first information and the reference information are the same, the comparison result can be determined as no change of the first information relative to the reference information; if the contents of the first information and the reference information are not completely the same, the change of the first information relative to the reference information can be further determined, so as to determine the comparison result.

[0054] The first device compares the received first information with the reference information, which can also determine the network connection baseline and the port opening baseline corresponding to the first information according to the first information, and compare the network connection baseline and the port opening baseline determined according to the first information with the network connection baseline and the port opening baseline as the reference information.

[0055] Step 203, determining whether to perform an isolation operation on the traffic of the target flow direction according to the comparison result.

[0056] In specific implementation, in the case that the comparison result is that the first information has no change relative to the reference information, the traffic of the target flow direction does not need to be isolated; in the case that the comparison result is that the first information has changed relative to the reference information, and the change is abnormal, the traffic of the target flow direction needs to be isolated. The target flow direction can be east-west, but is not limited thereto.

[0057] The isolation operation can be implemented in the following manner. Manner one: the micro-isolation security management platform calls an OSS interface, an NFVO interface, and a VIM northbound interface, calls a northbound interface of an SDN controller through the VIM northbound interface, and sends a security policy to the SDN controller; the micro-isolation security platform can also directly call the VIM northbound interface through the NFVO, and the VIM calls the northbound interface of the SDN controller to distribute the security policy. The SDN controller converts the security policy into a flow table and distributes it to a virtual switch, and blocks abnormal traffic on the virtual switch. Manner two: the isolation operation can also be performed manually, that is, an administrator checks abnormal alarms of the micro-isolation security management platform, checks the alarms, logs in the VIM, calls the northbound interface of the SDN controller to distribute the security policy, and blocks abnormal traffic by the virtual switch.

[0058] In the embodiment of the application, the first device receives the first information, then compares the received first information with reference information to obtain a comparison result, and finally determines whether to perform an isolation operation on the traffic of the target flow direction according to the comparison result. In this way, the micro-isolation of the traffic of the target flow direction can be implemented without installing a host agent on the virtual machine. Thus, the situation that the normal process of the virtual network is tampered with by the host agent after the host agent obtains the highest permission to obtain the topology information of the network element from the virtual machine is avoided, and the problem that the normal process of the virtual network is tampered with in the micro-isolation process is solved.

[0059] Optionally, the determining whether to perform the isolation operation on the traffic of the target flow direction according to the comparison result comprises:

[0060] In a case where the comparison result is that the first information has a new target object relative to the reference information, it is determined whether the target object meets a first condition, and the target object includes at least one of the following: a network element, a port, and a network connection.

[0061] In a case where the target object does not meet the first condition, it is determined to perform the isolation operation on the traffic of the target flow direction.

[0062] The first condition includes at least one of the following:

[0063] The new network element is a registered network element.

[0064] The new port is a registered port.

[0065] The new network connection is a registered network connection.

[0066] In a specific implementation, whenever there is a new network element in the network, or a port of a new network element is opened, or a new network connection is established, the new network element, the port of the new network element, or the new network connection needs to be registered on the micro-isolation security management platform first. If the registration is successful, it means that the added network element, the added port, and the added network connection are legitimate. After receiving the first information, the micro-isolation management platform compares the first information with the reference information. If the comparison result is that there is an added network element, and / or port, and / or network connection relative to the reference information, it needs to be further determined whether the added network element, and / or port, and / or network connection is a registered network element, and / or port, and / or network connection. If the added target object is registered, the reference information can be updated, and the information of the added target object can be added to the reference information. When an unregistered network element, and / or unregistered port, and / or unregistered network connection, etc. is found, the micro-isolation security management platform generates an alarm, and the isolation operation on the target flow traffic can be further determined.

[0067] It should be noted that when the micro-isolation security management platform finds an abnormal network connection (for example, an AMF is connected to a newly built virtual machine that does not belong to the AMF) or an abnormal port (for example, the AMF opens a port outside the port baseline), an alarm information is issued. The alarm information at least includes an abnormal network element identifier, a virtual machine identifier corresponding to the abnormal network element, a location, and a virtual machine where the abnormal port is located, a network element corresponding to the abnormal port, etc. The isolation operation on the target flow traffic can be that the security policy function of the micro-isolation security management platform generates a security policy, such as blocking all traffic of a virtual machine on a host or blocking traffic of a port of a virtual machine on a host, etc. Then the security policy is converted into a flow table by the SDN control, and is delivered to a virtual switch on a host where the abnormal virtual machine is located. Finally, the virtual switch disposes the traffic according to the flow table.

[0068] Regarding that the first device 11 receives the first information, in a specific implementation, the OMC can collect the first topology information of the network element and the log information of the network element, and the NFVO can collect the second topology information. The OMC and the NFVO can report the information collected by them to the OSS. The first device can obtain the first topology information and the second topology information from the OSS, the OMC, and the NFVO. The first device can obtain the log information from the OMC or the log server.

[0069] As an example, the receiving the first information includes:

[0070] The first topology information and the second topology information sent by an operation support system (OSS) are received. The first topology information is obtained by the OSS from an operation and maintenance center (OMC), and the second topology information is obtained by the OSS from a network function virtualization orchestrator (NFVO).

[0071] receiving the log information sent by a third device, the third device being a log server or an OMC of the network element.

[0072] As another example, the receiving the first information comprises:

[0073] receiving the first topology information sent by an operation and maintenance center (OMC) of the network element;

[0074] receiving the second topology information sent by a network function virtualization orchestrator (NFVO) of the network element;

[0075] receiving the log information sent by a third device, the third device being a log server or an OMC of the network element.

