Access Control Method, Apparatus, Device, and Storage Medium
By distinguishing the packets of public and dedicated line services in cloud networks and determining firewall rules based on service types for access control, security challenges such as DDoS attacks in cloud networks are solved, and security and resource utilization are improved.
Patent Information
- Application Number
- CN202310088881.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-17
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2043-01-17
AI Technical Summary
The existing technology is difficult to effectively respond to network security threats such as DDoS attacks in cloud networks, resulting in the deepening of security challenges.
By obtaining the service type of the original message and determining the target firewall rules based on the service type, access control is carried out on the message, distinguishing the service types of public networks and dedicated lines, and achieving unified access control.
It improves network security, reduces operation and maintenance costs, improves resource utilization, and effectively deals with network threats such as DDoS attacks.
Smart Images

Figure CN116055206B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of artificial intelligence, specifically to cloud computing, cloud storage, cloud network, and cloud database technologies, and can be applied in intelligent cloud scenarios. Background Art
[0002] With the continuous in-depth development of network technology, network security threats represented by DDoS (Distributed Denial of Service Attack) are becoming increasingly aggressive, resulting in a continuous escalation and deepening of the security challenges faced by cloud networks. How to address these network security threats is an urgent problem to be solved. Summary of the Invention
[0003] The present disclosure provides an access control method, apparatus, device, storage medium, and program product.
[0004] According to one aspect of the present disclosure, there is provided an access control method, including: obtaining an original message; determining the service type of the original message, where the service type includes a public network service type and a dedicated line service type; determining a target firewall rule corresponding to the original message according to the service type; and performing access control on the original message according to the target firewall rule.
[0005] According to another aspect of the present disclosure, there is provided an access control apparatus, including: an original message obtaining module for obtaining an original message; a service type determining module for determining the service type of the original message, where the service type includes a public network service type and a dedicated line service type; a rule determining module for determining a target firewall rule corresponding to the original message according to the service type; and a control module for performing access control on the original message according to the target firewall rule.
[0006] Another aspect of the present disclosure provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; where the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method shown in the embodiments of the present disclosure.
[0007] According to another aspect of the embodiments of the present disclosure, there is provided a non-transitory computer-readable storage medium storing computer instructions, where the computer instructions are used to cause a computer to execute the method shown in the embodiments of the present disclosure.
[0008] According to another aspect of the embodiments of the present disclosure, there is provided a computer program product, including computer programs / instructions, characterized in that when the computer programs / instructions are executed by a processor, the steps of the method shown in the embodiments of the present disclosure are implemented.
[0009] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] The drawings are used to better understand the solution and do not constitute a limitation to the present disclosure. Among them:
[0011] Figure 1 is a schematic diagram of the system architecture of the access control method and device according to an embodiment of the present disclosure;
[0012] Figure 2 schematically shows a flowchart of the access control method according to an embodiment of the present disclosure;
[0013] Figure 3A schematically shows a flowchart of the method for determining the service type of the original message according to an embodiment of the present disclosure;
[0014] Figure 3B schematically shows a schematic diagram of the method for determining the service type of the original message according to an embodiment of the present disclosure;
[0015] Figure 4 schematically shows a flowchart of the method for determining the target firewall rule corresponding to the original message according to an embodiment of the present disclosure;
[0016] Figure 5 schematically shows a flowchart of the method for performing access control on the original message according to the target firewall rule according to an embodiment of the present disclosure;
[0017] Figure 6 schematically shows a schematic diagram of the access control method according to another embodiment of the present disclosure;
[0018] Figure 7A schematically shows a flowchart of the access control method according to another embodiment of the present disclosure;
[0019] Figure 7B schematically shows a flowchart of the access control method according to another embodiment of the present disclosure;
[0020] Figure 8 schematically shows a block diagram of the access control device according to an embodiment of the present disclosure;
[0021] Figure 9 schematically shows a block diagram of an example electronic device that can be used to implement the embodiments of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0022] The following describes exemplary embodiments of the present disclosure with reference to the accompanying drawings. Various details of the embodiments of the present disclosure are included to assist in understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, descriptions of well-known functions and structures are omitted in the following description for clarity and conciseness.
[0023] The following will describe Figure 1 the system architecture of the access control method and device provided by the present disclosure.
[0024] Figure 1 FIG. is a schematic diagram of the system architecture of the access control method and device according to an embodiment of the present disclosure. It should be noted that Figure 1 the figure shown is only an example of the system architecture to which the embodiments of the present disclosure can be applied to help those skilled in the art understand the technical content of the present disclosure, but it does not mean that the embodiments of the present disclosure cannot be used in other devices, systems, environments or scenarios.
