Traffic security detection and cloud firewall configuration method, device and equipment
By configuring rules for cloud tenants and generating access control rules in the firewall backend, the problem of traditional hardware firewalls being unable to identify cloud tenant traffic needs is solved, achieving highly accurate traffic protection and multi-granular access control for cloud firewalls.
Patent Information
- Application Number
- CN202310202241.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-02
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2043-03-02
AI Technical Summary
Traditional hardware firewalls cannot identify the traffic protection needs of cloud tenants or websites at the granular level, resulting in low accuracy of traffic protection. Furthermore, the performance of general-purpose hardware servers developed in cloud service scenarios is poor.
Cloud tenants can issue configuration rules for each security detection function. The firewall backend server generates access control rules and issues them to the security detection policy group of the cloud firewall device, thereby achieving traffic access control at the cloud tenant level or the address object level.
It improves the accuracy of cloud firewall traffic protection, supports differentiated protection of inbound and outbound traffic, and provides a variety of security detection options through IPS mode.
Smart Images

Figure CN116318926B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud security technology, and more particularly to the field of cloud security protection technology, providing a method, apparatus, and device for traffic security detection and cloud firewall configuration. Background Technology
[0002] A firewall is a network security device used to inspect network traffic for security. It determines whether to allow or block network traffic based on the inspection results or pre-defined rules. With the development of cloud network technology and the increasing prevalence of cloud services, network security protection for cloud service scenarios has become increasingly important. Therefore, as a crucial security device for cloud network boundary protection, high performance and high stability are particularly important for cloud firewalls.
[0003] Currently, cloud firewalls typically deploy a traditional hardware firewall directly at the cloud's network egress point to protect traffic between the cloud's internal and external networks. However, cloud servers cater to a large number of cloud tenants, each of whom may deploy one or more websites. Traditional hardware firewalls, designed for physical servers that typically provide backend services for a single website, generally only support configuring traffic protection rules for that single website. Therefore, when directly applied to cloud service scenarios, traditional hardware firewalls cannot identify the specific traffic protection needs of each cloud tenant or website, resulting in low precision in traffic protection. Summary of the Invention
[0004] This application provides a traffic security detection and cloud firewall configuration method, apparatus, and device to enable cloud tenants to configure traffic protection rules and perform security detection, thereby improving the accuracy of cloud firewalls in traffic protection.
[0005] On the one hand, a traffic security detection method is provided for application in cloud firewall devices. This method includes:
[0006] Receive network traffic carrying a target address object, and match the target address object with each reference address object contained in the locally stored switch policy group; each reference address object is added to the switch policy group in response to the function launch request of the cloud tenant to which each reference address object belongs;
[0007] Upon successful matching, it is determined that the target address object has enabled the cloud firewall function, and the network traffic is matched with the access control rules contained in each of the multiple security detection policy groups. Each security detection policy group corresponds to a security detection function, and each access control rule is generated based on the rule template of the corresponding security detection function and the configuration rules sent by the cloud tenant.
[0008] When a match is successful, access control is applied to the network traffic based on the matched target access control rule.
[0009] On the one hand, a cloud firewall configuration method is provided, applied to a firewall backend server, the method comprising:
[0010] The system receives a configuration request triggered by a cloud tenant configuring at least one security detection function of a cloud firewall device. The configuration request carries the configuration rules corresponding to each of the at least one security detection function.
[0011] Based on at least one configuration rule and the target address object associated with the cloud tenant, the rule templates corresponding to each of the at least one security detection function are populated to generate access control rules corresponding to each of the at least one security detection function.
[0012] The generated access control rules are added to the corresponding security detection policy groups in the cloud firewall device, so that the cloud firewall device can perform security detection on network traffic carrying the target address object based on each security detection policy group.
[0013] On the one hand, a traffic security detection device is provided for use in cloud firewall devices. The device includes:
[0014] The traffic receiving unit is used to receive network traffic carrying target address objects;
[0015] A switch detection unit is used to match the target address object with each reference address object contained in the locally stored switch policy group; each reference address object is added to the switch policy group in response to the function launch request of the cloud tenant to which each reference address object belongs.
[0016] The security detection unit is used to determine that the target address object has enabled the cloud firewall function when the match is successful, and to match the network traffic with the access control rules contained in each of the multiple security detection policy groups; wherein, each security detection policy group corresponds to a security detection function, and each access control rule is generated based on the rule template of the corresponding security detection function and the configuration rules sent by the cloud tenant;
[0017] An execution unit is used to perform access control on the network traffic based on the matched target access control rule when a match is successful.
[0018] On the one hand, a cloud firewall configuration device is provided for use on a firewall backend server. The device includes:
[0019] A configuration receiving unit is configured to receive configuration requests triggered by cloud tenants performing configuration operations on at least one security detection function of a cloud firewall device, wherein the configuration request carries the configuration rules corresponding to each of the at least one security detection function.
[0020] The rule generation unit is used to fill in the rule templates corresponding to each of the at least one security detection function based on at least one configuration rule and the target address object associated with the cloud tenant, so as to generate the access control rules corresponding to each of the at least one security detection function.
[0021] The configuration distribution unit is used to add the generated access control rules to the corresponding security detection policy groups in the cloud firewall device, so that the cloud firewall device can perform security detection on network traffic carrying the target address object based on each security detection policy group.
[0022] On one hand, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of any of the above methods.
[0023] On the one hand, a computer storage medium is provided, on which a computer program is stored, which, when executed by a processor, implements the steps of any of the above methods.
[0024] On one hand, a computer program product is provided, comprising a computer program stored in a computer-readable storage medium. A processor of a computer device reads the computer program from the computer-readable storage medium, and executes the computer program, causing the computer device to perform the steps of any of the methods described above.
[0025] In this embodiment, cloud tenants can issue configuration rules for each security detection function. Correspondingly, the firewall backend server can generate corresponding access control rules based on the configuration rules and the rule template of the security detection function, and issue them to the corresponding security detection policy group in the cloud firewall device. Thus, when the cloud firewall device receives network traffic and determines that the target address object of the network traffic has enabled the cloud firewall function, it can perform rule matching on the network traffic based on the access control rules in its stored security detection policy groups. If the target access control rule is successfully matched, access control is performed on the network traffic based on the target access control rule. Thus, through the technical solution of this embodiment, firewall functions can be configured at the granularity of cloud tenants or the granularity of address objects associated with cloud tenants. Correspondingly, the cloud firewall device can perform traffic access control based on the granularity of cloud tenants or address objects, improving the accuracy of cloud firewall for traffic protection. Attached Figure Description
[0026] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0027] Figure 1 This is a schematic diagram illustrating an application scenario provided in the embodiments of this application;
[0028] Figure 2 This is a general architecture diagram of the cloud firewall system provided in the embodiments of this application;
[0029] Figure 3 A flowchart illustrating a cloud firewall configuration method provided in an embodiment of this application;
[0030] Figure 4 This is a schematic diagram of the startup page for launching the cloud firewall function provided in an embodiment of this application;
[0031] Figures 5a-5b This is a structural schematic diagram of the functional switch rule provided in the embodiments of this application;
[0032] Figure 6 Another flowchart illustrating the cloud firewall configuration method provided in this application embodiment;
[0033] Figures 7a to 7o A schematic diagram illustrating the configuration process provided in an embodiment of this application;
[0034] Figure 8 A flowchart illustrating the traffic security detection method provided in this application embodiment;
[0035] Figure 9 A flowchart illustrating the rule matching process provided in the embodiments of this application;
[0036] Figure 10 A schematic diagram of rule matching provided for embodiments of this application;
[0037] Figure 11 A schematic diagram illustrating log uploading and querying as provided in an embodiment of this application;
[0038] Figure 12 A flowchart illustrating the implementation process of the cloud firewall provided in this application embodiment;
[0039] Figure 13 A schematic diagram of the flow security detection device provided in the embodiments of this application;
[0040] Figure 14 A schematic diagram of a cloud firewall configuration device provided in an embodiment of this application;
[0041] Figure 15 This is a schematic diagram of the composition structure of a computer device provided in an embodiment of this application. Detailed Implementation
[0042] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application. Unless otherwise specified, the embodiments and features in the embodiments of this application can be arbitrarily combined with each other. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than that shown here.
[0043] It is understood that in the following specific embodiments of this application, cloud tenant-related data, such as address objects or network traffic, are involved. When the various embodiments of this application are applied to specific products or technologies, relevant licenses or consents need to be obtained, and the collection, use and processing of related data need to comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0044] To facilitate understanding of the technical solutions provided in the embodiments of this application, some key terms used in the embodiments of this application will be explained below:
[0045] Cloud firewall: A cloud firewall is a firewall in a cloud environment. Controlled and monitored via a cloud console, it's a firewall device used for network security protection in cloud service scenarios, providing precise protection and granular management of cloud network traffic. A cloud firewall can uniformly manage access control policies from the internet to cloud services, as well as micro-segmentation policies between cloud services.
[0046] Address objects: In cloud service scenarios, cloud tenants can deploy one or more cloud services. Cloud services refer to services obtained on demand and in a scalable manner via the network. These services can be IT and software, internet-related, or other services. This means that computing power can also be exchanged as a commodity via the internet. Cloud services are based on the provision, use, and interaction modes of internet-related services, typically involving the provision of dynamically scalable and often virtualized resources via the internet. For example, a cloud service can be a website backend, program service, or computing service, etc. An address object can uniquely correspond to a cloud service. When a cloud service needs to be used, it is usually accessed through an address object. For example, an address object can be the public Internet Protocol address (IP address) of the cloud service.
[0047] Network traffic: Network traffic refers to requests and responses to access cloud services through the cloud network. It can typically include inbound traffic entering the cloud server and outbound traffic leaving the cloud server.
[0048] Access control rules: To ensure the security of accessing cloud servers, risky network traffic needs to be filtered out through cloud firewalls. Access control rules are used to indicate the rules for filtering or allowing traffic. An access control rule includes the conditions for hitting the rule and the processing method for hitting the rule, thereby indicating which traffic needs to be filtered or allowed to pass directly when a specific type of traffic is received.
