A network micro-segmentation system, method, and storage medium

By introducing a micro-segmentation management center module into the micro-segmentation system, network security information from different vendors is aggregated, solving the problem of large workload in interfacing with multiple vendor network elements and realizing unified management and visualization of micro-segmentation network security information across the entire network.

CN118827091BActive Publication Date: 2026-01-06CHINA MOBILE COMM LTD RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311220115.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-20
Publication Date
2026-01-06
Estimated Expiration
2043-09-20

AI Technical Summary

Technical Problem

In cloud-based telecommunications networks, the workload of connecting micro-segmentation systems of network elements from multiple vendors is large, and it is difficult to form network security information for the entire network, making it difficult to locate problems and assign responsibility.

Method used

A micro-segmentation management center module is introduced, which connects with various micro-segmentation management modules to aggregate and stitch together network security information from different vendors, generating global network security information.

Benefits of technology

It simplifies the work of connecting network elements from different vendors with the micro-segmentation system, and realizes unified management and visualization of micro-segmentation network security information across the entire network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827091B_ABST
    Figure CN118827091B_ABST
Patent Text Reader

Abstract

This application discloses a network micro-segmentation system, method, and storage medium. The system includes: a micro-segmentation management center module and at least one micro-segmentation management module. The micro-segmentation management center module includes at least one first interface, and the micro-segmentation management center module is connected to at least one micro-segmentation management module through the at least one first interface, wherein one first interface corresponds to one micro-segmentation management module. The micro-segmentation management module is used to manage access traffic between network elements and obtain network security information from network traffic information collected from network elements. Each micro-segmentation management module manages different network elements. The micro-segmentation management center module is used to obtain at least one piece of network security information from at least one micro-segmentation management module and to summarize and splice the at least one piece of network security information to generate global network security information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network information security technology, and in particular to a network micro-segmentation system, method and storage medium. Background Technology

[0002] Micro-segmentation, a typical technology for fine-grained control of east-west traffic, was first proposed by Gartner in its software-defined data center technology framework. It is used to provide secure access control between hosts (virtual machines, containers, etc.) and to visualize and manage east-west traffic.

[0003] With the development of virtualization and cloudification, cloud-based telecommunications networks will evolve towards three-layer decoupling, meaning that virtualized network elements are decoupled from the virtual layer and hardware. At this point, the resource pool may contain network elements (Virtual Network Functions, VNFs) from multiple vendors. These VNFs from multiple vendors need to interface with the micro-segmentation management module. If the existing resource pool has already deployed a micro-segmentation system from vendor A, newly deployed VNFs from other vendors, such as vendor B, need to interface with vendor A's micro-segmentation system one by one. This involves a large amount of work and makes it difficult to locate and assign responsibility for problems. Furthermore, the various micro-segmentation systems within the same resource pool cannot form a comprehensive micro-segmentation network security information for the entire network. Summary of the Invention

[0004] In view of this, the embodiments of this application aim to provide a network micro-segmentation system, method and storage medium that can simplify the workload of interfacing network elements from different manufacturers with micro-segmentation systems from different manufacturers, and can form micro-segmentation network security information for the entire network.

[0005] The technical solution of this application embodiment is implemented as follows:

[0006] In a first aspect, embodiments of this application provide a network micro-segmentation system, the system comprising: a micro-segmentation management center module and at least one micro-segmentation management module; the micro-segmentation management center module includes at least one first interface, the micro-segmentation management center module being connected to at least one micro-segmentation management module through the at least one first interface, wherein one first interface corresponds to one micro-segmentation management module;

[0007] The micro-segmentation management module is used to manage access traffic between network elements and obtain network security information from the network traffic information collected from the network elements; wherein, each micro-segmentation management module manages different network elements;

[0008] The micro-segmentation management center module is used to obtain at least one network security information from at least one micro-segmentation management module, and to aggregate and splice the at least one network security information to generate global network security information.

[0009] Secondly, embodiments of this application provide a network micro-segmentation method applied to a network micro-segmentation system. The network micro-segmentation system includes: a micro-segmentation management center module and at least one micro-segmentation management module. The micro-segmentation management center module includes at least one first interface, and the micro-segmentation management center module is connected to at least one micro-segmentation management module through the at least one first interface, wherein one first interface corresponds to one micro-segmentation management module. The method includes:

[0010] The micro-segmentation management module manages the access traffic between network elements and obtains network security information from the network traffic information collected from the network elements; each micro-segmentation management module manages different network elements.

[0011] The micro-segmentation management center module obtains at least one piece of network security information from at least one micro-segmentation management module, and aggregates and splices the at least one piece of network security information to generate global network security information.

[0012] This application provides a network micro-segmentation system, method, and storage medium. The system includes: a micro-segmentation management center module and at least one micro-segmentation management module. The micro-segmentation management center module includes at least one first interface, and the micro-segmentation management center module is connected to at least one micro-segmentation management module through the at least one first interface, wherein one first interface corresponds to one micro-segmentation management module. The micro-segmentation management module is used to manage access traffic between network elements and obtain network security information from network traffic information collected from network elements. Each micro-segmentation management module manages different network elements. The micro-segmentation management center module is used to obtain at least one piece of network security information from at least one micro-segmentation management module and perform aggregation and splicing processing on the at least one piece of network security information to generate global network traffic information. By adopting the above implementation scheme, a micro-segmentation management center module is introduced into the micro-segmentation network system. Through the micro-segmentation management center module, network security information contained in micro-segmentation management modules from different vendors can be obtained, and the network security information in each micro-segmentation management module can be aggregated and spliced ​​to form global network security information. This allows for intuitive viewing of the network security information in each micro-segmentation management module. Furthermore, in the above scheme, network elements with the same vendor identifier are managed by the micro-segmentation management module corresponding to their vendor identifier, thus eliminating the need to interface with micro-segmentation management modules from other vendors and simplifying the interface workload. Attached Figure Description

[0013] Figure 1 This is a schematic diagram of an exemplary micro-segmentation management module framework;

[0014] Figure 2 This is an exemplary schematic diagram of network element interconnection between different vendors.

[0015] Figure 3 A schematic diagram of a network micro-segmentation system provided in this application embodiment. Figure 1 ;

[0016] Figure 4 This application provides a schematic diagram of a global network security information subscription process for an information subscription platform.

[0017] Figure 5 This is a schematic diagram illustrating a process for requesting and updating network asset information and security monitoring information, provided as an embodiment of this application.

[0018] Figure 6 This is a schematic diagram illustrating a process for summarizing and updating network asset information, provided as an embodiment of this application.

[0019] Figure 7 This is a schematic diagram illustrating a process for summarizing and updating security policy information, provided as an embodiment of this application.

[0020] Figure 8 This is a schematic diagram illustrating a process for summarizing and updating security monitoring information, provided as an embodiment of this application.

[0021] Figure 9 A schematic diagram of a network micro-segmentation system provided in this application embodiment. Figure 2 ;

[0022] Figure 10 This is a schematic flowchart of a network micro-segmentation method provided in an embodiment of this application. Detailed Implementation

[0023] To gain a more detailed understanding of the features and technical content of the embodiments of this application, the technical solution of this application will be further described in detail below with reference to the accompanying drawings and specific embodiments. The accompanying drawings are for reference only and are not intended to limit the embodiments of this application.

[0024] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to be limiting of this application.

[0025] In the following description, references to "some embodiments" refer to a subset of all possible embodiments. It is understood that "some embodiments" may be the same or different subsets of all possible embodiments and may be combined with each other without conflict. It should also be noted that the terms "first / second / third" used in the embodiments of this application are merely for distinguishing similar objects and do not represent a specific ordering of objects. It is understood that "first / second / third" may be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein.

[0026] Currently, micro-segmentation technology is commonly used for fine-grained control of east-west traffic. Micro-segmentation provides secure access control between hosts (virtual machines, containers), which differs from existing security access control between security domains. Furthermore, it enables visualized management of east-west traffic. Currently, the Guest OS (Guest Operating System) of virtual machines deploying core network network functions (NFs) in cloud-based telecommunications networks is often vendor-proprietary. The Host OS (Host Operating System) is also vendor-proprietary, bound to the virtualization layer. Considering the compatibility issues associated with installing third-party micro-segmentation proxy software, an extended BPF (eBPF) program is used within the Guest OS of the VM hosting the virtualized network function (VNF) to collect and report traffic information. This, combined with the micro-segmentation management module, enables the distribution and execution of security policies, thereby achieving fine-grained access control for east-west traffic. Figure 1 As shown.

