Methods and apparatus for identifying security domains
By generating a routing path tree for the firewall and combining it with network boundary devices to automatically identify the security domains of the data center, the inefficiency and inaccuracy caused by manual reliance in existing technologies are solved, achieving efficient and accurate security domain identification and network security management.
Patent Information
- Application Number
- CN202311784097.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-22
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2043-12-22
AI Technical Summary
Existing security domain identification methods rely on manual operation, which is inefficient and inaccurate, and difficult to adapt to changes in data center network architecture.
By acquiring routing and configuration information from network boundary devices and firewalls in the data center, a routing path tree corresponding to the firewall is generated. Based on the routing path tree and network boundary devices, security domains are automatically identified. The identification method includes generating the security domain direction of the firewall and traversing each hop routing address to determine the security domain boundary.
It can efficiently and accurately identify the security domains of a data center without human intervention, improving identification efficiency and accuracy, adapting to changes in network architecture in a timely manner, and providing a foundation for network security incident analysis.
Smart Images

Figure CN118827109B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, specifically to a method and apparatus for identifying security domains. Background Technology
[0002] A data center is a globally collaborative network of specific devices used to transmit, accelerate, display, compute, and store data. A security zone is a group of networks within the same network system that share the same security protection requirements and access control policies. Within a data center, different security zones are typically defined based on the functional characteristics and security requirements of the services offered, and these zones are isolated from each other using firewalls. For ease of operation and management, it is necessary to identify the security zones within the data center.
[0003] Existing security domain identification methods mainly rely on manual methods: In existing network security management platforms or network monitoring platforms, the physical connection topology data of network devices in the data center is first determined based on the name of the network device, the region where the network device is located, and the business function. Then, network operation and maintenance personnel manually identify the security domain based on the physical connection topology data of the network device and the configuration of each firewall in the data center.
[0004] However, existing solutions are difficult to eliminate their reliance on network maintenance personnel, are inefficient, and have low accuracy in security domain identification. Summary of the Invention
[0005] This application provides a method and apparatus for identifying security domains, which solves the technical problems of existing solutions being difficult to eliminate reliance on network operation and maintenance personnel, having low efficiency, and having low accuracy in identifying security domains.
[0006] In a first aspect, embodiments of this application provide a method for identifying a security domain, comprising: acquiring network boundary devices of a data center; acquiring routing information and configuration information of a firewall; generating a routing path tree corresponding to the firewall based on the routing information and configuration information; and identifying a security domain of the data center based on the routing path tree and the network boundary devices; wherein a security domain is a group of networks in a data center that have the same security protection requirements and the same security access control policies, and the network boundary of the security domain is a firewall or a network boundary device.
[0007] In one embodiment, generating a routing path tree corresponding to the firewall based on routing information and configuration information includes: classifying the security domain directions of the firewall based on routing information and configuration information to determine all security domain directions of the firewall; the security domain directions include trusted zone directions, untrusted zone directions, and non-military zone directions; traversing the next-hop routing address in each security domain direction of the firewall to determine each hop routing address of the firewall in each security domain direction; and generating a routing path tree corresponding to the firewall based on each hop routing address of the firewall in each security domain direction.
[0008] In one embodiment, a data center includes multiple firewalls, including an inner firewall and an outer firewall. The inner firewall is the network boundary of the core domain of the data center, while the outer firewall is not the network boundary of the core domain. The core domain is a set of networks in the data center used to process core services. Based on the routing path tree and network boundary devices, the security domain of the data center is identified, including: determining the routing address of each hop of the inner firewall in the direction of the untrusted area based on the routing path tree corresponding to the inner firewall; the untrusted area direction includes the direction of the untrusted area and the direction of the non-military area; determining the routing address of each hop of the outer firewall in the direction of the untrusted area based on the routing path tree corresponding to the outer firewall; the untrusted area direction includes the direction of the trusted area and the direction of the non-military area; if all routing addresses of the inner firewall in the direction of the untrusted area and all routing addresses of the outer firewall in the direction of the untrusted area have the same routing address, and the same routing address is not a firewall interface routing address, then it is determined that a security domain exists between the inner firewall and the outer firewall.
[0009] In one embodiment, the data center includes a core domain, which is a set of networks in the data center used to process core services. Identifying the security domain of the data center based on the routing path tree and network boundary devices includes: determining the routing address of each hop of the firewall in the direction of the untrusted area based on the routing path tree corresponding to the firewall; the direction of the untrusted area includes the direction of the untrusted area and the direction of the non-military area; if the routing address of the firewall in each hop of the firewall in the direction of the untrusted area contains the routing address of the network boundary device, and there is no routing address of the firewall interface, then it is determined that there is a security domain between the network boundary device and the firewall.
[0010] In one embodiment, the data center includes a core domain, which is a set of networks in the data center used to process core services. Identifying the security domain of the data center based on the routing path tree and network boundary devices further includes: obtaining the routing address of the network boundary device of the data center; determining the routing address of each hop of the firewall in the direction of the untrusted area based on the routing path tree corresponding to the firewall; the direction of the untrusted area includes the direction of the untrusted area and the direction of the non-military area; if the routing address of the network boundary device is different from the routing address of each hop of the firewall in the direction of the untrusted area, then it is determined that there is a security domain between the network boundary device and the core domain.
[0011] In one embodiment, the firewall further includes an intra-regional firewall, which is a firewall located within a security domain between the inner firewall and the outer firewall. Identifying the security domain of the data center based on the routing path tree and network boundary devices includes: determining the routing address of each hop of the intra-regional firewall in each security domain direction based on the routing path tree corresponding to the intra-regional firewall; identifying the security domain and sub-security domain to which the intra-regional firewall belongs based on the routing address of each hop of the intra-regional firewall in each security domain direction; a sub-security domain is a group of networks within the security domain between the inner firewall and the outer firewall, and the network boundary of the sub-security domain is the intra-regional firewall.