[0076] Optionally, before the receiving the first information, the method further comprises:

[0077] sending a subscription request, the subscription request being used to request to acquire the first topology information, the second topology information and the log information.

[0078] In a specific implementation, the first device can send a subscription request to the log server to acquire the log information of the network element. The first device can also send a subscription request to the OMC to acquire the first topology information of the network element, and send a subscription request to the NFVO to acquire the second topology information of the network element. The first device can also send a subscription request to the OSS to acquire the first topology information and the second topology information of the network element. The first device can also send a subscription request to the OMC to acquire the log information of the network element. It should be noted that the log information of the network element in the log server is forwarded to the log server by the OMC. After the first device sends the subscription request, the device receiving the subscription request can report the subscribed information to the first device at a certain time interval, the subscribed information being the first topology information, the second topology information and the log information.

[0079] As another example, before the receiving the first information, the method further comprises:

[0080] sending a fourth sub-subscription request to the OSS, the fourth sub-subscription request being used to request to acquire the first topology information and the second topology information;

[0081] sending a fifth sub-subscription request to a third device, the fifth sub-subscription request being used to request to acquire the log information.

[0082] The third device can be the log server.

[0083] As another example, before the receiving the first information, the method further comprises:

[0084] sending a first sub-subscription request to the OMC, the first sub-subscription request being used to request to acquire the first topology information;

[0085] sending a second sub-subscription request to the NFVO, the second sub-subscription request being used to request to acquire the second topology information;

[0086] sending a third sub-subscription request to a third device, the third sub-subscription request being used to request to acquire the log information.

[0087] The third device can be a log server.

[0088] The reference information can be open port conditions of each network element in the network element, connection relationships between each network element in the network element, correspondence relationships between the network element and the virtual machine, and connection relationships between the virtual networks, which are determined by the first device according to the first information received in a historical time period. Further, the first device can generate a network connection baseline and a port open baseline as content of the reference information according to the first information received in the historical time period. In the case where the reference information includes the network connection baseline and the port open baseline generated according to the first information received in the historical time period, when the first information is compared with the reference information, the network connection baseline and the port open baseline corresponding to the first information need to be determined according to the first information received by the first device in real time, and then the network connection baseline and the port open baseline corresponding to the first information are compared with the network connection baseline and the port open baseline in the reference information.

[0089] In the case where the device manufacturer provides a network connection list and a port list, the micro-isolation security management platform can also sort out a network connection list including connection relationships between each network element and a port list including open port conditions of each network element according to the received first information, and compare the network connection list and the port list sorted out according to the first information with the network connection list and the port list preset by the device manufacturer. When the two are consistent, the current network connection relationship and the port open state can be generated as the network connection baseline and the port open baseline as content of the reference information.

[0090] In addition to the above-mentioned manner of determining the reference information, the reference information can also be determined by the following manner. Before the received first information is compared with the reference information to obtain a comparison result, the method further includes:

[0091] P pieces of first information received in a first historical time period are acquired, P being a positive integer;

[0092] In the case where the P pieces of first information are all the same, baseline information corresponding to the P pieces of first information is determined as the reference information, the baseline information including a network connection baseline and a port open baseline determined according to the P pieces of first information.

[0093] In a specific implementation, in a stable service running scenario, the micro-isolation security management platform determines that the connection relationship between the network elements, the opening situation of each network element port, the correspondence between each network element and virtual machine, and the connection relationship of the virtual network are all the same in a first historical period, such as a week, according to the received first information. Therefore, the current network connection relationship and port opening state can be generated as the network connection baseline and port opening baseline as the content of the reference information. The specific length of the above first historical period is related to the specific scenario, and can be determined according to the specific scenario.

[0094] The micro-isolation method provided in the present application is described below with two complete examples.

[0095] As an example, referring to Figure 3 In this scenario, the first device can be a micro-isolation security management platform. The OMC can first report the first topology information to the OSS, and the NFVO can first report the second topology information to the OSS. Then the micro-isolation security management platform subscribes to the first topology information and the second topology information from the OSS. Then, the OMC and the NFVO can report the first topology information and the second topology information to the OSS in real time, respectively. After receiving the updated topology information, the OSS can report it to the micro-isolation security management platform in real time. It should be noted that after the OSS receives the subscription request, it can report the first topology information and the second topology information at the current time to the micro-isolation management platform at certain time intervals.

[0096] The micro-isolation security management platform can subscribe to log information from the log server, and the log server can report log information to the micro-isolation management platform at certain time intervals.

[0097] The micro-isolation security management platform can determine the reference information according to the first information received in the historical period. The reference information can include the opening port situation of each network element in the network element, the connection relationship between each network element in the network element, the correspondence between the network element and the virtual machine, and the connection relationship between the virtual networks. Further, the first device can generate the network connection baseline and the port opening baseline as the content of the reference information according to the first information received in the historical period.

[0098] The micro-isolation security management platform compares the real-time received first information with the reference information. In the case that the newly added target object in the first information meets the first condition, the reference information is updated, that is, the network connection baseline and the port opening baseline. In the case that the newly added target object in the first information does not meet the first condition, the micro-isolation security management platform alarms and generates a security policy.

