A security management method based on load balancing
By adopting a security management method based on load balancing in the data center network, the problem of data traffic imbalance is solved, the balanced allocation and security management of traffic are realized, and the network transmission performance is improved.
Patent Information
- Application Number
- CN202211571761.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-08
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2042-12-08
AI Technical Summary
The existing security management methods are difficult to achieve load balancing of data traffic in data center networks, resulting in unbalanced device interface traffic, affecting user experience and system performance.
The security management method based on load balancing is adopted to collect traffic data from the device interface, generate load balancing policies, and respond to management conditions to achieve balanced traffic allocation and security management.
The balanced allocation of traffic data is realized, the normal transmission and access of traffic data is ensured, the traffic load imbalance of the device interface is improved, and the network transmission performance is improved.
Smart Images

Figure CN116074251B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer security management, and particularly to a security management method based on load balancing. Background Art
[0002] At present, with the rapid development of information technology and network applications at a geometric and explosive rate, the data traffic in computer networks has increased sharply, and the processing capacity requirements for communication devices have also become higher and higher. After the performance improvement of single-core processors gradually reaches a bottleneck, devices in communication networks gradually adopt multi-core processors to improve data processing capabilities. However, there is often a problem of competition for data reception and transmission between multiple processors, which may lead to high occupancy and congestion of some processors while some processors are idling.
[0003] Existing security management methods make full use of the characteristics of data centers and improve or redesign solutions based on the Internet load balancing mechanism to solve the problem of the sharp increase in data traffic in data center networks. However, since different terminal servers and different business applications correspond to data streams with different traffic volumes, and even the traffic volumes of different data streams vary greatly, this results in unbalanced traffic on the interfaces of each device. Moreover, with the continuous expansion of the scale of data centers and the continuous increase in the functions carried by data centers, existing security management methods are difficult to achieve new goals, seriously affecting the user experience and reducing the usage performance of the entire system.
[0004] Therefore, how to provide a security management method based on load balancing is a technical problem to be solved at present. Summary of the Invention
[0005] In view of the above problems existing in the prior art, the object of the present invention is to provide a security management method based on load balancing, which can ensure the normal transmission of data traffic at the device interface, improve data processing capabilities, and achieve load balancing of traffic.
[0006] To achieve the above object, the present invention provides a security management method based on load balancing, and the method includes:
[0007] Collect traffic data transmitted to the first device interface, and obtain the outbound traffic of the first device interface according to the traffic data of the first device interface;
[0008] Obtain the to-be-configured conditions, and generate a load balancing policy based on the to-be-configured conditions;
[0009] Receive the load balancing policy, and respond to the first management condition according to the relationship between the load balancing policy and the first device interface;
[0010] Receive the outbound traffic of the first device interface and respond to the second management condition according to the relationship between the outbound traffic of the first device interface and the preset outbound traffic;
[0011] Perform security management on the first device interface according to the first management condition and the second management condition.
[0012] In one embodiment, before collecting the traffic data transmitted to the first device interface, it further includes:
[0013] Intercept the traffic data transmitted to the first device interface, determine the addressing information of the traffic data, and determine the destination address of the traffic data according to the addressing information;
[0014] Obtain the address information of the first device interface and determine whether the destination address conforms to the address information,
[0015] If the destination address does not conform to the address information, transmit the traffic data to the destination address;
[0016] If the destination address conforms to the address information, transmit the traffic data to the first device interface.
[0017] In one embodiment, the address information of the first device interface is the Internet protocol address and the Internet protocol port address.
[0018] In one embodiment, when collecting the traffic data transmitted to the first device interface and parsing the traffic data of the first device interface to obtain the outbound traffic of the first device interface, it includes:
[0019] Monitor the load status of the first device interface. When the first device interface is in an idle state, packetize the traffic data and transmit the packetized traffic data to the first device interface based on a preset transmission path;
[0020] Receive the traffic data transmitted to the first device interface and parse the traffic data of the first device interface to obtain the outbound traffic of the first device interface.
[0021] In one embodiment, when obtaining the to-be-configured conditions and generating a load balancing policy based on the to-be-configured conditions, it includes:
[0022] Obtain the initial configuration information, security protection information, and initial security protection policy;
[0023] Save the relationship among the initial configuration information, the security protection information, and the initial security protection policy, and generate the load balancing policy according to the relationship among the initial configuration information, the security protection information, and the initial security protection policy.