[0025] As Figure 1 shown, the system architecture 100 includes a virtual router (Virtual Router) 110, an external network gateway (EGW, External gateway) 120, a cloud firewall (CFW, Cloud Firewall) 130, a virtual switch 140, and a public-private network address translation device (NAT, Network Address Translation) 150.
[0026] Among them, the virtual router 110 can correspond to the dedicated line service. The virtual router 110 can be used to forward the packets of the dedicated line service to the private network. The virtual router 110 can include, for example, a Tofino-based virtual router (Tofino Virtual Router, TVR).
[0027] The external network gateway 120 can correspond to the public network service. The external network gateway 120 can be used to forward the packets in the public network to the private network.
[0028] The cloud firewall 130 can be used for access control of various network assets. Among them, the network assets can include, for example, EIP (Elastic IP), IPv6 gateway, NAT, VPC (virtual machine), etc. Exemplarily, the cloud firewall 130 can include modules such as APS (Availability Protection System), EIP, VPC, dedicated line, VPC NAT, NAT GW (gateway), etc. Among them, the APS module can be used to interact with APS. The EIP module can be used to protect the EIP. The VPC module can be used to provide VPC protection. The dedicated line module can be used to protect the dedicated line. The VPC NAT module can be used to provide VPC NAT protection. The NAT GW module can be used to provide NAT GW protection.
[0029] The virtual switch 140 can be used, for example, for data forwarding between multiple virtual machines.
[0030] The public-private network address conversion device 150 can be used to convert public network addresses and private network addresses. For example, when a private network node communicates with the public network, the private IP address of the private network node can be converted into a public IP address. Exemplarily, the public-private network address conversion device 150 can include modules such as EGW, NAT-EIP, NAT-GW, NAT-VPC, etc. Among them, the EGW module can be used to determine the next-hop node according to the hash table of the path. NAT-EIP can be used to provide public-private network address conversion services for EIP. NAT-GW can be used to provide public-private network address conversion services for GW. NAT-VPC can be used to provide public-private network address conversion services for VPC.
[0031] In the technical solution of the present disclosure, the collection, storage, use, processing, transmission, provision, disclosure, and application, etc., of the user's personal information involved all comply with the provisions of relevant laws and regulations, take necessary confidentiality measures, and do not violate public order and good customs.
[0032] In the technical solution of the present disclosure, before obtaining or collecting the user's personal information, the authorization or consent of the user has been obtained.
[0033] The following will be combined with Figure 2 to describe the access control method provided by the present disclosure.
[0034] Figure 2 Schematically shows a flowchart of an access control method according to an embodiment of the present disclosure. This method can be executed, for example, by the cloud firewall shown above.
[0035] As Figure 2 shown, the access control method 200 includes, in operation S210, obtaining an original message.
[0036] According to an embodiment of the present disclosure, for example, the original message can be obtained from the public network, and in addition, the original message can also be obtained from the dedicated line. Then, in operation S220, the service type of the original message is determined.
[0037] According to an embodiment of the present disclosure, the service type can include, for example, the public network service type and the dedicated line service type. Exemplarily, the message of the public network service type can be obtained from the public network, and the message of the dedicated line service type can be obtained from the dedicated line.
[0038] In operation S230, according to the service type, the target firewall rule corresponding to the original message is determined.
[0039] According to an embodiment of the present disclosure, the firewall rule can include, for example, the rule when performing access control on the message.
[0040] In this embodiment, corresponding firewall rules can be set for the public network service type and the dedicated line service type respectively, which are adapted to the characteristics of the messages of the public network service type and the dedicated line service type respectively.
[0041] In operation S240, according to the target firewall rule, access control is performed on the original message.
[0042] According to an embodiment of the present disclosure, by determining the target firewall rule corresponding to the original message through the service type and performing access control on the original message according to the target firewall rule, network assets in the network can be protected and network security threats can be reduced.
[0043] In addition, the access control method according to an embodiment of the present disclosure can perform unified access control on messages of two types, namely, the public network service type and the dedicated line service type, with high resource utilization rate and low operation and maintenance cost.
[0044] According to an embodiment of the present disclosure, for example, the original message can be obtained from the public network through the public network gateway. Based on this, the first message from the public network gateway can be received as the original message. In addition, the original message can be obtained from the dedicated line through the virtual router. Based on this, the second message from the virtual router can be received as the original message.
[0045] The following will be combined with Figure 3A The method for determining the service type of the original message provided by the present disclosure will be described.
[0046] Figure 3A A flowchart of the method for determining the service type of the original message according to an embodiment of the present disclosure is schematically shown.