[0012] In one embodiment, a data center includes a business system and multiple firewalls. The firewalls include an inner firewall, which serves as the network boundary of the core domain of the data center. The core domain is a set of networks within the data center used to process core business operations. Based on the routing path tree and network boundary devices, the security domain of the data center is identified, including: determining the routing address of each hop of the inner firewall in the direction of the untrusted area based on the routing path tree corresponding to the inner firewall; the untrusted area direction includes the direction of the untrusted area and the direction of the non-military area; if the interface routing address of the business system exists among all the routing addresses of the inner firewall in the direction of the untrusted area, then it is determined that a security domain exists between the inner firewall and the business system.
[0013] In one embodiment, a data center includes multiple firewalls, including an inner firewall, an outer firewall, and an intra-regional firewall. The inner firewall is the network boundary of the core domain of the data center, the outer firewall is not the network boundary of the core domain, and the intra-regional firewall is a firewall located in a security domain between the inner and outer firewalls. The core domain is a set of networks in the data center used to process core services. Before identifying the security domain of the data center based on the routing path tree and network boundary devices, the process includes: determining the type of each firewall based on the routing path tree corresponding to each firewall; determining the type of each firewall based on the routing path tree corresponding to each firewall includes: if, based on the routing path tree corresponding to the firewall, it is determined that the firewall does not exist in all routing addresses in the trusted zone direction... If the firewall interface routing address is used, the firewall is determined to be an inner firewall. If, based on the routing path tree corresponding to the firewall, the firewall interface routing address exists among all routing addresses in the trusted zone direction, and the firewall interface routing address is the routing address of another firewall in the trusted zone direction, then the firewall is determined to be an inner firewall. If, based on the routing path tree corresponding to the firewall, the firewall interface routing address does not exist among all routing addresses in the untrusted zone direction, and the routing address of a network boundary device exists among all routing addresses in the untrusted zone direction, then the firewall is determined to be an outer firewall. If, based on the routing path tree corresponding to the firewall, the firewall is determined to be neither an inner nor an outer firewall, then the firewall is determined to be an intra-area firewall.
[0014] In one embodiment, after identifying the security domains of the data center based on the routing path tree and network boundary devices, the method further includes: generating a security domain architecture diagram corresponding to the data center based on the routing path tree corresponding to each firewall, all network boundary devices, and all security domains.
[0015] Secondly, embodiments of this application provide a security domain identification device, comprising: a first acquisition module for acquiring network boundary devices of a data center; a second acquisition module for acquiring routing information and configuration information of a firewall; a generation module for generating a routing path tree corresponding to the firewall based on the routing information and configuration information; and an identification module for identifying a security domain of the data center based on the routing path tree and the network boundary devices; wherein a security domain is a group of networks in a data center with the same security protection requirements and the same security access control policies, and the network boundary of the security domain is a firewall or a network boundary device.
[0016] The security domain identification method and apparatus provided in this application embodiment acquire network boundary devices of a data center; acquire routing information and configuration information of a firewall; generate a routing path tree corresponding to the firewall based on the routing information and configuration information; and identify the security domain of the data center based on the routing path tree and the network boundary devices. A security domain is a group of networks in a data center with the same security protection requirements and the same security access control policies, and the network boundary of the security domain is a firewall or a network boundary device. Through this method, a routing path tree corresponding to the firewall is first generated based on the routing information and configuration information, and then the security domain of the data center is identified based on the routing path tree and the network boundary devices. This eliminates the need for network operation and maintenance personnel to manually identify security domains, reducing reliance on them and resulting in high efficiency and high accuracy in security domain identification. Attached Figure Description
[0017] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 This is a flowchart illustrating the security domain identification method provided in an embodiment of this application;
[0019] Figure 2 This is a schematic diagram of the routing path tree provided in an embodiment of this application;
[0020] Figure 3 This is a schematic diagram of the security domain between the inner firewall and the outer firewall provided in the embodiments of this application;
[0021] Figure 4 This is a schematic diagram of a network boundary with a network boundary device as the security domain, provided in an embodiment of this application.
[0022] Figure 5 This is a schematic diagram of the regional firewall and sub-security domains provided in the embodiments of this application;
[0023] Figure 6 This is a schematic diagram of the internal security domain provided in an embodiment of this application;
[0024] Figure 7 This is a schematic diagram of the security domain architecture provided in an embodiment of this application;
[0025] Figure 8 This is a schematic diagram of the security domain identification device provided in the embodiments of this application. Detailed Implementation
[0026] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0027] Please see Figure 1 , Figure 1 This is a flowchart illustrating the security domain identification method provided in this application embodiment. In this embodiment, the security domain identification method specifically includes steps S110 to S140, each step as follows:
[0028] S110: Obtain network boundary devices for the data center.
[0029] Network boundary devices refer to devices that serve as the network boundary of a data center, used to manage and control the input and output of data center network traffic.
[0030] In a data center, network boundary devices act as the boundary between the data center and the external network (such as the Internet). They provide secure access control policies, isolate the data center from the external network, and provide security protection for the data center. To ensure data security in the data center, devices in the data center typically cannot directly access the external network; instead, they access the external network through network boundary devices.
[0031] Specifically, based on the existing physical topology connection data of the data center, all network devices contained in the data center can be identified; after identifying all network devices contained in the data center, the next-hop routing address of each network device can be analyzed to identify all network boundary devices of the data center.
[0032] Specifically, after determining all network devices included in the data center, the next-hop routing address of each network device is obtained.
[0033] If the next-hop routing address of the network device is an unknown external routing address, that is, the next-hop routing address is not a routing address inside the data center, it indicates that the network device is the boundary between the data center and the external network, and the network device is identified as a network boundary device.
[0034] If the next-hop network device of this network device is not managed, that is, the next-hop network device is not a network device inside the data center, it means that the network device is the boundary between the data center and the external network, and the network device is identified as a network boundary device.
[0035] Furthermore, acquire all network boundary devices in the data center.
[0036] S120: Obtain the firewall's routing and configuration information.
[0037] A security domain is a group of networks within the same network system that have the same security protection requirements and the same security access control policies. In a data center, different security domains are typically divided based on the functional characteristics and security requirements of the services. These different security domains are isolated from each other through firewalls, which act as isolation nodes between the various security domains in the data center.
