Cloud platform-based multi-security product control method and device, equipment and medium
By parsing and orchestrating client security service requests in the cloud platform and creating multiple security instances, the problem of cumbersome operations for clients requesting multiple security products is solved, thus improving the user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA UNITED NETWORK COMM GRP CO LTD
- Filing Date
- 2023-06-08
- Publication Date
- 2026-04-21
AI Technical Summary
In existing technologies, when a client requests security services from multiple security products, it needs to send requests to different cloud platforms, which is cumbersome, time-consuming, and affects the user experience.
By obtaining the client's security service request, it determines whether a tag list exists, parses and arranges the tag data of multiple security products, and creates a security instance in the same cloud platform according to a preset combination mode to provide security services to the client.
It reduces the cumbersome process of clients requesting security services from multiple security products, reduces time consumption, and improves user experience.
Smart Images

Figure CN116668142B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud computing technology, and in particular to a method, apparatus, device and medium for controlling multiple security products based on a cloud platform. Background Technology
[0002] With the rapid development of cloud computing technology, maintaining the security of client data through security products in the cloud platform is of great significance.
[0003] In existing technologies, a cloud platform can typically only manage one security product. When a client requests security services through multiple security products, it needs to request different security products from different cloud platforms.
[0004] However, existing technologies involve clients requesting security services from multiple security products in a cumbersome and time-consuming process, which negatively impacts user experience. Summary of the Invention
[0005] This application provides a method, apparatus, device, and medium for controlling multiple security products based on a cloud platform, in order to solve the problem that the operation of requesting multiple security products to provide security services by the client in the prior art is cumbersome and time-consuming, which affects the user experience.
[0006] Firstly, this application provides a multi-security product control method based on a cloud platform, including:
[0007] Obtain the security service request sent by the client;
[0008] Based on the security service request, determine whether a first tag list exists in the security service request, wherein the first tag list includes tag data of multiple security products requesting to provide security services;
[0009] If the first tag list exists, the tag data of each security product in the first tag list is parsed to obtain the parsed tag data of each security product.
[0010] Based on a preset combination pattern, the parsed tag data of each security product is arranged to obtain the arranged tag data.
[0011] Based on the tag data arranged for each security product, the configuration information of each security product is obtained;
[0012] Based on the configuration information of each security product, a security instance corresponding to the configuration information is created in the regional cloud pool. The security instance is used to provide security services to the client.
[0013] Optionally, if the first tag list exists, parsing the tag data of each security product in the first tag list to obtain parsed tag data for each security product includes:
[0014] If the first tag list exists, generate a first hash table to store the tag data of each security product in the first tag list;
[0015] The tag data of each security product in the first tag list is traversed, and after a first preset time, the first traversal state of the first tag list is determined. The first traversal state includes a completed state and an incomplete state.
[0016] If the first traversal state is completed, store the tag data of each security product in the first hash table;
[0017] The tag data in the first hash table is converted into a list format to obtain the parsed tag data for each security product.
[0018] Optional, also includes:
[0019] If the first traversal state is incomplete, determine whether the first tag list has been persistently stored in advance;
[0020] If persistent storage processing has been performed in advance, obtain the second tag list after persistent storage processing;
[0021] The tag data of each security product in the second tag list is traversed, and after a second preset time, the second traversal state of the second tag list is determined. The second traversal state includes a completed state and an incomplete state.
[0022] If the second traversal state is completed, store the tag data of each security product in the first hash table;
[0023] The tag data in the first hash table is converted into a list format to obtain the parsed tag data for each security product.
[0024] Optionally, the method further includes:
[0025] If the second traversal state is incomplete, determine the second hash table storing the second tag list based on the identification information of the second tag list;
[0026] The tag data of each security product stored in the second hash table is overwritten and stored in the first hash table;
[0027] The tag data in the first hash table is converted into a list format to obtain the parsed tag data for each security product.