[0047] As Figure 3AAs shown, the method 320 for determining the service type of the original message includes, in operation S321, determining tunnel endpoint information corresponding to the original message.
[0048] According to an embodiment of the present disclosure, the tunnel endpoint information may include, for example, a VTEP (VXLAN Tunnel Endpoint).
[0049] In operation S322, determine the direction of the original message according to the tunnel endpoint information.
[0050] According to an embodiment of the present disclosure, the direction of the message may include, for example, an inbound direction and an outbound direction. The inbound direction means that the message flows from the outside of the private network into the inside of the private network. The outbound direction means that the message flows from the inside of the private network to the outside of the private network.
[0051] In operation S323, determine whether the direction of the original message is the inbound direction. If the direction of the original message is the inbound direction, perform operation S324. If the direction of the original message is the outbound direction, perform operation S325.
[0052] In operation S324, determine the service type according to at least one of the network identifier, the destination Mac address, and the destination IP address included in the original message.
[0053] According to an embodiment of the present disclosure, the network identifier may include, for example, a VNI (VXLAN Network Identifier). The destination Mac address may be the Mac address of the destination node corresponding to the original message. The destination IP address may be the IP address of the destination node corresponding to the original message.
[0054] In operation S325, determine the service type according to at least one of the network identifier, the source Mac address, and the source IP address included in the original message.
[0055] According to an embodiment of the present disclosure, the source Mac address may be the Mac address of the source node corresponding to the original message. The source IP address may be the IP address of the source node corresponding to the original message.
[0056] According to an embodiment of the present disclosure, different service types may be distinguished, for example, by the tunnel endpoint information. Based on this, the corresponding relationship between the tunnel endpoint information of the message and the service type may be recorded in the service table in advance. Thus, the service type matching the tunnel endpoint information may be found in the service table.
[0057] After obtaining the service type by looking up the service table through the tunnel endpoint information, the firewall rule information may be further obtained according to the found service table.
[0058] According to an embodiment of the present disclosure, there can be multiple services, and multiple services can correspond to multiple service tables. If different services use the same tunnel endpoint information, the cloud firewall needs to first check whether there is a matching service type in one of the service tables. If it is not found in this service table, then another service table is checked. If it is found in this service table, the search can be stopped. Among them, the search order can be set as needed. For example, the search order can be determined according to the priority of the service table. The higher the priority, the earlier the search is performed.
[0059] According to another embodiment of the present disclosure, in the case where different services use the same tunnel endpoint information, for the coexistence of dedicated line and public network service scenarios, there are two possibilities for outbound and inbound directions. For the outbound direction, in the case where the dedicated line service packets and public network service packets in the VPC outbound direction use different MAC addresses, the service table of the dedicated line service can be checked first, and if the search fails, the service table of the public network service is checked.
[0060] For the inbound direction, the difference in the packets received by the cloud firewall is that the dedicated line service packets use the VNI of the user VPC, and the public network service packets use the system VPC VNI, and the system VPC VNI is fixed. Based on this, the service type can be distinguished by the VNI.
[0061] Considering the traffic direction, cloud edge network elements (such as EGW, TVR) can distinguish outbound and inbound directions through different tunnel endpoint information. However, for non-edge network elements (such as the cloud gateway CNAT in the traffic splitting scenario), one tunnel endpoint information is used to process outbound and inbound traffic, and the outbound and inbound directions can be distinguished through table item search. The business logic of the cloud firewall needs to distinguish the outbound and inbound information of the packets. After the cloud firewall is independently deployed, it can be configured whether to use different tunnel endpoint information to process outbound and inbound traffic.
[0062] The following refers to Figure 3B , and in combination with specific embodiments, the method for determining the service type of the original packet shown above is further described. Those skilled in the art can understand that the following example embodiments are only for understanding the present disclosure, and the present disclosure is not limited thereto.
[0063] Figure 3B A schematic diagram showing the determination of the service type of the original packet according to an embodiment of the present disclosure is schematically shown.
[0064] In Figure 3B , it is shown that, for example, the VTEP in the original packet can be obtained, and then it is determined whether the direction of the packet is inbound according to the VTEP.
[0065] If it is an inbound direction, based on the network identifier VNI and the destination Mac address included in the original packet, check if there is a matching service table. If there is a matching service table, determine that the original packet is of the private line service type and the direction is inbound according to the service table. If there is no matching service table, further check, based on the network identifier and the destination IP address, if there is a matching service table. If there is a matching service table, determine that the original packet is of the public network service type and the direction is inbound according to the service table. If there is still no matching service table, the original packet can be discarded.