[0049] Intrusion Prevention System (IPS): An IPS is a supplement to antivirus programs and firewalls. It is a network security device that can detect network data transmission behavior of a network or network device, thereby detecting whether there is malicious activity in the network or system. The main function of an intrusion prevention system is to identify malicious activities, record information about the activities, report them, and attempt to block or prevent them, so as to interrupt, adjust, or isolate abnormal or harmful network data transmission behavior in a timely manner.
[0050] Security Domain: In a system, a domain is a logical entity. One or more interfaces can be bound to a domain. A domain to which policy rules are applied is a security domain. A security domain is a logical area composed of a group of systems with the same security protection requirements and mutual trust. For example, the intranet and the extranet can be different security domains.
[0051] Cloud tenant: A cloud tenant is a user of cloud services. Cloud tenants can purchase cloud services provided by cloud service providers to deploy their own applications or websites through cloud services.
[0052] Cloud technology refers to a hosting technology that unifies a series of resources such as hardware, software, and networks within a wide area network or local area network to achieve data computing, storage, processing, and sharing.
[0053] Cloud technology is a collective term for network technology, information technology, integration technology, management platform technology, and application technology applied to the cloud computing business model. It can form resource pools, providing flexible and convenient on-demand access. Cloud computing technology will become a crucial support. Backend services of technical network systems require substantial computing and storage resources, such as video websites, image websites, and many portal websites. With the rapid development and application of the internet industry, every item may have its own identification mark in the future, requiring transmission to backend systems for logical processing. Data at different levels will be processed separately, and various industry data will all require robust system support, which can only be achieved through cloud computing.
[0054] Cloud security refers to the collective term for security software, hardware, users, organizations, and security cloud platforms based on cloud computing business models. Cloud security integrates emerging technologies and concepts such as parallel processing, grid computing, and the identification of unknown virus behavior. Through a large network of clients, it monitors abnormal software behavior on the network, obtains the latest information on Trojans and malware on the internet, sends it to the server for automatic analysis and processing, and then distributes solutions for viruses and Trojans to each client.
[0055] The main research areas of cloud security include: cloud computing security, which focuses on how to ensure the security of the cloud itself and various applications on the cloud, including cloud computer system security, secure storage and isolation of user data, user access authentication, information transmission security, network attack protection, and compliance auditing; cloudification of security infrastructure, which focuses on how to use cloud computing to build and integrate security infrastructure resources and optimize security protection mechanisms, including building a large-scale security incident and information collection and processing platform through cloud computing technology to achieve the collection and correlation analysis of massive amounts of information and improve the ability to control and manage network-wide security incidents; and cloud security services, which focuses on various security services provided to users based on cloud computing platforms, such as antivirus services.
[0056] The embodiments of this application mainly involve security protection provided for cloud services, namely, deploying firewalls for cloud services to achieve security isolation between different security domains.
[0057] The design concept of the embodiments of this application will be briefly introduced below.
[0058] North-south cloud firewalls, as serial security devices between the cloud network and the physical network boundary, need to possess high performance and high stability, while also supporting management, configuration, and statistics at the cloud tenant level. However, current north-south cloud firewall solutions typically include the following two types:
[0059] The first approach is to deploy a traditional hardware firewall directly at the cloud's network egress point to protect traffic between the cloud's internal and external networks. However, traditional hardware firewalls are designed for backend protection of a single website and only support the configuration and detection of traffic protection rules for that single website. Therefore, when used in cloud service scenarios, they cannot support the configuration of traffic protection rules at the individual level of cloud tenants or websites. This makes it impossible to identify the traffic protection needs of each cloud tenant or website, resulting in low accuracy in traffic protection.
[0060] The second approach is to develop a cloud firewall for general-purpose servers in cloud service scenarios. However, this approach has a long development cycle and takes a long time to stabilize. Furthermore, the performance of general-purpose hardware servers is lower than that of dedicated hardware firewalls, resulting in poor firewall performance.
[0061] To ensure the high performance of cloud firewalls, it is necessary to use them in conjunction with dedicated firewall devices to achieve optimal performance. However, traditional firewall devices have the drawback of not being able to support the configuration of traffic protection rules at the individual level of cloud tenants or websites, and cannot achieve mutual isolation between cloud tenants. Therefore, if we want to reuse traditional firewall devices, we need to enable the configuration of traffic protection rules at the individual level of cloud tenants or websites to achieve unified management of cloud assets and security protection.
[0062] Based on this, in the technical solution provided in this application embodiment, cloud tenants can issue configuration rules for each security detection function. Correspondingly, the firewall backend server can generate corresponding access control rules based on the configuration rules and the rule template of the security detection function, and issue them to the corresponding security detection policy group in the cloud firewall device. Thus, when the cloud firewall device receives network traffic and determines that the target address object of the network traffic has enabled the cloud firewall function, it can perform rule matching on the network traffic based on the access control rules in each security detection policy group stored in itself. If the target access control rule is successfully matched, access control is performed on the network traffic based on the target access control rule. Thus, through the technical solution of this application embodiment, firewall functions can be configured at the granularity of cloud tenants or the granularity of address objects associated with cloud tenants. Correspondingly, the cloud firewall device can perform traffic access control based on the granularity of cloud tenants or address objects, thereby improving the accuracy of cloud firewall for traffic protection.
[0063] Furthermore, traditional firewall devices typically inspect traffic passing through them but do not support the differentiation between inbound and outbound traffic. The cloud firewall protection rules provided in this embodiment, however, have cloud security features. For example, when configuring rules for inbound and outbound traffic, cloud tenants are given the option to choose between inbound and outbound traffic. This allows the firewall's backend server to configure the security domain fields in the rule template based on the tenant's selection and to configure corresponding access control rules for each. Thus, when the firewall device performs security inspections, it can control inbound and outbound traffic using different access control rules. Additionally, IPS modes can be configured, such as observation mode, blocking mode, and strict mode.
[0064] The following is a brief introduction to the application scenarios to which the technical solutions of the embodiments of this application are applicable. It should be noted that the application scenarios described below are only for illustrating the embodiments of this application and are not intended to limit the scope. In specific implementation, the technical solutions provided by the embodiments of this application can be flexibly applied according to actual needs.
[0065] The solutions provided in this application can be applied to cloud security protection scenarios. For example... Figure 1 The diagram shown is an application scenario provided by an embodiment of this application. In this scenario, a first terminal device 101, a firewall backend server 102, a cloud firewall device 103, a cloud server 104, and a second terminal device 105 may be included.
[0066] The first terminal device 101 can be any device such as a mobile phone, tablet computer (PAD), laptop computer, desktop computer, smart TV, smart in-vehicle device, and smart wearable device. The first terminal device 101 can have a target application installed. The target application is used to implement the functions of the cloud console and to configure functions related to the cloud firewall. The application involved in this application embodiment can be a software client, or a webpage, mini-program, or other client; the specific type of client is not limited.
[0067] Firewall backend server 102 is the backend server corresponding to the aforementioned cloud console. For example, it can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, i.e., content delivery network (CDN), as well as big data and artificial intelligence platforms, but it is not limited to these.
[0068] The cloud firewall device 103 is a dedicated device for implementing firewall functions. The firewall backend server 102 configures various functions of the cloud firewall device 103 based on configuration rules issued by the cloud console. The cloud firewall device 103 then implements the traffic security detection process in actual applications based on these configurations. The cloud firewall device 103 can, for example, be implemented using a traditional firewall device. However, considering the potentially large traffic volume of the cloud server 104 in practical applications, one or more traditional firewall devices can be deployed to meet the needs of the actual scenario.
[0069] Cloud server 104 represents the cloud assets protected by the cloud tenant, which are the devices deployed for the cloud services of each cloud tenant. This is the object of protection of the cloud firewall in this embodiment of the application. The cloud firewall in this embodiment of the application protects network traffic entering and leaving the cloud server. Of course, cloud assets may include other assets besides cloud servers, and this embodiment of the application does not impose any restrictions on this.
[0070] In this embodiment, the firewall backend server 102 and the cloud server 104 can be implemented through the same device, or the firewall backend server 102 and the cloud server 104 can be implemented through different devices. That is, the firewall backend server 102 can also be used as a dedicated device for the function configuration and management of the cloud firewall. This embodiment does not limit this.
[0071] The second terminal device 105 can be any device such as a mobile phone, tablet computer (PAD), laptop computer, desktop computer, smart TV, smart in-vehicle device, and smart wearable device. The second terminal device 105 can interact with the cloud server 104 to obtain relevant cloud service functions.
[0072] For specific usage, please refer to Figure 1 As shown, cloud tenants can configure cloud firewall functions through the cloud console of the first terminal device 101, thereby sending the configuration rules to the firewall backend server 102. The firewall backend server 102 can then populate the rule template for the corresponding security detection function based on the configuration rules and the address object associated with the cloud tenant, thus generating corresponding firewall protection rules and sending the access control rules to the corresponding policy group of the cloud firewall device 103. The cloud firewall device 103 is located between the second terminal device 105 and the cloud server 104. When there is network traffic between the second terminal device 105 and the cloud server 104, the cloud firewall device 103 can receive the network traffic and then perform corresponding security detection based on the configured firewall protection rules to achieve traffic security protection. The protection logs generated within the cloud firewall device 103 are also uploaded to the firewall backend server 102 for querying through the cloud console of the first terminal device 101.
[0073] Both the firewall backend server 102 and the cloud firewall device 103 may include one or more processors, memory, and I / O interfaces for interaction. Furthermore, the firewall backend server 102 may be configured with a database to store data such as security detection logs for each cloud tenant. When a cloud tenant queries the database, the database can be retrieved and feedback can be provided to the cloud tenant. The memory of the firewall backend server 102 may store program instructions required for executing the cloud firewall configuration method provided in this embodiment. When these program instructions are executed by the processor, they can be used to implement the cloud firewall configuration process provided in this embodiment. Similarly, the cloud firewall device 103 may store program instructions required for executing the traffic security detection method provided in this embodiment. When these program instructions are executed by the processor, they can be used to implement the traffic security detection method process provided in this embodiment.
[0074] In this embodiment of the application, the various devices described above can be directly or indirectly connected to each other through one or more networks. Each of these networks can be a wired network or a wireless network. For example, a wireless network can be a mobile cellular network or a Wireless-Fidelity (WIFI) network. Of course, it can also be other possible networks. This embodiment of the application does not limit this.