[0027] In Adoption Figure 1In this approach, it is more suitable for two-layer decoupling, which can be understood as the decoupling of the hardware layer and the software layer. That is, the virtualization layer software and network element software are provided by the same vendor, while the hardware server and the virtualization software and network element software deployed on the hardware server are provided by different vendors. In other words, the virtualization software and network element software are decoupled from the hardware server. The virtualization network elements and virtualization layer in the resource pool are provided by the same vendor. In this case, the micro-segmentation management module can be a function of the Operation Maintenance Center (OMC) or an independent function. It is provided by the same vendor as the virtualization network elements. The VNF management virtual machine and the micro-segmentation management module can communicate using a private interface, which is easier to implement and promote. With the development of virtualization and cloudification, cloud-based telecommunications networks will evolve towards three-layer decoupling. This means that virtualized network elements (VNFs) are decoupled from virtualization layer software and hardware servers. Specifically, VNFs, virtualization layer software, and hardware servers are all provided by different vendors. In this scenario, the resource pool may contain network elements from multiple vendors. The management virtual machines (VMs) of these VNFs from different vendors need to interface with the micro-segmentation management module, requiring the development of standardized northbound interfaces for the network elements. Currently, the northbound interfaces of these network elements interface with the OMC (Original Management Console), which is a proprietary, non-standardized, and not open interface, making implementation difficult. Furthermore, if an existing two-layer decoupled resource pool has already deployed a micro-segmentation system from vendor A, upgrading to three-layer decoupling requires newly deployed VNFs from other vendors, such as vendor B, to individually interface with vendor A's micro-segmentation system. This integration workload is significant, and troubleshooting and assigning responsibility for problems are difficult. Figure 2 As shown.

[0028] exist Figure 2 As shown in the diagram, if each VNF vendor provides its own micro-segmentation management module to perform security control and traffic visibility for that vendor's VNF traffic, it is difficult to form a micro-segmentation traffic view for the entire network. Furthermore, when third-party systems (such as situational awareness, security event management systems, etc.) need to obtain network element security events, they need to obtain them from the micro-segmentation management module provided by each virtualization network element vendor, resulting in a large amount of interface work.

[0029] Based on this, this application provides a network micro-segmentation system that not only enables three-layer decoupling and / or addresses the issues of poor compatibility and unclear problem identification and responsibility when multiple vendor network elements are deployed in the same resource pool, but also solves the problem of large workload when multiple vendor micro-segmentation management modules are connected to multiple third-party systems.

[0030] To address the aforementioned technical problems, embodiments of this application provide a network micro-segmentation system 1, such as... Figure 3As shown, the system 1 may include: a micro-segmentation management center module 10 and at least one micro-segmentation management module 11; the micro-segmentation management center module 10 includes at least one first interface, and the micro-segmentation management center module 10 is connected to at least one micro-segmentation management module 11 through at least one first interface, wherein one first interface corresponds to one micro-segmentation management module; the micro-segmentation management module 11 is used to manage the access traffic between network elements 12 and obtain network security information from the network traffic information collected from the network elements 12; wherein each micro-segmentation management module manages different network elements; the micro-segmentation management center module 10 is used to obtain at least one piece of network security information from at least one micro-segmentation management module 11, and perform summary and splicing processing on at least one piece of network security information to generate global network security information.

[0031] In this embodiment, there can be one micro-segmentation management center module or multiple micro-segmentation management modules. The micro-segmentation management center module connects to each micro-segmentation management module via a first interface. This first interface can be a southbound interface, and the number of southbound interfaces is the same as the number of micro-segmentation management modules; that is, the number of southbound interfaces equals the number of micro-segmentation management modules.

[0032] In the embodiments of this application, each micro-segmentation management module has a different vendor identifier, and the network elements managed by each micro-segmentation management module belong to the same vendor identifier as each micro-segmentation management module. That is, it can be understood that different micro-segmentation management modules manage different network elements.

[0033] For example, if there are three micro-segmentation management modules, and the vendor identifiers of the three micro-segmentation management modules are A, B and C respectively, then the network elements managed by the micro-segmentation management module with vendor identifier A are network elements with vendor identifier A, the network elements managed by the micro-segmentation management module with vendor identifier B are network elements with vendor identifier B, and the network elements managed by the micro-segmentation management module with vendor identifier C are network elements with vendor identifier C. That is, the vendors of the network elements managed by the micro-segmentation management modules A, B and C are also different.

[0034] In this embodiment, each micro-segmentation management module manages the access traffic between the network elements it manages. For example, vendor A's micro-segmentation management module manages the access traffic between the network elements of vendor A it manages.

[0035] In this embodiment, each micro-segmentation management module manages network elements that collect network traffic information, and the network elements report the collected network traffic information to the micro-segmentation management module.

[0036] For example, the network traffic information received by vendor A's micro-segmentation management module is the network traffic information collected and reported by network elements of vendor A managed by vendor A's micro-segmentation management module. Similarly, micro-segmentation management modules of different vendors receive network traffic information collected and reported by network elements with the same vendor identifier.

[0037] In this embodiment, the micro-segmentation management module obtains network security information from the network traffic information collected and reported by the network elements.

[0038] In this application embodiment, network security information includes at least one of the following: network asset information, security policy information, and security monitoring information.

[0039] In this embodiment, the micro-segmentation management module can obtain network asset information, security policy information, and security monitoring information from network traffic information collected by network elements. Micro-segmentation management modules from different vendors obtain different network asset information, security policy information, and security monitoring information.

[0040] In this embodiment of the application, after obtaining the network asset information, security policy information, and security monitoring information corresponding to each micro-segmentation management module, the micro-segmentation management center module can further process the network asset information, security policy information, and security monitoring information corresponding to each micro-segmentation management module.

[0041] In this embodiment, before obtaining at least one network security information from at least one micro-segmentation management module, the micro-segmentation management center module first performs two-way authentication with at least one micro-segmentation management module to establish a secure channel, and then sends a network security information request message to at least one micro-segmentation management module.

[0042] In this embodiment, when at least one micro-segmentation management module receives a network security information request message, it responds to the request message and sends network security information to the micro-segmentation management center module. The network security information corresponds one-to-one with at least one micro-segmentation management module.

[0043] For example, if there are three micro-segmentation management modules, the micro-segmentation management center sends network security information request messages to the three micro-segmentation management modules respectively. After receiving the request message, the three micro-segmentation management modules respond to the request message and send network security information A, B and C to the micro-segmentation management center respectively.

[0044] In this embodiment, the micro-segmentation management center aggregates and splices at least one network security information sent by at least one micro-segmentation management module to form global network security information.

[0045] For example, if the micro-segmentation management center obtains three network security information messages A, B, and C sent by the three micro-segmentation management modules respectively, it can summarize and concatenate the three network security information messages A, B, and C to obtain the global network security information corresponding to the three micro-segmentation management modules.

[0046] It should be noted that since the three micro-segmentation management modules belong to different vendors, by introducing the micro-segmentation management center module, it is possible to aggregate the network security information corresponding to different vendors. Therefore, when obtaining global network security information, there is no need to interface with the micro-segmentation management modules of other vendors one by one with the micro-segmentation management modules of the initially deployed vendor, thus improving efficiency.

[0047] In this embodiment of the application, when the network security information is network asset information, when the micro-segmentation management center module obtains at least one network asset information from at least one micro-segmentation management module, the micro-segmentation management center module and at least one micro-segmentation management module perform two-way authentication respectively, establish a secure channel, and then send a network asset information request to at least one micro-segmentation management module.

[0048] It should be noted that network asset information may include VNF names, VM names, and related IP addresses.

[0049] In this embodiment, when at least one micro-segmentation management module receives a network asset information request, at least one micro-segmentation management module sends a network asset information response to the micro-segmentation management center module. This response includes network asset information obtained from network traffic information reported by network elements by the asset management function of each micro-segmentation management module, as well as the network topology information generated corresponding to each network asset information. The network topology information corresponding to the network asset information includes the VNF ID, the VM ID of the virtual machine within the VNF, the physical location of the VM (e.g., data center name), its province of origin, and the connection relationships between the VM and other VMs.

[0050] It should be noted that network topology information can be understood as network topology information generated based on network asset information identified from network traffic information, that is, network asset information can be directly displayed from network topology information.

[0051] It should be noted that network asset information can also be reported proactively by at least one micro-segmentation management module to the micro-segmentation management center module after a secure connection is established between the micro-segmentation management center module and at least one micro-segmentation management module.

[0052] In this embodiment, after obtaining at least one network asset information, the micro-segmentation management center module summarizes the network asset information obtained from at least one micro-segmentation management module and the network topology information corresponding to each network asset information, and then splices the network topology information together, that is, it summarizes and splices at least one network asset information to form global network asset information.

[0053] It should be noted that, since at least one network asset information is provided by a different micro-segmentation management module, the resulting global network asset information can show the network asset information corresponding to each micro-segmentation management module with a different vendor identifier.