[0038] Specifically, the data center includes multiple firewalls, and for each firewall, its routing information and configuration information can be obtained.
[0039] Optionally, the configuration information includes security policy information and interface configuration information; the routing information includes routing table entry information.
[0040] Optionally, for each firewall, after obtaining its routing and configuration information, the routing table information of the firewall can be collected via the SNMP (Simple Network Management Protocol). The routing table information includes the firewall interface routing address (which can be an IP address), LLDP (Link Layer Discovery Protocol) table, ARP (Address Resolution Protocol) table, MAC (Medium Access Control) table, and routing table, etc.
[0041] Based on the routing and configuration information of each firewall, the information of each hop network device connected to that firewall in the data center can be determined, so as to generate the routing path tree corresponding to the firewall in the future.
[0042] S130: Generates the routing path tree corresponding to the firewall based on routing information and configuration information.
[0043] The data center includes multiple firewalls. For each firewall, a corresponding routing path tree can be generated based on its routing and configuration information.
[0044] The firewall's corresponding routing path tree contains all the firewall's routing paths in the data center; the routing path tree contains multiple nodes, each of which is a routing address.
[0045] S140: Identify security domains in a data center based on routing path trees and network boundary devices.
[0046] A security domain is a group of networks in a data center that have the same security protection requirements and the same security access control policies. The network boundary of a security domain is a firewall or network boundary device.
[0047] Since the network boundary of a security domain is a firewall or network boundary device, the network boundary of each security domain in the data center can be determined by analyzing the routing path tree and network boundary devices, thereby identifying each security domain in the data center.
[0048] The security domain identification method provided in this application involves: acquiring network boundary devices in a data center; acquiring routing and configuration information of firewalls; generating a routing path tree corresponding to the firewall based on the routing and configuration information; and identifying the security domain of the data center based on the routing path tree and the network boundary devices. A security domain is a group of networks in a data center with the same security protection requirements and the same security access control policies, and the network boundary of the security domain is a firewall or a network boundary device. This method first generates a routing path tree corresponding to the firewall based on the routing and configuration information, and then identifies the security domain of the data center based on the routing path tree and the network boundary devices. This eliminates the need for manual identification of security domains by network operations personnel, reducing reliance on them and resulting in high efficiency and accuracy in security domain identification.
[0049] In some embodiments, generating a routing path tree corresponding to the firewall based on routing information and configuration information includes: classifying the security domain directions of the firewall based on routing information and configuration information to determine all security domain directions of the firewall; the security domain directions include trusted area directions, untrusted area directions, and non-military area directions; traversing the next-hop routing address in each security domain direction of the firewall to determine each hop routing address of the firewall in each security domain direction; and generating a routing path tree corresponding to the firewall based on each hop routing address of the firewall in each security domain direction.
[0050] Specifically, the data center includes multiple firewalls. For each firewall, the security domain directions can be classified based on the firewall's routing and configuration information, thus determining all security domain directions for that firewall.
[0051] Among them, the security domain direction includes the Trust Zone direction, the Untrust Zone direction, and the Demilitarized Zone (DMZ) direction.
[0052] It's important to note that firewalls, acting as isolation nodes between different security domains within a data center, can effectively isolate these domains. Generally, network devices within the same security domain have similar security requirements and need to be configured with the same security access control policies. However, network devices in different security domains have different security requirements and access control policies, meaning the security levels of different security domains differ. As an isolation node, a firewall can also serve as a boundary between different security domains. Network devices in different security domains typically cannot directly access each other but must communicate through the firewall. In this case, the firewall acts as a data transmission and flow medium between different security domains. Data flows between different security domains through the firewall, and the firewall's security domain orientation can be categorized based on the direction of data flow.
[0053] Specifically, in the field of network security, if data flows from a low-security network to a high-security network through a firewall, it is considered that the data has flowed from an untrusted area to a trusted area through the firewall; if data flows from a high-security network to a low-security network through a firewall, it is considered that the data has flowed from a trusted area to an untrusted area through the firewall.
[0054] In this embodiment, the firewall acts as an isolation node, isolating networks with different security levels. Based on the direction of data flow, the firewall's security domain direction can be divided into three categories: Each firewall can contain multiple interfaces. If data can flow from a low-security network to a high-security network through a certain interface of the firewall, then the firewall's security domain direction includes the trusted zone direction, and the interface routing address can be used to identify the firewall's trusted zone direction; if data can flow from a high-security network to a low-security network through a certain interface of the firewall, then the firewall's security domain direction includes the untrusted zone direction, and the interface routing address can be used to identify the firewall's untrusted zone direction; if the firewall is set up in a security domain composed of other firewalls, and data can flow in part of the network within the security domain through a certain interface of the firewall, then the firewall's security domain direction includes the non-military zone direction, and the interface routing address can be used to identify the firewall's non-military zone direction.
[0055] For each firewall, the directions of all security domains of that firewall can be determined based on its routing and configuration information.
[0056] Furthermore, the next-hop routing address in each security domain direction of the firewall is traversed to determine the routing address of each hop of the firewall in each security domain direction; based on the routing address of each hop of the firewall in each security domain direction, the routing path tree corresponding to the firewall is generated.
[0057] Please see Figure 2 , Figure 2This is a schematic diagram of the routing path tree provided in the embodiments of this application.
[0058] Specifically, for each security domain direction of each firewall, the interface routing address that identifies the security domain direction of the firewall is analyzed, and the routing address prefix of the interface routing address is determined. Since each hop routing address in the same security domain direction has the same routing address prefix as the interface routing address, the routing address of each hop in the same security domain direction can be determined by querying based on the routing address prefix of the interface routing address.
[0059] like Figure 2 As shown, for each security domain direction of each firewall, after determining the routing address prefix that identifies the interface routing address of the firewall in that security domain direction, the next-hop routing address of the firewall in that security domain direction is first determined based on the routing address prefix of the interface routing address. The next-hop routing address is then used as the first-hop routing address, and the corresponding path tree node is generated.