[0075] In one possible implementation, the network between the second terminal device 105 and the cloud firewall device 103 can be referred to as the external network or the public network, and the network between the cloud server 104 and the cloud firewall device 103 can be referred to as the internal network. The terms external network and internal network are relative. The external network refers to a more open network compared to the internal network, while the internal network can be a network connecting trusted areas.
[0076] It should be noted that, Figure 1 The examples shown are merely illustrative. In actual applications, the number of each of the above-mentioned devices is not limited, and no specific limitation is made in this embodiment.
[0077] like Figure 2 The diagram shown is an overall architecture diagram of a cloud firewall system provided in this application embodiment. The architecture may include a cloud console, a cloud firewall backend, and a cloud firewall engine. Each part will be described in detail below.
[0078] (1) The cloud console provides a user interface for cloud tenants to configure the cloud firewall. Through this interface, cloud tenants can configure cloud firewall functions and customize their individual firewall needs. The cloud console can be in the form of a client application or a World Wide Web (web) page. See also... Figure 2 As shown, each cloud tenant can send configurations to the cloud firewall backend through its own corresponding cloud console and receive logs returned by the cloud firewall backend.
[0079] (2) The cloud firewall backend is used to convert the cloud tenant's configuration rules into access control rules that the cloud firewall engine can recognize, and to store and manage the security detection logs sent by the cloud firewall engine. The cloud firewall backend can be deployed on the firewall backend server mentioned above.
[0080] (3) The cloud firewall engine is used to perform security inspections on received network traffic and perform corresponding access control based on the configured security inspection policy groups. The cloud firewall engine can be implemented, for example, through the cloud firewall device mentioned above.
[0081] In practical use, cloud tenants can send requests to the cloud firewall backend through the cloud console to configure the firewall and view firewall logs. The cloud firewall backend identifies different cloud tenants based on the request source and then sends the configuration to the firewall by calling the web interface of the cloud firewall engine, or queries the logs of the corresponding tenant to return the relevant log information. The log information stored in the cloud firewall backend is sent to the cloud firewall backend by the cloud firewall engine through the log outgoing function. After receiving it, the cloud firewall backend aggregates, analyzes, and stores it in a format that is convenient for tenants to query.
[0082] The following describes various methods provided by exemplary embodiments of this application in conjunction with the application scenarios described above and with reference to the accompanying drawings. It should be noted that the above application scenarios are only shown to facilitate understanding of the spirit and principles of this application, and the embodiments of this application are not limited in any way in this respect.
[0083] Traffic security inspection of cloud firewall devices needs to be performed in conjunction with the configured policy groups. Therefore, before the cloud firewall device performs security inspection, it is necessary to configure the relevant rules of the cloud firewall device. Therefore, the configuration process of each cloud firewall function will be introduced here.
[0084] See Figure 3 The diagram shown is a flowchart of a cloud firewall configuration method provided in this application embodiment. The specific implementation process of this method is as follows:
[0085] Step 301: The cloud console receives the cloud firewall function startup operation performed by the cloud tenant.
[0086] In this embodiment of the application, to ensure the security of cloud services, cloud tenants can typically enable the cloud firewall function for their deployed cloud services. Cloud tenants can then enable the cloud firewall function for their own cloud services through the cloud console. See also... Figure 4 The image shown is a schematic of the startup page for enabling the cloud firewall function presented in the cloud console. Cloud tenants can select whether to enable the cloud firewall, for example... Figure 4 As shown, selecting "Yes" indicates that the cloud firewall function will be enabled. When a cloud tenant has deployed multiple cloud services, they can also choose which cloud services to enable this function for. Selected cloud services will have the cloud firewall function enabled, while unselected services will not have the cloud firewall function enabled by default. Figure 4 As shown, cloud tenants can select the address objects that need to be started to configure cloud firewall functions for the corresponding cloud services.
[0087] Step 302: The cloud console sends a function start request to the firewall backend server, which instructs to start the cloud firewall function of the target address object.
[0088] In this embodiment, after completing the settings for each startup selection, the cloud console can send a function startup request to the cloud firewall backend based on the cloud tenant's confirmation operation, requesting the cloud firewall backend to start the cloud firewall function for the target address object. The function startup request can carry the target address object for which the cloud firewall function needs to be started, i.e., the address objects selected by the cloud tenant.
[0089] Step 303: The firewall backend server configures the target address object as an exception address object in the function switch rules of the cloud firewall device.
[0090] In this embodiment, each address object can be, for example, a public IP address. In the cloud firewall, firewall protection is enabled and disabled for each public IP address. Only when the firewall function for a specified public IP address is enabled will the network traffic of that public IP address be detected and protected by the cloud firewall device. However, traditional hardware firewalls do not have this function. This embodiment uses the access control and address object functions of a traditional hardware firewall to implement the on / off function of the cloud firewall.
[0091] The cloud firewall device includes a switch policy group, which has the highest priority. Before performing security checks on network traffic, it's necessary to determine whether the network traffic requires security checks. The switch policy group helps determine whether received network traffic needs further security checks. Only when security checks are deemed necessary will the subsequent detection and protection process continue. In other words, the function switch rules within the switch policy group instruct how to determine whether to enable the cloud firewall function. Only network traffic with the cloud firewall function enabled will continue to undergo security checks, while network traffic with the firewall function disabled is typically allowed to pass directly.
[0092] In one possible implementation, the switch policy group can be configured with a function switch rule, which can be configured to implement access control rules of traditional hardware firewalls through certain configuration methods.
[0093] See Figure 5a The diagram shown is an example of the structure of an access control rule. An access control rule may include, but is not limited to, the following fields:
[0094] (1) Security zone field, including source security zone field and destination security zone field, is used to configure the security zone corresponding to network traffic that requires access control.
[0095] (2) The IP address field, including the source IP address field and the destination IP address field, is used to configure the address objects corresponding to the network traffic that requires access control. The source IP address field and the destination IP address field reference the source address object and the destination address object, respectively.
[0096] (3) Port field, including source port field and destination port field, is used to configure the port corresponding to the network traffic that requires access control.
[0097] (4) Protocol field, used to configure the protocol corresponding to network traffic that requires access control.
[0098] (5) Action field, used to configure how to handle the access control rule after it is hit, such as whether to drop the network traffic or allow the network traffic.
[0099] In addition, address objects have the function of adding exceptions. When the default setting is used, it means that all address objects will be matched. If an exception address object is added, it means that all other address objects except the exception address object will be matched with the access control rule. Taking IP addresses as an example, when the default setting of the IP address field is "any", it means that all IP addresses will be matched. If an exception IP address is added, it means that all other IP addresses except the exception IP address will be matched.
[0100] Therefore, in this embodiment, both the source address object and the destination address object can be set to "any" by default. This means that by default, all IPs will match the function switch rules in the switch policy group, resulting in network traffic being directly allowed through without any security checks. Essentially, the cloud firewall switch is disabled by default for all address objects. When it's necessary to enable the cloud firewall function for a target address object, simply set the target address object as an exception address object in the function switch rules. For example, to enable the cloud firewall function switch for a specific IP address, simply add that IP address as an exception IP address in both the source and destination address objects.
[0101] See Figure 5b The diagram shown illustrates the configuration of a function switch rule. Figure 5b As shown, both the source security zone and destination security zone fields are set to "any," indicating that network traffic from all security zones can match the function switch rule. The source IP address and destination IP address fields reference the source and destination address objects respectively, and the target address object for enabling the cloud firewall function switch is set as the exception address object for both the source and destination address objects, ensuring that network traffic from all address objects except the target address object can match the function switch rule. The destination port and protocol fields are both set to "any," indicating that network traffic from all ports and network traffic using any protocol can match the function switch rule. The action field is set to "accept," meaning that network traffic that matches the function switch rule is allowed. Therefore, through this configuration, network traffic corresponding to the target address object with the cloud firewall switch enabled will not match the function switch rule, while the non-matching network traffic needs to undergo security checks to continue the subsequent detection process, thus enabling and disabling the cloud firewall function.
[0102] Similarly, the above process describes how to enable the cloud firewall function. Disabling the cloud firewall function is similar; you only need to delete the address object for disabling the cloud firewall function from the exception address object in the function switch rule.
[0103] In one possible implementation, the firewall backend server can configure the target address object as an exception address object for the function switch rule, generate an updated function switch rule, and then send the function switch rule to the cloud firewall device. The cloud firewall device can then update the locally stored switch policy group with the updated function switch rule.
[0104] In one possible implementation, the firewall backend server can also directly send a configuration instruction to the cloud firewall device. This configuration instruction can carry a target address object and a configuration command to add the target address object as an exception address object of the function switch rule. In response to the configuration command, the cloud firewall device can add the target address object as an exception address object of its own stored function switch rule.
[0105] In this embodiment, multiple security detection functions are provided for the network traffic to be detected. Therefore, if the cloud tenant has enabled the cloud firewall function, the cloud tenant can also configure these security detection functions. It should be noted that the configuration of the security detection functions and the configuration of the cloud firewall function can be performed simultaneously or sequentially. That is, the cloud tenant can configure the security detection functions when starting the cloud firewall function; or, it can configure each security detection function after starting the cloud firewall function; or, it can configure the security detection functions at the same time as starting the cloud firewall function, and then supplement or update the configuration for each security detection function later. This embodiment does not impose any restrictions on this.
[0106] See Figure 6 The diagram shown is another flowchart of the cloud firewall configuration method provided in this application embodiment. The method is described below.
[0107] Step 601: The cloud console receives configuration operations performed by the cloud tenant for at least one security detection function.
[0108] In this embodiment, cloud tenants can configure various security detection functions through the configuration interface provided by the cloud console to obtain configuration rules that meet their own security detection needs. See also Figure 7aThe image shows a schematic of the security detection function configuration page presented in the cloud console. Cloud tenants can select the security detection function to be configured from multiple options. Of course, once a security detection function is configured, more can be added, allowing multiple security detection functions to be configured in a single process. Furthermore, as shown... Figure 7a As shown, for the currently selected security detection function, cloud tenants can configure each of its configuration items separately to generate the configuration rules for that security detection function. It should be noted that... Figure 7a Only two configuration items are shown, but in actual applications, the number of configuration items is not limited. The corresponding configuration items can be configured according to the actual security detection functions.