[0028] Optionally, before obtaining the security service request sent by the client, the method further includes:
[0029] Get the creation request sent by the client;
[0030] Based on the creation request, determine whether a third tag list exists in the creation request;
[0031] If the third tag list exists, iterate through the tag data of each security product in the third tag list, and after a third preset time period, determine the third traversal state of the third tag list. The third traversal state includes a completed state and an incomplete state.
[0032] If the third traversal state is completed, the tag data of each security product is bound and cleaned to obtain the tag data of each security product after creation.
[0033] Optional, also includes:
[0034] If the third traversal state is incomplete, determine whether the third tag list has been persistently stored in advance;
[0035] If persistent storage has been performed in advance, the tag data of each security product is bound and cleaned to obtain the tag data of each security product after creation.
[0036] Optional, also includes:
[0037] If the third tag list does not exist, determine whether the creation request contains preset regular content;
[0038] If it contains preset regular content, the regular content is bound and cleaned to obtain the tag data of the regular content after creation.
[0039] Secondly, this application provides a cloud platform-based multi-security product management device, comprising:
[0040] The acquisition module is used to acquire security service requests sent by the client;
[0041] The judgment module is used to determine whether a first tag list exists in the security service request, based on the security service request. The first tag list includes tag data of multiple security products requesting to provide security services.
[0042] The parsing module is used to parse the tag data of each security product in the first tag list if the first tag list exists, so as to obtain the parsed tag data of each security product.
[0043] The processing module is used to arrange the parsed tag data of each security product according to a preset combination pattern to obtain the arranged tag data;
[0044] The acquisition module is also used to obtain the configuration information of each security product based on the tag data arranged for each security product;
[0045] A creation module is used to create a security instance in the regional cloud pool that corresponds to the configuration information of each security product. The security instance is used to provide security services to the client.
[0046] Thirdly, this application provides an electronic device, including: at least one processor and a memory;
[0047] The memory stores computer-executed instructions;
[0048] The at least one processor executes computer execution instructions stored in the memory to perform the cloud-based multi-security product control method according to any one of the first aspects.
[0049] Fourthly, embodiments of this application provide a readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the cloud-based multi-security product control method described in any one of the first aspects.
[0050] This application provides a method, apparatus, device, and medium for controlling multiple security products based on a cloud platform. It acquires security service requests sent by clients and determines whether a first tag list exists in the request. This first tag list includes tag data for multiple security products requesting security services. If the first tag list exists, the tag data for each security product in the first tag list is parsed to obtain parsed tag data for each security product. Then, according to a preset combination pattern, the parsed tag data for each security product is arranged to obtain arranged tag data. Based on the arranged tag data for each security product, configuration information for each security product is obtained. Finally, based on the configuration information of each security product, a security instance corresponding to the configuration information is created in a regional cloud pool. This security instance is used to provide security services to the client. This method, by deploying multiple security products on the same cloud platform, reduces the cumbersome process of requesting different security products from different cloud platforms when a client requests security services from multiple security products, reduces time consumption, and improves the user experience. Attached Figure Description
[0051] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0052] Figure 1 A schematic diagram of an existing cloud platform management security product provided in this application;
[0053] Figure 2A A schematic diagram of a series mode provided in this application;
[0054] Figure 2B A schematic diagram of a bypass mode provided in this application;
[0055] Figure 3 This application provides an illustration of an application scenario.
[0056] Figure 4 A flowchart illustrating a multi-security product control method based on a cloud platform, provided for an embodiment of this application;
[0057] Figure 5A This is a schematic diagram illustrating a type of tag data provided in an embodiment of this application;
[0058] Figure 5B This is a schematic diagram illustrating yet another type of tag data provided in an embodiment of this application;
[0059] Figure 6A This is a schematic diagram of a series configuration provided in an embodiment of this application;
[0060] Figure 6B This is a schematic diagram of a bypass mode provided in an embodiment of this application;
[0061] Figure 6C This is a schematic diagram of a hybrid mode provided in an embodiment of this application;
[0062] Figure 7 A flowchart illustrating a tag data parsing method provided in an embodiment of this application;
[0063] Figure 8 A flowchart illustrating a method for creating tag data provided in an embodiment of this application;
[0064] Figure 9 A schematic diagram of a cloud-based multi-security product management device provided in this application embodiment;
[0065] Figure 10 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0066] The accompanying drawings have illustrated specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to specific embodiments. Detailed Implementation
[0067] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0068] It should be noted that in the description of the embodiments of this application, terms such as "first," "second," and "third" are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate, so that the embodiments described herein can also be implemented in sequences other than those illustrated or described in this application. Terms such as "inner" and "outer," indicating directions or positional relationships, are based on the directions or positional relationships shown in the accompanying drawings and are merely for ease of description, not to indicate or imply that a device or component must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as limiting this application.