[0099] The micro-isolation security management platform sends the security policy to the SDN controller by calling the OSS interface, calling the NFVO interface, and then calling the VIM northbound interface, and calling the northbound interface of the SDN controller through the VIM northbound interface. The micro-isolation security platform can also directly call the VIM northbound interface through the NFVO, and the VIM calls the northbound interface of the SDN controller to issue the security policy. The SDN controller converts the security policy into a flow table and issues it to the virtual switch, and the virtual switch executes the actions of the flow table, so as to block the abnormal traffic on the virtual machine on the virtual switch.

[0100] As another example, see Figure 4 In this scenario, the first device can be a micro-isolation security management platform. The micro-isolation security management platform can subscribe to the first topology information and the second topology information from the OMC and the NFVO respectively, and the OMC and the NFVO can report the first topology information and the second topology information to the micro-isolation security management platform after receiving the subscription request. It should be noted that after the OMC and the NFVO receive the subscription request, they can report the first topology information and the second topology information to the micro-isolation management platform at a certain time interval.

[0101] The micro-isolation security management platform can subscribe to the log information from the log server, and the log server can report the log information to the micro-isolation management platform at a certain time interval.

[0102] The micro-isolation security management platform can determine reference information according to the first information received in the historical time period. The reference information can include the open port situation of each network element in the network element, the connection relationship between each network element in the network element, the correspondence between the network element and the virtual machine, and the connection relationship between the virtual networks. Further, the first device can generate a network connection baseline and a port opening baseline as the content of the reference information according to the first information received in the historical time period.

[0103] The micro-isolation security management platform compares the first information received in real time with the reference information. In the case that the target object newly added in the first information meets the first condition, the reference information is updated, that is, the network connection baseline and the port opening baseline. In the case that the target object newly added in the first information does not meet the first condition, the micro-isolation security management platform alarms and generates a security policy.

[0104] The micro-isolation security management platform sends the security policy to the SDN controller by calling the OSS interface, calling the NFVO interface, and then calling the VIM northbound interface, and calling the northbound interface of the SDN controller through the VIM northbound interface. The micro-isolation security platform can also directly call the VIM northbound interface through the NFVO, and the VIM calls the northbound interface of the SDN controller to issue the security policy. The SDN controller converts the security policy into a flow table and issues it to the virtual switch, and the virtual switch executes the action of the flow table, so as to block the abnormal traffic on the virtual machine on the virtual switch.

[0105] Referring to Figure 5 , Figure 5 is a second flowchart of a micro-isolation method provided by the embodiment of the application. Figure 5 The micro-isolation method shown in the figure can be executed by a first network element.

[0106] As shown in Figure 5 , the micro-isolation method can include the following steps:

[0107] Step 401, sending second information to a first device, the second information including at least one of the following: first topology information of the first network element, second topology information of a second device corresponding to the first network element, log information of the first network element.

[0108] It should be noted that the first network element represents each of the above network elements. The set of second information sent by each first network element in the network element to the first device is the first information.

[0109] Optionally, the sending of the second information to the first device includes:

[0110] sending the first topology information to the first device through the OMC;

[0111] sending the second topology information to the first device through the NFVO.

[0112] Optionally, the sending of the second information to the first device includes:

[0113] sending the first topology information and the second topology information to the first device through the OSS, the first topology information being obtained by the OSS from the OMC, and the second topology information being obtained by the OSS from the NFVO.

[0114] Optionally, the sending of the second information to the first device includes:

[0115] sending the log information to the first device through the OMC.

[0116] Optionally, before sending the second information to the first device, the method further includes:

[0117] The system receives a subscription request sent by the first device, the subscription request being used to request the acquisition of the first topology information, the second topology information, and the log information.

[0118] Optionally, receiving the subscription request sent by the first device includes:

[0119] The OMC receives a first sub-subscription request sent by the first device, the first sub-subscription request being used to request the first topology information;

[0120] The NFVO receives a second sub-subscription request sent by the first device, the second sub-subscription request being used to request the acquisition of the second topology information.

[0121] Optionally, receiving the subscription request sent by the first device includes:

[0122] The OSS receives a fourth sub-subscription request sent by the first device, the fourth sub-subscription request being used to request the acquisition of the first topology information and the second topology information.

[0123] Optionally, receiving the subscription request sent by the first device includes:

[0124] The OMC receives a third sub-subscription request sent by the first device, the third sub-subscription request being used to request the log information.

[0125] It should be noted that this embodiment is as a comparison with... Figure 2 The implementation method of the first network element corresponding to the method embodiment can therefore be found in the following examples. Figure 2 The relevant descriptions in the method embodiments can achieve the same beneficial effects. To avoid repetition, they will not be repeated here.

[0126] See Figure 6 , Figure 6 This is the third flowchart of the micro-isolation method provided in the embodiments of the present invention. Figure 6 The micro-isolation method shown can be performed by a third device.

[0127] like Figure 6 As shown, the micro-segmentation method may include the following steps:

[0128] Step 501: Receive a third sub-subscription request sent by the first device, wherein the third sub-subscription request is used to request log information;

[0129] Step 502: Send log information to the first device.

[0130] It should be noted that the embodiment is used as the method embodiment Figure 2 The method embodiment corresponds to the third device, and therefore, the related description of the method embodiment can be referred to, and the same beneficial effects can be achieved. To avoid repeated description, no longer description is made here. Figure 2 The method embodiment corresponds to the third device, and therefore, the related description of the method embodiment can be referred to, and the same beneficial effects can be achieved. To avoid repeated description, no longer description is made here.

[0131] The various optional embodiments introduced in the embodiment of the application can be combined with each other to be implemented in the case of not conflicting with each other, or can be implemented alone, and the embodiment of the application is not limited thereto.

