Traffic information acquisition methods, devices, electronic equipment, virtual machines and storage media
By utilizing eBPF technology in a micro-segmentation system to obtain abnormal traffic event notifications from virtual machines and dynamically updating the traffic acquisition cycle strategy, the problem of balancing the traffic information acquisition cycle and anomaly identification efficiency in existing technologies is solved, achieving efficient traffic monitoring and anomaly detection.
Patent Information
- Application Number
- CN202310551737.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-16
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2043-05-16
AI Technical Summary
Existing micro-segmentation systems cannot achieve a balance between setting the traffic information acquisition cycle and the efficiency of abnormal traffic identification, resulting in poor compatibility and difficulty in problem localization.
By acquiring abnormal traffic event notifications from the target virtual machine, target traffic acquisition cycle update information is generated and sent to the second device to adjust the target virtual machine's traffic acquisition cycle strategy. eBPF technology is used to collect and monitor traffic information in real time and dynamically update the acquisition cycle.
It enables dynamic setting and updating of traffic acquisition cycles, improves the efficiency of traffic monitoring and the ability to identify abnormal traffic, and solves the problems of compatibility and difficulty in locating traffic.
Smart Images

Figure CN119011157B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a method, apparatus, electronic device, virtual machine, and storage medium for acquiring traffic information. Background Technology
[0002] Micro-segmentation, a typical technology for fine-grained control of east-west traffic, was first proposed by Gartner in its Software Defined Data Center (SDDC) technology framework. It provides secure access control between hosts (virtual machines, containers) (distinct from past security domain-to-security access control) and enables visualized management of east-west traffic. Currently, micro-segmentation, along with Software Defined Perimeter (SDP) and Identity and Access Management (IAM), is considered one of the three key technologies for zero-trust solutions. Among the micro-segmentation solutions proposed in the industry, the most common deployment is based on host agents, where agents collect traffic information and periodically report it to the micro-segmentation management module for analysis. Because the guest OS of network elements in the telecom cloud has a certain degree of privacy, installing third-party agents has problems such as poor compatibility and difficulty in locating problems. Therefore, the industry has proposed a micro-segmentation solution with built-in agents in network elements. However, the existing methods for obtaining traffic information in micro-segmentation systems cannot achieve the setting of traffic information acquisition cycle, nor can they achieve a balance between network element performance and abnormal traffic identification efficiency. Summary of the Invention
[0003] The purpose of this invention is to provide a method, apparatus, virtual machine, electronic device and storage medium for acquiring traffic information, in order to solve the problem that existing methods for acquiring traffic information in micro-segmentation systems cannot set the traffic information acquisition period.
[0004] In a first aspect, the present invention provides a method for acquiring traffic information, applied to a first device, the method comprising:
[0005] Obtain abnormal traffic event notifications for the target virtual machine; generate target traffic acquisition periodic update information based on the abnormal traffic event notifications;
[0006] The target traffic acquisition cycle update information is sent to the second device, so that the second device sends the target traffic acquisition cycle update information to the target virtual machine, and the target virtual machine adjusts the current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy, and the target virtual machine performs traffic monitoring according to the adjusted traffic acquisition cycle strategy.
[0007] Optionally, before obtaining the abnormal traffic event notification of the target virtual machine, the method further includes:
[0008] Configure the initial traffic acquisition cycle strategy for the virtual machine;
[0009] Send the initial traffic acquisition cycle policy corresponding to the virtual machine to the second device, so that the second device sends the corresponding initial traffic acquisition cycle policy to the virtual machine, and the virtual machine performs traffic monitoring according to the initial traffic acquisition cycle policy;
[0010] The target virtual machine is one of the virtual machines;
[0011] The initial traffic acquisition cycle strategy includes at least one of the following:
[0012] The virtual machine's agent module obtains traffic information from the storage and data retrieval module at an initial interval;
[0013] The initial period during which the agent module of the virtual machine sends traffic information to the second device;
[0014] The initial period for the first device to obtain traffic information from the second device.
[0015] Optionally, obtaining abnormal traffic event notifications for the target virtual machine includes:
[0016] Based on the traffic information of the virtual machine sent by the second device, network topology information and the security policy corresponding to the virtual machine are generated;
[0017] Based on the target information and the initial traffic acquisition cycle strategy corresponding to the virtual machine, a first traffic acquisition cycle strategy corresponding to the virtual machine is obtained; the target information includes at least one of the following: the network topology information; the traffic processing volume information of the virtual machine; and the workload information of the second device;
[0018] Send the security policy and the corresponding first traffic acquisition cycle policy of the virtual machine to the second device, so that the second device sends the corresponding security policy and the corresponding first traffic acquisition cycle policy to the virtual machine, and so that the virtual machine performs traffic monitoring according to the corresponding security policy and the corresponding first traffic acquisition cycle policy;
[0019] Obtain abnormal traffic information of the target virtual machine sent by the second device. The abnormal traffic information is obtained by the target virtual machine through traffic monitoring according to the security policy corresponding to the target virtual machine sent by the second device, and then sent to the second device.
[0020] An abnormal traffic event notification for the target virtual machine is generated based on the abnormal traffic information;
[0021] Wherein, the target virtual machine is one of the virtual machines, and the target traffic acquisition period strategy is a traffic acquisition period strategy in the first traffic acquisition period strategy;
[0022] The first traffic acquisition cycle strategy includes at least one of the following:
[0023] The identity identifier of the virtual machine;
[0024] The period during which the proxy module in the virtual machine obtains traffic information from the storage and data retrieval module;
[0025] The period during which the proxy module in the virtual machine sends traffic information to the second device;
[0026] The period during which the first device obtains traffic information from the second device.
[0027] Optionally, obtaining the first traffic acquisition periodic strategy corresponding to the virtual machine based on the target information and the initial traffic acquisition periodic strategy corresponding to the virtual machine includes:
[0028] The initial traffic acquisition cycle strategy corresponding to the virtual machine is updated based on the target information to obtain the first traffic acquisition cycle strategy corresponding to the virtual machine.
[0029] The network topology information includes at least one of the following:
[0030] The type information of the virtual machine; the specification information of the virtual machine.
[0031] Optionally, the target traffic acquisition period strategy includes at least one of the following:
[0032] The period during which the proxy module in the target virtual machine obtains traffic information from the storage and data retrieval module;
[0033] The period during which the proxy module in the target virtual machine sends traffic information to the second device;
[0034] The period during which the first device obtains traffic information from the second device;
[0035] The adjusted traffic acquisition cycle strategy includes at least one of the following:
[0036] The adjusted period for the proxy module in the target virtual machine to obtain traffic information from the storage and data retrieval module;
[0037] The adjusted period for the proxy module in the target virtual machine to send traffic information to the second device;
[0038] The first device obtains the adjusted period of traffic information from the second device.
[0039] Optionally, the method further includes:
[0040] If no abnormal traffic event notification is received from the target virtual machine within a preset time period, target adjustment information is generated;
[0041] The target adjustment information is sent to the second device, so that the second device sends the target adjustment information to the target virtual machine, and the target virtual machine adjusts the adjusted traffic acquisition cycle policy to the target traffic acquisition cycle policy according to the target adjustment information, so that the target virtual machine performs traffic monitoring according to the target traffic acquisition cycle policy.
[0042] Secondly, embodiments of the present invention also provide a method for obtaining traffic information, applied to a target virtual machine, the method comprising:
[0043] Receive target traffic acquisition periodic update information sent by the second device;
[0044] The current target traffic acquisition cycle strategy is adjusted based on the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy; traffic monitoring is then performed based on the adjusted traffic acquisition cycle strategy.