[0109] Step 602: In response to the configuration operation, the cloud console sends a configuration request to the firewall backend server. The configuration request carries the configuration rules corresponding to at least one security detection function.
[0110] In this embodiment of the application, when a cloud tenant completes the configuration operation and confirms the initiation of the configuration request, the cloud console can generate configuration rules corresponding to at least one security detection function based on the cloud tenant's configuration operation, and send the configuration request to the firewall backend server based on these configuration rules.
[0111] Step 603: Based on at least one configuration rule and the target address object associated with the cloud tenant, the firewall backend server populates the rule templates corresponding to each of the at least one security detection function to generate access control rules corresponding to each of the at least one security detection function.
[0112] In this embodiment, the configuration rules for each security detection function already indicate how to configure the corresponding security detection function. Furthermore, by combining the target address object associated with the cloud tenant, the rule templates corresponding to each security detection function can be populated to generate the corresponding access control rules. However, it should be noted that although the access control rules here have the same names as those in traditional hardware firewalls, the configuration methods for different security detection functions are different. Therefore, the access control rules in this embodiment can achieve functions completely different from those in traditional hardware firewalls.
[0113] Specifically, considering that the access control rules in traditional hardware firewalls can be directly recognized by traditional hardware firewalls, the rule templates corresponding to each security detection function in this application embodiment can reuse the access control rules in traditional hardware firewalls, but different configuration methods are used to achieve different functions.
[0114] Traditional hardware firewalls lack the concept of outbound and inbound traffic, thus they do not support distinguishing between inbound and outbound traffic, nor do they support isolation between cloud tenants. In this embodiment, due to the involvement of traffic protection for a large number of cloud tenants, a cloud firewall solution that differentiates between outbound and inbound network traffic is proposed to improve the accuracy of traffic protection by configuring outbound and inbound rules accordingly. This allows for the use of different traffic protection rules for outbound and inbound traffic.
[0115] Therefore, the following approach can be used when filling in each security detection function, and we will take one security detection function as an example for introduction.
[0116] See Figure 5a As shown, access control rules include source security domain fields and destination security domain fields. The security domain distinguishes whether the connected network is an internal network or an external network. For example, when the source security domain is an internal network and the destination security domain is an external network, it indicates that the current network traffic is from the internal network to the external network, and therefore its flow direction is outbound. Based on this, inbound and outbound traffic can be distinguished. During configuration, the flow direction option can be provided in the configuration interface, allowing selection whether the current configuration is for inbound or outbound traffic. The generated configuration rules will then indicate the flow direction, and when filling in the rules, the security domain field in the rule template can be filled in based on the flow direction indicated by the configuration rules.
[0117] Since access control of traditional hardware firewalls supports security domain-based filtering, in this embodiment, a first security domain and a second security domain are created respectively. The first security domain connects to an untrusted network and is indicated by a first security domain identifier. For example, if the untrusted network is an external network, it can be identified by the "untrust" identifier. The firewall network interface connecting to the external network can then be added to the untrust domain. The second security domain connects to a trusted network and is indicated by a second security domain identifier. For example, if the network is an internal network, it can be identified by the "trust" identifier. The firewall network interface connecting to the internal network can then be added to the trust domain.
[0118] In one possible implementation, if the flow direction is the inbound direction, the source security field is filled with a first security field identifier, and the destination security field is filled with a second security field identifier.
[0119] In one possible implementation, if the flow direction is the outbound direction, which is opposite to the inbound direction described above, the source security field is filled with a second security field identifier, and the destination security field is filled with a first security field identifier.
[0120] In this embodiment of the application, in addition to the flow direction, the configuration rules can also indicate address objects. Depending on the security detection function, the meaning of these address objects is different. They may be address objects that are directly allowed to pass or address objects that need to be discarded. When configuring, they need to be added to the corresponding address object field.
[0121] In one possible implementation, if the flow direction is inbound, that is, the network traffic should be entering the internal network from the external network, then the source address should be the external network address, and the destination address should be the internal network address of the cloud service deployed by the cloud tenant on the firewall backend server. Therefore, the address object indicated by the configuration rule can be filled into the source address field in the rule template, and the target address object associated with the cloud tenant can be filled into the destination address field in the rule template.
[0122] In one possible implementation, if the flow direction is outbound, that is, the network traffic should be from the internal network to the external network, then the source address should be the internal network address and external network address corresponding to the cloud tenant, and the destination address should be the external network address. In this case, the source address field can be filled based on the destination address object, and the destination address field can be filled based on the address object indicated in the configuration rule.
[0123] Step 604: The firewall backend server adds the generated access control rules to the corresponding security detection policy groups in the cloud firewall device.
[0124] In this embodiment of the application, in order to distinguish the access control rules corresponding to different security detection functions, the aggregation policy group function of the access control module of the traditional hardware firewall is used to create security detection policy groups corresponding to each security detection function. Then, the firewall backend server adds the generated access control rules to the corresponding security detection policy groups in the cloud firewall device, so that the cloud firewall device can perform security detection on network traffic carrying the target address object of the cloud tenant based on each security detection policy group.
[0125] The following section uses specific examples of security detection functions to illustrate the configuration process for each function.
[0126] In this embodiment of the application, the security detection function may include, but is not limited to, the following security detection functions:
[0127] (1) Whitelist detection function. The whitelist means that the network traffic can be directly allowed. Therefore, in actual application, the function detects whether the network traffic meets the whitelist rules. If it does, the network traffic can be directly allowed.
[0128] As described above, in this embodiment of the application, the whitelist detection function of the cloud firewall device supports both inbound and outbound whitelist detection functions, that is, it can block or allow the inbound source IP and the outbound destination IP respectively, and supports tenant isolation. Moreover, when the number of configured IPs is large, it may be in the tens of thousands.
[0129] Specifically, the whitelist detection function distinguishes between outbound and inbound directions through the configuration of security zones, while tenant isolation is based on the public IP address of the cloud tenant.
[0130] See Figure 7b The image shows a schematic of the whitelist configuration interface. When the security detection function is selected as the whitelist detection function, you can set the address objects that can be directly allowed, as well as the flow direction of the traffic to be detected, as shown below. Figure 7b The IP addresses shown are those that are directly allowed. Of course, in practical applications, other possible methods besides IP addresses can be used to indicate address objects, and this application embodiment does not limit this.
[0131] Once the cloud tenant confirms the configuration, the configuration rules can be sent to the firewall backend server. Figure 7b Taking the example shown, this configuration is for the inbound direction of the whitelist detection function. The allowed IPs include IP1 to IP3 as shown in the figure. The configuration process for this rule is as follows: Figure 7c As shown.
[0132] The access control rules generated by the firewall backend server are as follows: Figure 7c As shown, the configuration rule is for the inbound direction of the whitelist detection function, and the configuration rule carries the allowed IPs. When the firewall backend server generates the corresponding access control rule, it sets the source and destination security zones to untrust and trust, respectively, to correspond to the inbound direction. It sets the source IP to the IP to be allowed, the destination IP to any public IP belonging to the cloud tenant, the destination port and protocol to ANY, and the action to ACCEPT. Then, the generated access control rule is added to the whitelist detection policy group of the traditional hardware firewall. This instructs the traditional hardware firewall that when it receives inbound network traffic from the cloud tenant, if its source address is one of the aforementioned allowed IPs, the access control rule will be triggered, and the traditional hardware firewall can directly allow the traffic.
[0133] Of course, the cloud tenants mentioned above have not configured the above functions for public IPs, so they can configure all their public IPs by default. However, in actual applications, cloud tenants can also choose to set some public IPs and perform security checks on the traffic of only some public IPs.
[0134] When the flow direction is the outbound direction, the process is similar to the one described above; see [link to relevant documentation]. Figure 7d The diagram illustrates the configuration process for the outbound whitelist detection function. Specifically, the cloud firewall configuration rules issued by the cloud tenant are configured for the outbound direction of the whitelist detection function, and these rules include the allowed IP addresses. When the firewall backend server generates the corresponding access control rules, please refer to... Figure 7d As shown, the source and destination security zones are set to trust and untrust, respectively, to correspond to the outbound direction. The source IP is set to any public IP address belonging to the cloud tenant, the destination IP is set to the IP to be allowed, the destination port and protocol are both set to ANY, and the action is set to ACCEPT. The generated access control rule is then added to the whitelist detection policy group of the traditional hardware firewall. This instructs the traditional hardware firewall that when it receives outbound network traffic from the cloud tenant, if the destination address is the aforementioned IP to be allowed, the access control rule will be triggered, and the traditional hardware firewall can directly allow the traffic.
[0135] (2) Blacklist detection function. A blacklist means that it can be directly blocked. Therefore, in practical applications, it detects whether network traffic meets the blacklist blocking rules. If it does, the network traffic can be directly blocked.
[0136] In this embodiment of the application, the blacklist detection function of the cloud firewall device supports both inbound and outbound blacklist detection functions, that is, it can intercept or block the source IP in the inbound direction and the destination IP in the outbound direction respectively, and supports tenant isolation.
[0137] Similarly, the blacklist detection function distinguishes between outbound and inbound directions through the configuration of security zones, while tenant isolation is based on the public IP address of the cloud tenant.
[0138] See Figure 7e The image shows a schematic of the blacklist configuration interface. When the selected security detection function is the blacklist detection function, the address objects to be directly blocked can be set, such as... Figure 7b The IP addresses shown are the ones that were directly intercepted.
[0139] Once the cloud tenant confirms the configuration, the configuration rules can be sent to the firewall backend server. Figure 7b Taking the example shown, this configuration is for the inbound direction of the blacklist detection function. The configured blocking IPs include IP4 to IP6 as shown in the figure. The configuration process for this rule is as follows: Figure 7f As shown.
[0140] The access control rules generated by the firewall backend server are as follows: Figure 7fAs shown, the configuration rule is for the inbound traffic of the blacklist detection function, and the configuration rule carries the IP to be blocked. When the firewall backend server generates the corresponding access control rule, it sets the source and destination security zones to untrust and trust, respectively, to correspond to the inbound traffic. It sets the source IP to the IP to be blocked, the destination IP to any public IP belonging to the cloud tenant, sets the destination port and protocol to ANY, and sets the action to DROP. The generated access control rule is then added to the blacklist detection policy group of the traditional hardware firewall. This instructs the traditional hardware firewall that when it receives inbound network traffic from the cloud tenant, if the source address is the aforementioned IP to be blocked, the access control rule will be triggered, allowing the traditional hardware firewall to directly block the traffic.