[0066] If it is an outbound direction, based on the network identifier VNI and the source Mac address included in the original packet, check if there is a matching service table. If there is a matching service table, determine that the original packet is of the private line service type and the direction is outbound according to the service table. If there is no matching service table, further check, based on the network identifier and the source IP address, if there is a matching service table. If there is a matching service table, determine that the original packet is of the public network service type and the direction is outbound according to the service table. If there is no matching service table, the original packet can be discarded.
[0067] According to another embodiment of the present disclosure, for example, key information in the original packet can be obtained, where the key information includes at least one of the source IP address, the destination IP address, the source port, the destination port, and the protocol information. Then, determine the firewall rule in the firewall rule set that matches the key information as the target firewall rule.
[0068] According to the embodiment of the present disclosure, at least one firewall rule set can be set, where each firewall rule set includes at least one firewall rule. In the cloud firewall, a unified entry can be used for storage management of the firewall rule set without distinguishing the service type. For example, an identifier, such as an ID, can be assigned to each firewall rule set, and each firewall rule can correspond to an entry in the firewall rule set. Each entry can include a key and a value. The key of each entry can include information such as the five-tuple, direction, priority, etc., and the value of each entry can include the processing action of the firewall rule, where the processing action can include deny and allow. In particular, if the firewall rule fails to match, the corresponding processing action can be allow, and if the firewall rule fails to match, it can be processed according to the processing action configured in the firewall rule.
[0069] According to an embodiment of the present disclosure, a cloud firewall may be associated with multiple firewall rule sets, and the priorities of each firewall rule set may be different. When the cloud firewall performs matching, it needs to proceed in sequence according to the priorities of the firewall rule sets. The priorities of different firewall rule sets cannot be repeated. For example, the default priority of the firewall rule set may be 65535 (the lowest). Multiple firewall rule sets may adopt the longest mask matching. The number of firewall rule sets associated with each cloud firewall is limited, and they can be converted into the format of masks according to the priorities of the associated firewall rule sets. When matching the cloud firewall rule sets, the longest mask matching is used for the firewall rule sets. The control plane may sort according to the priorities of the associated firewall rule sets issued, and allocate the converted masks to each firewall rule set according to the sorting result. When issuing firewall rules, the converted masks may be used.
[0070] According to an embodiment of the present disclosure, for example, a firewall rule set may be carried in a packet, and the cloud firewall may obtain the firewall rule set from the packet. Alternatively, the control plane may issue the corresponding firewall rule set to the cloud firewall, as well as the correspondence between the rule set index and the firewall rule set. The rule set index is carried in the packet, and the cloud firewall may obtain the rule set index from the packet and determine the corresponding firewall rule set according to the rule set index and the correspondence.
[0071] The following will be combined with Figure 4 to describe the method for determining a target firewall rule corresponding to an original packet according to the service type provided by the present disclosure.
[0072] Figure 4 A flowchart of a method for determining a target firewall rule corresponding to an original packet according to an embodiment of the present disclosure is schematically shown.
[0073] As Figure 4 shown, the method 430 for determining a target firewall rule corresponding to an original packet includes performing operations S431 - S433 when the service type is a dedicated line service type, and performing operations S434 - S436 when the service type is a public network service type.
[0074] In operation S431, obtain the service path identifier and service function index in the original packet.
[0075] According to an embodiment of the present disclosure, a packet of the dedicated line service type may include, for example, an SFC (Service Function Chain) packet. The SFC packet may include an SPI (Service Path ID) and an SI (Service Index). For example, the SPI and SI may be obtained from the SFC packet.
[0076] Then, in operation S432, according to the service path identifier and the service function index, determine the firewall rule set.
[0077] According to an embodiment of the present disclosure, for example, the service path identifier can be used as the key to find the corresponding firewall rule set.
[0078] In operation S433, determine the firewall rule in the firewall rule set that matches the original packet as the target firewall rule.
[0079] According to an embodiment of the present disclosure, for example, the service function index can be used as the key to find the corresponding entry in the firewall rule set, and the obtained firewall rule corresponding to the entry is used as the target firewall rule.
[0080] In operation S434, obtain the rule set index in the original packet.
[0081] According to an embodiment of the present disclosure, packets of the dedicated line service type may include, for example, Overlay packets. The Overlay packet may include a rule set index, such as the ID of the firewall rule set. For example, the rule set index can be obtained from the Overlay packet.
[0082] In operation S435, according to the rule set index, determine the firewall rule set.
[0083] According to an embodiment of the present disclosure, for example, the rule set index can be used as the key to find the corresponding firewall rule set.