[0024] In one embodiment, when receiving the load balancing policy and responding to the first management condition according to the relationship between the load balancing policy and the first device interface, it includes:
[0025] Based on the relationship among the initial configuration information, the security protection information, and the initial security protection policy, determine whether the first device interface has an abnormality.
[0026] If the first device interface has an abnormality, close the first device interface, transmit the traffic data of the first device interface to the second device interface, and complete the transmission of the traffic data according to the second device interface.
[0027] If the first device interface has no abnormality, respond to the second management condition according to the relationship between the outbound traffic of the first device interface and the preset outbound traffic.
[0028] In one embodiment, when receiving the outbound traffic of the first device interface and responding to the second management condition according to the relationship between the outbound traffic of the first device interface and the preset outbound traffic, it includes:
[0029] According to the relationship between the outbound traffic of the first device interface and the preset outbound traffic, determine whether to transmit the traffic data of the first device interface to the third device interface.
[0030] If the outbound traffic of the first device interface is greater than the preset outbound traffic, transmit the traffic data of the first device interface to the third device interface, and complete the transmission of the traffic data based on the third device interface.
[0031] If the outbound traffic of the first device interface is less than or equal to the preset outbound traffic, complete the transmission of the traffic data based on the first device interface.
[0032] In one embodiment, after completing the transmission of the traffic data based on the third device interface, it further includes:
[0033] Obtain the outbound traffic of the third device interface within a preset time period, and divide the outbound traffic of the third device interface into multiple traffic data groups.
[0034] Calculate the average traffic value of the third device interface according to multiple traffic data groups, and determine whether to defend the third device interface according to the relationship between the average traffic value and the preset average traffic value.
[0035] In one embodiment, when determining whether to defend the third device interface according to the relationship between the average traffic value and the preset average traffic value, it includes:
[0036] If the average traffic value is less than the preset average traffic value, it is determined that security defense is required for the third device interface;
[0037] If the average traffic value is greater than or equal to the preset average traffic value, it is determined that no security defense is required for the third device interface.
[0038] In one embodiment, it further includes:
[0039] Real-time monitor the utilization rate of the first device interface.
[0040] The present invention provides a security management method based on load balancing. Compared with the prior art, it has the following beneficial effects:
[0041] The present invention discloses a security management method based on load balancing, which collects traffic data transmitted to the first device interface, obtains the outbound traffic of the first device interface according to the traffic data of the first device interface, obtains the conditions to be configured, generates a load balancing policy based on the conditions to be configured, receives the load balancing policy, responds to the first management condition according to the relationship between the load balancing policy and the first device interface, receives the outbound traffic of the first device interface, and responds to the second management condition according to the relationship between the outbound traffic of the first device interface and the preset outbound traffic, and performs security management on the first device interface according to the first management condition and the second management condition. The present invention can achieve balanced distribution of traffic data, ensure the normal transmission and access of traffic data, effectively improve the problem of uneven load of traffic data on the device interface, and improve network transmission performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 Shows a flowchart of a security management method based on load balancing in an embodiment of the present invention;
[0043] Figure 2 Shows a flowchart of responding to the first management condition in an embodiment of the present invention;
[0044] Figure 3 Shows a flowchart of responding to the second management condition in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0045] The specific embodiments of the present invention will be further described in detail below in conjunction with the accompanying drawings and embodiments. The following embodiments are used to illustrate the present invention, but are not used to limit the scope of the present invention.
[0046] In the description of the present application, it should be understood that the orientation or positional relationship indicated by the terms "center", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. is based on the orientation or positional relationship shown in the accompanying drawings, and is only for the convenience of describing the present application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation to the present application.
[0047] The terms "first" and "second" are only used for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present application, unless otherwise stated, the meaning of "plurality" is two or more.
[0048] In the description of the present application, it should be noted that unless otherwise clearly specified and defined, the terms "installed", "connected", and "connected" should be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or an integral connection; it may be a mechanical connection or an electrical connection; it may be directly connected, or indirectly connected through an intermediate medium, and it may be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood according to specific situations.
[0049] The following is a description of the preferred embodiments of the present invention in conjunction with the accompanying drawings.
[0050] As Figure 1 shown, an embodiment of the present invention discloses a security management method based on load balancing, and the method includes:
[0051] S110: Collect the traffic data transmitted to the first device interface, and obtain the outbound traffic of the first device interface according to the traffic data of the first device interface;
[0052] S120: Obtain the to-be-configured conditions, and generate a load balancing policy based on the to-be-configured conditions;
[0053] S130: Receive the load balancing policy, and respond to the first management condition according to the relationship between the load balancing policy and the first device interface;
[0054] S140: Receive the outbound traffic of the first device interface and respond to the second management condition according to the relationship between the outbound traffic of the first device interface and the preset outbound traffic;
[0055] S150: Perform security management on the first device interface according to the first management condition and the second management condition.