[0132] For the convenience of understanding, the example is described as follows:

[0133] The micro-isolation security protection framework is based on the existing cloud-based telecommunication network architecture, and a micro-isolation security management platform is added, and an interface between the micro-isolation security management platform and OSS, OMC, NFVO, and a log server. Specifically:

[0134] Network topology reporting: OMC reports the first topology information (at least including the IP address of the virtualized network element, the open port, the protocol used by the open port, the opposite end IP address communicated by the open port, the virtual machine name contained by the virtualized network element, etc.) of the collected network element to OSS, and NFVO collects the virtual machine name and the host name information of the virtual machine from VIM;

[0135] Network topology subscription: The micro-isolation security management platform subscribes to the first topology information and the second topology information to OSS or directly to OMC and NFVO.

[0136] Log acquisition: The micro-isolation security management platform acquires the log information of the network element from the log server. The log information can be directly sent by the network element to the log server, or the network element forwards the log to the log server through OMC. The content of the log at least includes the port, the protocol, the communication opposite end address, the communication time, etc.

[0137] East-west traffic monitoring: In the initial learning stage, the micro-isolation security management platform combs the connection relationship of network elements, the opening situation of each network element port, the correspondence between network elements and virtual machines, the connection relationship of the network, and the like according to the acquired first topology information, second topology information and log information, and forms a network connection baseline and a port opening baseline according to the real-time acquired first topology information, second topology information and log information, which are used as the basis for security monitoring. For example, when the connection relationship of network elements, the port opening situation, the correspondence between network elements and virtual machines, and the connection relationship of virtual networks displayed on the micro-isolation security management platform do not change in a period (such as a week) under the condition that the service is stably running, it is considered that the learning has reached stability, and the current network connection and port opening state can be used as the baseline. In the scene where the network connection list and the port list are provided by the device manufacturer, the network connection baseline and the port opening baseline can also be generated by comparing the planned network connection list and the port list provided by the device manufacturer with the learned network connection and port opening state. In the monitoring stage, whether there is an abnormal connection and an abnormal port is checked according to the information obtained from the log server, OSS or OMC and NFVO. For example, when a new VNF is instantiated, a new port is opened, and a new network connection is established, they need to be registered on the micro-isolation security management platform. After successful registration, the new virtualized network element, the new opened port and the new network connection are considered to be a legal network element, a port and a network connection, and the security baseline is updated. When it is found that there is an unregistered virtual machine or an unregistered virtualized network element, or a port of a certain virtualized network element is unregistered, or a certain virtualized network element makes a connection outside the baseline, they are all defined as abnormal, and the micro-isolation security management platform generates an alarm.

[0138] East-west traffic security handling: The micro-isolation security management platform can locate the specific VNF, the corresponding virtual machine and host, and the five-tuple information of abnormal traffic according to the detected network connection or port abnormality. The micro-isolation security platform can call the VIM northbound interface through the NFVO, the VIM calls the SDN controller northbound interface, and the security policy is issued. The SDN controller converts the security policy into a flow table and issues it to the virtual switch, and the abnormal traffic on the virtual machine is blocked on the virtual switch. The security handling can also be performed manually, that is, the administrator checks the abnormal alarm of the micro-isolation security management platform, checks the alarm, logs in the VIM, calls the SDN controller northbound interface to realize the issuance of the security policy, and the virtual switch blocks the abnormal traffic.

[0139] (2) Micro-isolation security protection process

[0140] Referring to Figure 7 , the process of micro-isolation security protection is as follows:

[0141] 0.OMC and NFVO report the network element topology information (i.e., first topology information) and the IT infrastructure topology information (i.e., second topology information) to the OSS, respectively. The network element topology information at least contains the IP address of the virtualized network element, the open port, the corresponding virtual machine and virtual machine name, the host name where the virtual machine is located, and other virtualized network elements connected to the virtualized network element, etc. The IT infrastructure topology information at least contains the virtual machine name and the host name corresponding to the virtual machine, etc.

[0142] 1.The micro-isolation security management platform subscribes to the network element topology and IT infrastructure topology information from the OSS. The micro-isolation security management platform can also directly subscribe to the network element topology and IT infrastructure topology information from the OMC and NFVO, respectively (as shown in step 1').

[0143] 2.The micro-isolation security management platform subscribes to the network element log information from the log server.

[0144] 3.OMC and NFVO report the network element topology information and the IT infrastructure topology information to the OSS, respectively.

[0145] 4.After the OSS receives the updated topology information, it reports it to the micro-isolation security management platform in real time. When the micro-isolation security management platform directly subscribes to the topology information from the OMC and NFVO, respectively, the OMC and NFVO will report the network element topology and the IT infrastructure topology information to the micro-isolation security management platform in real time, respectively (as shown in step 4').

[0146] 5.The log server reports the network element log to the micro-isolation security management platform

[0147] 6. The micro-isolation security management platform learns the network connection baseline and port opening baseline according to the acquired topology information and log information, including combing the connection relationship of the virtualized network element, the port opening situation, the correspondence between the virtualized network element and the virtual machine, the host, the connection relationship of the virtual network, etc. according to the acquired topology and log information, and continuously correcting the network connection and port opening information according to the real-time acquired topology information and log information until reaching stability, forming the network connection baseline and the port opening baseline (for example, when the connection relationship of the virtualized network element, the port opening situation, the correspondence between the virtualized network element and the virtual machine, the connection relationship of the virtual network, etc. displayed on the micro-isolation security management platform do not change in a period (such as one week) under the condition that the service is stably running, it is considered that the learning has reached stability, and the current network connection and port opening state can be taken as the baseline; in the scene that the network cloud vendor provides the network connection list and the port list, the planned network connection list and the port list provided by the network cloud vendor can also be compared, and when the learned network connection and port opening state are consistent with those provided by the vendor, the network connection baseline and the port opening baseline can be generated). Thereafter, the cloud-based telecommunication network enters the micro-isolation security monitoring stage, and steps 4 (or 4’) and 5 are repeated.

