Firewall Closing Method, System, Electronic Device and Readable Storage Medium
By obtaining the current number of sessions and logout results at the firewall end, determining the load status and wall-off permission status of the firewall, the stability of the hardware firewall under frequent IP address changes is solved, and the stability and security of the firewall are improved.
Patent Information
- Application Number
- CN202211414827.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-11
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2042-11-11
AI Technical Summary
Because the software firewall is easily broken and the hardware firewall responds slowly or crashes under frequent IP address changes, the hardware firewall has poor stability and cannot meet the protection requirements.
By obtaining the current number of sessions at the firewall end and the cancellation result of the container group to be cancelled, determine the load status and wall-closing permission status of the firewall, avoid closing the firewall under high load states, and reduce frequent wall-opening and wall-closing operations.
Improve the stability and security of the firewall, avoid the slow response problem caused by frequent IP address replacement, and ensure the normal operation of the firewall.
Smart Images

Figure CN115766200B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of firewalls, and particularly to a method, a system, an electronic device and a readable storage medium for closing a firewall. Background Art
[0002] Currently, since software firewalls are easily breached and attacked and have limited security protection, for information security considerations, after various application systems choose to use software firewalls, hardware firewalls are used to further ensure information security. At the same time, in order to enhance the security of the firewall and save costs, usually hardware firewalls adopt precise firewall opening and do not provide full network segment opening. Therefore, after a certain path is deprecated, it is necessary to perform a firewall closing operation on the firewall of that path.
[0003] However, since the container IPs (Internet Protocol Addresses) of some service platforms (such as Kubernetes) change relatively frequently, the number of firewall opening and closing operations corresponding to the changes in container IPs is also relatively large. Frequent reading and writing of the configurations of hardware firewalls exceed the hardware computing power of the hardware firewalls, resulting in situations where the firewalls respond slowly, do not respond, or even crash, causing poor stability of the hardware firewalls and failing to meet the requirements of firewall protection. Summary of the Invention
[0004] To provide a basic understanding of some aspects of the disclosed embodiments, a simple summary is given below. The summary is not a comprehensive review nor is it intended to identify key / important elements or delineate the scope of protection of these embodiments, but rather serves as a preamble to the detailed description that follows.
[0005] In view of the above-mentioned disadvantages of the prior art, the present invention discloses a method, a system, an electronic device and a readable storage medium for closing a firewall to improve the stability of the hardware firewall.
[0006] The present invention provides a firewall closing method, including: obtaining a transmission path set and a firewall end, where the transmission path set includes at least one current container group and the transmission paths corresponding to each current container group, and the firewall end includes the firewalls corresponding to each transmission path; if a cancellation instruction corresponding to a container group to be cancelled is received, performing a current session query on the firewall end to obtain the current session number of the firewall end, and performing a status query on the container group to be cancelled to obtain the cancellation result corresponding to the container group to be cancelled, where the container group to be cancelled includes at least one current container group; determining the current load status of the firewall end according to the current session number, and determining the firewall closing permission status of the container group to be cancelled based on the current load status and the cancellation result, where the firewall closing permission status includes allowing firewall closing or prohibiting firewall closing; if the firewall closing permission status includes allowing firewall closing, sending the transmission path corresponding to the container group to be cancelled to the firewall end, so that the firewall end closes the firewall corresponding to the container group to be cancelled.
[0007] Optionally, performing a status query on the container group to be cancelled to obtain the cancellation result corresponding to the container group to be cancelled includes: obtaining a management database, where the management database includes the current service status corresponding to each current container group; sending a status query request corresponding to the container group to be cancelled to the management database; if the current service status corresponding to the container group to be cancelled is received as feedback from the management database, determining the cancellation result corresponding to the container group to be cancelled as not cancelled; if the management database feedbacks that the container group to be cancelled is not found, determining the cancellation result corresponding to the container group to be cancelled as cancelled.
[0008] Optionally, determining the current load status of the firewall end according to the current session number includes: comparing the current session number with a preset session threshold to obtain a session comparison result; if the session comparison result includes that the current session number is greater than or equal to the preset session threshold, determining the current load status of the firewall end as high load; if the session comparison result includes that the current session number is less than the preset session threshold, determining the current load status of the firewall end as idle.
[0009] Optionally, determining the firewall closing permission status of the container group to be cancelled based on the current load status and the cancellation result includes: presetting a first determination condition and a second determination condition, where the first determination condition includes that the current load status is idle, and the second determination condition includes that the cancellation result is cancelled; if the first determination condition and the second determination condition are satisfied, determining the firewall closing permission status of the container group to be cancelled as allowing firewall closing; if the first determination condition or the second determination condition is not satisfied, determining the firewall closing permission status of the container group to be cancelled as prohibiting firewall closing.
[0010] Optionally, after determining the wall closing permission status of the container group to be deactivated based on the current load status and the deactivation result, the method further includes: if the wall closing permission status includes prohibiting wall closing, adding the container group to be deactivated to a preset list of container groups to be deactivated; setting at least one of a first trigger condition, a second trigger condition, and a third trigger condition, where the first trigger condition is after a first preset period, the second trigger condition includes receiving a new deactivation instruction, and the third trigger condition includes that the current load status at the firewall end is idle after a second preset period; determining the wall closing permission status of each container group to be deactivated in the list of container groups to be deactivated when the first trigger condition, the second trigger condition, or the third trigger condition is satisfied; determining the container groups to be deactivated with the wall closing permission status including allowing wall closing as intermediate container groups, and sending the transmission paths corresponding to the intermediate container groups to the firewall end, so that the firewall end closes the firewalls corresponding to the intermediate container groups.