[0069] Furthermore, it should be noted that, in the description of the embodiments of this application, unless otherwise explicitly specified and limited, the terms "connected" and "linked" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in the embodiments of this application according to the specific circumstances.
[0070] With the rapid development of cloud computing technology, data security has always been a key concern. It has become particularly important to manage data security through security products in the cloud platform, deliver security capabilities in the cloud, and realize security services.
[0071] In existing technologies, public cloud vendors typically encapsulate a single security product within a designated cloud platform, with each cloud platform providing security services independently to the outside world. Figure 1 This application provides a schematic diagram of an existing cloud platform management security product, such as... Figure 1 As shown:
[0072] Among them, security products include Web Application Firewall (WAF), cloud firewall, and vulnerability scanning products. WAF, cloud firewall, and vulnerability scanning products are encapsulated in different cloud platforms. Through different cloud platforms, corresponding WAF instances, cloud firewall instances, and vulnerability scanning instances are output in the IASS regional cloud pool to provide users with corresponding security services.
[0073] When a client requests security services through multiple security products, existing technologies require the client to request different security products from different cloud platforms. For example, when a client requests a WAF instance, it needs to send a request to the cloud platform that encapsulates the WAF; when it requests a cloud firewall instance, it needs to send a request to the cloud platform that encapsulates the cloud firewall; and when it requests a vulnerability scanning instance, it needs to send a request to the cloud platform that encapsulates the vulnerability scanning product.
[0074] Among them, the operating modes of safety products include serial mode and bypass mode.
[0075] Figure 2A A schematic diagram of a series mode provided in this application is shown below. Figure 2A As shown, when a client requests a certain business instance, i.e. a security product instance, the security product instance connects to the client in a chained manner.
[0076] Figure 2B This is a schematic diagram of a bypass mode provided in this application. Figure 2B As shown, when a client requests a certain business instance, i.e. a security product instance, the security product instance connects to the client in a bypass mode.
[0077] However, in existing technologies, since a cloud platform can usually only manage one security product, when a client requests security services from multiple security products, it needs to send requests to different cloud platforms, which is cumbersome, time-consuming, and affects the user experience.
[0078] Therefore, addressing the aforementioned technical problems in the prior art, this application proposes a multi-security product control method, apparatus, device, and medium based on a cloud platform. This method involves acquiring a security service request sent by a client and determining whether a first tag list exists within the request. This first tag list includes tag data for multiple security products requesting security services. If the first tag list exists, the tag data for each security product in the first tag list is parsed to obtain parsed tag data for each security product. Then, according to a preset combination pattern, the parsed tag data for each security product is arranged to obtain arranged tag data. Based on the arranged tag data for each security product, configuration information for each security product is obtained. Finally, based on the configuration information of each security product, a security instance corresponding to the configuration information is created in a regional cloud pool. This security instance is used to provide security services to the client. This application reduces the cumbersome and time-consuming operation of clients requesting multiple security products to provide security services, thus improving the user experience.
[0079] To facilitate understanding of this application, an application scenario of this application is illustrated below. Figure 3 This application provides an illustration of an application scenario, such as... Figure 3 As shown: It includes a client 101 and a cloud platform 102, wherein the cloud platform 102 includes a distributed cloud management system 1021 and a distributed cloud security system 1022.
[0080] Client 101 is used to send a security service request to the Tag module of the distributed cloud management system 1021 of cloud platform 102. The Tag module parses the request and obtains the parsed security product tag data.