[0084] In operation S436, determine the firewall rule in the firewall rule set that matches the original packet as the target firewall rule.
[0085] According to an embodiment of the present disclosure, for example, find the firewall rule that matches the original packet in the found firewall rule set as the target firewall rule.
[0086] The following will be combined with Figure 5 Describe the method for performing access control on the original packet according to the target firewall rule provided by the present disclosure.
[0087] Figure 5 Schematically shows a flowchart of a method for performing access control on an original packet according to a target firewall rule according to an embodiment of the present disclosure.
[0088] As Figure 5 shown, the method 540 for determining the target firewall rule corresponding to the original packet includes, in operation S541, determining the processing action and the next-hop node corresponding to the original packet according to the target firewall rule.
[0089] In operation S542, it is determined whether the processing action is rejection. When the processing action is permission, operation S543 is executed. When the processing action is rejection, operations S544 to S545 are executed.
[0090] In operation S543, the original message is sent to the next-hop node corresponding to the original message.
[0091] In operation S544, a blocking log is generated based on the original message.
[0092] In operation S545, the blocking log is sent to the next-hop node corresponding to the original message.
[0093] According to another embodiment of the present disclosure, a log server (LogServer) can be preset to uniformly generate a blocking log for the rejected original log and send it to subsequent nodes to inform downstream nodes which messages are rejected. Through the blocking log, downstream nodes can be informed that the message is blocked so that downstream nodes can perform response measures such as resending a service request. There can be multiple log servers, and the corresponding log server can be selected by the method of symmetric consistent HASH (hash), so that in-coming and out-coming messages can be sent to the same log server.
[0094] Exemplarily, in this embodiment, for an SFC message, the SPI and SI have been obtained when the message is parsed. After the SFC message passes through the firewall rule matching, if the processing action of the firewall rule is rejection, the message can be forwarded to the log server to generate a blocking log. Before forwarding to the log server, the cloud firewall can strip information such as SPI and SI from the message. If the matching fails or the matching result is permission, the next-hop node can be found according to the SPI and SI for forwarding. The cloud firewall does not perceive the specific category of the next-hop information and directly encapsulates and forwards according to the destination VTEP and encapsulation format of the next-hop. The next-hop configuration of the SFC message can be issued through the control plane. If the next-hop node cannot be found by the SPI and SI, the message can be discarded, and at the same time, the discarded message is counted. When finding the next-hop node according to the SPI and SI, if the cloud firewall is the last node in the SFP, the information such as SPI and SI needs to be stripped when forwarding. If it is not the last node, the SI needs to be decremented by one when forwarding.
[0095] Exemplarily, in this embodiment, for Overlay packets, after finding the firewall rules, the distribution information is searched according to the firewall rules during distribution. Therefore, it is necessary to add a forwarding table with the rule set index as the key or add forwarding table information to the firewall rule set entry. After the packet searches the firewall rule set, the packets that cannot find the next-hop node are discarded or forwarded to the log server, and the statistical information is increased at the same time. If the next-hop node can be found through the firewall rule set, the packet is forwarded to the next-hop node. For example, when the processing action of the firewall rule is allowed, it is transferred to the next-hop service network element, and when the processing action is denied, it is transferred to the log server to generate a blocking log.
[0096] According to another embodiment of the present disclosure, the firewall can also be combined with other security devices. Other security devices can include, for example, AC (anti-DDoS-control, anti-DDoS control) devices, APS (Availability Protection System, availability protection system), etc.
[0097] Based on this, Figure 6 Schematically shows a schematic diagram of an access control method according to another embodiment of the present disclosure.
[0098] As Figure 6 shown, when the AC device detects a DDoS attack, it can instruct the external network gateway EGW to forward the original packet to the cloud firewall CFW and send an attack notification to the cloud firewall. According to an embodiment of the present disclosure, the attack defense device can include, for example, an AC device.
[0099] According to an embodiment of the present disclosure, the cloud firewall receives an attack notification from the attack defense device. In the case of receiving the attack notification, the availability protection system corresponding to the original packet is determined. Then the original packet is sent to the availability protection system so that the original packet can be data-cleaned by the availability protection system to obtain the target packet.
[0100] According to an embodiment of the present disclosure, for example, the corresponding availability protection system can be pre-configured in the cloud firewall. Or the corresponding availability protection system can also be specified in the attack notification.
[0101] According to an embodiment of the present disclosure, when the cloud firewall receives the attack notification, it can block the original packet and divert it to the APS device.
[0102] According to an embodiment of the present disclosure, the AC device can send a cleaning rule to the APS. The APS can perform data cleaning on the original packet according to the cleaning rule to obtain the target packet, and then send it to the cloud firewall.