[0141] When the flow direction is the outflow direction, the process is similar to the one described above; see [link to relevant documentation]. Figure 7g The diagram illustrates the configuration process for the outbound blacklist detection function. Specifically, the cloud firewall configuration rules issued by the cloud tenant are configured for the outbound blacklist detection function, and these rules include the IPs to be blocked. When the firewall backend server generates the corresponding access control rules, please refer to [the relevant documentation / reference]. Figure 7g As shown, the source and destination security zones are set to trust and untrust, respectively, to correspond to the outbound direction. The source IP is set to any public IP address belonging to the cloud tenant, the destination IP is set to the IP to be blocked, the destination port and protocol are both set to ANY, and the action is set to DROP. The generated access control rule is then added to the blacklist detection policy group of the traditional hardware firewall. This instructs the traditional hardware firewall that when it receives outbound network traffic from the cloud tenant, if the destination address is the aforementioned IP to be blocked, the access control rule will be triggered, allowing the traditional hardware firewall to directly block the traffic.
[0142] (3) Access control function. The black / white list detection mentioned above can enable the rapid passage or blocking of traffic, while the access control function is used to achieve more refined access control. The detection granularity is more refined than that of the black / white list detection function. Moreover, the access control function is not simply to allow or block traffic directly, but cloud tenants can choose the processing method themselves. For example, they can allow traffic to a certain IP address and block traffic to another IP address, or they can also issue alarms and other processing methods.
[0143] In this embodiment, the access control function also supports the distinction between outbound and inbound rules. Similar to the black / white list detection function mentioned above, when a cloud tenant configures inbound access control rules, the firewall backend server adds two rule conditions to the cloud tenant's configured packet conditions: a source security domain value of "untrust" and a destination security domain value of "trust". The resulting access control rules only apply to inbound network traffic. Conversely, when a cloud tenant configures outbound access control rules, the firewall backend server adds two rule conditions to the cloud tenant's configured packet conditions: a source security domain value of "trust" and a destination security domain value of "untrust". The resulting access control rules only apply to outbound network traffic.
[0144] Similarly, the access control function also supports tenant isolation. This is because different cloud tenants use different public IPs. When configuring rules, tenants are distinguished based on the source IP in the outbound direction and the destination IP in the inbound direction. This ensures that the access control rules between tenants do not affect each other, thus achieving tenant isolation at the business level. When the IP in this position is configured as ANY, all IPs of the same cloud tenant are used instead of ANY.
[0145] See Figure 7h The image shows a schematic diagram of the access control function configuration interface. When the security detection function is selected as the access control function, various configuration options can be finely configured, such as the flow direction, source IP, destination IP, destination port, protocol, and the action to take upon a hit, as shown in 7h. After the cloud tenant confirms the configuration, the configuration rules can be sent to the firewall backend server. Figure 7i As shown in the example, a cloud tenant has three public IPs, IP8 to IP10. The configuration rule issued by this tenant is to block traffic from IP7 from accessing TCP port 80 of "any" server within the cloud, i.e., the destination IP is ANY (ANY stands for "any"). The configuration process for this rule is as follows. Figure 7h As shown.
[0146] When the firewall's backend server generates the corresponding access control rules, the cloud firewall converts the "inbound" traffic direction in the configuration rules issued by the cloud tenant into a source security domain equal to "untrust" and a destination security domain equal to "trust" to correspond to the inbound direction. It then converts "ANY" in the destination IP to any IP address of the tenant, sets the source IP to IP7 (as mentioned above), the destination port to port 80, the protocol to TCP, and the action to DROP. The generated access control rule is then added to the access control policy group of the traditional hardware firewall. This instructs the traditional hardware firewall that when it receives inbound network traffic from the cloud tenant, if the packet conditions meet the above criteria, it can trigger the access control rule and thus block the traffic.
[0147] In addition, cloud tenants can selectively configure access control rules for a specific public IP address. Using the example above, if the cloud tenant only configures access control rules for IP address 10, then see... Figure 7j As shown, the destination IP can be filled with IP10, and the other conversions are the same as described above.
[0148] Similarly, when the flow direction is the outflow direction, the process is similar to the one described above; see [link to relevant documentation]. Figure 7j The diagram illustrates the configuration process for outbound access control. Specifically, the cloud firewall configuration rule issued by the cloud tenant prohibits traffic from any server's TCP port 80 to IP7. When the firewall's backend server generates the corresponding access control rules, please refer to [link to relevant documentation]. Figure 7k As shown, the source and destination security zones are set to untrust and trust, respectively, to correspond to the outbound direction. The source IP is set to any public IP address belonging to the cloud tenant, the destination IP is set to IP7, the source port and protocol are set to 80 and TCP, and the action is set to DROP. The generated access control rule is then added to the access control policy group of the traditional hardware firewall. This instructs the traditional hardware firewall that when it receives outbound network traffic from the cloud tenant, if the packet conditions described above are met, the access control rule can be triggered, allowing the traditional hardware firewall to block the traffic.
[0149] (4) Intrusion prevention function
[0150] In this embodiment, the intrusion prevention function is enabled based on access control rules. Upon receiving the configuration rules, if it is determined that the intrusion prevention function will be enabled based on the configuration rules, the switch field of all access control rules containing the target address object in the access control policy group (i.e., all access control rules of the cloud tenant) will be filled with a third value. This third value indicates that the intrusion prevention function is enabled. Furthermore, the configuration rules also carry the hit processing mode used by the intrusion prevention function; therefore, it is also necessary to associate each access control rule with the intrusion prevention template corresponding to the hit processing mode.
[0151] Since the intrusion prevention function is enabled based on access control rules, and tenant isolation of access control rules has already been implemented above, you only need to enable the intrusion prevention switch and reference the intrusion prevention template in the prevention and control rules of the specified tenant. It should be noted that when a tenant enables the intrusion prevention switch in its own console, the cloud firewall engine will enable the intrusion prevention switch for all access control rules belonging to that cloud tenant and reference the same intrusion prevention template.
[0152] See Figure 7l The image shown is a schematic diagram of the interface for configuring intrusion prevention functions in the cloud console. When the intrusion prevention function is selected for configuration, you can choose whether to enable the function. If the function is enabled, you also need to select the hit handling mode used by the intrusion prevention function, such as... Figure 7l The diagram shows the observation mode, interception mode, and strict mode. Of course, in practical applications, intrusion prevention templates can include system default settings or those customized by cloud tenants; therefore, there is no limit to the number of templates.
[0153] The intrusion prevention template includes intrusion prevention rules and hit handling modes. The hit handling mode refers to how to handle a packet when it hits an intrusion prevention rule. For example, in the observation mode, only logging is done without blocking the packet; in the intercept mode, both logging and blocking are done; and in the strict mode, logging is done, but blocking is only performed if the hit rule has a high confidence level. By setting different hit handling methods for different intrusion prevention templates, the hit handling modes can be isolated from each other.
[0154] In this embodiment of the application, the intrusion prevention template includes, but is not limited to, the following three intrusion prevention templates:
[0155] (1) Add a rule set group to template A. This group contains all the rules in the rule base. The action is set to "Log only". That is, once a rule is hit, the observation mode is used.
[0156] (2) Add a rule set group to template B. This group contains all the rules in the rule base. The action is set to "log and block". That is, once a rule is hit, the interception mode will be used.
[0157] (3) Add two rule set groups to template C. Group 1 contains all low-confidence rules and its action is set to "log". Group 2 contains all high-confidence rules and its action is set to "log and block". That is, when Group 1 is hit, "log" is used, and when Group 2 is hit, "log and block" is used.
[0158] In this embodiment, the configuration process of the intrusion prevention function is the process by which the firewall backend server converts the page configuration rules issued by the cloud tenant into the configuration method on the cloud firewall device side. See also Figure 7m As shown, when a cloud tenant sets the "Hit Handling Mode" of the global intrusion prevention function to "Observation" mode in the cloud console, the firewall backend server will set the intrusion prevention template referenced by all access control rules belonging to that cloud tenant in the cloud firewall device to the aforementioned intrusion prevention template A.
[0159] See Figure 7n As shown, when a cloud tenant sets the "Hit Handling Mode" of the global intrusion prevention function to "Intercept" mode on the page, the firewall backend server will set the intrusion prevention template referenced by all access control rules belonging to that cloud tenant in the cloud firewall device to the aforementioned intrusion prevention template B.
[0160] See Figure 7o As shown, when a cloud tenant sets the "Hit Handling Mode" of the global intrusion prevention function to "Strict" mode on the page, the firewall backend server will set the intrusion prevention template referenced by all access control rules belonging to that cloud tenant in the cloud firewall device to the above template C.
[0161] In this embodiment of the application, all access control rules mentioned above may refer to all access control rules in all security detection policy groups, or only to all access control rules in the access control policy. In actual application, they can be set according to requirements, and this embodiment of the application does not impose any restrictions on this.
[0162] In this embodiment, considering that all the aforementioned security detection functions are implemented using the access control module of a hardware firewall device, and that users may add whitelist, blacklist, and access control entries in an irregular alternation, but given that whitelists and blacklists can more quickly allow or filter access, from a security detection efficiency perspective, whitelists and blacklists should be prioritized. However, if ordinary access control rules are used for whitelists and blacklists, this priority relationship cannot be guaranteed. Therefore, this embodiment uses the aggregation policy group function of the access control module to create whitelist detection policy groups, blacklist detection policy groups, and access control policy groups, and sets their priorities to decrease sequentially. Thus, after placing the access control rule entries for whitelists, blacklists, and access control into their respective aggregation policy groups, they can be executed according to the aforementioned priorities in actual applications.
[0163] In this embodiment of the application, after configuring all the functions, it can be used in actual traffic security detection scenarios. Of course, during use, access control rules can also be updated as needed.
[0164] See Figure 8 The diagram shown is a flowchart of the traffic security detection method provided in this application embodiment. The flowchart of this method is described below.
[0165] Step 801: Receive network traffic carrying the target address object.