[0081] The distributed cloud management system 1021 sends the parsed security product tag data to the distributed cloud security system 1022. The distributed cloud security system 1022 arranges the tag data of multiple security products according to a preset combination mode and sends the arranged tag data to the distributed cloud management system 1021.
[0082] The distributed cloud management system 1021 parses the orchestrated tag data to obtain configuration information and distributes the configuration information to cloud pools in various regions to create security instances. These security instances are used to provide corresponding security services to clients.
[0083] It is understood that this application does not limit the number, form, or interaction method of the client 101 and cloud platform 102 in the application scenario, nor does it limit the type or function of the security product. The above scenario is only used as an example. In the specific application of the solution, it can be set according to actual needs.
[0084] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0085] Figure 4 A flowchart illustrating a cloud-based multi-security product control method provided in this application embodiment is shown below. Figure 4 As shown, the method specifically includes the following steps:
[0086] S401. Obtain the security service request sent by the client.
[0087] In this embodiment, the executing entity is a cloud platform, which manages multiple security products, including but not limited to: WAF, cloud firewall, and vulnerability scanning products. These security products provide corresponding security services to clients.
[0088] The client can be a personal computer, laptop, smartphone, tablet, portable wearable device, server or server cluster, etc. In this embodiment, the type of client is not limited.
[0089] When a client requests security services from multiple security products, the client sends a security service request to the cloud platform, and the cloud platform can then obtain the security service request.
[0090] S402. Based on the security service request, determine whether a first tag list exists in the security service request. The first tag list includes tag data of multiple security products that request to provide security services.
[0091] After the cloud platform receives the security service request, it determines whether the request contains a first tag list. The first tag list includes tag data for at least the multiple security products that are requesting the provision of security services.
[0092] The tag data can be of the following two types:
[0093] One is like Figure 5A The type shown Figure 5A This is a schematic diagram illustrating a type of tag data provided in an embodiment of this application. A tag data set may include a tag, and the information contained in a tag includes, but is not limited to, the types, versions, locations, and extended information of multiple security products. The extended information may include other settings associated with each security product.
[0094] Another one is like Figure 5B The type shown Figure 5BThis is a schematic diagram illustrating another type of tag data provided in an embodiment of this application. A tag data may include a tag, and a tag may include multiple sub-tags. Each sub-tag includes, but is not limited to, the type, version information, location information, and extended information of a security product. The extended information may be other settings information associated with the security product.
[0095] S403. If a first tag list exists, parse the tag data of each security product in the first tag list to obtain the parsed tag data of each security product.
[0096] If it is determined that the security service request contains a first tag list, the tag list is parsed to obtain the parsed tag data.
[0097] S404. Arrange the parsed tag data of each security product according to the preset combination mode to obtain the arranged tag data.
[0098] In cloud security scenarios, after the tag data requested by the client is parsed, the distributed cloud management system in the cloud platform automatically orchestrates multiple security products and deploys them in the optimal way to provide security services, thereby improving the client's protection capabilities.
[0099] The preset combination modes include series mode and bypass mode.
[0100] Figure 6A This is a schematic diagram of a series mode structure provided in an embodiment of this application, such as... Figure 6A As shown, when a client requests multiple business instances, i.e. security product instances, the multiple security product instances connect to the client in a cascaded manner.
[0101] Figure 6B This is a schematic diagram of a bypass mode provided in an embodiment of this application. Figure 6B As shown, when a client requests multiple service instances, i.e. security product instances, the security product instances connect to the client in a bypass mode.
[0102] It is important to note that if multiple security product instances exist in both cascaded and bypass modes, the remaining bypass mode security product instances can be connected to the last cascaded mode security product instance, resulting in the following: Figure 6C The diagram shows the structure of the hybrid mode.
[0103] S405. Based on the tag data arranged for each security product, obtain the configuration information for each security product.
[0104] After step S404 above, the arranged tag data of each security product is obtained. The arranged tag data is then parsed to obtain the general configuration information of each security product.