[0045] The target traffic acquisition periodic update information is generated by the first device based on the abnormal traffic event notification of the target virtual machine.
[0046] Optionally, the target traffic acquisition period strategy includes at least one of the following:
[0047] The period during which the proxy module in the target virtual machine obtains traffic information from the storage and data retrieval module;
[0048] The period during which the proxy module in the target virtual machine sends traffic information to the second device;
[0049] The adjusted traffic acquisition cycle strategy includes at least one of the following:
[0050] The adjusted period for the proxy module in the target virtual machine to obtain traffic information from the storage and data retrieval module;
[0051] The adjusted period for the proxy module in the target virtual machine to send traffic information to the second device.
[0052] Optionally, before receiving the target traffic acquisition periodic update information sent by the second device, the method further includes:
[0053] The system receives the initial traffic acquisition period policy corresponding to the target virtual machine sent by the second device, wherein the initial traffic acquisition period policy corresponding to the target virtual machine is set by the first device and sent to the second device.
[0054] Traffic monitoring is performed based on the initial traffic acquisition cycle strategy corresponding to the target virtual machine;
[0055] The initial traffic acquisition period strategy corresponding to the target virtual machine includes at least one of the following:
[0056] The initial period during which the proxy module of the target virtual machine obtains traffic information from the storage and data retrieval module;
[0057] The initial period during which the agent module of the target virtual machine sends traffic information to the second device.
[0058] Optionally, before receiving the target traffic acquisition periodic update information sent by the second device, the method further includes:
[0059] The system receives a security policy and a corresponding first traffic acquisition cycle policy for the target virtual machine sent by the second device. The security policy is generated by the first device based on the traffic information of the target virtual machine and sent to the second device. The first traffic acquisition cycle policy for the target virtual machine is generated by the first device based on network topology information and an initial traffic acquisition cycle policy and sent to the second device. The network topology information is generated by the first device based on the traffic information of the virtual machine.
[0060] Traffic monitoring is performed based on the security policy and the corresponding first traffic acquisition cycle policy of the target virtual machine.
[0061] When abnormal traffic information of the target virtual machine is obtained by traffic monitoring according to the security policy, the abnormal traffic information of the target virtual machine is sent to the second device, so that the second device sends the abnormal traffic information of the target virtual machine to the first device, and the first device generates an abnormal traffic event notification of the target virtual machine based on the abnormal traffic information of the target virtual machine.
[0062] The target virtual machine is one of the virtual machines;
[0063] The first traffic acquisition cycle strategy corresponding to the target virtual machine includes at least one of the following:
[0064] The identity identifier of the target virtual machine;
[0065] The period during which the proxy module in the target virtual machine obtains traffic information from the storage and data retrieval module;
[0066] The period during which the proxy module in the target virtual machine sends traffic information to the second device.
[0067] Optionally, the method further includes:
[0068] Receive target adjustment information sent by the second device;
[0069] The adjusted traffic acquisition cycle strategy is adjusted to the target traffic acquisition cycle strategy based on the target adjustment information.
[0070] Traffic monitoring is performed according to the target traffic acquisition cycle strategy;
[0071] The target adjustment information is generated by the first device when it does not receive an abnormal traffic event notification from the target virtual machine within a preset time period, and then sent to the second device.
[0072] Thirdly, embodiments of the present invention also provide a method for acquiring traffic information, applied to a second device, the method comprising:
[0073] The system receives target traffic acquisition periodic update information sent by a first device; the target traffic acquisition periodic update information is generated by the first device based on abnormal traffic event notifications from the target virtual machine.
[0074] Send the target traffic acquisition cycle update information to the target virtual machine so that the target virtual machine can adjust its current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information, thereby obtaining an adjusted traffic acquisition cycle strategy, and enabling the target virtual machine to operate according to the adjusted traffic acquisition cycle strategy.
[0075] Optionally, before receiving the target traffic acquisition periodic update information sent by the first device, the method further includes:
[0076] The system receives the initial traffic acquisition period policy corresponding to the virtual machine sent by the first device; the initial traffic acquisition period policy corresponding to the virtual machine is set by the first device.
[0077] Send the corresponding initial traffic acquisition cycle policy to the virtual machine so that the virtual machine can perform traffic monitoring according to the initial traffic acquisition cycle policy;
[0078] The target virtual machine is one of the virtual machines;
[0079] The initial traffic acquisition cycle strategy includes at least one of the following:
[0080] The virtual machine's agent module obtains traffic information from the storage and data retrieval module at an initial interval;
[0081] The virtual machine's agent module sends traffic information to the second device at an initial interval.
[0082] Optionally, before receiving the target traffic acquisition periodic update information sent by the first device, the method further includes:
[0083] Receive the security policy corresponding to the virtual machine and the corresponding first traffic acquisition period policy sent by the first device;
[0084] Send the corresponding security policy and the corresponding first traffic acquisition cycle policy to the virtual machine so that the virtual machine can perform traffic monitoring according to the corresponding security policy and the corresponding first traffic acquisition cycle policy.
[0085] The system receives abnormal traffic information of the target virtual machine sent by the target virtual machine; the abnormal traffic information of the target virtual machine is obtained by the target virtual machine through traffic monitoring based on the security policy sent by the second device.
[0086] Send abnormal traffic information of the target virtual machine to the first device, so that the first device generates an abnormal traffic event notification of the target virtual machine based on the abnormal traffic information;
[0087] Wherein, the target virtual machine is one of the virtual machines, and the target traffic acquisition period strategy is a traffic acquisition period strategy in the first traffic acquisition period strategy;
[0088] The first traffic acquisition cycle strategy includes at least one of the following:
[0089] The identity identifier of the virtual machine;
[0090] The period during which the proxy module in the virtual machine obtains traffic information from the storage and data retrieval module;
[0091] The period during which the proxy module in the virtual machine sends traffic information to the second device.
[0092] Optionally, the method further includes:
[0093] Receive target adjustment information sent by the first device;
[0094] Send the target adjustment information to the target virtual machine, so that the target virtual machine adjusts the adjusted traffic acquisition cycle policy to the target traffic acquisition cycle policy according to the target adjustment information, and so that the target virtual machine performs traffic monitoring according to the target traffic acquisition cycle policy;
[0095] The target adjustment information is generated by the first device when it does not receive an abnormal traffic event notification from the target virtual machine within a preset time period, and then sent to the second device.
[0096] Fourthly, embodiments of the present invention also provide a traffic information acquisition device, applied to a first device, the device comprising:
[0097] The first acquisition module is used to acquire abnormal traffic event notifications of the target virtual machine;
[0098] The first processing module is used to generate target traffic acquisition periodic update information based on the abnormal traffic event notification.
[0099] The first sending module is configured to send the target traffic acquisition cycle update information to the second device, so that the second device sends the target traffic acquisition cycle update information to the target virtual machine, and so that the target virtual machine adjusts the current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy, and so that the target virtual machine performs traffic monitoring according to the adjusted traffic acquisition cycle strategy.
[0100] Fifthly, embodiments of the present invention also provide a traffic information acquisition device, applied to a target virtual machine, the device comprising:
[0101] The first receiving module is used to receive target traffic acquisition periodic update information sent by the second device;
[0102] The first adjustment module is used to adjust the current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy.
[0103] The first monitoring module is used to monitor traffic according to the adjusted traffic acquisition cycle strategy.