[0103] According to an embodiment of the present disclosure, the cloud firewall receives a target packet from an availability protection system. According to the target firewall rule, the target packet is sent to the next-hop node.
[0104] According to an embodiment of the present disclosure, for example, the next-hop node can be determined according to the target firewall rule, and then the target packet is sent to the next-hop node.
[0105] According to another embodiment of the present disclosure, the firewall can also be externally attached with other firewalls, hereinafter referred to as externally attached firewalls. The externally attached firewall can be used for further security analysis of the packets. Exemplarily, packets for which the processing action in the firewall rule is allowed can also be forwarded to the externally attached cloud firewall for further security analysis. The externally attached firewall can include, for example, APS.
[0106] Based on this, Figure 7A A flowchart of an access control method according to another embodiment of the present disclosure is schematically shown.
[0107] As Figure 7A shown, the access control method 740 includes, in operation S741, determining an externally attached firewall corresponding to the original packet according to the target firewall rule.
[0108] In operation S742, the original packet is sent to the externally attached firewall so that the externally attached firewall is used for security analysis of the original data to obtain a re-injection packet.
[0109] According to an embodiment of the present disclosure, the externally attached firewall can perform security analysis on the original data to obtain a re-injection packet. The re-injection packet can be the original packet itself or a new packet generated according to the original packet. The new packet can be divided into two types. One is that the packet itself is modified and the packet forwarding logic remains unchanged; the other is that the packet itself is modified and the packet forwarding logic is also modified, such as inbound becoming outbound, or outbound becoming inbound.
[0110] In operation S743, the re-injection packet from the externally attached firewall is received.
[0111] In operation S744, the next-hop node corresponding to the re-injection packet is determined.
[0112] According to an embodiment of the present disclosure, if the forwarding logic of the re-injection packet is not modified relative to the original packet, the next-hop node corresponding to the original packet can be found. If the forwarding logic is modified, the corresponding next-hop node is found according to the modified forwarding logic.
[0113] In operation S745, the re-injection packet is sent to the next-hop node.
[0114] According to an embodiment of the present disclosure, the inbound security processing of a message can be before the NAT, and the outbound security processing can be after the NAT. The external firewall can bring the change of the message forwarding logic to the cloud firewall. The external firewall can implicitly transmit it by using different VTEPs, or it can be implemented by adding a protocol between the cloud firewall and the external firewall.
[0115] Figure 7B The flowchart of an access control method according to another embodiment of the present disclosure is schematically shown.
[0116] As Figure 7B shown, the cloud firewall receives the original message from the service network element 1. For the inbound original message, after being sent from the cloud firewall to the external firewall for processing, if the message forwarding logic remains unchanged, the external firewall can hang the inbound VTEP of the cloud firewall and inject the message back into the cloud firewall. If the message forwarding logic changes from inbound to outbound, the external firewall can hang the outbound VTEP of the cloud firewall and inject the message back into the cloud firewall. Then the cloud firewall sends the injected message to the next-hop node, that is, the service network element 2.
[0117] The following will be combined with Figure 8 to describe the access control device provided by the present disclosure.
[0118] Figure 8 The block diagram of an access control device according to an embodiment of the present disclosure is schematically shown.
[0119] As Figure 8 shown, the access control device 800 includes an original message acquisition module 810, a service type determination module 820, a rule determination module 830, and a control module 840.
[0120] The original message acquisition module 810 is configured to acquire the original message.
[0121] The service type determination module 820 is configured to determine the service type of the original message, where the service type includes a public network service type and a dedicated line service type.
[0122] The rule determination module 830 is configured to determine the target firewall rule corresponding to the original message according to the service type.
[0123] The control module 840 is configured to perform access control on the original message according to the target firewall rule.
[0124] According to an embodiment of the present disclosure, the rule determination module may include: a first acquisition sub-module, configured to acquire a service path identifier and a service function index in the original packet when the service type is a dedicated line service type; a first set determination sub-module, configured to determine a firewall rule set according to the service path identifier and the service function index, where the firewall rule set includes at least one firewall rule; and a first rule determination sub-module, configured to determine a firewall rule that matches the original packet in the firewall rule set as the target firewall rule.
[0125] According to an embodiment of the present disclosure, the rule determination module may include: a second acquisition sub-module, configured to acquire a rule set index in the original packet when the service type is a public network service type; a second set determination sub-module, configured to determine a firewall rule set according to the rule set index, where the firewall rule set includes at least one firewall rule; and a second rule determination sub-module, configured to determine a firewall rule that matches the original packet in the firewall rule set as the target firewall rule.