[0054] In this embodiment of the application, when the network security information is security policy information, when the micro-segmentation management center module obtains at least one security policy information from at least one micro-segmentation management module, the micro-segmentation management center module performs two-way authentication with at least one micro-segmentation management module, establishes a secure channel, and then sends a security policy information request to at least one micro-segmentation management module.

[0055] In this embodiment, when at least one micro-segmentation management module receives a security policy information request, at least one micro-segmentation management module sends a security policy information response to the micro-segmentation management center module. The response contains at least one security policy information from at least one micro-segmentation management module, including VNFid, related VM id, identifier of the security group to which the VM belongs, and security policy of the security group.

[0056] It should be noted that the security policy of a security group can be understood as the security policies of some VNFs being the same. They can be grouped together and share a security policy. As long as other VNFs join the group, the corresponding security policy of the group will be assigned to the other VNFs that join the group.

[0057] It should be noted that security policy information can also be reported proactively by at least one micro-segmentation management module to the micro-segmentation management center module after a secure connection is established between the micro-segmentation management center module and at least one micro-segmentation management module.

[0058] In this embodiment, after obtaining at least one security policy information, the micro-segmentation management center module summarizes and splices the security policy information obtained from at least one micro-segmentation management module to form global security policy information.

[0059] It should be noted that because of the security group identifier, the security policies of network elements with the same security group identifier can be naturally merged.

[0060] It should be noted that, since at least one security policy information is provided by a different micro-segmentation management module, the resulting global security policy information can show the security policy information corresponding to each micro-segmentation management module with a different vendor identifier.

[0061] In this embodiment of the application, when the network security information is security monitoring information, when the micro-segmentation management center module obtains at least one security monitoring information from at least one micro-segmentation management module, the micro-segmentation management center module performs two-way authentication with at least one micro-segmentation management module, establishes a secure channel, and then sends a security monitoring information request to at least one micro-segmentation management module.

[0062] In this embodiment of the application, when at least one micro-segmentation management module receives a security monitoring information request, at least one micro-segmentation management module sends a security monitoring information response to the micro-segmentation management center module. The response includes alarm information generated by the security monitoring function of at least one micro-segmentation management module after obtaining abnormal traffic from network traffic information.

[0063] It should be noted that security monitoring information can also be reported proactively by at least one micro-segmentation management module to the micro-segmentation management center module after a secure connection is established between the micro-segmentation management center module and at least one micro-segmentation management module.

[0064] In this embodiment, after obtaining at least one security monitoring information, the micro-segmentation management center module summarizes and splices the security monitoring information obtained from at least one micro-segmentation management module to form global security monitoring information.

[0065] It should be noted that security monitoring information mainly includes alarm information.

[0066] It should be noted that, since at least one security monitoring information is provided by a different micro-segmentation management module, the resulting global security monitoring information can show the security monitoring information corresponding to each micro-segmentation management module with a different vendor identifier.

[0067] It is understood that the network micro-segmentation system provided in this application embodiment introduces a micro-segmentation management center module into the micro-segmentation network system. Through the micro-segmentation management center module, it is possible to obtain network security information contained in the micro-segmentation management modules of different vendors, and to summarize and splice the network security information in each micro-segmentation management module to form global network security information. This allows for intuitive viewing of the network security information in each micro-segmentation management module. Furthermore, in the above scheme, network elements with the same vendor identifier are managed by the micro-segmentation management module corresponding to their vendor identifier, thus eliminating the need to interface with micro-segmentation management modules of other vendors and simplifying the interface workload.

[0068] Optionally, the network micro-segmentation system also includes an information subscription platform; the micro-segmentation management center module also includes a second interface; the micro-segmentation management center module connects to the information subscription platform through the second interface; the micro-segmentation management center module is also used to determine the target global network security information corresponding to the message subscription request when it receives a message subscription request for global network security information sent by the information subscription platform; and to send the target global network security information to the information subscription platform through the second interface.

[0069] In this embodiment, the information subscription platform can be a third-party information subscription platform, and the second interface can be a northbound interface.

[0070] In this embodiment, the micro-segmentation management center module can connect to a third-party information subscription platform through its included northbound interface.

[0071] In this embodiment of the application, before subscribing to global network security information from the micro-segmentation management center through a third-party information subscription platform, the third-party information subscription platform first performs mutual authentication with the micro-segmentation management center and establishes a secure channel. After that, the third-party information subscription platform subscribes to the micro-segmentation-related global network security information from the micro-segmentation management center, such as network asset information and corresponding network asset topology information, abnormal traffic alarms, etc.

[0072] It should be noted that when subscribing to global cybersecurity information through a third-party information subscription platform, the content of the global cybersecurity information related to micro-segmentation and the method of obtaining the global cybersecurity information should be clearly defined. The method of obtaining the information can be active acquisition or push notification.

[0073] In this embodiment, when global network security information related to micro-segmentation is actively acquired, the third-party information subscription platform can periodically obtain the subscribed micro-segmentation-related information from the micro-segmentation management center module. Specifically, when the micro-segmentation management center module receives a message subscription request for global network security information from the third-party information subscription platform, it determines the target global network traffic security information corresponding to the message subscription request and sends the target global network traffic security information to the third-party information subscription platform through the northbound interface.

[0074] In this embodiment of the application, when the global network security information related to micro-segmentation is obtained by push, the micro-segmentation management center module only needs to periodically push the micro-segmentation-related information subscribed to by the third-party information subscription platform to the third-party information subscription platform.

[0075] It should be noted that when subscribing to micro-segmentation-related information from the micro-segmentation management center through a third-party information subscription platform, the system can connect to the capability development module included in the micro-segmentation management center module via the northbound interface.

[0076] Based on the above process, in this embodiment of the application, when subscribing to micro-segmentation-related information in the micro-segmentation management center module through a third-party information subscription platform, the flowchart is as follows: Figure 4 As shown, the network micro-segmentation management system supports third-party platforms in subscribing to micro-segmentation-related information. Upon successful subscription, the system sends the subscribed micro-segmentation-related information to the third-party platform, either via request-based sending or direct push. The specific process is as described above and will not be repeated here.

[0077] Optionally, the micro-segmentation management center module is further configured to select one network asset information from at least one network asset information as the network asset information to be spliced; wherein, the network asset information is information contained in network traffic information; determine the first network asset contained in the network asset information to be spliced, and the second network asset contained in the remaining network asset information other than the network asset information to be spliced ​​from at least one network asset information, and determine the connection relationship between the first network asset and the second network asset, and the number of connections between the first network asset and the second network asset; based on the number of connections and the connection relationship, splice the remaining network asset information and the network asset information to be spliced ​​to generate global network asset information; wherein, the remaining network asset information is other network asset information other than the network asset information to be spliced.

[0078] In this embodiment of the application, when summarizing and splicing at least one network asset information to form global network asset information, it may be possible to first select one network asset information to be spliced ​​from the at least one network asset information obtained, and determine the network assets contained in the network asset information to be spliced, as well as the network assets contained in the remaining network asset information other than the network asset information to be spliced.

[0079] It should be noted that the network asset information to be spliced ​​can be the one containing the most network assets, that is, the one with the most complex network asset topology. The more complex the network asset topology, the more network assets it contains.

[0080] In this embodiment of the application, when splicing the network asset information to be spliced ​​with the remaining network asset information, one can be selected from the remaining network asset information first, and then the connection relationship between the first network asset corresponding to the network asset information to be spliced ​​and the second network asset corresponding to the selected network asset information in the remaining network asset information can be determined. The two are then spliced ​​together, and so on, until all the remaining network asset information is spliced ​​together in sequence to obtain the global network asset information.

[0081] In this embodiment of the application, when splicing the network asset information to be spliced ​​with the remaining network asset information, the number of the second network assets corresponding to the remaining network asset information can be counted, and the splicing can be carried out in order of descending quantity and the connection relationship between the second network assets and the first network assets to obtain the global network asset information.

[0082] In this embodiment, the connection relationship between the first network asset and the second network asset can be obtained through their respective network asset topologies.

[0083] Specifically, based on the network topology of a certain province (such as province A, which may be the province with the most assets and the most complex network topology), the connections between province A and network elements in other provinces or other devices not managed by the micro-segmentation management module are identified. The number of network elements in other provinces that are in the same physical location as the VNF in province A (which can be determined by identification information) and have connections to the VNF in province A are counted and sorted.

[0084] First, for network elements in provinces with the same physical location as the VNF in that province and the most connections to network elements in that province (such as province B), the information of network elements in province B that are connected to province A is extracted from the network topology of province B and incorporated into the topology of province A. Then, for network elements in province B that are incorporated into the topology of province A, the topological relationships of these network elements are completed based on the network topology of province B. That is, with VMs connected to province A and province B, the remaining network elements in province B are then spliced ​​with VMs in province A.