[0060] Furthermore, based on the first-hop routing address, the network device corresponding to the first-hop routing address is determined; based on the network device corresponding to the first-hop routing address, the next-hop routing address is queried to obtain the second-hop routing address, and the corresponding path tree node is generated; the process of querying the next-hop routing address and generating the corresponding path tree node is continuously performed until the network device corresponding to a certain next-hop routing address is a directly connected route, or the next-next-hop address of the network device corresponding to a certain next-hop routing address is an unknown external routing address, then the query is stopped; by associating each queried routing address, that is, associating each path tree node, the corresponding routing path subtree of the firewall in the direction of the security domain can be generated.
[0061] Understandably, each network device can have multiple next-hop routing addresses.
[0062] For example, such as Figure 2 As shown, there are two second-hop routing addresses, denoted as "second-hop routing address 1" and "second-hop routing address 2"; the network device corresponding to "second-hop routing address 1" also has two next-hop routing addresses, denoted as "third-hop routing address 1" and "third-hop routing address 2"; the network device corresponding to "second-hop routing address 2" also has two next-hop routing addresses, denoted as "third-hop routing address 3" and "third-hop routing address 4".
[0063] Furthermore, for each firewall, after determining the corresponding routing path subtree in each security domain direction, all routing path subtrees are associated to generate the routing path tree corresponding to that firewall.
[0064] The security domain identification method provided in this application classifies the security domain directions of the firewall based on routing information and configuration information, determines all security domain directions of the firewall, traverses the next-hop routing address of each security domain direction of the firewall, determines the routing address of each hop of the firewall in each security domain direction, and generates a routing path tree corresponding to the firewall. This allows the security domain of the data center to be identified based on the routing path tree, eliminating the reliance on network operation and maintenance personnel and improving the efficiency of security domain identification.
[0065] In some embodiments, a data center includes multiple firewalls, including an inner firewall and an outer firewall. The inner firewall is the network boundary of the core domain of the data center, while the outer firewall is not the network boundary of the core domain of the data center. The core domain is a set of networks in the data center used to process core business.
[0066] A data center is a specific network of devices used to transmit, accelerate, display, compute, and store data information. The core domain is a set of networks in the data center used to process core business data and stores the core business data of the data center. It is the network with the highest security level in the data center.
[0067] For example, if a data center is used to process data from a shopping website, and the core business of the shopping website is order processing, then the network used to process order processing is the core domain of that data center.
[0068] Understandably, the core business processes handled by the core domain may differ across different data centers.
[0069] In a data center, if data can flow from other networks to the core domain through a certain interface of the firewall, then the firewall's security domain direction includes the trusted zone direction, and the interface routing address can be used to identify the firewall's trusted zone direction; if data can flow from the core domain to the core domain through a certain interface of the firewall, then the firewall's security domain direction includes the untrusted zone direction, and the interface routing address can be used to identify the firewall's untrusted zone direction.
[0070] The core domain stores the core business data of the data center. In order to ensure the data security of the core domain and prevent network devices within the core domain from communicating directly with other networks, a firewall needs to be set up. The firewall can serve as an isolation node between the core domain and other networks, playing an isolation role to protect the data security of the core domain. Therefore, the firewall can serve as the network boundary of the core domain.
[0071] Since a data center includes multiple firewalls, which can serve as network boundaries for both the core domain and the security domain, firewalls can be divided into inner firewalls and outer firewalls based on their network location within the data center for easier differentiation.
[0072] The inner firewall serves as the network boundary of the data center's core domain and communicates with the core domain. The outer firewall is not the network boundary of the data center's core domain and does not communicate directly with the core domain, but it can communicate directly with the external network or network boundary devices.
[0073] Based on the routing path tree and network boundary devices, identify the security domains of the data center, including: determining the routing address of each hop of the inner firewall in the direction of the untrusted area based on the routing path tree corresponding to the inner firewall; the direction of the untrusted area includes the direction of the untrusted area and the direction of the non-military area; determining the routing address of each hop of the outer firewall in the direction of the untrusted area based on the routing path tree corresponding to the outer firewall; the direction of the untrusted area includes the direction of the trusted area and the direction of the non-military area; if there is a common routing address among all routing addresses of the inner firewall in the direction of the untrusted area and all routing addresses of the outer firewall in the direction of the untrusted area, and the common routing address is not a firewall interface routing address, then it is determined that there is a security domain between the inner firewall and the outer firewall.
[0074] Please see Figure 3 , Figure 3 This is a schematic diagram of the security domain between the inner firewall and the outer firewall provided in the embodiments of this application.
[0075] Specifically, based on the routing path tree corresponding to each firewall, the type of each firewall in the data center is determined. The types of firewalls include inner firewalls and outer firewalls.
[0076] Furthermore, based on the routing path tree corresponding to the inner firewall, query the routing address of each hop of the inner firewall in the direction of the untrusted area. The direction of the untrusted area includes the direction of the untrusted area and the direction of the non-military area.
[0077] Furthermore, based on the routing path tree corresponding to the outer firewall, query the routing address of each hop of the outer firewall in the direction of the non-untrusted area; the direction of the non-untrusted area includes the direction of the trusted area and the direction of the non-military area.
[0078] Compare the hop addresses of each route in the untrusted zone direction of the inner firewall with those of each route in the non-untrusted zone direction of the outer firewall. Extract all routes with the same prefix as both the inner and outer firewalls in the untrusted zone direction, and denote this set L. i , where i represents different routing prefixes.
[0079] If all routing addresses of an inner firewall in the untrusted zone direction and all routing addresses of an outer firewall in the non-untrusted zone direction contain the same routing address, and the same routing address is not an interface routing address of the firewall, then the following condition is met: This determines that a security domain exists between the inner firewall and the outer firewall; where M is the set of all firewall interface routing addresses. It is an empty set.
[0080] like Figure 3 As shown, the inner firewall is the network boundary of the core domain of the data center and communicates with the core domain; the outer firewall is not the network boundary of the core domain of the data center and does not communicate directly with the core domain. The security domain between the inner firewall and the outer firewall is denoted as security domain A.