[0126] According to an embodiment of the present disclosure, the control module may include: a determination sub-module, configured to determine a processing action and a next-hop node corresponding to the original packet according to the target firewall rule, where the processing action includes reject and allow; a next-hop node determination sub-module, configured to send the original packet to the next-hop node corresponding to the original packet when the processing action is allow; and a blocking sub-module, configured to generate a blocking log according to the original packet and send the blocking log to the next-hop node corresponding to the original packet when the processing action is reject.
[0127] According to an embodiment of the present disclosure, the above device may further include: a notification receiving module, configured to receive an attack notification from an attack prevention and defense device; where the control module may include: a system determination sub-module, configured to determine an availability protection system corresponding to the original packet when receiving the attack notification; a first sending sub-module, configured to send the original packet to the availability protection system so that the original packet is subjected to data cleaning by the availability protection system to obtain a target packet; a first receiving sub-module, configured to receive the target packet from the availability protection system; and a second sending sub-module, configured to send the target packet to the next-hop node according to the target firewall rule.
[0128] According to an embodiment of the present disclosure, the control module may include: an offload determination sub-module for determining an offload firewall corresponding to the original packet according to the target firewall rule; a third sending sub-module for sending the original packet to the offload firewall so that the original data can be used for security analysis through the offload firewall to obtain a re-injection packet; a second receiving sub-module for receiving the re-injection packet from the offload firewall; a next-hop determination sub-module for determining the next-hop node corresponding to the re-injection packet; and sending the re-injection packet to the next-hop node.
[0129] According to an embodiment of the present disclosure, the service type determination module may include: a tunnel determination sub-module for determining tunnel endpoint information corresponding to the original packet; a direction determination sub-module for determining the direction of the original packet according to the tunnel endpoint information; a first service determination sub-module for determining the service type according to at least one of the network identifier, destination Mac address, and destination IP address included in the original packet when the direction of the original packet is incoming; and a second service determination sub-module for determining the service type according to at least one of the network identifier, source Mac address, and source IP address included in the original packet when the direction of the original packet is outgoing.
[0130] According to an embodiment of the present disclosure, the first rule determination sub-module and the second rule determination sub-module may include: a key information acquisition sub-module for acquiring key information in the original packet, where the key information includes at least one of the source IP address, destination IP address, source port, destination port, and protocol information; and a rule matching sub-module for determining a firewall rule in the firewall rule set that matches the key information as the target firewall rule.
[0131] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0132] Figure 9 A block diagram of an example electronic device 900 that can be used to implement the embodiments of the present disclosure is schematically shown. The electronic device is intended to represent various forms of digital computers, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0133] As Figure 9As shown, device 900 includes a computing unit 901 that can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 902 or a computer program loaded from a storage unit 908 into a random access memory (RAM) 903. In the RAM 903, various programs and data required for the operation of the device 900 can also be stored. The computing unit 901, the ROM 902, and the RAM 903 are connected to each other via a bus 904. An input / output (I / O) interface 905 is also connected to the bus 904.
[0134] Multiple components in the device 900 are connected to the I / O interface 905, including: an input unit 906, such as a keyboard, a mouse, etc.; an output unit 907, such as various types of displays, speakers, etc.; a storage unit 908, such as a magnetic disk, an optical disc, etc.; and a communication unit 909, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 909 allows the device 900 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0135] The computing unit 901 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 901 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The computing unit 901 executes the various methods and processes described above, such as the access control method. For example, in some embodiments, the access control method can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as the storage unit 908. In some embodiments, part or all of the computer program can be loaded and / or installed onto the device 900 via the ROM902 and / or the communication unit 909. When the computer program is loaded into the RAM903 and executed by the computing unit 901, one or more steps of the access control method described above can be executed. Alternatively, in other embodiments, the computing unit 901 can be configured to execute the access control method in any other appropriate manner (e.g., by means of firmware).
[0136] The various embodiments of the systems and techniques described above in this specification can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), systems on chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which may be a special-purpose or general-purpose programmable processor that receives data and instructions from, and transmits data and instructions to, a storage system, at least one input device, and at least one output device.
[0137] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program codes, when executed by the processor or controller, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The program code may execute entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine, or entirely on the remote machine or server.
[0138] In the context of the present disclosure, a machine-readable medium may be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0139] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).
[0140] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.
[0141] A computer system can include a client and a server. The client and the server are generally far from each other and typically interact through a communication network. The relationship between the client and the server is created by computer programs running on the respective computers and having a client-server relationship with each other.