[0011] Optionally, the firewall is opened by the following method: establishing a current container group, and determining the wall opening address information corresponding to the current container group from preset idle address information, where the wall opening address information includes an access source address and at least one target access address; determining a transmission path from the access source address to the target access address at the firewall end, and storing the current container group and the transmission path corresponding to the current container group into a preset set to obtain a transmission path set; generating wall opening request information according to the transmission path, and sending the wall opening request information to a preset firewall end, so that the firewall end matches from a preset firewall policy set to obtain a security policy corresponding to the transmission path, and executes the security policy to open the firewall corresponding to the transmission path, where the firewall policy set includes at least one preset firewall policy.
[0012] Optionally, after sending the wall opening request information to the firewall end, the method further includes: receiving a wall opening request result fed back by the firewall end; if the wall opening request result includes successful wall opening, performing an initialization query on the current container group corresponding to the wall opening request result to obtain an initialization result of the current container group, and if the initialization result includes initialization completion, determining the current service status of the current container group as the running state; if the wall opening request result includes failed wall opening, determining the current service status of the current container group as prohibited service.
[0013] The present invention provides a firewall shutdown system, including: an acquisition module, configured to acquire a transmission path set and a firewall end, where the transmission path set includes at least one current container group and the transmission paths corresponding to each current container group, and the firewall end includes the firewalls corresponding to each transmission path; a query module, configured to, if a cancellation instruction corresponding to a container group to be cancelled is received, perform a current session query on the firewall end to obtain the current session number of the firewall end, and perform a status query on the container group to be cancelled to obtain the cancellation result corresponding to the container group to be cancelled, where the container group to be cancelled includes at least one current container group; a determination module, configured to determine the current load status of the firewall end according to the current session number, and determine the wall-closing permission status of the container group to be cancelled based on the current load status and the cancellation result, where the wall-closing permission status includes allowing wall closing or prohibiting wall closing; a shutdown module, configured to, if the wall-closing permission status includes allowing wall closing, send the transmission path corresponding to the container group to be cancelled to the firewall end, so that the firewall end closes the firewall corresponding to the container group to be cancelled.
[0014] The present invention provides an electronic device, including: a processor and a memory; the memory is configured to store a computer program, and the processor is configured to execute the computer program stored in the memory, so that the electronic device executes the above method.
[0015] The present invention provides a computer-readable storage medium, on which a computer program is stored: when the computer program is executed by a processor, the above method is implemented.
[0016] Advantages of the present invention:
[0017] If a cancellation instruction corresponding to a container group to be cancelled is received, respectively obtain the current session number of the firewall end and the cancellation result of the container group to be cancelled, and determine the current load status of the firewall end according to the current session number, and determine whether to close the firewall based on the current load status and the cancellation result. In this way, it is determined whether the container group to be cancelled has completed the cancellation instruction through the cancellation result of the container group to be cancelled. At the same time, the current load status of the firewall end is determined according to the current session number of the firewall end, avoiding the firewall end in a high-load state from closing the firewall of the container group to be cancelled, thereby solving the problems such as slow response caused by excessive opening and closing of the firewall end due to frequent IP address changes in software, platforms, etc., improving the stability of the firewall, and ensuring the security of the firewall. Description of the Drawings
[0018] Figure 1 It is a schematic diagram of an application scenario of a firewall shutdown method in an embodiment of the present invention;
[0019] Figure 2It is a schematic flowchart of a firewall closing method in an embodiment of the present invention;
[0020] Figure 3 It is a schematic flowchart of another firewall closing method in an embodiment of the present invention;
[0021] Figure 4 It is a schematic flowchart of another firewall closing method in an embodiment of the present invention;
[0022] Figure 5 It is a schematic structural diagram of a firewall closing system in an embodiment of the present invention;
[0023] Figure 6 It is a schematic diagram of an electronic device in an embodiment of the present invention. Detailed implementation manners
[0024] The following uses specific specific examples to illustrate the implementation manners of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that, without conflict, the following embodiments and sub-samples in the embodiments can be combined with each other.
[0025] It should be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present invention in a schematic manner. Therefore, only the components related to the present invention are shown in the diagrams, rather than being drawn according to the number, shape, and size of the components in actual implementation. The types, quantities, and proportions of the components in actual implementation can be arbitrarily changed, and the component layout type may also be more complex.
[0026] In the following description, a large number of details are discussed to provide a more thorough explanation of the embodiments of the present invention. However, it is obvious to those skilled in the art that the embodiments of the present invention can be implemented without these specific details. In other embodiments, well-known structures and devices are shown in the form of block diagrams rather than in detail to avoid making the embodiments of the present invention difficult to understand.
[0027] The terms "first", "second", etc. in the specification, claims, and above-mentioned drawings of the embodiments of the present disclosure are used to distinguish similar objects and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so as to implement the embodiments of the present disclosure described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion.
[0028] Unless otherwise specified, the term "a plurality of" means two or more.
[0029] In the embodiments of the present disclosure, the character " / " indicates that the objects before and after are in an "or" relationship. For example, A / B means: A or B.
[0030] The term "and / or" is an associative relationship describing an object, indicating that three relationships can exist. For example, A and / or B means: A or B, or, A and B.