[0104] The target traffic acquisition periodic update information is generated by the first device based on the abnormal traffic event notification of the target virtual machine.
[0105] Sixthly, embodiments of the present invention also provide a traffic information acquisition device, applied to a second device, the device comprising:
[0106] The second receiving module is used to receive target traffic acquisition periodic update information sent by the first device; the target traffic acquisition periodic update information is generated by the first device based on the abnormal traffic event notification of the target virtual machine;
[0107] The second sending module is used to send the target traffic acquisition cycle update information to the target virtual machine, so that the target virtual machine adjusts the current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy, and so that the target virtual machine follows the adjusted traffic acquisition cycle strategy.
[0108] In a seventh aspect, embodiments of the present invention also provide an electronic device, which is a first device, comprising: a transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; when the processor executes the program or instructions, it implements the steps in the traffic information acquisition method as described in any one of the first aspects.
[0109] Eighthly, embodiments of the present invention also provide a virtual machine, the virtual machine being a target virtual machine, comprising: a transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; when the processor executes the program or instructions, it implements the steps in the traffic information acquisition method as described in any one of the second aspects.
[0110] In a ninth aspect, embodiments of the present invention also provide an electronic device, which is a second device, comprising: a transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; when the processor executes the program or instructions, it implements the steps in the traffic information acquisition method as described in any one of the third aspects.
[0111] In a tenth aspect, embodiments of the present invention also provide a readable storage medium having a program or instructions stored thereon, wherein the program or instructions, when executed by a processor, implement the steps of the traffic information acquisition method as described in any one of the first aspects, or implement the steps of the traffic information acquisition method as described in any one of the second aspects, or implement the steps of the traffic information acquisition method as described in any one of the third aspects.
[0112] The beneficial effects of the above-described technical solution of the present invention are as follows:
[0113] The traffic information acquisition method provided by this invention involves obtaining abnormal traffic event notifications from a target virtual machine via a first device, generating target traffic acquisition cycle update information based on the abnormal traffic event notifications, sending the target traffic acquisition cycle update information to a second device, the second device sending the target traffic acquisition cycle update information to the target virtual machine, the target virtual machine adjusting its current target traffic acquisition cycle strategy based on the target traffic acquisition cycle update information to obtain an adjusted traffic acquisition cycle strategy, and the target virtual machine performing traffic monitoring based on the adjusted traffic acquisition cycle strategy. This method enables the setting and dynamic updating of the traffic acquisition cycle. Attached Figure Description
[0114] Figure 1 This is an architecture diagram of eBPF provided in an embodiment of the present invention;
[0115] Figure 2 A flowchart of a method for obtaining traffic information applied to a first device provided in an embodiment of the present invention;
[0116] Figure 3 This is a schematic diagram of the flow acquisition system of the micro-segmentation system provided in an embodiment of the present invention;
[0117] Figure 4 This is a schematic diagram of the structure of the traffic acquisition cycle management submodule provided in an embodiment of the present invention;
[0118] Figure 5 A flowchart illustrating a method for obtaining traffic information applied to a target virtual machine, provided in an embodiment of the present invention;
[0119] Figure 6 This is a schematic diagram of the agent structure provided in an embodiment of the present invention;
[0120] Figure 7 A flowchart of a method for obtaining traffic information applied to a second device provided in an embodiment of the present invention;
[0121] Figure 8 A detailed flowchart of the traffic information acquisition method provided in this embodiment of the invention;
[0122] Figure 9 This is a schematic diagram of the structure of a flow information acquisition device applied to a first device according to an embodiment of the present invention;
[0123] Figure 10 A schematic diagram of the structure of a traffic information acquisition device applied to a target virtual machine provided in an embodiment of the present invention;
[0124] Figure 11 This is a schematic diagram of the structure of a flow information acquisition device applied to a second device provided in an embodiment of the present invention;
[0125] Figure 12 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation
[0126] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.
[0127] It should be understood that the phrase "one embodiment" or "an embodiment" throughout the specification means that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of the invention. Therefore, phrases such as "in one embodiment," "in one embodiment," or "in an alternative embodiment" appearing throughout the specification do not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.
[0128] In various embodiments of the present invention, it should be understood that the sequence number of each process described below does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0129] In addition, the terms "system" and "network" are often used interchangeably in this article.
[0130] In the embodiments provided in this application, it should be understood that "B corresponding to A" means that B is associated with A, and B can be determined based on A. However, it should also be understood that determining B based on A does not mean determining B solely based on A; B can also be determined based on A and / or other information.
[0131] For ease of understanding, the following explanations will be provided before describing the specific embodiments of the present invention:
[0132] The industry has proposed the following main types of micro-segmentation solutions:
[0133] Independent physical security devices: By deploying physical security devices, such as firewalls, at the security domain boundaries to isolate different security domains, a large number of physical security devices will be deployed. Furthermore, data center networks are dynamic and do not have fixed physical boundaries, so statically deployed physical security devices will result in a large amount of traffic redirection and policy configuration.
[0134] Host proxy: Install proxy software on each virtual machine to inspect traffic entering and leaving the virtual machine, as well as applications and content inside the virtual machine. This method is dependent on the virtual machine's operating system.
[0135] Virtual switch: Virtual local area networks (VLNs) are created and access control lists (ACLs) are set on a virtual switch. This method requires certain capabilities from the switch.
[0136] Hypervisor-based control: The hypervisor works in conjunction with virtual switches to control the virtual network adapters of virtual machines. This method relies on the Application Programming Interface (API) provided by the hypervisor.
[0137] Traffic redirection: This involves redirecting the traffic of the virtual machine requiring protection to a dedicated secure virtual machine or physical security device for analysis. This method does not rely on a virtual environment but requires a traffic redirection mechanism.
[0138] Extended Berkeley Packet Filter (eBPF) is a packet filtering technology. The architecture of eBPF is shown in the diagram below. Figure 1 As shown, eBPF is an extension of Berkeley Packet Filter (BPF) technology. Utilizing a Just-In-Time (JIT) compiler, eBPF runs a virtual machine within the kernel, ensuring that only verified and safe eBPF instructions are executed by the kernel. Furthermore, because eBPF instructions still run within the kernel, there is no need to copy data to user space, significantly improving event handling efficiency. eBPF has found widespread application in fault diagnosis, network optimization, security control, and performance monitoring. eBPF requires an event to trigger before execution. These events include system calls, kernel tracepoints, kernel function and user-mode function call exits, network events, and more. eBPF programs are loaded into the kernel as bytecode, attached to mount points to trigger execution, and interact with user-mode programs through the eBPF Map.
[0139] To address the issue that existing methods for acquiring traffic information in micro-segmentation systems cannot set the traffic information acquisition period, this invention provides a method, apparatus, virtual machine, electronic device, and storage medium for acquiring traffic information.
[0140] like Figure 2 As shown, this embodiment of the invention provides a method for obtaining traffic information, applied to a first device, the method comprising:
[0141] Step 201: Obtain abnormal traffic event notifications for the target virtual machine, wherein the abnormal traffic event notifications include the identity identifier of the target virtual machine.