[0148] 7. After receiving the topology information and the log, the micro-isolation platform compares with the network connection baseline and the port baseline to check whether there is an abnormal connection and an abnormal port. When the micro-isolation security management platform finds that there is a new VNF added or reduced, and there is a corresponding virtual machine and a service port added or reduced, it will determine that it is a legal VNF addition or reduction, and give a prompt to update the baseline, which can be automatically updated after manual confirmation; or it can be directly automatically updated without manual confirmation. The baseline update needs to be recorded in the log.

[0149] Note: In the cloud-based telecommunication network, all assets are operator assets, and the reliability of the network is at least 5 nines, so the security baseline is automatically updated after manual confirmation to avoid affecting the service due to automatic update of the baseline by mistake.

[0150] 8. When the micro-isolation security management platform finds an abnormal network connection (such as that the AMF connects a newly built virtual machine which does not belong to the AMF) or an abnormal port (such as that the AMF opens a port outside the port baseline), an alarm is generated, which at least includes the abnormal VNF identifier, the corresponding virtual machine identifier, the location, and the virtual machine where the abnormal port is located, the corresponding VNF, etc. The security policy function of the micro-isolation security management platform generates a security policy, such as blocking all traffic of a virtual machine on a host or blocking the traffic of a port of a virtual machine on a host, etc.

[0151] 9. The micro-isolation security management platform sends the security policy to the SDN controller by invoking the OSS interface, the NFVO interface, and the VIM northbound interface, and invoking the northbound interface of the SDN controller through the VIM northbound interface. The micro-isolation security management platform can also directly invoke the NFVO northbound interface, invoke the VIM northbound interface through the NFVO, and then invoke the northbound interface of the SDN controller to send the security policy (as shown in step 9').

[0152] 10. The SDN controller converts the security policy into a flow table before sending it to the virtual switch on the host where the abnormal virtual machine is located.

[0153] 11. The virtual switch processes the traffic according to the flow table.

[0154] (3) Micro-isolation security management platform device

[0155] Referring to Figure 8 , the micro-isolation security management platform includes a subscription module, a topology and log acquisition module, a learning and monitoring module, a baseline management module, an alarm module, and a security policy management module. The above modules are described in detail as follows.

[0156] Subscription module: responsible for subscribing to network element topology and IT infrastructure topology information from the OSS or directly subscribing to network element topology and IT infrastructure topology information from the OMC and NFVO respectively; responsible for subscribing to network element log information from the log server.

[0157] Topology and log acquisition module: responsible for acquiring network element topology and IT infrastructure topology information from the OSS or directly acquiring network element topology and IT infrastructure topology information from the OMC and NFVO respectively; responsible for acquiring network element log information from the log server.

[0158] Learning and monitoring module: responsible for learning the connection relationship of virtualized network elements, port opening situation, correspondence between virtualized network elements and virtual machines, host, and connection relationship of virtual networks according to the acquired network element, infrastructure topology, and network element log information, and finally forming network connection baseline and port opening baseline; responsible for monitoring whether there is an abnormal network connection and port opening according to the acquired network element, infrastructure topology, and network element log information.

[0159] Baseline management module: responsible for storing the baseline and providing baseline query and update for the learning and monitoring module.

[0160] Alarm module: responsible for alarming abnormal network connection and / or abnormal port.

[0161] Security policy management module: responsible for generating a security policy and sending it to the SDN controller.

[0162] Referring toFigure 9 , Figure 9 is a structural diagram of a micro-isolation device provided by an embodiment of the present application. As shown in Figure 9 , the micro-isolation device 700 includes:

[0163] a first transceiver 701, configured to receive first information, the first information including at least one of the following: first topology information of a network element, second topology information of a second device, log information of the network element, the second device corresponding to the network element;

[0164] a first processor 702, configured to compare the first information with reference information to obtain a comparison result;

[0165] determine whether to perform an isolation operation on traffic of a target flow direction according to the comparison result.

[0166] Optionally, the first processor 702 includes:

[0167] in a case where the comparison result is that there is a new target object in the first information relative to the reference information, determine whether the target object meets a first condition, the target object including at least one of the following: a network element, a port and a network connection;

[0168] in a case where the target object does not meet the first condition, determine to perform the isolation operation on the traffic of the target flow direction;

[0169] wherein the first condition includes at least one of the following:

[0170] the new network element is a registered network element;

[0171] the new port is a registered port;

[0172] the new network connection is a registered network connection.

[0173] Optionally, the first transceiver 701 includes:

[0174] receive the first topology information sent by an operation and maintenance center (OMC) of the network element;

[0175] receive the second topology information sent by a network function virtualization orchestrator (NFVO) of the network element;

[0176] receive the log information sent by a third device, the third device being a log server or the OMC of the network element.