[0031] Combine Figure 1As shown in the figure, an application scenario schematic diagram of a firewall shutdown method is provided in an embodiment of the present disclosure. The application scenario includes a network 101 composed of multiple servers 1011, a firewall management system 102, and a client 103 that logs in to the firewall management system 102. A firewall 1012 is deployed between the servers. The firewall management system 102 includes a call relationship management module 1021, a policy management module 1022, a Configuration Management Database (CMDB) 1023, and a network description database 1024. Among them, the CMDB 1023 stores the servers corresponding to each business module in the network 101. A business module can correspond to one or more servers, that is, a business module can run on one or more servers. In specific implementation, the business administrator can configure the correspondence between the business module and the server through the client 103 and store it in the CMDB 1023, or the CMDB 1023 can actively collect configuration data from each server 1011, and obtain the business modules running on each server by analyzing the collected data, so as to obtain the correspondence between the business module and the server. The network description database 1024 stores the communication connection relationships between each firewall and each server in the network 101, that is, network structure description data. The call relationship management module 1021 translates the module call relationship between business modules into the communication relationship between servers in the network based on the correspondence between the business module and the server, thereby generating a firewall opening application. The policy management module 1022 determines the target firewall that needs to be configured based on the firewall opening application, generates a corresponding firewall policy configuration script, and sends it to the target firewall, so that the communication between business modules can be smoothly achieved through the firewall. Among them, the server 1011 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The terminal can be a smart phone, a tablet computer, a notebook computer, a desktop computer, a smart speaker, a smart watch, etc., but is not limited thereto. The terminal and the server can be directly or indirectly connected through wired or wireless communication methods, and this application does not make any restrictions here.
[0032] Network segment: It refers to an interval composed of multiple consecutive and uninterrupted IP addresses. The IP addresses in a network can be divided into multiple network segments to improve performance. For example, 10.1.1.0~10.1.1.255 can be a network segment, and 10.2.1.0~10.2.1.255 can be a network segment.
[0033] Mask: That is, the subnet mask, also known as the network mask, address mask, or subnetwork mask. It is a bit mask used to indicate which bits of an IP address identify the subnet where the host is located and which bits identify the host. The subnet mask cannot exist alone and must be used in combination with an IP address. The subnet mask has only one function, which is to divide an IP address into a network address and a host address. When the subnet mask is 8 bits, i.e., 255.0.0.0 / 8, the subnet occupies 24 bits, and the number of available IPs is 2^24 - 2 = 16777214; when the subnet mask is 24 bits, i.e., 255.255.255.0 / 24, the subnet occupies 8 bits, and the number of available IPs is 2^8 - 2 = 254.
[0034] A client, also known as a user - end, refers to a program that provides local services corresponding to a server. Except for some applications that only run locally, it is generally installed on ordinary client machines and needs to cooperate with the server - end to run. After the development of the Internet, common clients include web browsers used for the World Wide Web, email clients for sending and receiving emails, and instant messaging client software, etc. For this type of application programs, corresponding servers and service programs in the network are required to provide corresponding services, such as database services, email services, etc. Thus, a specific communication connection needs to be established between the client machine and the server - end to ensure the normal operation of the application program.
[0035] First of all, it should be noted that the embodiments of the present disclosure are implemented on the Kubernetes platform. Among them, Kubernetes (also known as k8s), as a portable and extensible open - source platform, provides a framework for running distributed systems elastically, promotes declarative configuration and automation, and its services, support, and tools are widely used. In the Kubernetes platform, the smallest resource management component is the pod (container group). A pod can run one or more containers. Containers under the same pod must run on the same node. Each pod will be assigned a unique IP address, and all containers share the network space, including the IP address and ports. Moreover, the containers inside the pod can communicate with each other using localhost.
[0036] Combined with Figure 2 As shown, the embodiments of the present disclosure provide a method for closing a firewall, including:
[0037] Step S201, obtaining a transmission path set and a firewall end;
[0038] Among them, the transmission path set includes at least one current container group and the transmission paths corresponding to each current container group, and the firewall end includes the firewalls corresponding to each transmission path;
[0039] Among them, the container group to be cancelled includes at least one current container group;
[0040] Step S202, if a cancellation instruction corresponding to the container group to be cancelled is received, perform a current session query on the firewall end to obtain the current session quantity of the firewall end, and perform a status query on the container group to be cancelled to obtain the cancellation result corresponding to the container group to be cancelled;
[0041] Step S203, determine the current load status of the firewall end according to the current session quantity, and determine the firewall closing permission status of the container group to be cancelled based on the current load status and the cancellation result;
[0042] Among them, the firewall closing permission status includes allowing firewall closing or prohibiting firewall closing;
[0043] Step S204, if the firewall closing permission status includes allowing firewall closing, send the transmission path corresponding to the container group to be cancelled to the firewall end, so that the firewall end closes the firewall corresponding to the container group to be cancelled.
[0044] Adopting the firewall closing method provided by the embodiments of the present disclosure, if a cancellation instruction corresponding to the container group to be cancelled is received, obtain the current session quantity of the firewall end and the cancellation result of the container group to be cancelled respectively, and determine the current load status of the firewall end based on the current session quantity, and determine whether to close the firewall based on the current load status and the cancellation result. In this way, it is determined whether the container group to be cancelled has completed the cancellation instruction through the cancellation result of the container group to be cancelled. At the same time, the current load status of the firewall end is determined according to the current session quantity of the firewall end, avoiding the firewall end in a high-load state from closing the firewall of the container group to be cancelled, thereby solving the problems such as slow response caused by excessive opening and closing of the firewall end due to frequent IP address changes in software, platforms, etc., improving the stability of the firewall, and ensuring the security of the firewall.