[0085] For network elements in the province with the same physical location as the VNF in that province and the second largest number of network element connections in that province (such as province C), the information of network elements connected between province C and province A is extracted from the network topology of province C and incorporated into the topology of province A; then, for network elements in province C that are incorporated into the topology of province A, the topological relationships of these network elements are completed based on the network topology of province C.

[0086] By analogy, this allows us to build upon the network topology of a specific province, stitching together the network topologies of all micro-segmentation management modules to form a global network topology, i.e., global network asset information.

[0087] Optionally, the micro-segmentation management module is further configured to, upon receiving updated network traffic information reported by network elements managed by the micro-segmentation management module, obtain updated network security information from the updated network traffic information and report the updated network security information to the micro-segmentation management center module; wherein, the updated network security information includes at least one of the following: updated network asset information, updated security policy information, and updated security monitoring information; the micro-segmentation management center module is further configured to, based on the updated network security information, determine the target network security information to be updated in the micro-segmentation management center module; and update the target network security information to achieve the update of global network security information.

[0088] In this embodiment, if the network traffic information collected by the network element is updated, the micro-segmentation management module can obtain updated network security information from the updated network traffic information. The updated network security information includes updated network asset information, updated security policy information, and updated security monitoring information.

[0089] In this embodiment of the application, when the network asset information on one or more micro-segmentation management modules in at least one micro-segmentation management module is updated, the micro-segmentation management module and the micro-segmentation management center module should synchronize the network asset information.

[0090] In this embodiment, one or more micro-segmentation management modules proactively report updated network asset information to the micro-segmentation management center module in real time or periodically. The updated network asset information includes at least the updated asset name (VNF type, etc.), associated VNF ID, VM ID, and connection relationships. Specifically, when a network element managed by the micro-segmentation management module collects updated network traffic information, the micro-segmentation management module obtains the updated network asset information from the updated network traffic information and reports the updated network asset information to the micro-segmentation management center module in real time or periodically.

[0091] In this embodiment, since the updated network asset information includes at least the updated asset name, associated VNF ID, VM ID, and connection relationship, the micro-segmentation management center module determines the target network asset information to be updated in the micro-segmentation management center module based on the updated network asset information; and updates the target network asset information, thereby updating the global network asset information.

[0092] In this embodiment, when the security policy information on one or more micro-segmentation management modules in at least one micro-segmentation management module is updated (for example, when a virtualized network element for a new service provided by a certain vendor is deployed in the resource pool, or when the micro-segmentation management module detects abnormal traffic and updates its corresponding security policy), the micro-segmentation management module and the micro-segmentation management center module should synchronize the update of the security policy information.

[0093] In this embodiment, one or more micro-segmentation management modules proactively report updated security policy information to the micro-segmentation management center module in real time or periodically. The updated security policy information includes at least the updated security policy, associated VNF ID, VM ID, and IP address. Specifically, when a network element managed by the micro-segmentation management module collects updated network traffic information, the micro-segmentation management module obtains the updated security policy information from the updated network traffic information and reports the updated security policy information to the micro-segmentation management center module in real time or periodically.

[0094] In this embodiment, since the updated security policy information includes at least the updated security policy, associated VNF ID, VM ID, IP address, etc., the micro-segmentation management center module determines the target security policy information to be updated in the micro-segmentation management center module based on the updated security policy information; and updates it, thereby updating the global security policy information.

[0095] In this embodiment of the application, when the security monitoring information on one or more micro-segmentation management modules in at least one micro-segmentation management module is updated, the micro-segmentation management module and the micro-segmentation management center module should synchronize the update of the security monitoring information.

[0096] In this embodiment, one or more micro-segmentation management modules proactively report updated security monitoring information to the micro-segmentation management center module in real time or periodically. The updated security monitoring information includes at least the updated alarms and alarm content, associated VNF IDs, VM IDs, etc. Specifically, when a network element managed by the micro-segmentation management module collects updated network traffic information, the micro-segmentation management module obtains the updated security monitoring information from the updated network traffic information, and reports the updated security monitoring information to the micro-segmentation management center module in real time or periodically.

[0097] In this embodiment, since the updated security monitoring information includes at least the updated alarms and alarm content, associated VNF IDs, VM IDs, etc., the micro-segmentation management center module can determine the target security monitoring information to be updated in the micro-segmentation management center module based on the updated security monitoring information; and update it, thereby updating the global security monitoring information.

[0098] Optionally, the micro-segmentation management center module is further configured to send a first request message to the micro-segmentation management module at preset intervals, the first request message being used to query updated network security information; the micro-segmentation management module is further configured to query the updated network security information based on the first request message; add the queried updated network security information to a first response message, and send the first response message to the micro-segmentation management center module; the micro-segmentation management center module is further configured to determine the updated network security information from the first response message; determine the target network security information to be updated in the micro-segmentation management center module based on the updated network security information; and update the target network security information to achieve the update of global network security information.

[0099] In this embodiment, when updating global network security information, the micro-segmentation management center module can periodically query the micro-segmentation management module for updated network security information, and then the micro-segmentation management module sends the updated network security information to the micro-segmentation management center module. The network security information includes network asset information, security policy information, security monitoring information, etc.

[0100] In this embodiment, the micro-segmentation management center module queries the micro-segmentation management module for updated network asset information at preset intervals, and the micro-segmentation management module sends the updated network asset information back to the micro-segmentation management center module. Specifically, the micro-segmentation management center module may send a request message to the micro-segmentation management module at preset intervals to query the updated network asset information. After receiving the request message, the micro-segmentation management module queries the updated network asset information from the network traffic information collected by the network elements, adds the queried network asset information to a response message, and sends the response message to the micro-segmentation management center module. Upon receiving the response message, the micro-segmentation management center module obtains the updated network asset information from the response message, determines the target network asset information to be updated based on the information contained in the network asset information, and updates the target network asset information, thereby achieving the update of the global network asset information.

[0101] It should be noted that the preset duration can be set according to specific needs, such as per second, per minute, or per hour. Specifically, it can be selected according to the actual situation, and no specific limitation is made in this application.

[0102] In this embodiment, the micro-segmentation management center module queries the micro-segmentation management module for updated security policy information at preset intervals, and the micro-segmentation management module sends the updated security policy information back to the micro-segmentation management center module. Specifically, the micro-segmentation management center module may send a request message to the micro-segmentation management module at preset intervals to query the updated security policy information. After receiving the request message, the micro-segmentation management module queries the updated security policy information from the network traffic information collected by the network elements, adds the queried security policy information to a response message, and sends the response message to the micro-segmentation management center module. Upon receiving the response message, the micro-segmentation management center module obtains the updated security policy information from the response message, determines the target security policy information to be updated based on the information contained in the security policy information, and updates the target security policy information, thereby updating the global security policy information.

[0103] In this embodiment, the micro-segmentation management center module queries the micro-segmentation management module for updated security monitoring information at preset intervals, and the micro-segmentation management module sends the updated security monitoring information back to the micro-segmentation management center module. Specifically, the micro-segmentation management center module may send a request message to the micro-segmentation management module at preset intervals to query updated security monitoring information. After receiving the request message, the micro-segmentation management module queries the updated security monitoring information from the network traffic information collected by the network elements, adds the queried security monitoring information to a response message, and sends the response message to the micro-segmentation management center module. Upon receiving the response message, the micro-segmentation management center module obtains the updated security monitoring information from the response message, determines the target security monitoring information to be updated based on the information contained in the security monitoring information, and updates the target security monitoring information, thereby achieving the update of global security monitoring information.

[0104] Optionally, the information subscription platform is also used to send updated security policy information to the micro-segmentation management center module. The updated security policy information is used to update the security policy corresponding to the network element to be updated in the micro-segmentation management module. The security policy information is information contained in the network security information. The micro-segmentation management center module is also used to send the updated security policy information to the micro-segmentation management module. The micro-segmentation management module is also used to determine the network element to be updated based on the network element identifier to be updated contained in the updated security policy information, and update the security policy information of the network element to be updated to the updated security policy information.

[0105] In this embodiment, the micro-segmentation management center module can serve as an entry point for updating security policy information. For example, when maintenance personnel analyze a situation or security event from a third-party information subscription platform, such as a situational awareness platform or a security event management system, and determine that a certain VNF needs an updated security policy, the information subscription platform sends the updated security policy information for the network element to be updated in the micro-segmentation management module to the micro-segmentation management center module. The micro-segmentation management center module authenticates the situational awareness platform or security event management system, and upon successful authentication, initiates a security policy information update request to the micro-segmentation management module, sending the updated security policy information. The micro-segmentation management module authenticates and authorizes the micro-segmentation management center module to update the security policy. The updated security policy information sent by the micro-segmentation management center module includes the security policy, related VNF ID, VM ID, IP address, etc. Based on the network element identifier information or other information contained in the updated security policy information, the micro-segmentation management module determines the network element to be updated, distributes it to the corresponding VM, and updates the security policy information corresponding to the network element to be updated.