[0081] Generally, a data center consists of multiple security domains, and the security level of a security domain is higher the closer it is to the core domain.
[0082] Optionally, if an interface of a firewall can be used to transmit data to multiple security domains, then these security domains are aggregated into one security domain.
[0083] In some embodiments, the data center includes a core domain, which is a set of networks within the data center used to process core business operations.
[0084] Based on the routing path tree and network boundary devices, identify the security domain of the data center, including: determining the routing address of each hop of the firewall in the direction of the untrusted area based on the routing path tree corresponding to the firewall; the direction of the untrusted area includes the direction of the untrusted area and the direction of the non-military area; if the routing address of the network boundary device exists in the routing address of each hop of the firewall in the direction of the untrusted area, and there is no routing address of the firewall interface, then it is determined that there is a security domain between the network boundary device and the firewall.
[0085] Please see Figure 4 , Figure 4 This is a schematic diagram of a network boundary with a network boundary device as the security domain, provided in an embodiment of this application.
[0086] Specifically, for each firewall, based on the routing path tree corresponding to the firewall, the routing address of each hop of the firewall in the direction of the untrusted zone is queried, and the set of all routing addresses of the firewall in the direction of the untrusted zone is denoted as R. i , i represents different routing prefixes; the non-trusted area direction includes the untrusted area direction and the non-military area direction.
[0087] If the set R of all route addresses of a firewall in the direction of the untrusted zone is... iThe network contains routing addresses for network boundary devices, but does not contain routing addresses for firewall interfaces, i.e., it meets the following conditions:
[0088]
[0089]
[0090] This determines that a security domain exists between the network boundary device and the firewall; where M is the set of routing addresses for all firewall interfaces, and O is the set of routing addresses for all network boundary devices. It is an empty set.
[0091] like Figure 4 As shown, the inner firewall is the network boundary of the core domain of the data center and communicates with the core domain; the outer firewall is not the network boundary of the core domain of the data center and does not communicate directly with the core domain. The security domain between the inner firewall and the outer firewall is denoted as security domain A.
[0092] Understandably, firewalls can be categorized into inner firewalls and outer firewalls, and security domains can exist between network boundary devices and either inner or outer firewalls.
[0093] like Figure 4 As shown, the security domain between the boundary device (i.e., the network boundary device) and the inner firewall is denoted as security domain B, and the security domain between the boundary device (i.e., the network boundary device) and the outer firewall is denoted as security domain D.
[0094] In some embodiments, the data center includes a core domain, which is a set of networks within the data center used to process core business operations.
[0095] Identifying security domains in a data center based on routing path trees and network boundary devices also includes: obtaining the routing addresses of the network boundary devices in the data center; determining the routing address of each hop of the firewall in the direction of the untrusted zone based on the routing path tree corresponding to the firewall; the direction of the untrusted zone includes the direction of the untrusted zone and the direction of the non-military zone; if the routing address of the network boundary device is different from the routing address of each hop of the firewall in the direction of the untrusted zone, then it is determined that there is a security domain between the network boundary device and the core domain.
[0096] Generally, to ensure data security in the core domain and prevent network devices within the core domain from directly communicating with other networks, a firewall needs to be configured. The firewall serves as an isolation node between the core domain and other networks. However, in some cases, some network devices within the core domain still need to directly interconnect with the external network through network boundary devices. Therefore, a security domain may exist between the network boundary devices and the core domain, which needs to be identified.
[0097] Specifically, for each network boundary device in the data center, obtain the routing address of that network boundary device.
[0098] Furthermore, for each firewall, based on the routing path tree corresponding to that firewall, the routing address of each hop of that firewall in the direction of the untrusted area is queried; the direction of the untrusted area includes the direction of the untrusted area and the direction of the non-military area.
[0099] If the routing address of a network boundary device is different from the routing address of the firewall at every hop in the direction of the untrusted zone, then the following conditions are met: This confirms that a security domain exists between the network boundary device and the core domain.
[0100] like Figure 4 As shown, the security domain between the boundary device (i.e., the network boundary device) and the core domain is denoted as security domain C.
[0101] It should be noted that when the core domain and network boundary device are isolated through a firewall, the core domain is protected by the firewall and cannot directly interconnect with the network boundary device. Therefore, core domain data is not easily leaked through the network boundary device, and in this case, the network boundary device can be considered the "security boundary" of the data center. Conversely, when the core domain and network boundary device are directly interconnected, meaning a security boundary exists between them, the core domain is not protected by a firewall, and its data is easily leaked through the network boundary device. In this case, the network boundary device can be considered an "illegal security boundary" of the data center.
[0102] Existing methods for manually identifying security domains rely too heavily on network operators' familiarity with the data center network architecture, resulting in low efficiency and a high risk of errors. When the data center network architecture is adjusted, it is difficult to synchronize manual data in a timely manner, making it impossible to intuitively identify illegal security boundaries in the current data center, which is detrimental to the network security management of the data center.
[0103] The security domain identification method provided in this application embodiment, based on routing path trees and network boundary devices, can identify security domains, security boundaries, and illegal security boundaries in data centers, providing an important data foundation for the analysis of network security incidents and facilitating network security management and control in data centers.
[0104] In some embodiments, the firewall further includes an intra-area firewall, which is a firewall located in a security domain between the inner firewall and the outer firewall.
[0105] Specifically, if a firewall is set up in a security zone between an inner firewall and an outer firewall, then the firewall is a zone firewall, and data can flow through a portion of the network within a certain security zone through the interface of the zone firewall.
[0106] Based on the routing path tree and network boundary devices, identify the security domains of the data center, including: determining the routing address of each hop of the firewall in each security domain direction based on the routing path tree corresponding to the firewall in the area; identifying the security domain and sub-security domains to which the firewall in the area belongs based on the routing address of each hop of the firewall in each security domain direction; a sub-security domain is a group of networks within the security domain between the inner firewall and the outer firewall, and the network boundary of the sub-security domain is the firewall in the area.
[0107] Please see Figure 5 , Figure 5 This is a schematic diagram of the regional firewall and sub-security domains provided in the embodiments of this application.