[0045] In some embodiments, after receiving a cancellation instruction corresponding to a container group to be cancelled, the container group to be cancelled is cancelled in the following manner: The client sends a cancellation instruction corresponding to the container group to be cancelled, where the cancellation instruction has a grace period, and the default grace period includes 30s; after the container group to be cancelled exceeds the grace period, the API status of the container group to be cancelled in the API (Application Program Interface) server is set to "dead". At the same time, the current service status of the container group to be cancelled in the client is set to the terminating state and stored in the management database. The client sends a termination signal (TERM) to the process of the container group to be cancelled to stop the process of the container group to be cancelled, and the container group to be cancelled is removed from the endpoint list of the server, so that the container group to be cancelled is no longer part of the Replication Controller (a Kubernetes resource used to ensure that the container group always remains in a running state). If the container group to be cancelled defines a PreStop hook (a container lifecycle hook used to monitor specific events in the container lifecycle and execute the registered callback function when the event occurs), then stopping the process of the container group to be cancelled will call the PreStop hook. And if the PreStop hook is still being called after the grace period, the grace period is increased, and the default increased grace period is 2s; the processes of some container groups to be cancelled continue to process the traffic forwarded by the load balance. After the container group to be cancelled exceeds the grace period, a deletion signal (SIGKILL) is sent to the processes still running in the container group to be cancelled to kill the still-running processes; the deletion of the container group to be cancelled is completed in the API server, and the graceful period is set to 0 (i.e., immediate deletion), and the container group to be cancelled disappears in the API server and the client.
[0046] Optionally, a status query is performed on the container group to be cancelled to obtain the cancellation result corresponding to the container group to be cancelled, including: obtaining the management database, where the management database includes the current service status of each current container group; sending a status query request corresponding to the container group to be cancelled to the management database; if the management database feedbacks the current service status corresponding to the container group to be cancelled, then the cancellation result corresponding to the container group to be cancelled is determined to be uncancelled; if the management database feedbacks that the container group to be cancelled is not queried, then the cancellation result corresponding to the container group to be cancelled is determined to be cancelled.
[0047] In some embodiments, the current service status includes a running state, a terminating state, and a deleting state; the current service status of each current container group is managed through a management database, where the management database includes a CMDB (Configuration Management Database) database; if the container group to be deactivated is in the process of being deactivated, the current service status of the container group to be deactivated is the terminating state or the deleting state; if the container group to be deactivated has been deactivated, the management database does not have the current service status of the container group to be deactivated.
[0048] Optionally, determining the current load status of the firewall side according to the current number of sessions includes: comparing the current number of sessions with a preset session threshold to obtain a session comparison result; if the session comparison result includes that the current number of sessions is greater than or equal to the preset session threshold, determining the current load status of the firewall side as high load; if the session comparison result includes that the current number of sessions is less than the preset session threshold, determining the current load status of the firewall side as idle.
[0049] In some embodiments, the preset session threshold is determined according to the computing power of the firewall side, and the preset session threshold includes 10 - 200. For example, if the preset session threshold is 50 and the current number of sessions is 75, the current load status of the firewall side is determined as high load; if the current number of sessions is less than 50, the current load status of the firewall side is determined as idle.
[0050] In some embodiments, the parameters for judging the current load status of the firewall side are not limited to the current number of sessions, but also include one or more of the computing power parameters such as current thread data, current network channel occupancy ratio, current operation memory occupancy ratio, and current CPU occupancy ratio; calculating the above one or more computing power parameters according to a preset computing power index algorithm to obtain a computing power index, and then comparing the computing power index with a preset index threshold can also determine the current load status of the firewall side, which is not limited in this application.
[0051] Optionally, determining the wall closing permission status of the container group to be deactivated based on the current load status and the deactivation result includes: presetting a first determination condition and a second determination condition, where the first determination condition includes that the current load status is idle, and the second determination condition includes that the deactivation result is deactivated; if the first determination condition and the second determination condition are satisfied, determining the wall closing permission status of the container group to be deactivated as allowing wall closing; if the first determination condition or the second determination condition is not satisfied, determining the wall closing permission status of the container group to be deactivated as prohibiting wall closing.
[0052] In some embodiments, if the current service status of the container group to be deactivated cannot be obtained from the management database, it indicates that the container group to be deactivated has been deactivated. At the same time, if the current number of sessions at the firewall end is less than the preset session threshold, it proves that the firewall end has sufficient computing power to perform the firewall closing operation, and then the firewall closing permission status of the container group to be deactivated is determined to be allowing firewall closing.
[0053] Optionally, after determining the firewall closing permission status of the container group to be deactivated based on the current load status and the deactivation result, the method further includes: if the firewall closing permission status includes prohibiting firewall closing, adding the container group to be deactivated to a preset list of container groups to be deactivated; setting at least one of a first trigger condition, a second trigger condition, and a third trigger condition, where the first trigger condition is after a first preset period, the second trigger condition includes receiving a new deactivation instruction, and the third trigger condition includes that the current load status at the firewall end is idle after a second preset period; when the first trigger condition, the second trigger condition, or the third trigger condition is satisfied, determining the firewall closing permission status of each container group to be deactivated in the list of container groups to be deactivated; determining the container groups to be deactivated with the firewall closing permission status including allowing firewall closing as intermediate container groups, and sending the transmission path corresponding to the intermediate container groups to the firewall end so that the firewall end closes the firewall corresponding to the intermediate container groups.