[0106] In this embodiment, after updating the security policy information, the micro-segmentation management module sends a security policy update response to the micro-segmentation management center module, and the micro-segmentation management center synchronously updates the local global security policy information based on the response message.

[0107] Optionally, the micro-segmentation management center module also includes a traffic visualization module; the traffic visualization module is used to visualize the global network security information in the micro-segmentation management center module.

[0108] In this embodiment, the micro-segmentation management center module can visualize global network security information through a traffic visualization module. Specifically, the traffic visualization module of the micro-segmentation management center module can obtain global network asset information and the corresponding network topology information from the network asset management module included in the micro-segmentation management center module, and display it, including connections between VNFs, VNF IDs, VMs contained in VNFs, VM IDs, the physical location of VMs, and connections between VMs.

[0109] In this embodiment, the traffic visualization module can obtain alarm information from the security monitoring module included in the micro-segmentation management center module and display it, such as displaying abnormal traffic between VMs using different colors.

[0110] In this embodiment, the traffic visualization module can also periodically request updates to network asset information from the network asset management module, and update the currently displayed global network asset information and the corresponding network topology information. The network asset management module can also proactively report updates to network asset information to the traffic visualization module.

[0111] In this embodiment, the traffic visualization module can also periodically request updates to the security monitoring information from the security monitoring module and update the displayed information accordingly. The security monitoring module can also proactively report updates to the security monitoring information to the traffic visualization module. The traffic visualization process is as follows: Figure 5 As shown, the traffic visualization process includes obtaining global network asset information and global security monitoring information from the network asset information management and security monitoring information modules of the micro-segmentation management center module, displaying global network asset information and abnormal connections, and updating the displayed content based on network asset information and alarm updates.

[0112] Based on the above embodiments, the process for summarizing, splicing, and updating global network asset information in this application embodiment is as follows: Figure 6 As shown, the network asset information management process includes obtaining network asset information and network topology information from micro-segmentation management modules; based on the network topology information reported by a micro-segmentation management module, filtering and sorting the number of VNF connections; identifying the VNF managed by another micro-segmentation management module with the most connection relationships to the VNF managed by the first micro-segmentation management module; and concatenating the network topology information of the two VNFs managed by these two micro-segmentation management modules. Then, following the sorting, the network topology of other VNFs managed by other micro-segmentation management modules is concatenated to generate the global network topology; and network asset update information is obtained to update the network asset information and network topology information. The specific process can be found in the implementation process described above, and will not be repeated here.

[0113] Based on the above embodiments, the process for summarizing, splicing, and updating global security policy information in this application embodiment is as follows: Figure 7 As shown, the security policy management process includes obtaining security policy information from the micro-segmentation management module, generating global security policy information, and obtaining security policy update information to update the security policy information. It also supports third-party platforms sending security policy update requests to the micro-segmentation management center module, which, along with the micro-segmentation management module, distributes the updated security policy information to the corresponding VNF's VM. For a detailed description of the process, please refer to the implementation process described above; it will not be repeated here.

[0114] Based on the above embodiments, the process for summarizing, splicing, and updating global security monitoring information in this application embodiment is as follows: Figure 8As shown, the security monitoring process includes acquiring security monitoring information from the micro-segmentation management module, generating global security monitoring information, and acquiring security monitoring update information to update the global security monitoring information. The specific process can be found in the implementation details above and will not be repeated here.

[0115] Based on this, embodiments of this application provide a network micro-segmentation system, such as... Figure 9 As shown, a micro-segmentation management center module is introduced, defining southbound and northbound interfaces. The southbound interface connects to the vendor's micro-segmentation management module, while the northbound interface connects to third-party information subscription platforms such as log management systems and situational awareness platforms. It is responsible for connecting with the micro-segmentation management modules of various vendors within the resource pool via the southbound interface to obtain network asset information, security policy information, security monitoring information, and other relevant information. This information is then aggregated and combined to form global network asset information, global security policy information, and global security monitoring information, resulting in a global traffic visualization. Additionally, the northbound interface can be opened to provide alarm logs, network topology, etc., to third-party information subscription platforms. Administrators can also configure network-wide security policies via the northbound interface.

[0116] The network micro-segmentation system introduces a micro-segmentation management center, which connects to the micro-segmentation management module via a southbound interface and to third-party platforms via a northbound interface. The micro-segmentation management center includes at least the following functional modules: asset management, security policy management, security monitoring, traffic visualization, and capability sharing.

[0117] The aforementioned network micro-segmentation system can solve the problems of poor compatibility and unclear problem localization and responsibility when three-layer decoupling and / or multi-vendor network elements are deployed in the same resource pool. It can also solve the problem of difficulty in forming a full network topology, security monitoring, security policies, and traffic view when deploying multi-vendor micro-segmentation management systems, and can solve the problem of large workload when multiple vendor micro-segmentation management modules are connected to multiple third-party systems.

[0118] Based on the above embodiments, this application provides a network micro-segmentation method applied to a network micro-segmentation system, such as... Figure 10 As shown, the network micro-segmentation system includes: a micro-segmentation management center module and at least one micro-segmentation management module; the micro-segmentation management center module includes at least one first interface, and the micro-segmentation management center module is connected to at least one micro-segmentation management module through the at least one first interface, wherein one first interface corresponds to one micro-segmentation management module; the method includes:

[0119] S101. The micro-segmentation management module manages the access traffic between network elements and obtains network security information from the network traffic information collected from the network elements; wherein, each micro-segmentation management module manages different network elements.

[0120] In this embodiment, there can be one micro-segmentation management center module or multiple micro-segmentation management modules. The micro-segmentation management center module connects to each micro-segmentation management module via a first interface. This first interface can be a southbound interface, and the number of southbound interfaces is the same as the number of micro-segmentation management modules; that is, the number of southbound interfaces equals the number of micro-segmentation management modules.

[0121] In the embodiments of this application, each micro-segmentation management module has a different vendor identifier, and the network elements managed by each micro-segmentation management module belong to the same vendor identifier as each micro-segmentation management module. That is, it can be understood that different micro-segmentation management modules manage different network elements.

[0122] For example, if there are three micro-segmentation management modules, and the vendor identifiers of the three micro-segmentation management modules are A, B and C respectively, then the network elements managed by the micro-segmentation management module with vendor identifier A are network elements with vendor identifier A, the network elements managed by the micro-segmentation management module with vendor identifier B are network elements with vendor identifier B, and the network elements managed by the micro-segmentation management module with vendor identifier C are network elements with vendor identifier C. That is, the vendors of the network elements managed by the micro-segmentation management modules A, B and C are also different.

[0123] In this embodiment, each micro-segmentation management module manages the access traffic between the network elements it manages. For example, vendor A's micro-segmentation management module manages the access traffic between the network elements of vendor A it manages.

[0124] In this embodiment, each micro-segmentation management module manages network elements that collect network traffic information, and the network elements report the collected network traffic information to the micro-segmentation management module.

[0125] For example, the network traffic information received by vendor A's micro-segmentation management module is the network traffic information collected and reported by network elements of vendor A managed by vendor A's micro-segmentation management module. Similarly, micro-segmentation management modules of different vendors receive network traffic information collected and reported by network elements with the same vendor identifier.

[0126] In this embodiment, the micro-segmentation management module obtains network security information from the network traffic information collected and reported by the network elements.

[0127] In this application embodiment, network security information includes at least one of the following: network asset information, security policy information, and security monitoring information.

[0128] In this embodiment, the micro-segmentation management module can obtain network asset information, security policy information, and security monitoring information from network traffic information collected by network elements. Micro-segmentation management modules from different vendors obtain different network asset information, security policy information, and security monitoring information.

[0129] In this embodiment of the application, after obtaining the network asset information, security policy information, and security monitoring information corresponding to each micro-segmentation management module, the micro-segmentation management center module can further process the network asset information, security policy information, and security monitoring information corresponding to each micro-segmentation management module.

[0130] S102. Using the micro-segmentation management center module, obtain at least one network security information from at least one micro-segmentation management module, and aggregate and splice the at least one network security information to generate global network security information.

[0131] In this embodiment, before obtaining at least one network security information from at least one micro-segmentation management module, the micro-segmentation management center module first performs two-way authentication with at least one micro-segmentation management module to establish a secure channel, and then sends a network security information request message to at least one micro-segmentation management module.