[0142] It should be noted that the traffic information acquisition method provided in this embodiment of the invention is applied to the traffic acquisition system of a micro-segmentation system, and the structure of the traffic acquisition system of the micro-segmentation system is as follows: Figure 3 As shown, the traffic acquisition system of this micro-segmentation system includes a micro-segmentation management module (including a security monitoring submodule), an aggregation and forwarding module connected to the micro-segmentation management module and set in a management virtual machine (VM), and newly added eBPF programs, agent modules, and storage and data retrieval modules (Map) in the management virtual machine (management VM) and service virtual machine (service VM1). The agent is connected to the aggregation and forwarding module. The eBPF program in the network element kernel collects traffic quintuple information (traffic information) in real time and filters the traffic according to the security policies issued by the micro-segmentation management module, i.e., the security monitoring phase. When abnormal traffic information is detected, an abnormal traffic log is generated and written to the Map; simultaneously, the traffic information is also stored in the Map. The agent periodically reads the traffic information from the Map (e.g., every 40 seconds) and, after initial integration, periodically (e.g., every 5 minutes) sends it to the aggregation and forwarding module, which then reports it to the micro-segmentation management center. The micro-segmentation management module includes a traffic acquisition cycle management submodule, and the agent includes a traffic acquisition cycle setting submodule.
[0143] In this embodiment of the invention, the first device is a micro-segmentation management module, the target virtual machine is one of the virtual machines connected to the first device, the target virtual machine can be a management VM or a service VM, and the second device is a convergence and forwarding module in the management VM.
[0144] In this step, during the security monitoring phase, when the agent reads abnormal traffic information of the target virtual machine from the Map, it generates an abnormal traffic log based on the abnormal traffic information. The agent immediately reports the abnormal traffic information and the abnormal traffic log to the second device, which then forwards them to the first device. The traffic acquisition cycle management submodule of the first device generates an abnormal traffic event notification for the target virtual machine based on the abnormal traffic information and the abnormal traffic log. Alternatively, the security monitoring submodule of the first device can generate the abnormal traffic event notification for the target virtual machine based on the abnormal traffic information and the abnormal traffic log, and send the abnormal traffic event notification to the traffic acquisition cycle management submodule. The abnormal traffic event notification for the target virtual machine includes the detection time of the abnormal traffic information and the identity identifier (i.e., VM ID) of the target virtual machine.
[0145] Step 202: Generate target traffic acquisition cycle update information based on the abnormal traffic event notification. The target traffic acquisition cycle update information includes the adjustment method of the current target traffic acquisition cycle strategy of the target virtual machine.
[0146] In this step, after the traffic acquisition cycle management submodule obtains the abnormal traffic event notification of the target virtual machine, the traffic acquisition cycle management submodule generates target traffic acquisition cycle update information based on the abnormal traffic event notification and the identity of the target virtual machine. The target traffic acquisition cycle update information includes the adjustment method of the current target traffic acquisition cycle policy of the VM (target virtual machine) accessed by abnormal traffic and the identity of the target virtual machine (VM id).
[0147] The target traffic acquisition cycle strategy includes at least one of the following:
[0148] The period during which the agent module in the target virtual machine obtains traffic information from the storage and data retrieval module (Map);
[0149] The period during which the agent module in the target virtual machine sends traffic information to the second device;
[0150] The period during which the first device obtains traffic information from the second device.
[0151] Step 203: Send the target traffic acquisition cycle update information to the second device, so that the second device sends the target traffic acquisition cycle update information to the target virtual machine, and the target virtual machine adjusts the current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy, and the target virtual machine performs traffic monitoring according to the adjusted traffic acquisition cycle strategy.
[0152] For example, the adjustment method of the target traffic acquisition period strategy in the target traffic acquisition period update information is to shorten the period in the target traffic acquisition period strategy, including at least one of the following:
[0153] The time interval for the agent in the target virtual machine to obtain traffic information from the Map is shortened by one time unit.
[0154] The period during which the agent in the target virtual machine sends traffic information to the second device is shortened by one time unit;
[0155] The time interval for the first device to obtain traffic information from the second device is shortened by one time unit;
[0156] One of the time units can be 20 seconds or 30 seconds.
[0157] For another example, the adjustment method of the target traffic acquisition period strategy in the target traffic acquisition period update information is to shorten the period in the target traffic acquisition period strategy, including at least one of the following:
[0158] The time interval for the agent in the target virtual machine to obtain traffic information from the Map is shortened by the first preset time.
[0159] The period during which the agent in the target virtual machine sends traffic information to the second device is shortened by a second preset duration;
[0160] The cycle for the first device to obtain traffic information from the second device is shortened by a third preset time.
[0161] Among them, the first preset duration is longer than the third preset duration, the second preset duration is longer than the third preset duration, or the first preset duration, the second preset duration and the third preset duration are all different, and there is no limitation on the relationship between them.
[0162] The adjusted traffic acquisition cycle strategy includes:
[0163] The agent module in the target virtual machine obtains the adjusted period of traffic information from the storage and data retrieval module (Map);
[0164] The adjusted period for the agent module in the target virtual machine to send traffic information to the second device.
[0165] In this step, the traffic acquisition cycle management submodule of the first device sends the target traffic acquisition cycle update information and the identity identifier of the target virtual machine to the second device. The second device sends the target traffic acquisition cycle update information to the agent of the target virtual machine according to the identity identifier of the target virtual machine. The agent includes a traffic acquisition cycle setting submodule. The traffic acquisition cycle setting submodule adjusts the current target traffic acquisition cycle policy according to the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle policy. It sets the adjusted cycle for the agent to obtain traffic information from the Map and / or the adjusted cycle for the agent to send traffic information to the second device, and monitors and reports traffic information according to the adjusted cycle.
[0166] In an optional embodiment of the present invention, step 201 includes:
[0167] Prior to the security monitoring phase, this embodiment of the invention also includes a traffic learning phase, i.e., before step 201. The method further includes: during the traffic learning phase, the traffic acquisition cycle management submodule of the micro-segmentation management module sets the initial traffic policy corresponding to the virtual machine; wherein each of the initial traffic acquisition cycle policies includes at least one of the following: the initial cycle for the agent module of the virtual machine to acquire traffic information from the storage and data retrieval module (Map); the initial cycle for the agent module of the virtual machine to send traffic information to the second device; and the initial cycle for the first device to acquire traffic information from the second device.
[0168] The second device sends a corresponding initial traffic acquisition cycle policy to each of the virtual machines. This initial traffic acquisition cycle policy includes at least one of the following: an initial cycle for the virtual machine's agent to acquire traffic information from the storage and data retrieval module (Map); and an initial cycle for the virtual machine's agent to send traffic information to the second device. The traffic acquisition cycle setting submodule in the virtual machine's agent sets the initial cycle for the agent to acquire traffic information from the Map and / or the initial cycle for the agent to send traffic information to the second device according to the initial traffic acquisition cycle policy. The agent monitors traffic and sends traffic information to the second device according to the aforementioned initial cycles.
[0169] It should be noted that the traffic learning phase is also called the testing phase, which requires a large amount of traffic information for learning. Therefore, the type of virtual machine in the Virtualized Network Function (VNF) can be disregarded. The initial traffic acquisition period strategy for generating the virtual machine is set by the traffic acquisition period management submodule of the first device. The target virtual machine is one of the at least one virtual machines, that is, the target virtual machine can be a management VM or a service VM.