[0166] In this embodiment, the cloud firewall device is positioned between the terminal device and the cloud server. Therefore, any network traffic will be received by the cloud firewall device for subsequent security detection.
[0167] Step 802: Match the target address object with each reference address object contained in the local storage switch policy group.
[0168] In this embodiment, the cloud firewall device is configured with a switch policy group to store reference address objects (i.e., those with the cloud firewall function enabled) that have been enabled. Figure 3 The target address object shown in the configuration process is added to the switch policy group by the firewall backend server in response to the function start request of the cloud tenant to which each reference address object belongs. This process has been explained in detail before, so it will not be repeated here.
[0169] Specifically, since the reference address object for which the cloud firewall function is enabled is configured as an exception address object for access control, the process of matching the target address object with each reference address object contained in the locally stored switch policy group is essentially matching the target address object with the exception address objects set by the function switch rules in the switch policy group. If the target address object successfully matches an exception address object, it is considered that the target address object has enabled the cloud firewall function; otherwise, it is considered that the target address object has not enabled the cloud firewall function. A successful match means that among all exception address objects, there is an exception address object that is identical to the target address object.
[0170] For example, when IPs 1 through 10 are set as exception address objects in the function switch rule, if network traffic carrying IP 2 is received, it will be successfully matched, that is, the function switch rule will be hit.
[0171] It should be noted that, since this application embodiment refers to performing security checks on both the inbound and outbound directions, it is necessary to perform object matching on the source address object and the destination address object separately. If either one can be successfully matched, the subsequent security check process can continue.
[0172] Step 803: Upon successful matching, determine that the target address object has enabled the cloud firewall function. For target address objects with the cloud firewall function enabled, subsequent security detection processes are required for network traffic.
[0173] Step 804: Match the network traffic with the access control rules contained in each of the multiple security detection policy groups; wherein each security detection policy group corresponds to a security detection function, and each access control rule is generated based on the rule template of the corresponding security detection function and the configuration rules sent by the cloud tenant.
[0174] In this embodiment of the application, the cloud firewall device pre-configures corresponding security detection policy groups for each security detection function, so it can detect whether the access control rules of each security detection policy group can be matched one by one.
[0175] In one possible implementation, access control rules for each security detection policy group can be matched in parallel to improve the efficiency of the rule matching process.
[0176] In one possible implementation, the network traffic can be matched with the access control rules contained in each of the multiple security detection policy groups in turn, based on the priority relationship between them.
[0177] Specifically, taking the aforementioned security detection policy groups, including the whitelist detection policy group, blacklist detection policy group, and access control function policy group, as examples, you can refer to... Figure 9 The diagram shown is a flowchart illustrating the rule matching process provided in an embodiment of this application.
[0178] Step 901: Match the network traffic with each access control rule in the whitelist detection policy group.
[0179] Step 902: Determine whether the access control rules in the whitelist detection policy group are matched. If matched, proceed to step 907.
[0180] Step 903: If no match is found, i.e., the network traffic is matched against the access control rules contained in the blacklist detection policy group.
[0181] Step 904: Determine whether the access control rules contained in the blacklist detection policy group are matched. If matched, proceed to step 907.
[0182] Step 905: If no match is found, i.e., the network traffic is matched against the access control rules contained in the access control policy group.
[0183] Step 906: Determine whether the access control rules contained in the access control function policy group are matched. If matched, proceed to step 907. If not matched, the process ends.
[0184] Step 907: Determine the matched access control rule as the target access control rule.
[0185] In this embodiment of the application, each access control rule is composed of various fields, so the rule matching process essentially refers to field matching for each field.
[0186] Specifically, when network traffic is received, the interface identifier of the target network interface receiving the traffic is matched with the interface identifiers in a preset first security domain and a second security domain. Each network interface in the first security domain connects to an untrusted network, and each network interface in the second security domain connects to a trusted network. Therefore, if a match is successful with the first security domain, it indicates that the target network interface is connected to the untrusted security domain, thus determining the traffic flow direction as inbound. Conversely, if a match is successful with the second security domain, it indicates that the target network interface is connected to the trusted security domain, thus determining the traffic flow direction as outbound.
[0187] Furthermore, based on the flow direction of network traffic, the corresponding source and destination security domain information can be determined. This process is similar to the configuration process described above. When the flow direction is inbound, the source security domain information should be "untrust" and the destination security domain information should be "trust," indicating that the network traffic is from the external network to the internal network. When the flow direction is outbound, the source security domain information should be "trust" and the destination security domain information should be "untrust," indicating that the network traffic is from the internal network to the external network. In addition, during traffic transmission, network traffic also carries necessary information for transmission, such as address information, protocol, and port number. Therefore, the corresponding source and destination address information can be extracted from the network traffic.
[0188] When performing rule matching with each access control rule, the source security domain information, destination security domain information, source address information, and destination address information can be matched with the corresponding fields in the access control rule.
[0189] See Figure 10 The diagram illustrates the matching of access control rules within a whitelist detection policy group. If the received network traffic flows inbound, the corresponding source security domain information should be "untrust," and the destination security domain information should be "trust." Furthermore, the destination IP address of this network traffic is IP8 of cloud tenant 1, and the source IP address is IP2. An access control rule within the whitelist detection policy group is as follows: Figure 10 As shown, the rule that allows IP2 and IP3 to access any port of IP8-10 will be matched, meaning that this access control rule will be identified as the target access control rule.
[0190] Step 805: When a match is successful, perform access control on network traffic based on the matched target access control rule.
[0191] For example, if the target access control rule's action is ACCEPT, then the network traffic is allowed; if the target access control rule's action is DROP, then the network traffic is blocked.
[0192] It should be noted that the above process is illustrated using a single network traffic packet as an example. In practice, the above process can be implemented for each network traffic packet to provide traffic security protection for terminal devices or cloud servers, thereby improving security. Furthermore, the above process is detailed down to each cloud tenant, and even the public IP address of each cloud tenant. Compared to traditional hardware firewalls, the accuracy of traffic protection is relatively higher.
[0193] In this embodiment of the application, an intrusion prevention function is also provided. Therefore, if the matching is successful, it is also necessary to verify whether the intrusion prevention function is enabled.
[0194] Specifically, upon successful matching, it is determined whether the switch field included in the target access control rule is a third value, that is, whether the switch field indicates that the intrusion prevention function has been enabled. If it is a third value, it is determined that the target address object has enabled the intrusion prevention function, and the network traffic is matched with the intrusion prevention template associated with the target access control rule. If the intrusion prevention rule in the intrusion prevention template is matched, access control is performed on the network traffic based on the handling method indicated by the intrusion prevention template.
[0195] In this embodiment, the cloud firewall device generates relevant security detection logs during the traffic security detection process for subsequent querying. The cloud firewall device has a log outgoing function, which can directly send the generated logs outgoing. The cloud firewall sets up a log receiving server on the firewall backend server to receive the logs, aggregate, analyze and store the logs in a format that is convenient for tenants to query.
[0196] See Figure 11 The diagram illustrates the log uploading and querying process provided in this embodiment. After the cloud firewall device sends the security detection logs to the firewall backend server, the firewall backend server determines the corresponding cloud tenant for each log entry based on the address information carried in the log, adds the cloud tenant's tenant identifier to the log, and stores it in the database. When a cloud tenant queries the log, the firewall backend server responds to the target tenant identifier carried in the log query request by sending the logs carrying the target tenant identifier from the locally stored logs to the corresponding cloud tenant. For example, the cloud tenant can be identified based on the IP address carried in the log, and the log entry can be tagged with the cloud tenant and stored. When the cloud tenant queries the logs in the cloud console, the firewall backend server retrieves the logs tagged with the cloud tenant and returns them to the cloud tenant's cloud console.
[0197] The technical solution of this application embodiment will be described below with a complete example. See also... Figure 12 The diagram shown is a flowchart illustrating the implementation process of a cloud firewall.
[0198] S1: Cloud tenants send configurations to the firewall backend server through the cloud console.
[0199] S2: The firewall backend server calls the web configuration interface of the cloud firewall device to send the configuration to the cloud firewall device.
[0200] S3: Cloud firewall devices receive network traffic.
[0201] S4: The cloud firewall device matches network traffic to the switch aggregation policy group and determines whether the function switch rule is matched.
[0202] S5: If the hit occurs, the cloud firewall device will directly allow network traffic.
[0203] S6: If no match is found, it means the firewall is enabled. The cloud firewall device will then match network traffic against the whitelist detection policy group and determine whether the access control rules in the whitelist detection policy group are matched.
[0204] If the hit occurs, the cloud firewall device will execute step S5.
[0205] S7: If no match is found, the cloud firewall device will match the network traffic against the blacklist detection policy group and determine whether the access control rules in the blacklist detection policy group are matched.
[0206] S8: If a hit occurs, the cloud firewall device will directly block network traffic and generate logs.
[0207] S9: If no match is found, the cloud firewall device will match the network traffic against the access control policy group and determine whether the access control rules in the access control policy group are matched.
[0208] S10: If a hit occurs, the cloud firewall device determines whether to enable the intrusion prevention function.
[0209] S11: If no match is found, the cloud firewall device will directly execute the action of the access control rule in the access control policy group that was matched, and generate a log.
[0210] S12: If enabled, the cloud firewall device will perform intrusion prevention detection, execute actions based on the detected rules and intrusion prevention configuration, and generate logs.
[0211] S13: The cloud firewall device reports logs to the firewall backend server.
[0212] In summary, in this embodiment, a traditional hardware firewall is used as a cloud firewall engine to detect and control traffic. Combined with cloud console configuration and background configuration services provided by the firewall backend server, a cloud tenant-level firewall security device is implemented. Supported functions include access control, intrusion prevention, blacklists, whitelists, and logging. The access control and blacklist / whitelist functions can distinguish between inbound and outbound rules. The intrusion prevention function does not depend on access control but has a separate page for global control of enabling and disabling intrusion prevention and setting a global hit handling mode to configure how to handle packets that hit intrusion prevention rules. Each cloud tenant can individually enable or disable intrusion prevention for its own traffic and set its own traffic hit handling mode.