[0056] In this embodiment, traffic data transmitted to the first device interface is collected, the outbound traffic of the first device interface is obtained based on the traffic data of the first device interface, a condition to be configured is obtained, a load balancing policy is generated based on the condition to be configured, the load balancing policy is received, the first management condition is responded according to the relationship between the load balancing policy and the first device interface, the outbound traffic of the first device interface is received, and the second management condition is responded according to the relationship between the outbound traffic of the first device interface and the preset outbound traffic. Security management is performed on the first device interface according to the first management condition and the second management condition. The present invention can achieve balanced distribution of traffic data, ensure normal transmission and access of traffic data, effectively improve the problem of uneven load of traffic data on the device interface, and improve network transmission performance.
[0057] In some embodiments of the present application, before collecting the traffic data transmitted to the first device interface, it further includes:
[0058] Intercept the traffic data transmitted to the first device interface, determine the addressing information of the traffic data, and determine the destination address of the traffic data according to the addressing information;
[0059] Obtain the address information of the first device interface, and determine whether the destination address conforms to the address information,
[0060] If the destination address does not conform to the address information, transmit the traffic data to the destination address;
[0061] If the destination address conforms to the address information, transmit the traffic data to the first device interface.
[0062] In some embodiments of the present application, the address information of the first device interface is the Internet protocol address and the Internet protocol port address.
[0063] In this embodiment, the present invention can ensure the normal transmission of traffic data by obtaining the address information of the first device interface and determining whether the destination address conforms to the address information, prevent traffic data from being transmitted to an incorrect device interface, and effectively ensure the normal transmission of traffic data.
[0064] In some embodiments of the present application, when collecting traffic data transmitted to the first device interface and parsing the traffic data of the first device interface to obtain the outbound traffic of the first device interface, it includes:
[0065] Monitor the load status of the first device interface. When the first device interface is in an idle state, packetize the traffic data and transmit the packetized traffic data to the first device interface based on a preset transmission path;
[0066] Receive the traffic data transmitted to the first device interface and parse the traffic data of the first device interface to obtain the outbound traffic of the first device interface.
[0067] In this embodiment, when it is determined that traffic data needs to be transmitted to the first device interface, the load status of the first device interface is also monitored. When it is determined that the first device interface is in an idle state, traffic data is continuously received and the traffic data is transmitted to the first device interface according to a preset transmission path. The present invention can effectively prevent the phenomenon of excessive data traffic on the first device interface.
[0068] In some embodiments of the present application, when obtaining the conditions to be configured and generating a load balancing policy based on the conditions to be configured, it includes:
[0069] Obtain initial configuration information, security protection information, and an initial security protection policy;
[0070] Save the relationship among the initial configuration information, the security protection information, and the initial security protection policy, and generate the load balancing policy according to the relationship among the initial configuration information, the security protection information, and the initial security protection policy.
[0071] In this embodiment, a load balancing policy is generated according to the relationship among the initial configuration information, the security protection information, and the initial security protection policy. The initial configuration information can be configuration interfaces, members, policies, rules, etc. The security protection information can be behaviors such as the interface being disconnected or attacked. The initial security protection policy can be a policy for solving the security protection information, which can be specifically set and selected according to the actual situation and is not specifically limited here. Finally, a load balancing policy is generated according to the initial configuration information, the security protection information, and the initial security protection policy. Through the load balancing policy, abnormal monitoring and management of the device interface can be achieved.
[0072] As Figure 2 shown, in some embodiments of the present application, when receiving the load balancing policy and responding to the first management condition according to the relationship between the load balancing policy and the first device interface, it includes:
[0073] S131: Determine whether there is an abnormality in the first device interface based on the relationship between the initial configuration information, the security protection information, and the initial security protection policy.
[0074] S132: If there is an abnormality in the first device interface, close the first device interface, transfer the traffic data of the first device interface to the second device interface, and complete the transmission of the traffic data according to the second device interface.
[0075] S133: If there is no abnormality in the first device interface, respond to the second management condition according to the relationship between the outbound traffic of the first device interface and the preset outbound traffic.