[0170] In an optional embodiment of the present invention, step 201 includes: during the traffic learning phase, a second device acquires traffic information of virtual machines sent by the agents of virtual machines in virtualized network functions (VNFs) connected to the second device (the number of VNFs connected to the second device is at least one, and the number of virtual machines in each VNF is also at least one, and the traffic information of the virtual machines can be monitored and sent by the virtual machines according to the initial traffic acquisition cycle policy); the second device sends the traffic information of each virtual machine to the first device; the traffic acquisition cycle management submodule of the first device acquires the traffic information of each virtual machine sent by the second device; the first device learns based on the traffic information of each virtual machine, generates network topology information and a security policy corresponding to each virtual machine; and the first device sends the security policy and the corresponding virtual machine identity (VM) to the second device. The second device sends a security policy to the agent of the corresponding virtual machine based on the virtual machine's identity (id). The agent stores the security policy in the virtual machine's Map. The virtual machine's eBPF program retrieves the security policy from the Map and performs traffic monitoring according to the security policy, entering the security monitoring stage. Additionally, the security policy corresponding to each virtual machine is sent to the agent in the corresponding virtual machine, entering the security monitoring stage. Furthermore, the traffic acquisition cycle management submodule of the first device generates a corresponding first traffic acquisition cycle policy based on the target information and the initial traffic acquisition cycle policy corresponding to each virtual machine. The target information includes at least one of the following: the network topology information; the traffic processing volume information of the virtual machine; and the workload information of the second device.
[0171] Each of the first traffic acquisition cycle strategies includes at least one of the following:
[0172] The identity identifier of the virtual machine;
[0173] The agent module in the virtual machine obtains traffic information from the storage and data retrieval module (Map) periodically;
[0174] The period during which the agent module in the virtual machine sends traffic information to the second device;
[0175] The period during which the first device obtains traffic information from the second device.
[0176] The traffic acquisition cycle management submodule of the first device forwards the updated first traffic acquisition cycle policy to the second device. This first traffic acquisition cycle policy includes at least one of the following: the identity identifier of the virtual machine; the cycle for the agent to acquire traffic information from the Map; and the cycle for the agent to send traffic information to the second device. The second device sends the first traffic acquisition cycle policy to the corresponding agent of the virtual machine based on the virtual machine's identity identifier. The traffic acquisition cycle setting submodule in the agent sets the cycle for the agent to acquire traffic information from the Map and / or the cycle for the agent to send traffic information to the second device according to the first traffic acquisition cycle policy. The agent monitors and reports traffic information according to the aforementioned cycles.
[0177] If the eBPF program of the target virtual machine obtains abnormal traffic information by monitoring traffic according to the security policy corresponding to the target virtual machine, the eBPF program of the target virtual machine sends the abnormal traffic information to the agent of the target virtual machine. The agent sends the abnormal traffic information and the identity of the target virtual machine to the second device. The second device reports the abnormal traffic information and the identity of the target virtual machine to the first device. The first device generates an abnormal traffic event notification for the target virtual machine based on the identity of the target virtual machine, network topology information, and abnormal traffic information.
[0178] The network topology information includes at least one of the following or can demonstrate at least one of the following:
[0179] The VNF connected to the first device, the identity of the VNF, the virtual machines in the VNF, the identity of each virtual machine, the connection relationship between VNFs, the connection relationship between virtual machines, the VM type of the VNF, the network function carried by the VM, the workload of the first device, the workload of the second device, whether the VM receives abnormal traffic, and the duration of abnormal traffic.
[0180] The target virtual machine is one of the virtual machines.
[0181] Further, based on the target information and the initial traffic acquisition cycle strategy corresponding to the virtual machine, a first traffic acquisition cycle strategy corresponding to the virtual machine is obtained, including:
[0182] The traffic acquisition cycle management submodule of the first device updates the initial traffic acquisition cycle strategy based on the VM type, VM specification information, virtual machine traffic processing volume information, and micro-segmentation management module workload information displayed in the VNF network topology information, to obtain the first traffic acquisition cycle strategy corresponding to each virtual machine, wherein the first traffic acquisition cycle strategy includes the target traffic acquisition cycle strategy.
[0183] For example, for virtual VMs, which communicate with both the management domain's network management system and the service VMs in the VNF, the exposed area is relatively large. Therefore, when updating the initial traffic acquisition cycle policy, the initial period for the agent to read traffic information from the Map and the initial period for the agent to report traffic information to the second device are increased by time, for example, by 1 time unit and 2 time units respectively, resulting in the first traffic acquisition cycle policy's period for the agent to obtain traffic information from the Map and the period for the agent to send traffic information to the second device. For service VMs that perform data / signaling processing, there are no directly exposed interfaces, and their security risks are relatively low. Therefore, when updating the initial traffic acquisition cycle policy, the initial period for the agent to read traffic information from the Map and the initial period for the agent to report traffic information to the second device are increased by time, for example, by 2 time units and 3 time units respectively, resulting in the first traffic acquisition cycle policy's period for the agent to obtain traffic information from the Map and the period for the agent to send traffic information to the second device. For all VMs in a VNF with an internet exposure surface, when updating the initial traffic acquisition cycle policy, the initial cycle period for the agent to read traffic information from the Map and the initial cycle period for the agent to report traffic information to the second device are each increased by 1 time unit, and the initial cycle period for the first device to acquire traffic information from the second device is also increased by 1 time unit.
[0184] One time unit can be 20 seconds or 30 seconds.
[0185] It should also be noted that the specific time unit added when updating the initial traffic acquisition cycle strategy, and the definition of the time unit, are determined by the traffic acquisition cycle management submodule. This can be based on factors such as the VM type of the VNF, the CPU size inferred from the type, and the average traffic processed. The traffic acquisition cycle management submodule updates the cycle time of the traffic information read from the aggregation and forwarding module based on the target traffic acquisition cycle update information.
[0186] Furthermore, after the first device generates target traffic acquisition periodic update information based on the abnormal traffic event notification, it starts the abnormal traffic monitoring timer. In an optional embodiment of the present invention, the method further includes:
[0187] If no abnormal traffic event notification is received from the target virtual machine within a preset time period, target adjustment information is generated;
[0188] The target adjustment information is sent to the second device, so that the second device sends the target adjustment information to the target virtual machine, and the target virtual machine adjusts the adjusted traffic acquisition cycle policy to the target traffic acquisition cycle policy according to the target adjustment information, so that the target virtual machine performs traffic monitoring according to the target traffic acquisition cycle policy.
[0189] Specifically, after the traffic acquisition cycle management submodule of the first device generates target traffic acquisition cycle update information based on the abnormal traffic event notification, it starts an abnormal traffic monitoring timer. If no abnormal traffic event notification is received from the target virtual machine within a preset time period, the traffic acquisition cycle management submodule considers the abnormality to have ended, generates target adjustment information, and sends the target adjustment information and the identity identifier of the target virtual machine to the second device. The second device sends the target adjustment information to the target virtual machine based on the identity identifier of the target virtual machine. The target virtual machine adjusts the adjusted traffic acquisition cycle strategy back to the target traffic acquisition cycle strategy, that is, adjusts it to the traffic acquisition cycle strategy before the abnormal traffic occurred. The traffic acquisition cycle setting submodule of the target virtual machine's agent sets the agent's traffic acquisition cycle period from Map and / or the agent's traffic information sending period to the second device based on the target traffic acquisition cycle strategy (including at least one of the following: the period during which the agent module in the target virtual machine obtains traffic information from the storage and data retrieval module, and the period during which the agent module in the target virtual machine sends traffic information to the second device), and monitors and reports traffic information according to the above periods.
[0190] For example, the preset duration is the duration of the cycle in which 3 agents send traffic information to the second device.