[0213] Please see Figure 13 Based on the same inventive concept, this application also provides a traffic security detection device 130, applied to a cloud firewall device, the device comprising:
[0214] The traffic receiving unit 1301 is used to receive network traffic carrying a target address object;
[0215] The switch detection unit 1302 is used to match the target address object with each reference address object contained in the locally stored switch policy group; each reference address object is added to the switch policy group in response to the function start request of the cloud tenant to which each reference address object belongs.
[0216] The security detection unit 1303 is used to determine that the target address object has enabled the cloud firewall function when the match is successful, and to match the network traffic with the access control rules contained in each of the multiple security detection policy groups; wherein, each security detection policy group corresponds to a security detection function, and each access control rule is generated based on the rule template of the corresponding security detection function and the configuration rules sent by the cloud tenant.
[0217] The execution unit 1304 is used to perform access control on network traffic based on the matched target access control rule when a match is successful.
[0218] In one possible implementation, the security detection unit 1303 is specifically used for:
[0219] Based on the priority relationship among multiple security detection policy groups, network traffic is matched with the access control rules contained in each of the multiple security detection policy groups in turn.
[0220] In one possible implementation, the multiple security detection policy groups include a whitelist detection policy group, a blacklist detection policy group, and an access control function policy group; then the security detection unit 1303 is specifically used for:
[0221] The network traffic is matched against each access control rule in the whitelist detection policy group.
[0222] When a match fails, the network traffic is matched against each access control rule in the blacklist detection policy group.
[0223] When a match fails, the network traffic is matched against each access control rule in the access control policy group.
[0224] In one possible implementation, the security detection unit 1303 is specifically used for:
[0225] Based on the flow direction of network traffic, determine the corresponding source security domain information and destination security domain information, and extract the corresponding source address information and destination address information from the network traffic;
[0226] For each access control rule, perform the following steps: For an access control rule, match the source security domain information, destination security domain information, source address information, and destination address information with the corresponding fields in the access control rule.
[0227] In one possible implementation, the security detection unit 1303 is specifically used for:
[0228] The interface identifier of the target network interface receiving network traffic is matched with the interface identifiers in the preset first security domain and second security domain respectively; wherein, each network interface in the first security domain is connected to an untrusted network, and each network interface in the second security domain is connected to a trusted network.
[0229] If a match is found with the first security domain, the direction of network traffic is determined to be inbound.
[0230] If a match is found with the second security domain, the direction of network traffic is determined to be outbound.
[0231] In one possible implementation, the security detection unit 1303 is specifically used for:
[0232] When a match is successful, determine whether the switch field included in the target access control rule is a third value; where the third value is used to indicate that the intrusion prevention function has been enabled.
[0233] If it is the third value, it is determined that the target address object has enabled the intrusion prevention function, and the network traffic is matched with the intrusion prevention template associated with the target access control rule;
[0234] If the intrusion prevention rules in the intrusion prevention template are matched, then network traffic access control will be implemented based on the handling method indicated by the intrusion prevention template.
[0235] The aforementioned device enables firewall functionality to be configured at the cloud tenant granularity or the address object granularity associated with the cloud tenant. Correspondingly, the cloud firewall device can perform traffic access control based on the cloud tenant granularity or the address object granularity, thereby improving the accuracy of the cloud firewall in traffic protection.
[0236] This device can be used to execute the methods performed by the cloud firewall devices in the various embodiments of this application. Therefore, the functions that each functional module of this device can achieve can be referred to the description of the foregoing embodiments, and will not be repeated here.
[0237] Please see Figure 14Based on the same inventive concept, this application also provides a cloud firewall configuration device 140, applied to a firewall backend server, the device comprising:
[0238] The configuration receiving unit 1401 is used to receive configuration requests triggered by cloud tenants performing configuration operations on at least one security detection function of the cloud firewall device. The configuration requests carry configuration rules corresponding to each of the at least one security detection function.
[0239] The rule generation unit 1402 is used to fill in the rule templates corresponding to at least one security detection function based on at least one configuration rule and the target address object associated with the cloud tenant, so as to generate access control rules corresponding to at least one security detection function.
[0240] The configuration distribution unit 1403 is used to add the generated access control rules to the corresponding security detection policy groups in the cloud firewall device, so that the cloud firewall device can perform security detection on network traffic carrying target address objects based on each security detection policy group.
[0241] In one possible implementation, the rule generation unit 1402 is specifically used for:
[0242] For at least one security detection function, perform the following operations respectively:
[0243] For a security detection function, the security field in the rule template is populated based on the flow direction indicated by the configuration rule;
[0244] If the flow direction is inbound, then the source address field in the rule template is populated based on the address object indicated by the configuration rule, and the destination address field in the rule template is populated based on the destination address object;
[0245] If the flow direction is outbound, the source address field is filled based on the target address object, and the destination address field is filled based on the address object indicated in the configuration rule.
[0246] In one possible implementation, the rule generation unit 1402 is specifically used for:
[0247] If the flow direction is inbound, then the source security domain field is filled with a first security domain identifier, and the destination security domain field is filled with a second security domain identifier; wherein, the first security domain identifier indicates the first security domain connecting to an untrusted network, and the second security domain identifier indicates the second security domain connecting to a trusted network; or...
[0248] If the flow direction is outbound, then the source security field is filled with the second security field identifier, and the destination security field is filled with the first security field identifier.
[0249] In one possible implementation, the cloud firewall device's switching policy group contains function switching rules, and network traffic that does not match a function switching rule needs to undergo security detection; then the rule generation unit 1402 is specifically used for:
[0250] Receive a feature launch request sent by a cloud tenant. The feature launch request indicates that the cloud firewall function of the target address object be launched.
[0251] Configure the target address object as an exception address object for the feature switch rule so that network traffic carrying the target address object cannot hit the feature switch rule.
[0252] In one possible implementation, at least one security detection function includes an intrusion prevention function; then the rule generation unit 1402 is specifically used for:
[0253] Based on the configuration rules, the intrusion prevention function is activated; whereby the configuration rules indicate the hit handling mode used by the intrusion prevention function.
[0254] In the access control policy group, fill the switch field of all access control rules containing the target address object with the third value, and associate each access control rule with the intrusion prevention template corresponding to the hit handling mode; the third value is used to indicate that the intrusion prevention function has been enabled.
[0255] In one possible implementation, the device further includes a log processing unit 1404, for:
[0256] Receive security detection logs sent by cloud firewall devices;
[0257] For each log entry in the security detection log, perform the following steps:
[0258] For a log entry, based on the address information carried in the log, determine the cloud tenant corresponding to the log and add the cloud tenant's tenant identifier to the log.
[0259] In response to the target tenant identifier carried in the log query request, the logs containing the target tenant identifier from the locally stored logs are sent to the corresponding cloud tenant.
[0260] The aforementioned device enables firewall functionality to be configured at the cloud tenant granularity or the address object granularity associated with the cloud tenant. Correspondingly, the cloud firewall device can perform traffic access control based on the cloud tenant granularity or the address object granularity, thereby improving the accuracy of the cloud firewall in traffic protection.
[0261] This device can be used to execute the methods performed by the firewall backend server in the various embodiments of this application. Therefore, the functions that each functional module of this device can achieve can be referred to the description of the foregoing embodiments, and will not be repeated here.
[0262] Please see Figure 15 Based on the same technical concept, embodiments of this application also provide a computer device. In one embodiment, the computer device can be... Figure 1 The firewall backend server or cloud firewall device shown, or, Figure 2 The device corresponding to the cloud firewall backend or cloud firewall engine shown is a computer device such as... Figure 15 As shown, it includes a memory 1501, a communication module 1503, and one or more processors 1502.
[0263] The memory 1501 is used to store computer programs executed by the processor 1502. The memory 1501 may mainly include a program storage area and a data storage area. The program storage area may store the operating system and programs required to run instant messaging functions, etc.; the data storage area may store various instant messaging information and operation instruction sets, etc.
[0264] Memory 1501 may be volatile memory, such as random-access memory (RAM); memory 1501 may also be non-volatile memory, such as read-only memory, flash memory, hard disk drive (HDD), or solid-state drive (SSD); or memory 1501 may be any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto. Memory 1501 may be a combination of the above-described memories.
[0265] Processor 1502 may include one or more central processing units (CPUs) or digital processing units, etc. Processor 1502 is used to implement the various methods provided in the embodiments of this application when calling computer programs stored in memory 1501.
[0266] The communication module 1503 is used to communicate with other devices.
[0267] This application embodiment does not limit the specific connection medium between the memory 1501, communication module 1503, and processor 1502. This application embodiment... Figure 15The memory 1501 and the processor 1502 are connected via a bus 1504, and the bus 1504 is in Figure 15 The diagram uses thick lines to describe the connections between other components; these are for illustrative purposes only and should not be considered limiting. The 1504 bus can be divided into address bus, data bus, control bus, etc. For ease of description, Figure 15 It is described using only a thick line, but does not indicate that there is only one bus or one type of bus.
[0268] The memory 1501 stores a computer storage medium, which stores computer-executable instructions. The computer-executable instructions are used to implement various methods provided in the embodiments of this application, and the processor 1502 is used to execute the various methods of the above embodiments.
[0269] Based on the same inventive concept, embodiments of this application also provide a storage medium storing a computer program that, when run on a computer, causes the computer to perform the steps in the search result reordering method according to various exemplary embodiments of this application described above.
[0270] In some possible implementations, various aspects of the traffic security detection or cloud firewall configuration method provided in this application can also be implemented in the form of a computer program product, which includes a computer program. When the program product is run on a computer device, the computer program is used to cause the computer device to perform the steps in the traffic security detection or cloud firewall configuration method according to various exemplary embodiments of this application described above. For example, the computer device can perform the steps of each embodiment.
[0271] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0272] The program product of the embodiments of this application may employ a portable compact disc read-only memory (CD-ROM) and include a computer program, and may run on a computer device. However, the program product of this application is not limited thereto. In this application, the readable storage medium may be any tangible medium that contains or stores a program, and the computer program included therein may be used by or in conjunction with a command execution system, apparatus, or device.
[0273] A readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying a readable computer program. This propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting a program for use by or in conjunction with a command execution system, apparatus, or device.
[0274] Computer programs contained on readable media may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.
[0275] Computer programs for performing the operations of this application can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java and C++, as well as conventional procedural programming languages such as the "C" language or similar programming languages.