[0076] In this embodiment, if there is an abnormality in the first device interface, close the first device interface, transfer the traffic data of the first device interface to the second device interface, and complete the transmission of the traffic data according to the second device interface. If there is no abnormality in the first device interface, respond to the second management condition according to the relationship between the outbound traffic of the first device interface and the preset outbound traffic. The present invention can transfer the traffic data to the second device interface when there is an abnormality in the first device interface, and complete the normal transmission of the traffic data through the second device interface, which can not only prevent the first device from being attacked, but also ensure the transmission of the traffic data, improving the stability and reliability of data transmission.
[0077] As Figure 3 shown, in some embodiments of the present application, when receiving the outbound traffic of the first device interface and responding to the second management condition according to the relationship between the outbound traffic of the first device interface and the preset outbound traffic, it includes:
[0078] S141: Determine whether to transfer the traffic data of the first device interface to the third device interface according to the relationship between the outbound traffic of the first device interface and the preset outbound traffic.
[0079] S142: If the outbound traffic of the first device interface is greater than the preset outbound traffic, transfer the traffic data of the first device interface to the third device interface, and complete the transmission of the traffic data based on the third device interface.
[0080] S143: If the outbound traffic of the first device interface is less than or equal to the preset outbound traffic, complete the transmission of the traffic data based on the first device interface.
[0081] In this embodiment, if the outbound traffic of the first device interface is greater than the preset outbound traffic, the traffic data of the first device interface is transmitted to the third device interface, and the transmission of the traffic data is completed based on the third device interface. If the outbound traffic of the first device interface is less than or equal to the preset outbound traffic, the transmission of the traffic data is completed based on the first device interface. The present invention can, when the outbound traffic of the first device interface is greater than the preset outbound traffic, complete the transmission of the traffic data through the third device interface, and can ensure that the data after splitting meets the subsequent processing requirements for user data.
[0082] In some embodiments of the present application, after completing the transmission of the traffic data based on the third device interface, it further includes:
[0083] Obtain the outbound traffic of the third device interface within a preset time period, and divide the outbound traffic of the third device interface into multiple traffic data groups;
[0084] Calculate the average traffic value of the third device interface according to the multiple traffic data groups, and judge whether to defend the third device interface according to the relationship between the average traffic value and the preset average traffic value.
[0085] In this embodiment, calculate the average traffic value of the third device interface according to the multiple traffic data groups, and judge whether to defend the third device interface according to the relationship between the average traffic value and the preset average traffic value. The present invention can effectively defend against malicious attacks by defending the third device interface.
[0086] In some embodiments of the present application, when judging whether to defend the third device interface according to the relationship between the average traffic value and the preset average traffic value, it includes:
[0087] If the average traffic value is less than the preset average traffic value, it is judged that security defense is required for the third device interface;
[0088] If the average traffic value is greater than or equal to the preset average traffic value, it is judged that no security defense is required for the third device interface.
[0089] In this embodiment, if the average traffic value is less than the preset average traffic value, it is judged that security defense is required for the third device interface. By performing security defense on the third device interface, the safe access of users can be guaranteed, the device interface can be prevented from being further attacked, and network penetration attacks and abnormal data access can be effectively prevented.
[0090] In some embodiments of the present application, it further includes:
[0091] Real-time monitor the utilization rate of the first device interface.
[0092] In this embodiment, the present invention can make flexible adjustments to the transmission of traffic data by monitoring the utilization rate of the first device interface in real time, improving the working efficiency and stability of the device interface.
[0093] In summary, the present invention discloses a security management method based on load balancing, which collects traffic data transmitted to the first device interface, obtains the outbound traffic of the first device interface according to the traffic data of the first device interface, obtains the to-be-configured conditions, generates a load balancing policy based on the to-be-configured conditions, receives the load balancing policy, responds to the first management condition according to the relationship between the load balancing policy and the first device interface, receives the outbound traffic of the first device interface, and responds to the second management condition according to the relationship between the outbound traffic of the first device interface and the preset outbound traffic, and performs security management on the first device interface according to the first management condition and the second management condition. The present invention can achieve balanced distribution of traffic data, ensure the normal transmission and storage of traffic data, and at the same time effectively improve the problem of unbalanced traffic data load on the device interface, improving the network transmission performance.
[0094] In the description of the above embodiments, specific features, structures, materials, or characteristics may be combined in a suitable manner in any one or more embodiments or examples.
[0095] Although the present invention has been described above with reference to the embodiments, various improvements can be made to it and components therein can be replaced with equivalents without departing from the scope of the present invention. In particular, as long as there is no structural conflict, the various features in the embodiments disclosed in the present invention can be combined with each other in any way. The situations of these combinations are not all described in this specification only for the sake of saving space and resources. Therefore, the present invention is not limited to the specific embodiments disclosed in the text, but includes all technical solutions falling within the scope of the claims.