[0132] In this embodiment, when at least one micro-segmentation management module receives a network security information request message, it responds to the request message and sends network security information to the micro-segmentation management center module. The network security information corresponds one-to-one with at least one micro-segmentation management module.

[0133] For example, if there are three micro-segmentation management modules, the micro-segmentation management center sends network security information request messages to the three micro-segmentation management modules respectively. After receiving the request message, the three micro-segmentation management modules respond to the request message and send network security information A, B and C to the micro-segmentation management center respectively.

[0134] In this embodiment, the micro-segmentation management center aggregates and splices at least one network security information sent by at least one micro-segmentation management module to form global network security information.

[0135] For example, if the micro-segmentation management center obtains three network security information messages A, B, and C sent by the three micro-segmentation management modules respectively, it can summarize and concatenate the three network security information messages A, B, and C to obtain the global network security information corresponding to the three micro-segmentation management modules.

[0136] It should be noted that since the three micro-segmentation management modules belong to different vendors, by introducing the micro-segmentation management center module, it is possible to aggregate the network security information corresponding to different vendors. Therefore, when obtaining global network security information, there is no need to interface with the micro-segmentation management modules of other vendors one by one with the micro-segmentation management modules of the initially deployed vendor, thus improving efficiency.

[0137] In this embodiment of the application, when the network security information is network asset information, when the micro-segmentation management center module obtains at least one network asset information from at least one micro-segmentation management module, the micro-segmentation management center module and at least one micro-segmentation management module perform two-way authentication respectively, establish a secure channel, and then send a network asset information request to at least one micro-segmentation management module.

[0138] It should be noted that network asset information may include VNF names, VM names, and related IP addresses.

[0139] In this embodiment, when at least one micro-segmentation management module receives a network asset information request, at least one micro-segmentation management module sends a network asset information response to the micro-segmentation management center module. This response includes network asset information obtained from network traffic information reported by network elements by the asset management function of each micro-segmentation management module, as well as the network topology information generated corresponding to each network asset information. The network topology information corresponding to the network asset information includes the VNF ID, the VM ID of the virtual machine within the VNF, the physical location of the VM (e.g., data center name), its province of origin, and the connection relationships between the VM and other VMs.

[0140] It should be noted that network topology information can be understood as network topology information generated based on network asset information identified from network traffic information, that is, network asset information can be directly displayed from network topology information.

[0141] It should be noted that network asset information can also be reported proactively by at least one micro-segmentation management module to the micro-segmentation management center module after a secure connection is established between the micro-segmentation management center module and at least one micro-segmentation management module.

[0142] In this embodiment, after obtaining at least one network asset information, the micro-segmentation management center module summarizes the network asset information obtained from at least one micro-segmentation management module and the network topology information corresponding to each network asset information, and then splices the network topology information together, that is, it summarizes and splices at least one network asset information to form global network asset information.

[0143] It should be noted that, since at least one network asset information is provided by a different micro-segmentation management module, the resulting global network asset information can show the network asset information corresponding to each micro-segmentation management module with a different vendor identifier.

[0144] In this embodiment of the application, when the network security information is security policy information, when the micro-segmentation management center module obtains at least one security policy information from at least one micro-segmentation management module, the micro-segmentation management center module performs two-way authentication with at least one micro-segmentation management module, establishes a secure channel, and then sends a security policy information request to at least one micro-segmentation management module.

[0145] In this embodiment, when at least one micro-segmentation management module receives a security policy information request, at least one micro-segmentation management module sends a security policy information response to the micro-segmentation management center module. The response contains at least one security policy information from at least one micro-segmentation management module, including VNFid, related VM id, identifier of the security group to which the VM belongs, and security policy of the security group.

[0146] It should be noted that the security policy of a security group can be understood as the security policies of some VNFs being the same. They can be grouped together and share a security policy. As long as other VNFs join the group, the corresponding security policy of the group will be assigned to the other VNFs that join the group.

[0147] It should be noted that security policy information can also be reported proactively by at least one micro-segmentation management module to the micro-segmentation management center module after a secure connection is established between the micro-segmentation management center module and at least one micro-segmentation management module.

[0148] In this embodiment, after obtaining at least one security policy information, the micro-segmentation management center module summarizes and splices the security policy information obtained from at least one micro-segmentation management module to form global security policy information.

[0149] It should be noted that because of the security group identifier, the security policies of network elements with the same security group identifier can be naturally merged.

[0150] It should be noted that, since at least one security policy information is provided by a different micro-segmentation management module, the resulting global security policy information can show the security policy information corresponding to each micro-segmentation management module with a different vendor identifier.

[0151] In this embodiment of the application, when the network security information is security monitoring information, when the micro-segmentation management center module obtains at least one security monitoring information from at least one micro-segmentation management module, the micro-segmentation management center module performs two-way authentication with at least one micro-segmentation management module, establishes a secure channel, and then sends a security monitoring information request to at least one micro-segmentation management module.

[0152] In this embodiment of the application, when at least one micro-segmentation management module receives a security monitoring information request, at least one micro-segmentation management module sends a security monitoring information response to the micro-segmentation management center module. The response includes alarm information generated by the security monitoring function of at least one micro-segmentation management module after obtaining abnormal traffic from network traffic information.

[0153] It should be noted that security monitoring information can also be reported proactively by at least one micro-segmentation management module to the micro-segmentation management center module after a secure connection is established between the micro-segmentation management center module and at least one micro-segmentation management module.

[0154] In this embodiment, after obtaining at least one security monitoring information, the micro-segmentation management center module summarizes and splices the security monitoring information obtained from at least one micro-segmentation management module to form global security monitoring information.

[0155] It should be noted that security monitoring information mainly includes alarm information.

[0156] It should be noted that, since at least one security monitoring information is provided by a different micro-segmentation management module, the resulting global security monitoring information can show the security monitoring information corresponding to each micro-segmentation management module with a different vendor identifier.

[0157] It is understood that the embodiments of this application provide a network micro-segmentation method. By introducing a micro-segmentation management center module into the micro-segmentation network system, the micro-segmentation management center module can obtain network security information contained in micro-segmentation management modules from different vendors, and can summarize and splice the network security information in each micro-segmentation management module to form global network security information. This allows for intuitive viewing of the network security information in each micro-segmentation management module. Furthermore, in the above scheme, network elements with the same vendor identifier are managed by the micro-segmentation management module corresponding to their vendor identifier, thus eliminating the need to interface with micro-segmentation management modules from other vendors and simplifying the interface workload.

[0158] Optionally, the network micro-segmentation system also includes an information subscription platform; the micro-segmentation management center module also includes a second interface; the micro-segmentation management center module connects to the information subscription platform through the second interface; when receiving a message subscription request for global network security information sent by the information subscription platform, the micro-segmentation management center module determines the target global network security information corresponding to the message subscription request; and sends the target global network security information to the information subscription platform through the second interface.

[0159] In this embodiment, the information subscription platform can be a third-party information subscription platform, and the second interface can be a northbound interface.

[0160] In this embodiment, the micro-segmentation management center module can connect to a third-party information subscription platform through its included northbound interface.

[0161] In this embodiment of the application, before subscribing to global network security information from the micro-segmentation management center through a third-party information subscription platform, the third-party information subscription platform first performs mutual authentication with the micro-segmentation management center and establishes a secure channel. After that, the third-party information subscription platform subscribes to the micro-segmentation-related global network security information from the micro-segmentation management center, such as network asset information and corresponding network asset topology information, abnormal traffic alarms, etc.

[0162] It should be noted that when subscribing to global cybersecurity information through a third-party information subscription platform, the content of the global cybersecurity information related to micro-segmentation and the method of obtaining the global cybersecurity information should be clearly defined. The method of obtaining the information can be active acquisition or push notification.

[0163] In this embodiment, when global network security information related to micro-segmentation is actively acquired, the third-party information subscription platform can periodically obtain the subscribed micro-segmentation-related information from the micro-segmentation management center module. Specifically, when the micro-segmentation management center module receives a message subscription request for global network security information from the third-party information subscription platform, it determines the target global network traffic security information corresponding to the message subscription request and sends the target global network traffic security information to the third-party information subscription platform through the northbound interface.

[0164] In this embodiment of the application, when the global network security information related to micro-segmentation is obtained by push, the micro-segmentation management center module only needs to periodically push the micro-segmentation-related information subscribed to by the third-party information subscription platform to the third-party information subscription platform.

[0165] It should be noted that when subscribing to micro-segmentation-related information from the micro-segmentation management center through a third-party information subscription platform, the system can connect to the capability development module included in the micro-segmentation management center module via the northbound interface.