[0105] S406. Based on the configuration information of each security product, create a security instance in the regional cloud pool that corresponds to the configuration information. The security instance is used to provide security services to the client.
[0106] Then, based on the configuration information of each security product, security instances are created in various IASS region cloud pools.
[0107] In the above embodiments of this application, a security service request sent by the client is obtained, and based on the security service request, it is determined whether a first tag list exists in the security service request. The first tag list includes tag data for multiple security products requesting security services. If a first tag list exists, the tag data for each security product in the first tag list is parsed to obtain parsed tag data for each security product. Then, according to a preset combination pattern, the parsed tag data for each security product is arranged to obtain arranged tag data. Based on the arranged tag data for each security product, the configuration information for each security product is obtained. Finally, based on the configuration information for each security product, a security instance corresponding to the configuration information is created in the regional cloud pool. This security instance is used to provide security services to the client. The method of this embodiment, by deploying multiple security products on the same cloud platform, reduces the cumbersome process of requesting different security products from different cloud platforms when a client requests security services from multiple security products, reduces time consumption, and improves the user experience.
[0108] Furthermore, based on the above embodiments, the following embodiments illustrate the process in step S403 of parsing the tag data of each security product in the first tag list to obtain the parsed tag data of each security product if a first tag list exists.
[0109] One possible implementation is:
[0110] If a first tag list exists, a first hash table is generated to store the tag data for each security product in the first tag list. The tag data for each security product in the first tag list is traversed, and after a first preset time period, the first traversal state of the first tag list is determined, including a completed state and an incomplete state. If the first traversal state is completed, the tag data for each security product is stored in the first hash table, and the tag data in the first hash table is converted into a list format to obtain the parsed tag data for each security product.
[0111] If the first traversal state is incomplete, determine whether the first tag list has been persistently stored beforehand. If it has, obtain the persistently stored second tag list. Traverse the tag data of each security product in the second tag list, and after a second preset time, determine the second traversal state of the second tag list. The second traversal state includes completed and incomplete states. If the second traversal state is completed, store the tag data of each security product in the first hash table, and convert the tag data in the first hash table into a list format to obtain the parsed tag data of each security product.
[0112] If the second traversal state is incomplete, the second hash table storing the second tag list is determined based on the identification information of the second tag list. The tag data of each security product stored in the second hash table is overwritten and stored in the first hash table. The tag data in the first hash table is then converted into a list format to obtain the parsed tag data of each security product.
[0113] For example, Figure 7 A flowchart illustrating a tag data parsing method provided in this application embodiment is shown below. Figure 7 As shown:
[0114] Obtain the security service request sent by the client, and determine whether the first tag list exists in the security service request. If the first tag list does not exist, return an indication message that the user request parameters are incorrect. If the first tag list exists, generate a first hash table to store the tag data of each security product in the first tag list.
[0115] Determine whether the tag data of each security product in the first tag list has been traversed. If the traversal is complete, store the tag data of each security product in the first hash table, and convert the tag data in the first hash table into a list format to obtain the parsed tag data of each security product.
[0116] If the above traversal is not completed, check whether the first tag list has been persistently stored beforehand. If not, return a message indicating that the requested resource does not exist. If persistent storage has been performed, output the recursively processed second tag list and check if the output was successful. If the output was unsuccessful, return a message indicating that the user requested an error. If the output was successful, check whether the tag data for each security product in the second tag list has been traversed. If the traversal is successful, continue execution from the step of checking whether the tag data for each security product in the first tag list has been traversed.
[0117] If the tag data of each security product in the second tag list has not been traversed, the second hash table storing the second tag list is determined based on the identification information of the second tag list. The tag data of each security product stored in the second hash table is overwritten and stored in the first hash table. The process continues from the step of determining whether the tag data of each security product in the second tag list has been traversed.
[0118] In the above embodiments of this application, by parsing the tag data of each security product in the tag list, the convenience of the client requesting security services from multiple security products is effectively improved, further enhancing the user experience.
[0119] In this application, the tag data needs to be created before it can be used. The creation process can be carried out through the distributed cloud management system in the cloud platform.