[0054] In this way, if the firewall does not meet the firewall closing conditions, the container group to be deactivated is first added to a preset list of container groups to be deactivated, and the action of closing the firewall is centrally processed when the firewall is relatively idle, thereby reducing the number of calls to the firewall.
[0055] In some embodiments, the first preset period includes 30s - 1hr, and the second preset period includes 30s - 1hr.
[0056] In some embodiments, the container groups to be deactivated that fail to close the firewall successfully are added to a preset list of container groups to be deactivated, and trigger conditions are set for the list of container groups to be deactivated, including timed trigger, trigger upon receiving a new deactivation instruction, and trigger when the current load status at the firewall end is idle, and the firewall closing permission status of the container groups to be deactivated in the list of container groups to be deactivated is redetermined according to at least one of these methods.
[0057] In this way, the firewall end performs the previous unfinished firewall closing operation when it is idle, avoiding the software, platform, etc. from reacting slowly due to frequent IP address changes causing excessive opening and closing of the firewall end, improving the stability of the firewall and ensuring firewall security.
[0058] Optionally, the firewall is opened by the following method: create the current container group, and determine the firewall-opening address information corresponding to the current container group from the preset free address information, where the firewall-opening address information includes an access source address and at least one target access address; determine the transmission path from the access source address to the target access address in the firewall end, and store the current container group and the corresponding transmission path of the current container group into a preset set to obtain a transmission path set; generate firewall-opening request information according to the transmission path, and send the firewall-opening request information to a preset firewall end, so that the firewall end matches from a preset firewall policy set to obtain the security policy corresponding to the transmission path, and execute the security policy to open the firewall corresponding to the transmission path, where the firewall policy set includes at least one preset firewall policy.
[0059] In some embodiments, different security policies are specified according to the firewall-opening requirements. Each security policy corresponds to a firewall-opening address information (AddressSet, address group), and a current container group corresponds to each security policy; when opening the firewall, two IP addresses are randomly assigned to the current container group, and the IP addresses are placed in the server.
[0060] In some embodiments, to enhance network security, firewalls of different brands are deployed in different security domains. Each firewall provided by a firewall manufacturer has different policy configuration grammars. Therefore, policy configuration templates can be generated in advance according to the policy configuration grammars of each firewall manufacturer. During use, determine the firewall manufacturer corresponding to the target firewall, obtain the policy configuration template corresponding to the firewall manufacturer, then, based on the module call relationship, determine the source service module and the destination service module in the module call relationship, and determine the source IP address corresponding to the source service module and the destination IP address corresponding to the destination service module. Fill the source IP address and the destination IP address into the policy configuration template of the target firewall to obtain the firewall policy configuration script that needs to be sent to the target firewall. This firewall policy configuration script is used to open the target firewall between the server corresponding to the source IP address and the server corresponding to the destination IP address, so that the server corresponding to the source IP address can access the server corresponding to the destination IP address.
[0061] In some embodiments, the firewall policy includes an access source address, a target access address, a service application, a time schedule, a security mode (for example, allow passing if all elements match, prohibit passing if all elements match, encrypt if all elements match, etc.), and a security action (for example, perform network address translation NAT on the data packet, broadband control, user authentication, content filtering, logging, etc.).
[0062] Optionally, after sending the firewall opening request information to the firewall side, the method further includes: receiving the firewall opening request result fed back by the firewall side; if the firewall opening request result includes successful firewall opening, performing an initialization query on the current container group corresponding to the firewall opening request result to obtain the initialization result of the current container group, and if the initialization result includes completion of initialization, determining the current service state of the current container group as the running state; if the firewall opening request result includes failed firewall opening, determining the current service state of the current container group as prohibited service.
[0063] In some embodiments, if the firewall opening is not successful, the service provided to the current container group is blocked; if the firewall opening is successful and the initialization of the current container group is completed, the service is provided and the current service state of the current container group is determined as the running state.
[0064] Combined with Figure 3 As shown, the embodiments of the present disclosure provide a firewall closing method, including:
[0065] Step S301, obtaining a transmission path set and a firewall side;
[0066] Wherein, the transmission path set includes at least one current container group and the transmission paths corresponding to each current container group, and the firewall side includes the firewalls corresponding to each transmission path;
[0067] Wherein, the container group to be de-registered includes at least one current container group;
[0068] Step S302, sending a status query request corresponding to the container group to be de-registered to the management database;
[0069] Step S303, determining whether to receive the current service state corresponding to the container group to be de-registered fed back by the management database. If so, jump to step S308; if not, jump to step S304;
[0070] Step S304, performing a current session query on the firewall side to obtain the current session quantity of the firewall side;
[0071] Step S305, comparing the current session quantity with a preset session threshold to obtain a session comparison result;
[0072] Step S306, determining whether the current session quantity is greater than or equal to the preset session threshold. If so, jump to step S308; if not, jump to step S307;
[0073] Step S307, sending the transmission path corresponding to the container group to be de-registered to the firewall side, so that the firewall side closes the firewall corresponding to the container group to be de-registered.