[0177] Optionally, the first transceiver 701 includes:

[0178] receive the first topology information and the second topology information sent by an operation support system (OSS), wherein the first topology information is acquired by the OSS from an OMC, and the second topology information is acquired by the OSS from a network function virtualization orchestrator (NFVO);

[0179] receive the log information sent by a third device, wherein the third device is a log server or an OMC of the network element.

[0180] Optionally, before the first transceiver 701, the apparatus 700 further comprises:

[0181] send a subscription request, wherein the subscription request is used to request to acquire the first topology information, the second topology information and the log information.

[0182] Optionally, the sending of the subscription request comprises:

[0183] send a first sub-subscription request to an OMC, wherein the first sub-subscription request is used to request to acquire the first topology information;

[0184] send a second sub-subscription request to a NFVO, wherein the second sub-subscription request is used to request to acquire the second topology information;

[0185] send a third sub-subscription request to a third device, wherein the third sub-subscription request is used to request to acquire the log information.

[0186] Optionally, the sending of the subscription request comprises:

[0187] send a fourth sub-subscription request to an OSS, wherein the fourth sub-subscription request is used to request to acquire the first topology information and the second topology information;

[0188] send a fifth sub-subscription request to a third device, wherein the fifth sub-subscription request is used to request to acquire the log information.

[0189] Optionally, before the first processor 702, the apparatus 700 further comprises:

[0190] acquire P first information received in a first historical time period, wherein P is a positive integer;

[0191] in a case where the P first information are all same, determine a baseline information corresponding to the P first information as the reference information, wherein the baseline information comprises a network connection baseline and a port opening baseline determined according to the P first information.

[0192] The micro-isolation apparatus 700 can realize the various processes of the method embodiments in the present application Figure 2 The various processes of the method embodiments and the same beneficial effects are not repeated here to avoid repetition.

[0193] Referring to Figure 10 , Figure 10 is a structural diagram of a micro-isolation device provided by an embodiment of the present application. As shown in Figure 10 , the micro-isolation device 800 includes:

[0194] The second transceiver 801 is configured to: send second information to the first device, the second information including at least one of the following: first topology information of the first network element, second topology information of a second device corresponding to the first network element, log information of the first network element.

[0195] Optionally, the second transceiver 801 includes:

[0196] sending the first topology information to the first device through the OMC;

[0197] sending the second topology information to the first device through the NFVO.

[0198] Optionally, the second transceiver 801 includes:

[0199] sending the first topology information and the second topology information to the first device through the OSS, the first topology information being acquired by the OSS from the OMC, and the second topology information being acquired by the OSS from the NFVO.

[0200] Optionally, the second transceiver 801 includes:

[0201] sending log information to the first device through the OMC.

[0202] Optionally, before the second transceiver 801, the device 800 further includes:

[0203] receiving a subscription request sent by the first device, the subscription request being used to request to acquire the first topology information, the second topology information, and the log information.

[0204] Optionally, the receiving the subscription request sent by the first device includes:

[0205] receiving a first sub-subscription request sent by the first device through the OMC, the first sub-subscription request being used to request to acquire the first topology information;

[0206] receiving a second sub-subscription request sent by the first device through the NFVO, the second sub-subscription request being used to request to acquire the second topology information.

[0207] Optionally, the receiving the subscription request sent by the first device includes:

[0208] The fourth sub-subscription request is used to request the first topology information and the second topology information.

[0209] Optionally, the receiving the subscription request sent by the first device comprises:

[0210] The third sub-subscription request is used to request the log information.

[0211] The micro-isolation device 800 can implement various processes of the method embodiments in the present application Figure 5 embodiments, and achieve the same beneficial effects. To avoid repetition, they will not be described here.

[0212] Referring to Figure 11 , Figure 11 is one of the structural diagrams of the micro-isolation device provided by the embodiments of the present application. As shown in Figure 11 , the micro-isolation device 900 comprises:

[0213] The third transceiver 901 is configured to receive a third sub-subscription request sent by a first device, the third sub-subscription request being used to request log information.

[0214] The third transceiver 901 is configured to receive a third sub-subscription request sent by a first device, the third sub-subscription request being used to request log information.

[0215] The micro-isolation device 900 can implement various processes of the method embodiments in the present application Figure 6 embodiments, and achieve the same beneficial effects. To avoid repetition, they will not be described here.

[0216] The embodiments of the present application also provide a communication device. Referring to Figure 12 , the communication device can comprise a processor 1001, a memory 1002, and a program 10021 stored in the memory 1002 and executable on the processor 1001.

[0217] In the case of the communication device being the first device, the program 10021, when executed by the processor 1001, can implement Figure 2 any steps in the corresponding method embodiments and achieve the same beneficial effects. Here, they will not be described.

[0218] In the case of the communication device being the fourth device, the program 10021, when executed by the processor 1001, can implement Figure 5 any steps in the corresponding method embodiments and achieve the same beneficial effects. Here, they will not be described.

[0219] In the case of the communication device being the third device, the program 10021, when executed by the processor 1001, can implement Figure 6Any step in the corresponding method embodiments and achieve the same beneficial effects, not repeated here.

[0220] A person of ordinary skill in the art can understand that all or part of the steps of the method of the above embodiments can be completed by relevant hardware through program instructions. The programs can be stored in a readable medium. The embodiments of the present application also provide a readable storage medium, which stores computer programs. When the computer programs are executed by a processor, the above-mentioned Figure 2 , Figure 5 or Figure 6 Any step in the corresponding method embodiments and achieve the same technical effects, to avoid repetition, not repeated here.

[0221] The storage medium, such as read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, etc.