[0120] The distributed cloud management system performs persistent storage processing on two commonly used types of tag data. The content of the tag data after persistent storage processing cannot be changed, and can only be used or copied.
[0121] Specifically, the creation process can be as follows: Obtain the creation request sent by the client, and based on the request, determine whether a third tag list exists. If a third tag list exists, iterate through the tag data of each security product in the list, and after a third preset time period, determine the third iteration status of the third tag list. The third iteration status includes a completed state and an incomplete state. If the third iteration status is completed, bind and clean the tag data of each security product to obtain the tag data for each created security product.
[0122] If the third traversal is incomplete, determine whether the third tag list has been persistently stored beforehand. If it has been persistently stored beforehand, bind and clean the tag data for each security product to obtain the tag data for each security product after creation.
[0123] If the third tag list does not exist, determine whether the creation request contains preset regular content.
[0124] If it contains preset regular content, bind and clean the regular content to obtain the tag data of the created regular content.
[0125] For example, Figure 8 A flowchart illustrating a method for creating tag data provided in an embodiment of this application is shown below. Figure 8 As shown.
[0126] The system retrieves the creation request sent by the client and determines whether a third-party tag list exists within it. If such a list exists, it checks whether the tag data for each security product in the list has been traversed. If traversal is complete, it binds and cleans the tag data for each security product, then stores the bound and cleaned tag data and obtains the corresponding ID information.
[0127] If the above traversal is not completed, determine whether the third tag list has been persistently stored beforehand. If it has not been persistently stored, return an indication that the user's requested parameters are incorrect. If it has been persistently stored, continue from the step of determining whether the tag data for each security product in the third tag list has been traversed completely.
[0128] If the third tag list does not exist, check if the creation request contains preset regular content. If it does, bind and clean the content, then store the bound and cleaned content and obtain its corresponding ID. If it does not contain preset regular content, return an error message indicating that the user's request parameters are incorrect.
[0129] In the above embodiments of this application, by creating tag data, it is easier to parse the tag data subsequently and provide security services of multiple security products to the client based on the parsed tag data. This reduces the cumbersome process of the client requesting different security products from different cloud platforms, reduces time consumption, and improves the user experience.
[0130] Figure 9 This application provides a schematic diagram of the structure of a cloud-based multi-security product management device, as shown in the embodiments of this application. Figure 9 As shown, the device includes: an acquisition module 901, a judgment module 902, a parsing module 903, a processing module 904, and a creation module 905.
[0131] Module 901 is used to obtain security service requests sent by the client.
[0132] The judgment module 902 is used to determine whether a first tag list exists in the security service request based on the security service request. The first tag list includes tag data of multiple security products that request to provide security services.
[0133] The parsing module 903 is used to parse the tag data of each security product in the first tag list if a first tag list exists, so as to obtain the parsed tag data of each security product.
[0134] The processing module 904 is used to arrange the parsed tag data of each security product according to a preset combination pattern to obtain the arranged tag data.
[0135] The acquisition module 901 is also used to obtain the configuration information of each security product based on the tag data arranged for each security product.
[0136] Module 905 is used to create security instances in the regional cloud pool that correspond to the configuration information of each security product. These security instances are used to provide security services to clients.
[0137] One possible implementation is that the parsing module 903 is specifically used for:
[0138] If a first tag list exists, generate a first hash table to store the tag data for each security product in the first tag list.
[0139] The tag data of each security product in the first tag list is traversed, and after a first preset time period, the first traversal state of the first tag list is determined. The first traversal state includes a completed state and an incomplete state.
[0140] If the first traversal state is completed, store the tag data of each security product in the first hash table.
[0141] The tag data in the first hash table is converted into a list format to obtain the parsed tag data for each security product.
[0142] One possible implementation is that the parsing module 903 is also specifically used for:
[0143] If the first traversal is incomplete, determine whether the first tag list has been persisted in advance.
[0144] If persistent storage processing has been performed in advance, obtain the second tag list after persistent storage processing.