[0074] Step S308, adding the container group to be de-registered to a preset list of container groups to be de-registered;
[0075] Step S309: If at least one of the first trigger condition, the second trigger condition, and the third trigger condition is satisfied, determine the wall-closing permission status of each container group to be cancelled in the list of containers to be cancelled.
[0076] Step S310: Determine whether there is permission to close the wall for the wall-closing permission status of each container group to be cancelled in the list of containers to be cancelled. If so, jump to Step S311; if not, jump to Step S309.
[0077] Step S311: Send the transmission path corresponding to the intermediate container group to the firewall end, so that the firewall end closes the firewall corresponding to the intermediate container group.
[0078] Among them, the container groups to be cancelled with the wall-closing permission status including permission to close the wall are determined as intermediate container groups.
[0079] Using the firewall closing method provided in the embodiments of the present disclosure, if a cancellation instruction corresponding to a container group to be cancelled is received, the current session number of the firewall end and the cancellation result of the container group to be cancelled are respectively obtained, and the current load status of the firewall end is determined based on the current session number. Whether to close the firewall is determined based on the current load status and the cancellation result. In this way, it is determined whether the container group to be cancelled has completed the cancellation instruction through the cancellation result of the container group to be cancelled. At the same time, the current load status of the firewall end is determined according to the current session number of the firewall end, avoiding the firewall end in a high-load state from closing the firewall of the container group to be cancelled, thereby solving problems such as slow response caused by excessive opening and closing of the firewall by software, platforms, etc. due to frequent IP address changes, improving the stability of the firewall, and ensuring firewall security.
[0080] Combined with Figure 4 As shown, the embodiments of the present disclosure provide a firewall closing method, including:
[0081] Step S401: The container group to be cancelled receives the cancellation instruction and starts to cancel.
[0082] Step S402: After the container group to be cancelled is cancelled, the management database deletes the current service status of the container group to be cancelled.
[0083] Step S403: The server end queries the current sessions of the firewall end.
[0084] Step S404: The firewall end feeds back the current session number to the server end.
[0085] Step S405: If the session comparison result includes that the current session number is less than the preset session threshold, the server determines the current load status of the firewall end as idle.
[0086] Step S406: The server end sends a status query request corresponding to the container group to be cancelled to the management database.
[0087] Step S407, the management database feeds back to the server side that the current service status corresponding to the container group to be cancelled is not queried;
[0088] Step S408, the server side determines the cancellation result corresponding to the container group to be cancelled as cancelled;
[0089] Step S409, if the current load status of the firewall side is idle and the cancellation result corresponding to the container group to be cancelled is determined as cancelled, the server side determines the firewall closing permission status of the container group to be cancelled as allowing firewall closing;
[0090] Step S410, the server side sends the transmission path corresponding to the container group to be cancelled to the firewall side, so that the firewall side closes the firewall corresponding to the container group to be cancelled.
[0091] Adopting the firewall closing method provided by the embodiments of the present disclosure, if a cancellation instruction corresponding to a container group to be cancelled is received, the current session number of the firewall side and the cancellation result of the container group to be cancelled are respectively obtained, the current load status of the firewall side is determined based on the current session number, and whether to close the firewall is determined based on the current load status and the cancellation result. In this way, it is determined whether the container group to be cancelled has completed the cancellation instruction through the cancellation result of the container group to be cancelled. At the same time, the current load status of the firewall side is determined according to the current session number of the firewall side, avoiding the firewall side in a high load state from closing the firewall of the container group to be cancelled, thereby solving the problems such as slow response caused by excessive opening and closing times of the firewall side due to frequent IP address changes in software, platforms, etc., improving the stability of the firewall, and ensuring the security of the firewall.
[0092] Combined with Figure 5As shown in the figure, an embodiment of the present disclosure provides a firewall shutdown system, including an acquisition module 501, a query module 502, a determination module 503, and a shutdown module 504. The acquisition module 501 is configured to acquire a transmission path set and a firewall end, where the transmission path set includes at least one current container group and the transmission paths corresponding to each current container group, and the firewall end includes the firewalls corresponding to each transmission path; the query module 502 is configured to, if a cancellation instruction corresponding to a container group to be cancelled is received, perform a current session query on the firewall end to obtain the current session number of the firewall end, and perform a status query on the container group to be cancelled to obtain the cancellation result corresponding to the container group to be cancelled, where the container group to be cancelled includes at least one current container group; the determination module 503 is configured to determine the current load status of the firewall end according to the current session number, and determine the firewall shutdown permission status of the container group to be cancelled based on the current load status and the cancellation result, where the firewall shutdown permission status includes allowing firewall shutdown or prohibiting firewall shutdown; the shutdown module 504 is configured to, if the firewall shutdown permission status includes allowing firewall shutdown, send the transmission path corresponding to the container group to be cancelled to the firewall end, so that the firewall end shuts down the firewall corresponding to the container group to be cancelled.
[0093] When using the firewall shutdown system provided by the embodiment of the present disclosure, if a cancellation instruction corresponding to a container group to be cancelled is received, the current session number of the firewall end and the cancellation result of the container group to be cancelled are respectively acquired, and the current load status of the firewall end is determined according to the current session number, and it is determined whether to shut down the firewall based on the current load status and the cancellation result. In this way, it is determined whether the container group to be cancelled has completed the cancellation instruction through the cancellation result of the container group to be cancelled. At the same time, the current load status of the firewall end is determined according to the current session number of the firewall end, avoiding shutting down the firewall of the container group to be cancelled by the firewall end in a high-load state, thereby solving problems such as slow response caused by excessive opening and closing of the firewall end due to frequent IP address changes in software, platforms, etc., improving the stability of the firewall, and ensuring firewall security.