[0222] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above specific embodiments, which are only illustrative, not restrictive. A person of ordinary skill in the art can make many forms without departing from the scope of the present application and the protection scope of the claims under the inspiration of the present application.

Claims

1. A method for micro-isolation, applied to a first device, comprising: The method comprises: receiving first information, the first information comprising at least one of the following: first topology information of a network element, second topology information of a second device, log information of the network element, the second device corresponding to the network element; comparing the first information with reference information to obtain a comparison result; determining whether to perform an isolation operation on traffic of a target flow direction according to the comparison result; wherein, before the comparing the first information with reference information to obtain a comparison result, the method further comprises: obtaining P first information received in a first historical time period, P being a positive integer; in the case that the P first information are all the same, determining baseline information corresponding to the P first information as the reference information, the baseline information comprising a network connection baseline and a port opening baseline determined according to the P first information; wherein, the comparison result is that the first information has a newly added target object relative to the reference information or the first information has no change relative to the reference information, wherein the target object comprises at least one of the following: a network element, a port and a network connection; wherein, the determining whether to perform an isolation operation on traffic of a target flow direction according to the comparison result comprises: in the case that the comparison result is that the first information has a newly added target object relative to the reference information, determining whether the target object meets a first condition; in the case that the target object does not meet the first condition, determining to perform an isolation operation on traffic of a target flow direction; wherein, the first condition comprises at least one of the following: the newly added network element is a registered network element; the newly added port is a registered port; the newly added network connection is a registered network connection.

2. The method of claim 1, wherein, The receiving first information comprises: receiving the first topology information sent by an operation and maintenance center (OMC) of the network element; receiving the second topology information sent by a network function virtualization orchestrator (NFVO) of the network element; receiving the log information sent by a third device, the third device being a log server or an OMC of the network element.

3. The method of claim 1, wherein, The receiving first information comprises: receiving the first topology information and the second topology information sent by an operation support system (OSS), the first topology information being obtained by the OSS from an OMC, and the second topology information being obtained by the OSS from an NFVO; receiving the log information sent by a third device, the third device being a log server or an OMC of the network element.

4. The method of claim 1, wherein, Before the receiving first information, the method further comprises: sending a subscription request, the subscription request being used to request to obtain the first topology information, the second topology information and the log information.

5. The method of claim 4, wherein, The sending a subscription request comprises: sending a first sub-subscription request to an OMC, the first sub-subscription request being used to request to obtain the first topology information; sending a second sub-subscription request to an NFVO, the second sub-subscription request being used to request to obtain the second topology information; sending a third sub-subscription request to a third device, the third sub-subscription request being used to request to obtain the log information.

6. The method of claim 4, wherein, The sending a subscription request comprises: sending a fourth sub-subscription request to the OSS, the fourth sub-subscription request being used to request to obtain the first topology information and the second topology information; sending a fifth sub-subscription request to the third device, the fifth sub-subscription request being used to request to obtain the log information. 7.A micro-isolation method applied to a first network element, the first network element comprising an OSS, an OMC and an NFVO, characterized in that, The method comprises: sending second information to the first device, the second information comprising at least one of the following: first topology information of the first network element, second topology information of a second device corresponding to the first network element, log information of the first network element; a set of second information sent by each first network element in the network element to the first device is first information, the first information being used for the first device to compare the first information with reference information to obtain a comparison result, and whether to perform an isolation operation on traffic of a target flow being determined according to the comparison result, wherein, in a case where P first information are all the same in a first historical time period, the reference information is baseline information corresponding to the P first information, P being a positive integer, and the baseline information comprising a network connection baseline and a port opening baseline determined according to the P first information; wherein the comparison result is that the first information has a newly added target object relative to the reference information or the first information has no change relative to the reference information, wherein the target object comprises at least one of the following: a network element, a port, and a network connection; in a case where the comparison result is that the first information has a newly added target object relative to the reference information, the target object being used for the first device to determine whether a first condition is met and to determine to perform an isolation operation on traffic of a target flow in a case where the target object does not meet the first condition, wherein the first condition comprises at least one of the following: the newly added network element being a registered network element; the newly added port being a registered port; the newly added network connection being a registered network connection.

8. The method of claim 7, wherein, The sending of the second information to the first device comprises: sending the first topology information to the first device through the OMC; sending the second topology information to the first device through the NFVO.

9. The method of claim 7, wherein, The sending of the second information to the first device comprises: sending the first topology information and the second topology information to the first device through the OSS, the first topology information being obtained by the OSS from the OMC, and the second topology information being obtained by the OSS from the NFVO.

10. The method of claim 7, wherein, The sending of the second information to the first device comprises: sending log information to the first device through the OMC.

11. The method of claim 7, wherein, Before the sending of the second information to the first device, the method further comprises: receiving a subscription request sent by the first device, the subscription request being used to request to obtain the first topology information, the second topology information, and the log information.

12. The method of claim 11, wherein, The receiving of the subscription request sent by the first device comprises: receiving a first sub-subscription request sent by the first device through the OMC, the first sub-subscription request being used to request to obtain the first topology information; receiving a second sub-subscription request sent by the first device through the NFVO, the second sub-subscription request being used to request to obtain the second topology information.

13. The method of claim 11, wherein, The receiving the subscription request sent by the first device comprises: Receiving a fourth sub-subscription request sent by the first device through the OSS, the fourth sub-subscription request being used to request to obtain the first topology information and the second topology information.