[0166] Optionally, the micro-segmentation management center module selects one network asset from at least one network asset information as the network asset information to be spliced; wherein, the network asset information is information contained in the network traffic information; the first network asset contained in the network asset information to be spliced, and the second network asset contained in the remaining network asset information other than the network asset information to be spliced, are determined, and the connection relationship between the first network asset and the second network asset, and the number of connections between the first network asset and the second network asset are determined; based on the number of connections and the connection relationship, the remaining network asset information and the network asset information to be spliced ​​are spliced ​​to generate global network asset information; wherein, the remaining network asset information is other network asset information other than the network asset information to be spliced.

[0167] In this embodiment of the application, when summarizing and splicing at least one network asset information to form global network asset information, it may be possible to first select one network asset information to be spliced ​​from the at least one network asset information obtained, and determine the network assets contained in the network asset information to be spliced, as well as the network assets contained in the remaining network asset information other than the network asset information to be spliced.

[0168] It should be noted that the network asset information to be spliced ​​can be the one containing the most network assets, that is, the one with the most complex network asset topology. The more complex the network asset topology, the more network assets it contains.

[0169] In this embodiment of the application, when splicing the network asset information to be spliced ​​with the remaining network asset information, one can be selected from the remaining network asset information first, and then the connection relationship between the first network asset corresponding to the network asset information to be spliced ​​and the second network asset corresponding to the selected network asset information in the remaining network asset information can be determined. The two are then spliced ​​together, and so on, until all the remaining network asset information is spliced ​​together in sequence to obtain the global network asset information.

[0170] In this embodiment of the application, when splicing the network asset information to be spliced ​​with the remaining network asset information, the number of the second network assets corresponding to the remaining network asset information can be counted, and the splicing can be carried out in order of descending quantity and the connection relationship between the second network assets and the first network assets to obtain the global network asset information.

[0171] In this embodiment, the connection relationship between the first network asset and the second network asset can be obtained through their respective network asset topologies.

[0172] Specifically, based on the network topology of a certain province (such as province A, which may be the province with the most assets and the most complex network topology), the connections between province A and network elements in other provinces or other devices not managed by the micro-segmentation management module are identified. The number of network elements in other provinces that are in the same physical location as the VNF in province A (which can be determined by identification information) and have connections to the VNF in province A are counted and sorted.

[0173] First, for network elements in provinces with the same physical location as the VNF in that province and the most connections to network elements in that province (such as province B), the information of network elements in province B that are connected to province A is extracted from the network topology of province B and incorporated into the topology of province A. Then, for network elements in province B that are incorporated into the topology of province A, the topological relationships of these network elements are completed based on the network topology of province B. That is, with VMs connected to province A and province B, the remaining network elements in province B are then spliced ​​with VMs in province A.

[0174] For network elements in the province with the same physical location as the VNF in that province and the second largest number of network element connections in that province (such as province C), the information of network elements connected between province C and province A is extracted from the network topology of province C and incorporated into the topology of province A; then, for network elements in province C that are incorporated into the topology of province A, the topological relationships of these network elements are completed based on the network topology of province C.

[0175] By analogy, this allows us to build upon the network topology of a specific province, stitching together the network topologies of all micro-segmentation management modules to form a global network topology, i.e., global network asset information.

[0176] Optionally, after receiving updated network traffic information reported by network elements managed by the micro-segmentation management module, the micro-segmentation management module obtains updated network security information from the updated network traffic information and reports the updated network security information to the micro-segmentation management center module. The updated network security information includes at least one of the following: updated network asset information, updated security policy information, and updated security monitoring information. Based on the updated network security information, the micro-segmentation management center module determines the target network security information to be updated within the micro-segmentation management center module and updates the target network security information to achieve global network security information updates.

[0177] In this embodiment, if the network traffic information collected by the network element is updated, the micro-segmentation management module can obtain updated network security information from the updated network traffic information. The updated network security information includes updated network asset information, updated security policy information, and updated security monitoring information.

[0178] In this embodiment of the application, when the network asset information on one or more micro-segmentation management modules in at least one micro-segmentation management module is updated, the micro-segmentation management module and the micro-segmentation management center module should synchronize the network asset information.

[0179] In this embodiment, one or more micro-segmentation management modules proactively report updated network asset information to the micro-segmentation management center module in real time or periodically. The updated network asset information includes at least the updated asset name, associated VNF ID, VM ID, and connection relationships. Specifically, when a network element managed by a micro-segmentation management module collects updated network traffic information, the micro-segmentation management module obtains the updated network asset information from the updated network traffic information and reports the updated network asset information to the micro-segmentation management center module in real time or periodically.

[0180] In this embodiment, since the updated network asset information includes at least the updated asset name, associated VNF ID, VM ID, and connection relationship, the micro-segmentation management center module determines the target network asset information to be updated in the micro-segmentation management center module based on the updated network asset information; and updates the target network asset information, thereby updating the global network asset information.

[0181] In this embodiment, when the security policy information on one or more micro-segmentation management modules in at least one micro-segmentation management module is updated (for example, when a virtualized network element for a new service provided by a certain vendor is deployed in the resource pool, or when the micro-segmentation management module detects abnormal traffic and updates its corresponding security policy), the micro-segmentation management module and the micro-segmentation management center module should synchronize the update of the security policy information.

[0182] In this embodiment, one or more micro-segmentation management modules proactively report updated security policy information to the micro-segmentation management center module in real time or periodically. The updated security policy information includes at least the updated security policy, associated VNF ID, VM ID, and IP address. Specifically, when a network element managed by the micro-segmentation management module collects updated network traffic information, the micro-segmentation management module obtains the updated security policy information from the updated network traffic information and reports the updated security policy information to the micro-segmentation management center module in real time or periodically.

[0183] In this embodiment, since the updated security policy information includes at least the updated security policy, associated VNF ID, VM ID, IP address, etc., the micro-segmentation management center module determines the target security policy information to be updated in the micro-segmentation management center module based on the updated security policy information; and updates it, thereby updating the global security policy information.

[0184] In this embodiment of the application, when the security monitoring information on one or more micro-segmentation management modules in at least one micro-segmentation management module is updated, the micro-segmentation management module and the micro-segmentation management center module should synchronize the update of the security monitoring information.

[0185] In this embodiment, one or more micro-segmentation management modules proactively report updated security monitoring information to the micro-segmentation management center module in real time or periodically. The updated security monitoring information includes at least the updated alarms and alarm content, associated VNF IDs, VM IDs, etc. Specifically, when a network element managed by the micro-segmentation management module collects updated network traffic information, the micro-segmentation management module obtains the updated security monitoring information from the updated network traffic information, and reports the updated security monitoring information to the micro-segmentation management center module in real time or periodically.

[0186] In this embodiment, since the updated security monitoring information includes at least the updated alarms and alarm content, associated VNF IDs, VM IDs, etc., the micro-segmentation management center module can determine the target security monitoring information to be updated in the micro-segmentation management center module based on the updated security monitoring information; and update it, thereby updating the global security monitoring information.

[0187] Optionally, the micro-segmentation management center module sends a first request message to the micro-segmentation management module at preset intervals. The first request message is used to query updated network security information. Based on the first request message, the micro-segmentation management module queries the updated network security information and adds the queried updated network security information to a first response message, which is then sent to the micro-segmentation management center module. The micro-segmentation management center module determines the updated network security information from the first response message. Based on the updated network security information, it determines the target network security information to be updated in the micro-segmentation management center module and updates the target network security information to achieve the update of global network security information.

[0188] In this embodiment, when updating global network security information, the micro-segmentation management center module can periodically query the micro-segmentation management module for updated network security information, and then the micro-segmentation management module sends the updated network security information to the micro-segmentation management center module. The network security information includes network asset information, security policy information, security monitoring information, etc.

[0189] In this embodiment, the micro-segmentation management center module queries the micro-segmentation management module for updated network asset information at preset intervals, and the micro-segmentation management module sends the updated network asset information back to the micro-segmentation management center module. Specifically, the micro-segmentation management center module may send a request message to the micro-segmentation management module at preset intervals to query the updated network asset information. After receiving the request message, the micro-segmentation management module queries the updated network asset information from the network traffic information collected by the network elements, adds the queried network asset information to a response message, and sends the response message to the micro-segmentation management center module. Upon receiving the response message, the micro-segmentation management center module obtains the updated network asset information from the response message, determines the target network asset information to be updated based on the information contained in the network asset information, and updates the target network asset information, thereby achieving the update of the global network asset information.

[0190] It should be noted that the preset duration can be set according to specific needs, such as per second, per minute, or per hour. Specifically, it can be selected according to the actual situation, and no specific limitation is made in this application.