[0191] Furthermore, if an abnormal traffic event notification is received again from the target virtual machine within a preset time period, the adjusted traffic acquisition cycle policy is used as the current target traffic acquisition cycle policy for the target virtual machine. The step of generating target traffic acquisition cycle update information based on the abnormal traffic event notification is repeated, and the target traffic acquisition cycle update information is sent to the second device again, so that the second device sends the target traffic acquisition cycle update information to the target virtual machine, and the target virtual machine adjusts its current target traffic acquisition cycle policy based on the target traffic acquisition cycle update information to obtain an adjusted traffic acquisition cycle policy. The target virtual machine then performs traffic monitoring based on the adjusted traffic acquisition cycle policy, and the above steps are repeated.
[0192] In summary, the traffic acquisition cycle management submodule has the following functions: managing the cycle for the agent to acquire traffic information from the Map, the cycle for the agent to send traffic information to the second device, and the cycle for the micro-segmentation management module to acquire traffic information from the aggregation and forwarding module. This includes initial configuration, updating the cycle time based on the VNF's VM type, the network function carried by the VM, the workload of the aggregation and forwarding module and the micro-segmentation management module, whether the VM receives abnormal traffic, and the duration of abnormal traffic. Traffic acquisition cycle management can be an independent submodule within the micro-segmentation management module or a function within the security monitoring submodule.
[0193] This invention also provides the structure of a traffic acquisition cycle management submodule. Figure 4 A structural diagram of the traffic acquisition cycle management submodule, as shown below. Figure 4 As shown, the traffic acquisition period management submodule includes at least traffic acquisition period settings, network topology query, abnormal traffic event notification reception, micro-segmentation management module matching query, abnormal traffic event timer, and traffic acquisition period library. Its specific functions are as follows:
[0194] The traffic acquisition cycle setting function has three main features: first, setting the traffic acquisition cycle strategy based on network topology, virtual machine type and specifications, and the load of the micro-segmentation management module; second, updating the traffic acquisition cycle based on abnormal traffic and abnormal traffic timing cycles; and third, setting and updating the cycle time for the micro-segmentation management module to acquire traffic information from the aggregation and forwarding module.
[0195] Abnormal traffic event notification reception: Receive abnormal traffic event notifications.
[0196] Abnormal traffic timer: times the received abnormal traffic.
[0197] Network topology query: Query network topology from the traffic visualization submodule of the micro-segmentation management module.
[0198] Micro-segmentation management module load query: Obtain the load of the micro-segmentation management module (such as the central processing unit (CPU) and memory usage).
[0199] Traffic acquisition cycle library: Stores VM IDs and related traffic acquisition cycles, as well as traffic acquisition cycles for various management modules.
[0200] like Figure 5 As shown in the figure, this embodiment of the invention also provides a method for obtaining traffic information, applied to a target virtual machine, the method comprising:
[0201] Step 501: Receive target traffic acquisition periodic update information sent by the second device; wherein the target traffic acquisition periodic update information is generated by the first device based on the abnormal traffic event notification of the target virtual machine, and the abnormal traffic event notification includes the identity identifier of the target virtual machine.
[0202] In this embodiment of the invention, the first device is a micro-segmentation management module, and the second device is a aggregation and forwarding module that manages the VM.
[0203] Step 502: Adjust the current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy. Step 503: Perform traffic monitoring according to the adjusted traffic acquisition cycle strategy.
[0204] The target traffic acquisition cycle strategy includes at least one of the following:
[0205] The period during which the proxy module in the target virtual machine obtains traffic information from the storage and data retrieval module;
[0206] The period during which the proxy module in the target virtual machine sends traffic information to the second device;
[0207] The adjusted traffic acquisition cycle strategy includes at least one of the following:
[0208] The adjusted period for the proxy module in the target virtual machine to obtain traffic information from the storage and data retrieval module;
[0209] The adjusted period for the proxy module in the target virtual machine to send traffic information to the second device.
[0210] It should be noted that the target virtual machine provided in this embodiment of the invention can be a management VM or a service VM. A traffic acquisition period setting submodule is added to the agent of the target virtual machine. The function of the traffic acquisition period setting submodule is to set the period for the agent to acquire traffic information from the Map and the period for the agent to report traffic information to the aggregation and forwarding module, based on the target traffic acquisition period update information issued by the traffic acquisition management submodule. In an optional embodiment of the invention, before receiving the target traffic acquisition period update information sent by the second device, the method further includes:
[0211] The system receives the initial traffic acquisition period policy corresponding to the target virtual machine sent by the second device, wherein the initial traffic acquisition period policy corresponding to the target virtual machine is set by the first device and sent to the second device.
[0212] Traffic monitoring is performed based on the initial traffic acquisition cycle strategy corresponding to the target virtual machine;
[0213] The initial traffic acquisition period strategy corresponding to the target virtual machine includes at least one of the following:
[0214] The initial period during which the proxy module of the target virtual machine obtains traffic information from the storage and data retrieval module;
[0215] The initial period during which the agent module of the target virtual machine sends traffic information to the second device.
[0216] In an optional embodiment of the present invention, before receiving the target traffic acquisition periodic update information sent by the second device, the method further includes:
[0217] The system receives a security policy and a corresponding first traffic acquisition cycle policy for the target virtual machine sent by the second device. The security policy is generated by the first device based on the traffic information of the target virtual machine and sent to the second device. The first traffic acquisition cycle policy for the target virtual machine is generated by the first device based on network topology information and an initial traffic acquisition cycle policy and sent to the second device. The network topology information is generated by the first device based on the traffic information of the virtual machine.
[0218] Traffic monitoring is performed based on the security policy and the corresponding first traffic acquisition cycle policy of the target virtual machine.
[0219] When abnormal traffic information of the target virtual machine is obtained by traffic monitoring according to the security policy, the abnormal traffic information of the target virtual machine is sent to the second device, so that the second device sends the abnormal traffic information of the target virtual machine to the first device, and the first device generates an abnormal traffic event notification of the target virtual machine based on the abnormal traffic information of the target virtual machine.
[0220] The target virtual machine is one of the virtual machines;
[0221] The first traffic acquisition cycle strategy corresponding to the target virtual machine includes at least one of the following:
[0222] The identity identifier of the target virtual machine;
[0223] The period during which the proxy module in the target virtual machine obtains traffic information from the storage and data retrieval module;
[0224] The period during which the proxy module in the target virtual machine sends traffic information to the second device.
[0225] In an optional embodiment of the present invention, the method further includes:
[0226] Receive target adjustment information sent by the second device;
[0227] The adjusted traffic acquisition cycle strategy is adjusted to the target traffic acquisition cycle strategy based on the target adjustment information.
[0228] Traffic monitoring is performed according to the target traffic acquisition cycle strategy;
[0229] The target adjustment information is generated by the first device when it does not receive an abnormal traffic event notification from the target virtual machine within a preset time period, and then sent to the second device.
[0230] It should be noted that the embodiments of the present invention also provide a structural diagram of an agent, such as... Figure 6 As shown, the agent includes at least a Map creation module, a traffic and log information acquisition module, a traffic and log information reporting module, a security policy receiving module, a security policy distribution module, and an eBPF management module. These modules respectively create Maps associated with the eBPF program, acquire traffic 5-tuple information and abnormal traffic information from the Maps, and report them to the aggregation and forwarding module; receive security policies from the aggregation and forwarding module and store them in the Maps; and notify the eBPF program to update its security policies. The agent also manages the eBPF program, including loading it into the kernel space, mounting it to relevant kernel functions, and monitoring its runtime status. Furthermore, the agent adds a traffic acquisition period setting function; specifically, the traffic and log information acquisition module and the traffic and log information reporting module each include read period setting and report period setting functions, which can set the period time based on the received initial traffic acquisition period policy and traffic acquisition period update policy.