[0145] The tag data of each security product in the second tag list is traversed, and after a second preset time, the second traversal state of the second tag list is determined. The second traversal state includes a completed state and an incomplete state.
[0146] If the second traversal state is completed, store the tag data of each security product in the first hash table.
[0147] The tag data in the first hash table is converted into a list format to obtain the parsed tag data for each security product.
[0148] One possible implementation is that the parsing module 903 is also specifically used for:
[0149] If the second traversal state is incomplete, determine the second hash table that stores the second tag list based on the identification information of the second tag list.
[0150] The tag data of each security product stored in the second hash table is overwritten and stored in the first hash table.
[0151] The tag data in the first hash table is converted into a list format to obtain the parsed tag data for each security product.
[0152] One possible implementation is that the device also includes a creation module for:
[0153] Get the creation request sent by the client.
[0154] Based on the creation request, determine whether a third tag list exists in the creation request.
[0155] If a third tag list exists, iterate through the tag data of each security product in the third tag list, and after a third preset time period, determine the third traversal state of the third tag list. The third traversal state includes a completed state and an incomplete state.
[0156] If the third traversal state is completed, bind and clean the tag data for each security product to obtain the tag data for each security product after creation.
[0157] One possible implementation is to create a module specifically for:
[0158] If the third traversal state is incomplete, determine whether the third tag list has been persisted in advance.
[0159] If persistent storage has been performed in advance, the tag data of each security product is bound and cleaned to obtain the tag data of each security product after creation.
[0160] One possible implementation is to create modules, specifically for:
[0161] If the third tag list does not exist, determine whether the creation request contains preset regular content.
[0162] If it contains preset regular content, bind and clean the regular content to obtain the tag data of the created regular content.
[0163] The cloud-based multi-security product management device provided in this embodiment is used to execute the aforementioned method embodiment. Its implementation principle and technical effect are similar, and will not be described again.
[0164] Figure 10 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application, such as... Figure 10 As shown, the device may include at least one processor 1001 and a memory 1002.
[0165] The memory 1002 is used to store programs. Specifically, the program may include program code, which may include computer operation instructions or executable instructions of the processor 1001, etc.
[0166] The memory 1002 may include high-speed RAM memory, and may also include non-volatile memory, such as at least one disk storage device.
[0167] The processor 1001 is used to execute computer execution instructions stored in the memory 1002 to implement the method described in any of the foregoing embodiments. The processor 1001 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application.
[0168] Optionally, the electronic device may also include a communication interface 1003. In specific implementations, if the communication interface 1003, memory 1002, and processor 1001 are implemented independently, they can be interconnected via a bus to complete communication. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc., but this does not imply that there is only one bus or one type of bus.
[0169] Optionally, in a specific implementation, if the communication interface 1003, memory 1002 and processor 1001 are integrated on a single chip, then the communication interface 1003, memory 1002 and processor 1001 can communicate through an internal interface.
[0170] The electronic device provided in this embodiment is used to execute the multi-security product control method of the cloud platform executed in the aforementioned embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.
[0171] This application also provides a computer-readable storage medium, which may include various media capable of storing program code, such as a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a disk, or an optical disk. Specifically, the computer-readable storage medium stores computer-executable instructions, which are used in the multi-security product control method of the cloud platform in the above embodiments.
[0172] This application also provides a computer program product comprising executable instructions or a computer program stored in a readable storage medium. At least one processor of an electronic device can read the executable instructions from the readable storage medium, and the at least one processor executes the executable instructions to cause the electronic device to implement the multi-security product control method of the cloud platform provided in the various embodiments described above.
[0173] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0174] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A method for controlling multiple security products based on a cloud platform, characterized in that, This is applied to a cloud platform that manages multiple security products, each of which provides security services to clients, including: Obtain the security service request sent by the client; Based on the security service request, it is determined whether a first tag list exists in the security service request. The first tag list includes tag data of multiple security products requesting the provision of security services. The tag data includes the type, version information, location information, and extended information of the security products. If the first tag list exists, the tag data of each security product in the first tag list is parsed to obtain the parsed tag data of each security product. According to a preset combination mode, the parsed tag data of each security product is arranged to obtain the arranged tag data; wherein, the preset combination mode includes a serial mode and a bypass mode; Based on the tag data arranged for each security product, the configuration information of each security product is obtained; Based on the configuration information of each security product, a security instance corresponding to the configuration information is created in the regional cloud pool. The security instance is used to provide security services to the client.