[0108] Specifically, for each firewall within a data center, the routing address of each firewall in each security domain direction is determined based on the routing path tree corresponding to the firewall within that region.
[0109] Furthermore, for each firewall within a region, if there are other firewall interface routing addresses among all routing addresses of the firewall in each security domain direction, it indicates that the firewall in that region is set up in a security domain composed of other firewalls. The security domain to which the firewall in that region belongs can be determined based on the routing addresses of other firewall interfaces.
[0110] like Figure 5 As shown, there are two security domains between the inner firewall and the outer firewall, denoted as security domain A and security domain A1 respectively; the security domain between the boundary device (i.e., network boundary device) and the inner firewall is denoted as security domain B; there are two security domains between the boundary device (i.e., network boundary device) and the outer firewall, denoted as security domain D and security domain F respectively; the security domain between the boundary device (i.e., network boundary device) and the core domain is denoted as security domain C, and this network boundary device is the "illegal security boundary" of the data center.
[0111] Security domain A1 contains an intra-regional firewall, and the intra-regional firewall belongs to security domain A1.
[0112] Furthermore, after determining the security domain to which the firewalls within the region belong, for each security domain direction of the firewalls within the region, all network devices in that security domain direction are determined based on all routing addresses in that security domain direction. Since a sub-security domain is a group of networks within the security domain between the inner and outer firewalls, and this group of networks consists of multiple network devices, a group of networks, namely the sub-security domain, can be determined based on all network devices in that security domain direction. The network boundary of this sub-security domain is the firewall within the region.
[0113] like Figure 5 As shown, a regional firewall is set up within security domain A1, and the regional firewall serves as the network boundary for sub-security domains a and b.
[0114] In some embodiments, a data center includes a business system and multiple firewalls. The firewalls include an inner firewall, which serves as the network boundary of the core domain of the data center. The core domain is a set of networks within the data center used to process core business operations.
[0115] The data center also includes internal business systems that are securely isolated from the core domain. These business systems can provide some business data to the core domain. To ensure the security of both business system data and core domain data, a firewall needs to be set up between the business systems and the core domain.
[0116] Based on the routing path tree and network boundary devices, identify the security domain of the data center, including: determining the routing address of each hop of the inner firewall in the direction of the untrusted area based on the routing path tree corresponding to the inner firewall; the direction of the untrusted area includes the direction of the untrusted area and the direction of the non-military area; if the interface routing address of the business system exists among all the routing addresses of the inner firewall in the direction of the untrusted area, then it is determined that there is a security domain between the inner firewall and the business system.
[0117] Please see Figure 6 , Figure 6 This is a schematic diagram of the internal security domain provided in the embodiments of this application.
[0118] Specifically, based on the routing path tree corresponding to the inner firewall, the routing address of each hop of the inner firewall in the direction of the untrusted area is determined; the direction of the untrusted area includes the direction of the untrusted area and the direction of the non-military area.
[0119] Generally, in a data center, since business systems need to provide some business data to the core domain, if a firewall is set up between the business system and the core domain, some interfaces of the firewall need to be interconnected with some business interfaces in the business system. The routing addresses of some interfaces of the firewall and the routing addresses of some business interfaces in the business system have the same network segment characteristics, that is, they have the same routing address prefix. Routing address retrieval and matching can be performed based on the same routing address prefix.
[0120] Furthermore, if the inner firewall contains the interface routing address of the business system among all routing addresses in the direction of the non-trusted zone, then it is determined that a security domain exists between the inner firewall and the business system.
[0121] like Figure 6As shown, there are two security domains between the inner and outer firewalls, denoted as security domain A and security domain A1 respectively; the security domain between the boundary device (i.e., network boundary device) and the inner firewall is denoted as security domain B; there are two security domains between the boundary device (i.e., network boundary device) and the outer firewall, denoted as security domain D and security domain F respectively; the security domain between the boundary device (i.e., network boundary device) and the core domain is denoted as security domain C, and this network boundary device is the "illegal security boundary" of the data center; a regional firewall is set up within security domain A1, and the regional firewall is the network boundary of sub-security domain a and sub-security domain b.
[0122] Security isolation between the core domain and internal business systems is achieved through an inner firewall, and an internal security domain G exists between the core domain and internal business systems.
[0123] The security domain identification method provided in this application first generates a routing path tree corresponding to the firewall based on routing information and configuration information. Then, based on the routing path tree and network boundary devices, it automatically identifies and generates each security domain, security boundary, and illegal security boundary in the data center. This eliminates the need for network operation and maintenance personnel to manually identify security domains, thus reducing reliance on them. It is highly efficient and accurate in identifying security domains. When the data center network architecture is adjusted, data synchronization can be performed automatically without manual intervention. This provides an important data foundation for the analysis of network security incidents and facilitates network security management and control in the data center.
[0124] In some embodiments, a data center includes multiple firewalls, including an inner firewall, an outer firewall, and a regional firewall. The inner firewall is the network boundary of the core domain of the data center, while the outer firewall is not the network boundary of the core domain of the data center. The regional firewall is a firewall located in a security domain between the inner firewall and the outer firewall. The core domain is a set of networks in the data center used to process core services.
[0125] Before identifying the security domain of a data center based on the routing path tree and network boundary devices, the process includes: determining the type of each firewall based on the routing path tree corresponding to each firewall.
[0126] Firewalls can be categorized into inner firewalls, outer firewalls, and intra-area firewalls.
[0127] Based on the routing path tree corresponding to each firewall, the type of each firewall is determined, including: if, based on the routing path tree corresponding to the firewall, it is determined that there is no firewall interface routing address among all routing addresses in the trusted zone direction, then the firewall is determined to be an inner firewall; if, based on the routing path tree corresponding to the firewall, it is determined that there is a firewall interface routing address among all routing addresses in the trusted zone direction, and the firewall interface routing address is the routing address of another firewall in the trusted zone direction, then the firewall is determined to be an inner firewall.
[0128] Generally, a data center includes multiple security domains. The closer a security domain is to the core domain, the higher its security level, with the security domain closest to the core domain having the highest security level.