[0231] like Figure 7 As shown, this embodiment of the invention also provides a method for obtaining traffic information, applied to a second device, the method comprising:
[0232] Step 701: Receive target traffic acquisition periodic update information sent by the first device; the target traffic acquisition periodic update information is generated by the first device based on the abnormal traffic event notification of the target virtual machine, and the abnormal traffic event notification includes the identity identifier of the target virtual machine.
[0233] Step 702: Send the target traffic acquisition cycle update information to the target virtual machine, so that the target virtual machine adjusts the current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy, and make the target virtual machine follow the adjusted traffic acquisition cycle strategy.
[0234] In an optional embodiment of the present invention, before receiving the target traffic acquisition periodic update information sent by the first device, the method further includes:
[0235] The system receives the initial traffic acquisition period policy corresponding to the virtual machine sent by the first device; the initial traffic acquisition period policy corresponding to the virtual machine is set by the first device.
[0236] Send the corresponding initial traffic acquisition cycle policy to the virtual machine so that the virtual machine can perform traffic monitoring according to the initial traffic acquisition cycle policy;
[0237] The target virtual machine is one of the virtual machines;
[0238] The initial traffic acquisition cycle strategy includes at least one of the following:
[0239] The virtual machine's agent module obtains traffic information from the storage and data retrieval module at an initial interval;
[0240] The virtual machine's agent module sends traffic information to the second device at an initial interval.
[0241] In an optional embodiment of the present invention, before receiving the target traffic acquisition periodic update information sent by the first device, the method further includes:
[0242] Receive the security policy corresponding to the virtual machine and the corresponding first traffic acquisition period policy sent by the first device;
[0243] Send the corresponding security policy and the corresponding first traffic acquisition cycle policy to the virtual machine so that the virtual machine can perform traffic monitoring according to the corresponding security policy and the corresponding first traffic acquisition cycle policy.
[0244] The system receives abnormal traffic information of the target virtual machine sent by the target virtual machine; the abnormal traffic information of the target virtual machine is obtained by the target virtual machine through traffic monitoring based on the security policy sent by the second device.
[0245] Send abnormal traffic information of the target virtual machine to the first device, so that the first device generates an abnormal traffic event notification of the target virtual machine based on the abnormal traffic information;
[0246] Wherein, the target virtual machine is one of the virtual machines, and the target traffic acquisition period strategy is a traffic acquisition period strategy in the first traffic acquisition period strategy;
[0247] The first traffic acquisition cycle strategy includes at least one of the following:
[0248] The identity identifier of the virtual machine;
[0249] The period during which the proxy module in the virtual machine obtains traffic information from the storage and data retrieval module;
[0250] The period during which the proxy module in the virtual machine sends traffic information to the second device.
[0251] In an optional embodiment of the present invention, the method further includes:
[0252] Receive target adjustment information sent by the first device;
[0253] Send the target adjustment information to the target virtual machine, so that the target virtual machine adjusts the adjusted traffic acquisition cycle policy to the target traffic acquisition cycle policy according to the target adjustment information, and so that the target virtual machine performs traffic monitoring according to the target traffic acquisition cycle policy;
[0254] The target adjustment information is generated by the first device when it does not receive an abnormal traffic event notification from the target virtual machine within a preset time period, and then sent to the second device.
[0255] The following is combined with Figure 8 The following describes the specific process of the traffic information acquisition method provided in the embodiments of the present invention:
[0256] Step 1: During the traffic learning phase, the traffic acquisition cycle management submodule sends the initial traffic acquisition cycle strategy to the second device.
[0257] Step 2: During the traffic learning phase, the second device sends the initial traffic acquisition cycle policy to the agent in each VM.
[0258] Step 3: During the security monitoring phase, the traffic acquisition cycle management submodule sets a traffic acquisition cycle update strategy based on the VM type and the load information of the first device, and updates the cycle of reading traffic information sent from the second device (i.e., the initial traffic acquisition cycle strategy) to obtain the first traffic acquisition cycle strategy.
[0259] Step 4: The traffic acquisition cycle management submodule sends the first traffic acquisition cycle policy to the second device;
[0260] Step 5: The second device sends the first traffic acquisition cycle policy to the agent in each VM;
[0261] Step 6: The agent in the management VM (target virtual machine) reports abnormal traffic information and abnormal traffic logs to the second device;
[0262] Step 7: The traffic acquisition cycle management submodule generates target traffic acquisition cycle update information based on abnormal traffic information and abnormal traffic logs.
[0263] Step 8: The traffic acquisition cycle management submodule sends the target traffic acquisition cycle update information to the second device;
[0264] Step 9: The second device sends target traffic acquisition cycle update information to the target virtual machine. The target virtual machine adjusts the current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy. Traffic monitoring is performed according to the adjusted traffic acquisition cycle strategy.
[0265] Step 10: When the abnormal traffic monitoring timer of the traffic acquisition cycle management submodule completes a timer cycle without detecting any abnormal traffic event notification, the traffic acquisition cycle management submodule considers the abnormality to have ended and generates target adjustment information.
[0266] Step 11: The traffic acquisition cycle management submodule sends target adjustment information to the second device;
[0267] Step 12: The second device sends target adjustment information to the target virtual machine. The target virtual machine adjusts the adjusted traffic acquisition cycle policy back to the target traffic acquisition cycle policy according to the target adjustment information and performs traffic monitoring according to the target traffic acquisition cycle policy. If abnormal traffic information is obtained again, the adjusted traffic acquisition cycle policy is used as the target traffic acquisition cycle policy, and steps 6 to 12 are repeated.
[0268] The traffic acquisition framework and dynamic setting process for the traffic acquisition cycle of the micro-segmentation system provided in this invention include: adding a traffic acquisition cycle setting function to the agent in the VM of the VNF; adding a traffic acquisition cycle management submodule to the micro-segmentation management module; during the traffic learning phase, the traffic acquisition cycle management submodule initially sets the cycle for the agent to read traffic information from the Map, the cycle for the agent to report traffic information, and the cycle for the micro-segmentation management module to obtain traffic information from the aggregation and forwarding module; during the security monitoring phase, the traffic acquisition cycle management submodule updates the traffic acquisition cycle time based on the VM type of the VNF, the network function carried by the VM, the workload of the aggregation and forwarding module and the micro-segmentation management module, whether the VM receives abnormal traffic, and the duration of abnormal traffic; the traffic acquisition cycle management sets and updates the cycle time for the micro-segmentation management module to read traffic information from the aggregation and forwarding module; the traffic acquisition cycle settings in the agent execute the initial traffic acquisition cycle policy and the traffic acquisition cycle update policy, and set the traffic acquisition cycle time. By dynamically setting the traffic acquisition cycle, a balance can be achieved between the resources occupied by traffic acquisition and the efficiency of identifying security threats.
[0269] like Figure 9As shown, this embodiment of the invention also provides a traffic information acquisition device, applied to a first device, the device comprising:
[0270] The first acquisition module 901 is used to acquire abnormal traffic event notifications of the target virtual machine;
[0271] The first processing module 902 is used to generate target traffic acquisition periodic update information based on the abnormal traffic event notification.
[0272] The first sending module 903 is used to send the target traffic acquisition cycle update information to the second device, so that the second device sends the target traffic acquisition cycle update information to the target virtual machine, and causes the target virtual machine to adjust the current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy, and causes the target virtual machine to perform traffic monitoring according to the adjusted traffic acquisition cycle strategy.