2. The method according to claim 1, characterized in that, If the first tag list exists, the tag data of each security product in the first tag list is parsed to obtain the parsed tag data of each security product, including: If the first tag list exists, generate a first hash table to store the tag data of each security product in the first tag list; The tag data of each security product in the first tag list is traversed, and after a first preset time, the first traversal state of the first tag list is determined. The first traversal state includes a completed state and an incomplete state. If the first traversal state is completed, store the tag data of each security product in the first hash table; The tag data in the first hash table is converted into a list format to obtain the parsed tag data for each security product.
3. The method according to claim 2, characterized in that, Also includes: If the first traversal state is incomplete, determine whether the first tag list has been persistently stored in advance; If persistent storage processing has been performed in advance, obtain the second tag list after persistent storage processing; The tag data of each security product in the second tag list is traversed, and after a second preset time, the second traversal state of the second tag list is determined. The second traversal state includes a completed state and an incomplete state. If the second traversal state is completed, store the tag data of each security product in the first hash table; The tag data in the first hash table is converted into a list format to obtain the parsed tag data for each security product.
4. The method according to claim 3, characterized in that, The method further includes: If the second traversal state is incomplete, determine the second hash table storing the second tag list based on the identification information of the second tag list; The tag data of each security product stored in the second hash table is overwritten and stored in the first hash table; The tag data in the first hash table is converted into a list format to obtain the parsed tag data for each security product.
5. The method according to claim 1, characterized in that, Before obtaining the security service request sent by the client, the process also includes: Get the creation request sent by the client; Based on the creation request, determine whether a third tag list exists in the creation request; If the third tag list exists, iterate through the tag data of each security product in the third tag list, and after a third preset time period, determine the third traversal state of the third tag list. The third traversal state includes a completed state and an incomplete state. If the third traversal state is completed, the tag data of each security product is bound and cleaned to obtain the tag data of each security product after creation.
6. The method according to claim 5, characterized in that, Also includes: If the third traversal state is incomplete, determine whether the third tag list has been persistently stored in advance; If persistent storage has been performed in advance, the tag data of each security product is bound and cleaned to obtain the tag data of each security product after creation.
7. The method according to claim 5, characterized in that, Also includes: If the third tag list does not exist, determine whether the creation request contains preset regular content; If it contains preset regular content, the regular content is bound and cleaned to obtain the tag data of the regular content after creation.
8. A multi-security product management device based on a cloud platform, characterized in that, include: The acquisition module is used to acquire security service requests sent by the client; The judgment module is used to determine whether a first tag list exists in the security service request, based on the security service request. The first tag list includes tag data of multiple security products requesting to provide security services. The parsing module is used to parse the tag data of each security product in the first tag list if the first tag list exists, so as to obtain the parsed tag data of each security product; wherein, the tag data includes the type, version information, location information and extended information of the security product; The processing module is used to arrange the parsed tag data of each security product according to a preset combination mode to obtain the arranged tag data; wherein, the preset combination mode includes a serial mode and a bypass mode; The acquisition module is also used to obtain the configuration information of each security product based on the tag data arranged for each security product; A creation module is used to create a security instance in the regional cloud pool that corresponds to the configuration information of each security product. The security instance is used to provide security services to the client.
9. An electronic device, characterized in that, include: At least one processor and memory; The memory stores computer-executed instructions; The at least one processor executes computer execution instructions stored in the memory, causing the electronic device to perform the cloud-based multi-security product control method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the cloud-based multi-security product control method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Cloud management platform and method for managing various firewall resources
CN112003720A
Docking method of cloud security management platform and cloud security product and related equipment
CN115459939A