[0129] If, based on the routing path tree corresponding to the firewall, it is determined that there is no firewall interface routing address among all routing addresses in the trusted zone direction, then it means that the firewall does not interconnect with other firewalls in the trusted zone direction, but directly interconnects with network devices in the core domain. Therefore, this firewall is an inner firewall.
[0130] If, based on the routing path tree corresponding to the firewall, it is determined that among all the routing addresses of the firewall in the trusted zone direction, there exists a firewall interface routing address, and the firewall interface routing address is the routing address of another firewall in the trusted zone direction, then it means that the firewall is interconnected with other firewalls through a network device in the trusted zone direction, and that network device is also a network device in the trusted zone direction of other firewalls. When a network device is a network device in the trusted zone direction of different firewalls, it means that the network device is a network device in the core domain. Therefore, the connection between this firewall and other firewalls is the core domain, and this firewall is an inner firewall.
[0131] Specifically, let J be the set of all routed addresses of a firewall in the trusted zone direction. i , i represents different routing prefixes; M is the set of all firewall interface routing addresses; N is the set of all firewall interface routing addresses in the trusted zone direction; the set {x,y,z…} represents the firewall interface routing addresses that a firewall passes through in the trusted zone direction in sequence. If the set is empty, then the firewall satisfies the following condition:
[0132]
[0133] Or, if the following conditions are met:
[0134] J i ∩M={x,y,z…};
[0135] x∈N;
[0136] This determines that the firewall is an inner firewall.
[0137] If, based on the routing path tree corresponding to the firewall, it is determined that there are no firewall interface routing addresses of other firewalls among all routing addresses in the direction of the untrusted zone, and there are routing addresses of network boundary devices among all routing addresses in the direction of the untrusted zone, then the firewall is determined to be an outer firewall.
[0138] Specifically, the set of all route addresses of the firewall in the direction of the untrusted zone is denoted as K. i , i represents different routing prefixes; M is the set of routing addresses for all firewall interfaces; O is the set of routing addresses for all network border devices; If the set is empty, then the firewall satisfies the following condition:
[0139]
[0140]
[0141] This determines that the firewall is an inner firewall.
[0142] If, based on the routing path tree corresponding to the firewall, it is determined that the firewall is neither an inner nor an outer firewall, then the firewall is determined to be a firewall within the region.
[0143] The security domain identification method provided in this application determines the type of each firewall based on the routing path tree corresponding to each firewall, which can realize the automatic classification of firewalls and facilitate the subsequent division and identification of security domains according to the type of firewall.
[0144] In some embodiments, after identifying the security domains of the data center based on the routing path tree and network boundary devices, the method further includes: generating a security domain architecture diagram corresponding to the data center based on the routing path tree corresponding to each firewall, all network boundary devices, and all security domains.
[0145] Please see Figure 7 , Figure 7 This is a schematic diagram of the security domain architecture provided in the embodiments of this application.
[0146] Specifically, after obtaining the identification results of each security domain, for each security domain, the firewall interface routing address information on the routing path tree, the device name keyword characteristics of all network boundary devices, network segment characteristics, etc., the security domain is classified and named, and then a visual security domain architecture diagram is generated for network operation and maintenance personnel to refer to.
[0147] like Figure 7 As shown, there are two security domains between the inner and outer firewalls, denoted as Security Domain A and Security Domain A1; the security domain between the boundary device (i.e., network boundary device) and the inner firewall is denoted as Security Domain B; there are two security domains between the boundary device (i.e., network boundary device) and the outer firewall, denoted as Security Domain D and Security Domain F; the security domain between the boundary device (i.e., network boundary device) and the core domain is denoted as Security Domain C, and this network boundary device is the "illegal security boundary" of the data center; a regional firewall is set up within Security Domain A1, and the regional firewall is the network boundary of sub-security domains a and b; the core domain and the two internal business systems are respectively securely isolated through the inner firewall, and there are internal security domains G and H between the core domain and the two internal business systems.
[0148] The security domain identification method provided in this application embodiment provides reference data to network operation and maintenance personnel based on a visualized security domain architecture diagram. This enables network operation and maintenance personnel to intuitively and quickly discover illegal security boundaries in the data center, providing an important data foundation for network security incident analysis and facilitating network security management and control of the data center.
[0149] This application also provides a security domain identification device; please refer to [link to relevant documentation]. Figure 8 , Figure 8 This is a schematic diagram of the structure of the security domain identification device provided in this application embodiment. In this embodiment, the garbage throwing behavior detection device includes a first acquisition module 810, a second acquisition module 820, a generation module 830, and an identification module 840.
[0150] The first acquisition module 810 is used to acquire network boundary devices of the data center.
[0151] The second acquisition module 820 is used to acquire the firewall's routing information and configuration information.
[0152] The generation module 830 is used to generate the routing path tree corresponding to the firewall based on routing information and configuration information.
[0153] The identification module 840 is used to identify the security domain of the data center based on the routing path tree and network boundary devices.
[0154] A security domain is a group of networks in a data center that have the same security protection requirements and the same security access control policies. The network boundary of a security domain is a firewall or network boundary device.
[0155] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0156] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A method for identifying security domains, characterized in that, include: Acquire network boundary devices in the data center; Obtain the firewall's routing and configuration information; Based on the routing information and the configuration information, a routing path tree corresponding to the firewall is generated; Based on the routing path tree and the network boundary device, the security domain of the data center is identified; the security domain is a group of networks in the data center with the same security protection requirements and the same security access control policy, and the network boundary of the security domain is a firewall or a network boundary device.
2. The method for identifying security domains according to claim 1, characterized in that, The step of generating the routing path tree corresponding to the firewall based on the routing information and the configuration information includes: Based on the routing information and the configuration information, the security domain directions of the firewall are classified to determine all security domain directions of the firewall; the security domain directions include trusted zone directions, untrusted zone directions, and non-military zone directions; The next-hop routing address of the firewall in each security domain direction is traversed to determine the routing address of the firewall in each security domain direction. Based on the routing address of each hop of the firewall in each security domain direction, a routing path tree corresponding to the firewall is generated.