[0096] Those of ordinary skill in the art can understand that the above are only the preferred embodiments of the present invention and are not used to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, for those skilled in the art, they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A security management method based on load balancing, characterized in that, the method includes: Collect traffic data transmitted to the first device interface, and obtain the outbound traffic of the first device interface according to the traffic data of the first device interface; Obtain the to-be-configured conditions, and generate a load balancing policy based on the to-be-configured conditions; Receive the load balancing policy, and respond to the first management condition according to the relationship between the load balancing policy and the first device interface; Receive the outbound traffic of the first device interface, and respond to the second management condition according to the relationship between the outbound traffic of the first device interface and the preset outbound traffic; Perform security management on the first device interface according to the first management condition and the second management condition; When obtaining the to-be-configured conditions and generating a load balancing policy based on the to-be-configured conditions, it includes: Obtain the initial configuration information, security protection information, and initial security protection policy; Save the relationship between the initial configuration information, the security protection information, and the initial security protection policy, and generate the load balancing policy according to the relationship between the initial configuration information, the security protection information, and the initial security protection policy; When receiving the load balancing policy and responding to the first management condition according to the relationship between the load balancing policy and the first device interface, it includes: Based on the relationship between the initial configuration information, the security protection information, and the initial security protection policy, determine whether the first device interface is abnormal, If the first device interface is abnormal, close the first device interface, and transmit the traffic data of the first device interface to the second device interface, and complete the transmission of the traffic data according to the second device interface; If the first device interface is not abnormal, respond to the second management condition according to the relationship between the outbound traffic of the first device interface and the preset outbound traffic; When receiving the outbound traffic of the first device interface and responding to the second management condition according to the relationship between the outbound traffic of the first device interface and the preset outbound traffic, it includes: According to the relationship between the outbound traffic of the first device interface and the preset outbound traffic, determine whether to transmit the traffic data of the first device interface to the third device interface, If the outbound traffic of the first device interface is greater than the preset outbound traffic, transmit the traffic data of the first device interface to the third device interface, and complete the transmission of the traffic data based on the third device interface; If the outbound traffic of the first device interface is less than or equal to the preset outbound traffic, complete the transmission of the traffic data based on the first device interface.
2. The security management method based on load balancing according to claim 1, characterized in that, Before collecting the traffic data transmitted to the first device interface, it further includes: Intercept the traffic data transmitted to the first device interface, determine the addressing information of the traffic data, and determine the destination address of the traffic data according to the addressing information; Obtain the address information of the first device interface, and determine whether the destination address conforms to the address information, If the destination address does not match the address information, the traffic data is transmitted to the destination address; If the destination address matches the address information, the traffic data is transmitted to the first device interface.
3. The load balancing-based security management method according to claim 2, characterized in that the address information of the first device interface is the Internet protocol address and the Internet protocol port address.
4. The load balancing-based security management method according to claim 1, characterized in that when collecting the traffic data transmitted to the first device interface and parsing the traffic data of the first device interface to obtain the outbound traffic of the first device interface, it includes: monitoring the load status of the first device interface, and when the first device interface is in an idle state, packetizing the traffic data and transmitting the packetized traffic data to the first device interface based on a preset transmission path; receiving the traffic data transmitted to the first device interface and parsing the traffic data of the first device interface to obtain the outbound traffic of the first device interface.
5. The load balancing-based security management method according to claim 1, characterized in that after the transmission of the traffic data is completed based on the third device interface, it further includes: obtaining the outbound traffic of the third device interface within a preset time period and dividing the outbound traffic of the third device interface into multiple traffic data groups; calculating the average traffic value of the third device interface according to the multiple traffic data groups, and judging whether to defend the third device interface according to the relationship between the average traffic value and the preset average traffic value.
6. The load balancing-based security management method according to claim 5, characterized in that when judging whether to defend the third device interface according to the relationship between the average traffic value and the preset average traffic value, it includes: if the average traffic value is less than the preset average traffic value, it is judged that security defense is required for the third device interface; if the average traffic value is greater than or equal to the preset average traffic value, it is judged that no security defense is required for the third device interface.
7. The load balancing-based security management method according to claim 1, characterized in that it further includes: real-time monitoring of the utilization rate of the first device interface.
Citation Information
Patent Citations
Method and device for managing link in load sharing
CN105991426A
Load balancing method and equipment
CN113132249A