14. The method of claim 11, wherein, The receiving the subscription request sent by the first device comprises: Receiving a third sub-subscription request sent by the first device through the OMC, the third sub-subscription request being used to request to obtain the log information.

15. A method for micro-isolation, applied to a third device, comprising: Comprise: Receiving a third sub-subscription request sent by the first device, the third sub-subscription request being used to request to obtain log information; Sending the log information to the first device; The log information belongs to the first information, and the log information is used to compare with reference information to obtain a comparison result, and whether to perform an isolation operation on traffic of a target flow direction is determined according to the comparison result, wherein, in the case that the log information is the same in the first historical time period, the reference information is baseline information corresponding to the log information, and the baseline information comprises a network connection baseline and a port opening baseline determined according to the log information; wherein the comparison result is that the log information has a new target object relative to the reference information or the log information has no change relative to the reference information, wherein the target object comprises at least one of the following: a network element, a port and a network connection; in the case that the comparison result is that the log information has a new target object relative to the reference information, the target object is used for the first device to determine whether a first condition is met and to determine to perform an isolation operation on traffic of a target flow direction in the case that the target object does not meet the first condition, wherein the first condition comprises at least one of the following: The new network element is a registered network element; The new port is a registered port; The new network connection is a registered network connection.

16. A micro-isolation device, characterized by Comprise: The first transceiver is configured to: receive first information, the first information comprising at least one of the following: first topology information of a network element, second topology information of a second device, and log information of the network element, the second device corresponding to the network element; The first processor is configured to: compare the first information with reference information to obtain a comparison result; According to the comparison result, it is determined whether to perform an isolation operation on traffic of a target flow direction; Before the first transceiver compares the first information with reference information to obtain a comparison result, the apparatus further comprises: Obtain P first information received in a first historical time period, P being a positive integer; In the case that the P first information is the same, baseline information corresponding to the P first information is determined as the reference information, the baseline information comprising a network connection baseline and a port opening baseline determined according to the P first information; The comparison result is that the first information has a new target object relative to the reference information or the first information has no change relative to the reference information, wherein the target object comprises at least one of the following: a network element, a port and a network connection; The determination whether to perform an isolation operation on traffic of a target flow direction according to the comparison result comprises: In a case where the comparison result is that the first information has a newly added target object relative to the reference information, it is determined whether the target object meets a first condition; In a case where the target object does not meet the first condition, it is determined to perform an isolation operation on traffic of a target flow direction; The first condition includes at least one of the following: The newly added network element is a registered network element; The newly added port is a registered port; The newly added network connection is a registered network connection.

17. A microisolation device, characterized by Comprise: The second transceiver is configured to: send second information to the first device, the second information including at least one of the following: first topology information of the first network element, second topology information of a second device corresponding to the first network element, and log information of the first network element; The set of second information sent by each first network element in the network element to the first device is first information, the first information is used by the first device to compare the first information with reference information to obtain a comparison result, and whether to perform an isolation operation on traffic of a target flow direction is determined according to the comparison result, wherein in a case where P first information is the same in a first historical time period, the reference information is baseline information corresponding to the P first information, P is a positive integer, and the baseline information includes a network connection baseline and a port opening baseline determined according to the P first information; wherein the comparison result is that the first information has a newly added target object relative to the reference information or the first information has no change relative to the reference information, wherein the target object includes at least one of the following: a network element, a port, and a network connection; in a case where the comparison result is that the first information has a newly added target object relative to the reference information, the target object is used by the first device to determine whether a first condition is met and, in a case where the target object does not meet the first condition, to determine to perform an isolation operation on traffic of a target flow direction, wherein the first condition includes at least one of the following: The newly added network element is a registered network element; The newly added port is a registered port; The newly added network connection is a registered network connection.

18. A microisolation device, characterized by Comprise: The third transceiver is configured to: receive a third sub-subscription request sent by the first device, the third sub-subscription request being used to request to obtain log information; Send the log information to the first device; The log information belongs to first information, and the log information is used to compare with reference information to obtain a comparison result. Whether to perform an isolation operation on traffic of a target flow direction is determined according to the comparison result. In a case where the log information is the same in a first historical time period, the reference information is baseline information corresponding to the log information. The baseline information includes a network connection baseline and a port opening baseline determined according to the log information. The comparison result is that the log information has a new target object relative to the reference information or that the log information has no change relative to the reference information. The target object includes at least one of the following: a network element, a port, and a network connection. In a case where the comparison result is that the log information has a new target object relative to the reference information, the target object is used to determine whether a first condition is met, and in a case where the target object does not meet the first condition, it is determined to perform an isolation operation on traffic of a target flow direction. The first condition includes at least one of the following: The new network element is a registered network element. The new port is a registered port. The new network connection is a registered network connection.

19. A communication device comprising: The transceiver, the memory, the processor, and a program stored in the memory and executable on the processor; the processor is configured to read the program in the memory to implement the steps in the micro-isolation method according to any one of claims 1 to 6; or the steps in the micro-isolation method according to any one of claims 7 to 14; or the steps in the micro-isolation method according to claim 15.

20. A readable storage medium for storing a program, characterized in that, The program is executed by the processor to implement the steps in the micro-isolation method according to any one of claims 1 to 6; Or the steps in the micro-isolation method according to any one of claims 7 to 14; Or the steps in the micro-isolation method according to claim 15.

Citation Information

Patent Citations

  • Method, apparatus and system for virtualizing network management system

    CN105359459A

  • Attack surface transfer method and system of virtual network

    CN111262840A