3. The method for identifying security domains according to claim 2, characterized in that, The data center includes multiple firewalls, including an inner firewall and an outer firewall. The inner firewall is the network boundary of the core domain of the data center, while the outer firewall is not the network boundary of the core domain of the data center. The core domain is a set of networks in the data center used to process core services. The step of identifying the security domain of the data center based on the routing path tree and the network boundary device includes: Based on the routing path tree corresponding to the inner firewall, determine the routing address of each hop of the inner firewall in the direction of the untrusted area; the direction of the untrusted area includes the direction of the untrusted area and the direction of the non-military area. Based on the routing path tree corresponding to the outer firewall, determine the routing address of each hop of the outer firewall in the non-untrusted area direction; the non-untrusted area direction includes the trusted area direction and the non-military area direction. If the inner firewall and the outer firewall share the same routing address in the direction of the non-trusted zone, and the same routing address is not a firewall interface routing address, then it is determined that a security domain exists between the inner firewall and the outer firewall.
4. The method for identifying security domains according to claim 2, characterized in that, The data center includes a core domain, which is a set of networks in the data center used to process core services. The step of identifying the security domain of the data center based on the routing path tree and the network boundary device includes: Based on the routing path tree corresponding to the firewall, determine the routing address of each hop of the firewall in the direction of the untrusted area; the direction of the untrusted area includes the direction of the untrusted area and the direction of the non-military area. If the firewall contains a routing address of a network boundary device in each hop of its routing address in the direction of the non-trusted zone, but does not contain a routing address of the firewall interface, then it is determined that a security domain exists between the network boundary device and the firewall.
5. The method for identifying security domains according to claim 2, characterized in that, The data center includes a core domain, which is a set of networks in the data center used to process core services. The step of identifying the security domain of the data center based on the routing path tree and the network boundary device further includes: Obtain the routing address of the network boundary device in the data center; Based on the routing path tree corresponding to the firewall, determine the routing address of each hop of the firewall in the direction of the untrusted area; the direction of the untrusted area includes the direction of the untrusted area and the direction of the non-military area. If the routing address of the network boundary device is different from the routing address of the firewall in each hop in the direction of the untrusted zone, then it is determined that a security domain exists between the network boundary device and the core domain.
6. The method for identifying security domains according to claim 3, characterized in that, The firewall also includes an intra-regional firewall, which is a firewall located in a security domain between the inner firewall and the outer firewall; The step of identifying the security domain of the data center based on the routing path tree and the network boundary device includes: Based on the routing path tree corresponding to the firewalls within the region, determine the routing address of each hop of the firewalls in each security domain direction within the region. Based on the routing address of each hop of the firewall in each security domain direction within the region, the security domain and sub-security domain to which the firewall in the region belongs are identified; the sub-security domain is a group of networks within the security domain between the inner firewall and the outer firewall, and the network boundary of the sub-security domain is the firewall within the region.
7. The method for identifying security domains according to claim 2, characterized in that, The data center includes business systems and multiple firewalls. The firewalls include an inner firewall, which serves as the network boundary of the core domain of the data center. The core domain is a set of networks in the data center used to process core business. The step of identifying the security domain of the data center based on the routing path tree and the network boundary device includes: Based on the routing path tree corresponding to the inner firewall, determine the routing address of each hop of the inner firewall in the direction of the untrusted area; the direction of the untrusted area includes the direction of the untrusted area and the direction of the non-military area. If the interface routing address of the business system exists among all routing addresses of the inner firewall in the direction of the non-trusted zone, then it is determined that a security domain exists between the inner firewall and the business system.
8. The method for identifying security domains according to claim 2, characterized in that, The data center includes multiple firewalls, including an inner firewall, an outer firewall, and a regional firewall. The inner firewall is the network boundary of the core domain of the data center, while the outer firewall is not the network boundary of the core domain of the data center. The regional firewall is a firewall located in a security domain between the inner firewall and the outer firewall. The core domain is a set of networks in the data center used to process core services. Before identifying the security domain of the data center based on the routing path tree and the network boundary device, the process includes: The type of each firewall is determined based on the routing path tree corresponding to each firewall. The process of determining the type of each firewall based on the routing path tree corresponding to each firewall includes: If, based on the routing path tree corresponding to the firewall, it is determined that there is no firewall interface routing address among all routing addresses in the trusted zone direction, then the firewall is determined to be an inner firewall. If, based on the routing path tree corresponding to the firewall, it is determined that there is a firewall interface routing address among all routing addresses of the firewall in the trusted zone direction, and the firewall interface routing address is the routing address of another firewall in the trusted zone direction, then the firewall is determined to be an inner firewall. If, based on the routing path tree corresponding to the firewall, it is determined that there are no firewall interface routing addresses of other firewalls among all routing addresses in the direction of the untrusted area, and there are routing addresses of network boundary devices among all routing addresses in the direction of the untrusted area, then the firewall is determined to be an outer firewall. If, based on the routing path tree corresponding to the firewall, it is determined that the firewall is neither an inner nor an outer firewall, then the firewall is determined to be a firewall within the region.
9. The method for identifying security domains according to claim 2, characterized in that, After identifying the security domain of the data center based on the routing path tree and the network boundary device, the process further includes: Based on the routing path tree corresponding to each firewall, all network boundary devices, and all security domains, a security domain architecture diagram corresponding to the data center is generated.
10. A security domain identification device, characterized in that, include: The first acquisition module is used to acquire network boundary devices of the data center; The second acquisition module is used to acquire the firewall's routing information and configuration information; The generation module is used to generate a routing path tree corresponding to the firewall based on the routing information and the configuration information; The identification module is used to identify the security domain of the data center based on the routing path tree and the network boundary device; the security domain is a group of networks in the data center with the same security protection requirements and the same security access control policy, and the network boundary of the security domain is a firewall or a network boundary device.
Citation Information
Patent Citations
Distributed security domain logic boundary protection method
CN101951384A
Firewall policy processing method and device
CN108092979A