[0191] In this embodiment, the micro-segmentation management center module queries the micro-segmentation management module for updated security policy information at preset intervals, and the micro-segmentation management module sends the updated security policy information back to the micro-segmentation management center module. Specifically, the micro-segmentation management center module may send a request message to the micro-segmentation management module at preset intervals to query the updated security policy information. After receiving the request message, the micro-segmentation management module queries the updated security policy information from the network traffic information collected by the network elements, adds the queried security policy information to a response message, and sends the response message to the micro-segmentation management center module. Upon receiving the response message, the micro-segmentation management center module obtains the updated security policy information from the response message, determines the target security policy information to be updated based on the information contained in the security policy information, and updates the target security policy information, thereby updating the global security policy information.

[0192] In this embodiment, the micro-segmentation management center module queries the micro-segmentation management module for updated security monitoring information at preset intervals, and the micro-segmentation management module sends the updated security monitoring information back to the micro-segmentation management center module. Specifically, the micro-segmentation management center module may send a request message to the micro-segmentation management module at preset intervals to query updated security monitoring information. After receiving the request message, the micro-segmentation management module queries the updated security monitoring information from the network traffic information collected by the network elements, adds the queried security monitoring information to a response message, and sends the response message to the micro-segmentation management center module. Upon receiving the response message, the micro-segmentation management center module obtains the updated security monitoring information from the response message, determines the target security monitoring information to be updated based on the information contained in the security monitoring information, and updates the target security monitoring information, thereby achieving the update of global security monitoring information.

[0193] Optionally, updated security policy information is sent to the micro-segmentation management center module through an information subscription platform. The updated security policy information is used to update the security policy corresponding to the network element to be updated in the micro-segmentation management module. The security policy information is information contained in the network security information. The updated security policy information is sent to the micro-segmentation management module through the micro-segmentation management center module. The micro-segmentation management module determines the network element to be updated based on the network element identifier to be updated contained in the updated security policy information, and updates the security policy information of the network element to be updated with the updated security policy information.

[0194] In this embodiment, the micro-segmentation management center module can serve as an entry point for updating security policy information. For example, when maintenance personnel analyze a situation or security event from a third-party information subscription platform, such as a situational awareness platform or a security event management system, and determine that a certain VNF needs an updated security policy, the information subscription platform sends the updated security policy information for the network element to be updated in the micro-segmentation management module to the micro-segmentation management center module. The micro-segmentation management center module authenticates the situational awareness platform or security event management system, and upon successful authentication, initiates a security policy information update request to the micro-segmentation management module, sending the updated security policy information. The micro-segmentation management module authenticates and authorizes the micro-segmentation management center module to update the security policy. The updated security policy information sent by the micro-segmentation management center module includes the security policy, related VNF ID, VM ID, IP address, etc. Based on the network element identifier information or other information contained in the updated security policy information, the micro-segmentation management module determines the network element to be updated, distributes it to the corresponding VM, and updates the security policy information corresponding to the network element to be updated.

[0195] In this embodiment, after updating the security policy information, the micro-segmentation management module sends a security policy update response to the micro-segmentation management center module, and the micro-segmentation management center synchronously updates the local global security policy information based on the response message.

[0196] Optionally, the micro-segmentation management center module also includes a traffic visualization module; the traffic visualization module visualizes the global network security information in the micro-segmentation management center module.

[0197] In this embodiment, the micro-segmentation management center module can visualize global network security information through a traffic visualization module. Specifically, the traffic visualization module of the micro-segmentation management center module can obtain global network asset information and the corresponding network topology information from the network asset management module included in the micro-segmentation management center module, and display it, including connections between VNFs, VNF IDs, VMs contained in VNFs, VM IDs, the physical location of VMs, and connections between VMs.

[0198] In this embodiment, the traffic visualization module can obtain and display alarm information from the security monitoring module included in the micro-segmentation management center module, such as using different colors to display abnormal traffic between VMs. The traffic visualization module can also periodically request updates to network asset information from the network asset management module and update the currently displayed global network asset information and the corresponding network topology information. The network asset management module can also proactively report updates to network asset information to the traffic visualization module.

[0199] In this embodiment, the traffic visualization module can also periodically request updates to the security monitoring information from the security monitoring module and update the displayed information accordingly. The security monitoring module can also proactively report updates to the security monitoring information to the traffic visualization module.

[0200] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0201] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the related technology, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause an image display device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this disclosure.

[0202] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A network micro-segmentation system, comprising: The system comprises a micro-isolation management center module and at least one micro-isolation management module; the micro-isolation management center module comprises at least one first interface, and the micro-isolation management center module is connected with the at least one micro-isolation management module through the at least one first interface, wherein one first interface corresponds to one micro-isolation management module; The micro-isolation management module is configured to manage access traffic between network elements and obtain network security information from network traffic information collected from the network elements; wherein each micro-isolation management module manages different network elements; The micro-isolation management center module is configured to obtain at least one network security information from the at least one micro-isolation management module, and perform a splicing process on the at least one network security information to generate global network security information.

2. The system of claim 1, wherein, The system further comprises an information subscription platform; the micro-isolation management center module further comprises a second interface; and the micro-isolation management center module is connected with the information subscription platform through the second interface; The micro-isolation management center module is further configured to, when receiving a message subscription request for the global network security information sent by the information subscription platform, determine target global network security information corresponding to the message subscription request, and send the target global network security information to the information subscription platform through the second interface.

3. The system of claim 1, wherein The micro-isolation management center module is further configured to: select one network asset information from at least one network asset information as to-be-spliced network asset information; wherein the network asset information is information contained in the network traffic information; determine a first network asset contained in the to-be-spliced network asset information and a second network asset contained in remaining network asset information of the at least one network asset information except the to-be-spliced network asset information, and determine a connection relationship between the first network asset and the second network asset and a connection quantity between the first network asset and the second network asset; splice the remaining network asset information and the to-be-spliced network asset information based on the connection quantity and the connection relationship to generate global network asset information; wherein the remaining network asset information is other network asset information except the to-be-spliced network asset information.

4. The system of claim 1, wherein, The network security information comprises at least one of network asset information, security policy information, and security monitoring information.

5. The system of claim 1, wherein The micro-isolation management module is further configured to, after receiving updated network traffic information reported by a network element managed by the micro-isolation management module, obtain updated network security information from the updated network traffic information, and report the updated network security information to the micro-isolation management center module; wherein the updated network security information comprises at least one of updated network asset information, updated security policy information, and updated security monitoring information. The micro-isolation management center module is further configured to determine target network security information to be updated in the micro-isolation management center module based on the updated network security information, and update the target network security information to update the global network security information.

6. The system of claim 1, wherein, The micro-isolation management center module is further configured to send a first request message to the micro-isolation management module every preset time interval, the first request message being used to query updated network security information. The micro-isolation management module is further configured to query updated network security information based on the first request message, add the updated network security information to a first response message, and send the first response message to the micro-isolation management center module. The micro-isolation management center module is further configured to determine the updated network security information from the first response message, determine target network security information to be updated in the micro-isolation management center module based on the updated network security information, and update the target network security information to update the global network security information.

7. The system of claim 2, wherein, The information subscription platform is further configured to send updated security policy information to the micro-isolation management center module, the updated security policy information being used to update security policies of network elements to be updated in the micro-isolation management module, and the security policy information being included in the network security information. The micro-isolation management center module is further configured to send the updated security policy information to the micro-isolation management module. The micro-isolation management module is further configured to determine network elements to be updated based on network element identifiers included in the updated security policy information, and update security policy information of the network elements to be updated to the updated security policy information.

8. The system of claim 1, wherein, The micro-isolation management center module further comprises a traffic visualization module. The traffic visualization module is configured to visually display the global network security information in the micro-isolation management center module.

9. A network micro-segmentation method, characterized in that, The method is applied to a network micro-isolation system, and the network micro-isolation system comprises a micro-isolation management center module and at least one micro-isolation management module. The micro-isolation management center module comprises at least one first interface, and the micro-isolation management center module is connected with the at least one micro-isolation management module through the at least one first interface. One first interface corresponds to one micro-isolation management module. The method comprises the following steps: The micro-isolation management module is used to manage access traffic between network elements and obtain network security information from network traffic information collected from the network elements. Each micro-isolation management module manages different network elements. The micro-isolation management center module is used to obtain at least one network security information from the at least one micro-isolation management module, and perform splicing processing on the at least one network security information to generate global network security information.

10. A storage medium having stored thereon a computer program, characterized in that The computer program is executed by a processor to implement the method of claim 9.

Citation Information

Patent Citations

  • Safety protection system, method and equipment and storage medium

    CN109995794A

  • Network isolation method and device, electronic equipment and storage medium

    CN112003877A