[0094] Figure 6 The figure shows a schematic structural diagram of a computer system of an electronic device suitable for implementing the embodiments of the present application. It should be noted that Figure 6 The computer system 600 of the electronic device shown is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present application.
[0095] As Figure 6As shown, the computer system 600 includes a Central Processing Unit (CPU) 601, which can perform various appropriate actions and processes according to the program stored in the Read-Only Memory (ROM) 602 or the program loaded from the storage section 608 into the Random Access Memory (RAM) 603, such as executing the methods in the above embodiments. In the RAM 603, various programs and data required for system operation are also stored. The CPU 601, ROM 602, and RAM 603 are connected to each other via a bus 604. An Input / Output (I / O) interface 605 is also connected to the bus 604.
[0096] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, etc.; an output section 607 including, for example, a Cathode Ray Tube (CRT), a Liquid Crystal Display (LCD), etc. and a speaker, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as needed. A removable medium 611, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 610 as needed so that the computer program read from it can be installed into the storage section 608 as needed.
[0097] Specifically, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network via the communication section 609, and / or installed from the removable medium 611. When the computer program is executed by the Central Processing Unit (CPU) 601, various functions defined in the system of the present application are executed.
[0098] It should be noted that the computer-readable medium shown in the embodiments of the present application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable computer program. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The computer program included on the computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0099] The embodiments of the present disclosure also provide a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements any one of the methods in this embodiment.
[0100] For the computer-readable storage medium in the embodiments of the present disclosure, those of ordinary skill in the art can understand that all or part of the steps for implementing the above method embodiments can be completed by hardware related to the computer program. The aforementioned computer program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps including the above method embodiments; and the aforementioned storage medium includes: ROM, RAM, magnetic disk, or optical disc, etc., various media that can store program codes.
[0101] The electronic device disclosed in this embodiment includes a processor, a memory, a transceiver, and a communication interface. The memory and the communication interface are connected to the processor and the transceiver and complete communication with each other. The memory is used to store a computer program, the communication interface is used for communication, and the processor and the transceiver are used to run the computer program so that the electronic device executes each step of the above method.
[0102] In this embodiment, the memory may include a Random Access Memory (RAM), and may also include a non-volatile memory, such as at least one disk memory.
[0103] The above-mentioned processor may be a general-purpose processor, including a Central Processing Unit (CPU), a Graphics Processing Unit (GPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0104] The above description and the accompanying drawings fully illustrate the embodiments of the present disclosure, enabling those skilled in the art to practice them. Other embodiments may include structural, logical, electrical, process, and other changes. Embodiments merely represent possible variations. Unless explicitly required, individual components and functions are optional, and the order of operations may vary. Parts and sub-samples of some embodiments may be included in or replace parts and sub-samples of other embodiments. Moreover, the terms used in this application are only for describing embodiments and do not limit the claims. As used in the description of embodiments and claims, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" are intended to also include the plural forms. Similarly, as used in this application, the term "and / or" refers to any and all possible combinations of one or more of the associated listed items. Additionally, when used in this application, the term "comprise" and its variants "comprises" and / or "comprising" etc. mean the presence of the stated sub-samples, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other sub-samples, wholes, steps, operations, elements, components, and / or groupings of these. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, or device comprising the element. Herein, each embodiment may focus on the differences from other embodiments, and the same or similar parts among the embodiments may be referred to each other. For the methods, products, etc. disclosed in the embodiments, if they correspond to the method parts disclosed in the embodiments, the relevant parts may refer to the description of the method parts.
[0105] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner may depend on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the embodiments of the present disclosure. Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0106] In the embodiments disclosed in this document, the disclosed methods, products (including but not limited to devices, equipment, etc.) can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units can be merely a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some sub-samples can be ignored or not executed. Additionally, the couplings or direct couplings or communication connections shown or discussed among each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical, or other forms. The units described as separate components can be or can not be physically separated. The components shown as units can be or can not be physical units, that is, they can be located in one place or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to implement this embodiment. Additionally, in the embodiments of this disclosure, each functional unit can be integrated in a processing unit, or each unit can physically exist alone, or two or more units can be integrated in one unit.
[0107] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to the embodiments of this disclosure. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions marked in the blocks can occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, which can depend on the functions involved. In the descriptions corresponding to the flowcharts and block diagrams in the accompanying drawings, the operations or steps corresponding to different blocks can also occur in a different order than that disclosed in the description. Sometimes, there is no specific order between different operations or steps. For example, two consecutive operations or steps can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, which can depend on the functions involved. Each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
Claims
1. A firewall shutdown method, characterized in that, Including: Obtain a set of transmission paths and firewall ends, where the set of transmission paths includes at least one current container group and the transmission paths corresponding to each current container group, and the firewall ends include firewalls corresponding to each transmission path; If a cancellation instruction corresponding to a container group to be cancelled is received, perform a current session query on the firewall end to obtain the current session quantity of the firewall end, and perform a status query on the container group to be cancelled to obtain a cancellation result corresponding to the container group to be cancelled, where the container group to be cancelled includes at least one current container group; Determine the current load status of the firewall end according to the current session quantity, and determine the wall-closing permission status of the container group to be cancelled based on the current load status and the cancellation result, where the wall-closing permission status includes allowing wall-closing or prohibiting wall-closing; If the wall-closing permission status includes allowing wall-closing, send the transmission path corresponding to the container group to be cancelled to the firewall end, so that the firewall end closes the firewall corresponding to the container group to be cancelled.