[0142] The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services (″Virtual Private Server″, or simply ″VPS″). The server can also be a server of a distributed system, or a server combined with a blockchain.
[0143] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and no limitation is made herein.
[0144] The above specific embodiments do not constitute a limitation on the protection scope of the present disclosure. Those skilled in the art should understand that various modifications, combinations, sub - combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present disclosure shall be included within the protection scope of the present disclosure.
Claims
1. An access control method, comprising: Obtaining an original message; Determining the service type of the original message according to tunnel endpoint information corresponding to the original message, wherein the service type includes a public network service type and a dedicated line service type; Determining a target firewall rule corresponding to the original message according to the service type; and Performing access control on the original message according to the target firewall rule; Wherein, the determining a target firewall rule corresponding to the original message according to the service type includes: In the case where the service type is a dedicated line service type, Obtaining a service path identifier and a service function index in the original message; Determining a firewall rule set according to the service path identifier and the service function index, wherein the firewall rule set includes at least one firewall rule; and Determining a firewall rule in the firewall rule set that matches the original message as the target firewall rule.
2. The method according to claim 1, wherein, The determining a target firewall rule corresponding to the original message according to the service type further includes: In the case where the service type is a public network service type, Obtaining a rule set index in the original message; Determining a firewall rule set according to the rule set index, wherein the firewall rule set includes at least one firewall rule; and Determining a firewall rule in the firewall rule set that matches the original message as the target firewall rule.
3. The method according to claim 1, wherein, The performing access control on the original message according to the target firewall rule includes: Determining a processing action and a next-hop node corresponding to the original message according to the target firewall rule, wherein the processing action includes reject and allow; In the case where the processing action is allow, sending the original message to the next-hop node corresponding to the original message; and In the case where the processing action is reject, generating a blocking log according to the original message and sending the blocking log to the next-hop node corresponding to the original message.
4. The method according to claim 1, further comprising: Receiving an attack notification from an attack prevention and defense device; Wherein, the performing access control on the original message according to the target firewall rule includes: In the case of receiving the attack notification, determining an availability protection system corresponding to the original message; Sending the original message to the availability protection system so that the original message is subjected to data cleaning by the availability protection system to obtain a target message; Receiving the target message from the availability protection system; and Sending the target message to the next-hop node according to the target firewall rule.
5. The method according to claim 1, wherein The performing access control on the original message according to the target firewall rule includes: Determining an external firewall corresponding to the original message according to the target firewall rule; Sending the original message to the external firewall so that the original message is subjected to security analysis by the external firewall to obtain a re-injection message; Receiving the re-injection message from the external firewall; Determine the next-hop node corresponding to the re-injection message; and Send the re-injection message to the next-hop node.
6. The method according to claim 1, wherein The determination of the service type of the original message includes:[[]] Determine the tunnel endpoint information corresponding to the original message; Determine the direction of the original message according to the tunnel endpoint information; When the direction of the original message is inbound, determine the service type according to at least one of the network identifier, destination Mac address, and destination IP address included in the original message; and When the direction of the original message is outbound, determine the service type according to at least one of the network identifier, source Mac address, and source IP address included in the original message.
7. The method according to claim 2, wherein The determination of the firewall rule in the firewall rule set that matches the original message as the target firewall rule includes:[[]] Obtain the key information in the original message, where the key information includes at least one of the source IP address, destination IP address, source port, destination port, and protocol information; and Determine the firewall rule in the firewall rule set that matches the key information as the target firewall rule.
8. An access control device, comprising:[[]] An original message acquisition module for acquiring an original message; A service type determination module for determining the service type of the original message according to the tunnel endpoint information corresponding to the original message, where the service type includes a public network service type and a dedicated line service type; A rule determination module for determining the target firewall rule corresponding to the original message according to the service type; and A control module for performing access control on the original message according to the target firewall rule; Wherein, the rule determination module includes:[[]] A first acquisition sub-module for acquiring the service path identifier and service function index in the original message when the service type is a dedicated line service type; A first set determination sub-module for determining a firewall rule set according to the service path identifier and service function index, where the firewall rule set includes at least one firewall rule; and A first rule determination sub-module for determining the firewall rule in the firewall rule set that matches the original message as the target firewall rule.
9. An electronic device, comprising:[[]] At least one processor; And A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method according to any one of claims 1-7.
10. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to execute the method according to any one of claims 1-7.
11. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, the steps of the method according to any one of claims 1-7 are implemented.
Citation Information
Patent Citations
Public network IP sharing method suitable for multiple tenants of cloud data center and device
CN105978957A
Method and apparatus for autonomous firewall rule management
US20210084013A1