[0276] It should be noted that although several units or sub-units of the device have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of this application, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units.
[0277] Furthermore, although the operations of the method of this application are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.
[0278] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0279] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.
[0280] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A method for detecting traffic flow security, characterized in that, Applied to a cloud firewall device, wherein the cloud firewall device is a hardware firewall device, the method includes: Receive network traffic carrying the target address object; The target address object is matched with each reference address object of the function switch rule contained in the locally stored switch policy group; each reference address object is added to the switch policy group in response to the function start request of the cloud tenant to which each reference address object belongs; wherein, the function switch rule adopts the data structure of the access control rule of the hardware firewall device, and the function switch rule is: the address object that does not hit the address object field enables the cloud firewall function, and each reference address object is configured as an exception address object of the address object field, and the exception address object will not hit the address object field; Upon successful matching, it is determined that the target address object has enabled the cloud firewall function; The network traffic is matched against the access control rules contained in each of the multiple security detection policy groups. The access control rules in the multiple security detection policy groups adopt the data structure of the access control rules of the hardware firewall device. Each security detection policy group corresponds to a security detection function, and each access control rule is generated based on the rule template of the corresponding security detection function and the configuration rules sent by the cloud tenant. The configuration rules are used to indicate the processing method for a specific address object under each security detection function. When a match is successful, access control is applied to the network traffic based on the matched target access control rule.
2. The method as described in claim 1, characterized in that, The network traffic is matched against the access control rules contained in each of the multiple security detection policy groups, including: Based on the priority relationship among the multiple security detection policy groups, the network traffic is sequentially matched with the access control rules contained in each of the multiple security detection policy groups.
3. The method as described in claim 2, characterized in that, The multiple security detection policy groups include a whitelist detection policy group, a blacklist detection policy group, and an access control function policy group; Based on the priority relationship among the multiple security detection policy groups, the network traffic is sequentially matched with the access control rules contained in each security detection policy group, including: The network traffic is matched against each access control rule in the whitelist detection policy group. When a match fails, the network traffic is matched against each access control rule in the blacklist detection strategy group. When a match fails, the network traffic is matched against each access control rule in the access control policy group.
4. The method according to any one of claims 1 to 3, characterized in that, The network traffic is matched against the access control rules contained in each of the multiple security detection policy groups, including: Based on the flow direction of the network traffic, the corresponding source security domain information and destination security domain information are determined, and the corresponding source address information and destination address information are extracted from the network traffic. For each access control rule, the following steps are performed: For an access control rule, the source security domain information, the destination security domain information, the source address information, and the destination address information are matched with the corresponding fields in the access control rule.
5. The method as described in claim 4, characterized in that, Before determining the source security domain information and destination security domain information of the network traffic based on the flow direction of the network traffic, the method further includes: The interface identifier of the target network interface receiving the network traffic is matched with the interface identifiers in the preset first security domain and the second security domain, respectively; wherein, each network interface in the first security domain is connected to an untrusted network, and each network interface in the second security domain is connected to a trusted network. If a match is found with the first security domain, the direction of the network traffic is determined to be: inbound. If a match is found with the second security domain, the flow direction of the network traffic is determined to be: outbound direction.
6. The method according to any one of claims 1 to 3, characterized in that, Upon successful matching, access control is applied to the network traffic based on the matched target access control rule, including: When a match is successful, it is determined whether the switch field included in the target access control rule is a third value; wherein, the third value is used to indicate that the intrusion prevention function has been enabled; If the value is the third, it is determined that the target address object has enabled intrusion prevention function, and the network traffic is matched with the intrusion prevention template associated with the target access control rule; If the intrusion prevention rules in the intrusion prevention template are matched, then access control is applied to the network traffic based on the handling method indicated by the intrusion prevention template.
7. A cloud firewall configuration method, characterized in that, The method, applied to a firewall backend server, includes: Receive a function start request sent by a cloud tenant, the function start request instructing the cloud firewall function of the target address object to be started on the cloud firewall device; The target address object is configured as an exception address object in the function switch rule so that network traffic carrying the target address object cannot hit the function switch rule; the cloud firewall device is a hardware firewall device, and the function switch rule adopts the data structure of the access control rule of the hardware firewall device. The function switch rule is: the address object that does not hit the address object field enables the cloud firewall function, and the exception address object will not hit the address object field. The cloud tenant receives a configuration request triggered by configuring at least one security detection function of the cloud firewall device. The configuration request carries the configuration rules corresponding to each of the at least one security detection function. The configuration rules are used to indicate the processing method for a specific address object under each security detection function. Based on at least one configuration rule and the target address object associated with the cloud tenant, the rule templates corresponding to each of the at least one security detection function are populated to generate access control rules corresponding to each of the at least one security detection function. The rule templates adopt the data structure of the access control rules of the hardware firewall device. The generated access control rules are added to the corresponding security detection policy groups in the cloud firewall device, so that the cloud firewall device can perform security detection on network traffic carrying the target address object based on each security detection policy group.
8. The method as described in claim 7, characterized in that, Based on at least one configuration rule and the target address object associated with the cloud tenant, the rule templates corresponding to at least one security detection function are populated, including: For each of the at least one security detection function, the following operations are performed respectively: For a security detection function, the security field in the rule template is populated based on the flow direction indicated by the configuration rule; If the flow direction is an inbound direction, then the source address field in the rule template is filled based on the address object indicated by the configuration rule, and the destination address field in the rule template is filled based on the target address object; If the flow direction is an outbound direction, then the source address field is filled based on the target address object, and the destination address field is filled based on the address object indicated in the configuration rule.
9. The method as described in claim 8, characterized in that, The security domain field includes a source security domain field and a destination security domain field; The security field in the rule template, which is filled based on the flow direction indicated by the configuration rules, includes: If the flow direction is the inbound direction, then the source security domain field is filled with a first security domain identifier, and the destination security domain field is filled with a second security domain identifier; wherein the first security domain identifier indicates a first security domain connecting to an untrusted network, and the second security domain identifier indicates a second security domain connecting to a trusted network; or... If the flow direction is the outbound direction, then the source security field is filled with a second security field identifier, and the destination security field is filled with a first security field identifier.
10. The method according to any one of claims 7 to 9, characterized in that, The at least one security detection function includes intrusion prevention function; Based on at least one configuration rule and the target address object associated with the cloud tenant, the rule templates corresponding to each of the at least one security detection function are populated to generate access control rules corresponding to each of the at least one security detection function, including: Based on the configuration rules, the intrusion prevention function is activated; wherein, the configuration rules indicate the hit handling mode used by the intrusion prevention function. In the access control policy group, fill the switch field of all access control rules containing the target address object with a third value, and associate each access control rule with the intrusion prevention template corresponding to the hit handling mode; wherein, the third value is used to indicate that the intrusion prevention function has been enabled.
11. The method according to any one of claims 7 to 9, characterized in that, The method further includes: Receive security detection logs sent by the cloud firewall device; For each log entry in the security detection log, perform the following steps: For a log entry, based on the address information carried in the log entry, the cloud tenant corresponding to the log entry is determined, and the tenant identifier of the cloud tenant is added to the log entry. In response to the target tenant identifier carried in the log query request, the logs carrying the target tenant identifier in the locally stored logs are sent to the corresponding cloud tenant.
12. A flow safety detection device, characterized in that, Applied to cloud firewall devices, wherein the cloud firewall device is a hardware firewall device, the device includes: The traffic receiving unit is used to receive network traffic carrying target address objects; A switch detection unit is used to match the target address object with each reference address object of the function switch rules contained in the locally stored switch policy group; each reference address object is added to the switch policy group in response to the function start request of the cloud tenant to which each reference address object belongs; wherein, the function switch rule adopts the data structure of the access control rule of the hardware firewall device, and the function switch rule is: if the address object field is not hit, the cloud firewall function is enabled, and each reference address object is configured as an exception address object of the address object field, and the exception address object will not hit the address object field; A security detection unit is used to determine that the target address object has enabled the cloud firewall function when a match is successful, and to match the network traffic with the access control rules contained in each of the multiple security detection policy groups. The access control rules included in the multiple security detection policy groups adopt the data structure of the access control rules of the hardware firewall device. Each security detection policy group corresponds to a security detection function, and each access control rule is generated based on the rule template of the corresponding security detection function and the configuration rules sent by the cloud tenant. The configuration rules are used to indicate the processing method for a specific address object under each security detection function. An execution unit is used to perform access control on the network traffic based on the matched target access control rule when a match is successful.
13. A cloud firewall configuration device, characterized in that, The device, used in a firewall backend server, includes: The rule generation unit is used to receive a function startup request sent by a cloud tenant, the function startup request indicating that the cloud firewall function of the target address object be started on the cloud firewall device; configure the target address object as an exception address object of the function switch rule so that network traffic carrying the target address object cannot hit the function switch rule; the cloud firewall device is a hardware firewall device, the function switch rule adopts the data structure of the access control rule of the hardware firewall device, and the function switch rule is: the address object that does not hit the address object field enables the cloud firewall function, and the exception address object will not hit the address object field; A configuration receiving unit is configured to receive a configuration request triggered by the cloud tenant performing a configuration operation on at least one security detection function of the cloud firewall device. The configuration request carries the configuration rules corresponding to each of the at least one security detection function. The configuration rules are used to indicate the processing method for a specific address object under each security detection function. The rule generation unit is further configured to fill in the rule templates corresponding to at least one security detection function based on at least one configuration rule and the target address object associated with the cloud tenant, so as to generate access control rules corresponding to each of the at least one security detection function. The rule template adopts the data structure of the access control rules of the hardware firewall device. The configuration distribution unit is used to add the generated access control rules to the corresponding security detection policy groups in the cloud firewall device, so that the cloud firewall device can perform security detection on network traffic carrying the target address object based on each security detection policy group.
14. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6 or 7 to 11.
15. A computer storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program performs the steps of the method according to any one of claims 1 to 6 or 7 to 11.
16. A computer program product, comprising a computer program, characterized in that, When executed by a processor, the computer program performs the steps of the method according to any one of claims 1 to 6 or 7 to 11.
Citation Information
Patent Citations
Method and device for deploying security access control policy
CN105100109A
Security protection method and security protection system
CN113810420A