2. The method according to claim 1, characterized in that, Performing a status query on the container group to be cancelled to obtain a cancellation result corresponding to the container group to be cancelled includes: Obtain a management database, where the management database includes the current service status corresponding to each current container group; Send a status query request corresponding to the container group to be cancelled to the management database; If the current service status corresponding to the container group to be cancelled is received as feedback from the management database, determine the cancellation result corresponding to the container group to be cancelled as not cancelled; If the management database feedbacks that the container group to be cancelled is not found, determine the cancellation result corresponding to the container group to be cancelled as cancelled.
3. The method according to claim 1, characterized in that Determining the current load status of the firewall end according to the current session quantity includes: Compare the current session quantity with a preset session threshold to obtain a session comparison result; If the session comparison result includes that the current session quantity is greater than or equal to the preset session threshold, determine the current load status of the firewall end as high load; If the session comparison result includes that the current session quantity is less than the preset session threshold, determine the current load status of the firewall end as idle.
4. The method according to claim 1, wherein Determining the wall-closing permission status of the container group to be cancelled based on the current load status and the cancellation result includes: Pre-set a first determination condition and a second determination condition, where the first determination condition includes that the current load status is idle, and the second determination condition includes that the cancellation result is cancelled; If the first determination condition and the second determination condition are satisfied, determine the wall-closing permission status of the container group to be cancelled as allowing wall-closing; If the first determination condition or the second determination condition is not satisfied, determine the wall-closing permission status of the container group to be cancelled as prohibiting wall-closing.
5. The method according to any one of claims 1 to 4, characterized in that, After determining the wall-closing permission status of the container group to be cancelled based on the current load status and the cancellation result, the method further includes: If the wall-closing permission status includes prohibiting wall-closing, add the container group to be cancelled to a preset list of container groups to be cancelled; Set at least one of a first trigger condition, a second trigger condition, and a third trigger condition, where the first trigger condition is after a first preset period, the second trigger condition includes receiving a new cancellation instruction, and the third trigger condition includes that the current load status of the firewall end is idle after a second preset period; When the first trigger condition, the second trigger condition, or the third trigger condition is satisfied, determine the wall-closing permission status of each container group to be cancelled in the list of containers to be cancelled; Determine the container groups to be cancelled whose wall-closing permission status includes allowing wall-closing as intermediate container groups, and send the transmission paths corresponding to the intermediate container groups to the firewall end, so that the firewall end closes the firewalls corresponding to the intermediate container groups.
6. The method according to any one of claims 1 to 4, characterized in that, Open the firewall by the following method: Establish a current container group, and determine the wall-opening address information corresponding to the current container group from the preset free address information, where the wall-opening address information includes an access source address and at least one target access address; Determine the transmission path from the access source address to the target access address in the firewall end, and store the current container group and the transmission path corresponding to the current container group into a preset set to obtain a transmission path set; Generate wall-opening request information according to the transmission path, and send the wall-opening request information to a preset firewall end, so that the firewall end matches from a preset firewall policy set to obtain the security policy corresponding to the transmission path, and execute the security policy to open the firewall corresponding to the transmission path, where the firewall policy set includes at least one preset firewall policy.
7. The method according to claim 6, characterized in that, After sending the wall-opening request information to the firewall end, the method further includes: Receive the wall-opening request result feedback by the firewall end; If the wall-opening request result includes successful wall opening, perform an initialization query on the current container group corresponding to the wall-opening request result to obtain the initialization result of the current container group. If the initialization result includes completion of initialization, determine the current service status of the current container group as the running state; If the wall-opening request result includes failed wall opening, determine the current service status of the current container group as prohibited service.
8. A firewall shutdown system, characterized in that, Include: An acquisition module for acquiring a transmission path set and a firewall end, where the transmission path set includes at least one current container group and the transmission paths corresponding to each current container group, and the firewall end includes the firewalls corresponding to each transmission path; A query module for, if receiving a cancellation instruction corresponding to a container group to be cancelled, performing a current session query on the firewall end to obtain the current session number of the firewall end, and performing a status query on the container group to be cancelled to obtain the cancellation result corresponding to the container group to be cancelled, where the container group to be cancelled includes at least one current container group; A determination module, configured to determine the current load status of the firewall side according to the current session quantity, and determine the firewall permission status of the container group to be cancelled according to the current load status and the cancellation result, where the firewall permission status includes allowing firewall closing or prohibiting firewall closing; A closing module, configured to, if the firewall permission status includes allowing firewall closing, send the transmission path corresponding to the container group to be cancelled to the firewall side, so that the firewall side closes the firewall corresponding to the container group to be cancelled.
9. An electronic device, characterized in that, including: a processor and a memory; The memory is configured to store a computer program, and the processor is configured to execute the computer program stored in the memory, so that the electronic device executes the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, on which a computer program is stored, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
PAAS cloud cluster construction method and device, electronic device and storage medium
CN111193782A
Firewall opening method and device, computer equipment and storage medium
CN111711635A