[0273] Optionally, the device further includes:
[0274] The first generation module is used to set the initial traffic acquisition period strategy corresponding to the virtual machine;
[0275] The first strategy sending module is used to send the initial traffic acquisition cycle strategy corresponding to the virtual machine to the second device, so that the second device sends the corresponding initial traffic acquisition cycle strategy to the virtual machine, and the virtual machine performs traffic monitoring according to the initial traffic acquisition cycle strategy.
[0276] The target virtual machine is one of the virtual machines;
[0277] The initial traffic acquisition cycle strategy includes at least one of the following:
[0278] The virtual machine's agent module obtains traffic information from the storage and data retrieval module at an initial interval;
[0279] The initial period during which the agent module of the virtual machine sends traffic information to the second device;
[0280] The initial period for the first device to obtain traffic information from the second device.
[0281] Optionally, the first acquisition module 901 includes:
[0282] The first processing unit is configured to generate network topology information and a security policy corresponding to the virtual machine based on the traffic information of the virtual machine sent by the second device.
[0283] The second processing unit is configured to obtain a first traffic acquisition cycle strategy corresponding to the virtual machine based on the target information and the initial traffic acquisition cycle strategy corresponding to the virtual machine; the target information includes at least one of the following: the network topology information; the traffic processing volume information of the virtual machine; and the workload information of the second device.
[0284] The first sending unit is configured to send the security policy and the corresponding first traffic acquisition cycle policy of the virtual machine to the second device, so that the second device sends the corresponding security policy and the corresponding first traffic acquisition cycle policy to the virtual machine, and the virtual machine performs traffic monitoring according to the corresponding security policy and the corresponding first traffic acquisition cycle policy.
[0285] The first acquisition unit is used to acquire abnormal traffic information of the target virtual machine sent by the second device. The abnormal traffic information is obtained by the target virtual machine through traffic monitoring according to the security policy corresponding to the target virtual machine sent by the second device, and then sent to the second device.
[0286] The third processing unit is used to generate an abnormal traffic event notification for the target virtual machine based on the abnormal traffic information.
[0287] Wherein, the target virtual machine is one of the virtual machines, and the target traffic acquisition period strategy is a traffic acquisition period strategy in the first traffic acquisition period strategy;
[0288] The first traffic acquisition cycle strategy includes at least one of the following:
[0289] The identity identifier of the virtual machine;
[0290] The period during which the proxy module in the virtual machine obtains traffic information from the storage and data retrieval module;
[0291] The period during which the proxy module in the virtual machine sends traffic information to the second device;
[0292] The period during which the first device obtains traffic information from the second device.
[0293] Optionally, the second processing unit is specifically used for:
[0294] The initial traffic acquisition cycle strategy corresponding to the virtual machine is updated based on the target information to obtain the first traffic acquisition cycle strategy corresponding to the virtual machine.
[0295] The network topology information includes at least one of the following:
[0296] The type information of the virtual machine; the specification information of the virtual machine.
[0297] Optionally, the target traffic acquisition period strategy includes at least one of the following:
[0298] The period during which the proxy module in the target virtual machine obtains traffic information from the storage and data retrieval module;
[0299] The period during which the proxy module in the target virtual machine sends traffic information to the second device;
[0300] The period during which the first device obtains traffic information from the second device;
[0301] The adjusted traffic acquisition cycle strategy includes at least one of the following:
[0302] The adjusted period for the proxy module in the target virtual machine to obtain traffic information from the storage and data retrieval module;
[0303] The adjusted period for the proxy module in the target virtual machine to send traffic information to the second device;
[0304] The first device obtains the adjusted period of traffic information from the second device.
[0305] Optionally, the device further includes:
[0306] The second generation module is used to generate target adjustment information if no abnormal traffic event notification is received from the target virtual machine within a preset time period.
[0307] The first information sending module is used to send the target adjustment information to the second device, so that the second device sends the target adjustment information to the target virtual machine, and so that the target virtual machine adjusts the adjusted traffic acquisition cycle policy to the target traffic acquisition cycle policy according to the target adjustment information, so that the target virtual machine performs traffic monitoring according to the target traffic acquisition cycle policy.
[0308] It should be noted that the traffic information acquisition device for the first device provided in the embodiments of the present invention is a device capable of executing the above-described traffic information acquisition method for the first device. Therefore, all embodiments of the above-described traffic information acquisition method for the first device are applicable to this device and can achieve the same or similar technical effects.
[0309] like Figure 10 As shown, this embodiment of the invention also provides a traffic information acquisition device, applied to a target virtual machine, the device comprising:
[0310] The first receiving module 1001 is used to receive the adjusted traffic acquisition period strategy sent by the second device;
[0311] The first adjustment module 1002 is used to adjust the current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy.
[0312] The first monitoring module 1003 is used to monitor traffic according to the adjusted traffic acquisition cycle strategy.
[0313] The target traffic acquisition periodic update information is generated by the first device based on the abnormal traffic event notification of the target virtual machine.
[0314] Optionally, the target traffic acquisition period strategy includes at least one of the following:
[0315] The period during which the proxy module in the target virtual machine obtains traffic information from the storage and data retrieval module;
[0316] The period during which the proxy module in the target virtual machine sends traffic information to the second device;
[0317] The adjusted traffic acquisition cycle strategy includes at least one of the following:
[0318] The adjusted period for the proxy module in the target virtual machine to obtain traffic information from the storage and data retrieval module;
[0319] The adjusted period for the proxy module in the target virtual machine to send traffic information to the second device.
[0320] Optionally, the device further includes:
[0321] The first policy receiving module is used to receive the initial traffic acquisition period policy corresponding to the target virtual machine sent by the second device, wherein the initial traffic acquisition period policy corresponding to the target virtual machine is set by the first device and sent to the second device;
[0322] The first target monitoring module is used to monitor traffic according to the initial traffic acquisition cycle strategy corresponding to the target virtual machine;
[0323] The initial traffic acquisition period strategy corresponding to the target virtual machine includes at least one of the following:
[0324] The initial period during which the proxy module of the target virtual machine obtains traffic information from the storage and data retrieval module;
[0325] The initial period during which the agent module of the target virtual machine sends traffic information to the second device.
[0326] Optionally, the device further includes:
[0327] The first target receiving module is configured to receive the security policy and the corresponding first traffic acquisition cycle policy of the target virtual machine sent by the second device. The security policy of the target virtual machine is generated by the first device based on the traffic information of the target virtual machine and sent to the second device. The first traffic acquisition cycle policy of the target virtual machine is generated by the first device based on the network topology information and the initial traffic acquisition cycle policy and sent to the second device. The network topology information is generated by the first device based on the traffic information of the virtual machine.
[0328] The second target monitoring module is used to perform traffic monitoring based on the security policy corresponding to the target virtual machine and the corresponding first traffic acquisition cycle policy.
[0329] The second information sending module is used to send the abnormal traffic information of the target virtual machine to the second device when abnormal traffic information of the target virtual machine is obtained by traffic monitoring according to the security policy, so that the second device sends the abnormal traffic information of the target virtual machine to the first device, and the first device generates an abnormal traffic event notification of the target virtual machine based on the abnormal traffic information of the target virtual machine.
[0330] The target virtual machine is one of the virtual machines;
[0331] The first traffic acquisition cycle strategy corresponding to the target virtual machine includes at least one of the following:
[0332] The identity identifier of the target virtual machine;
[0333] The period during which the proxy module in the target virtual machine obtains traffic information from the storage and data retrieval module;
[0334] The period during which the proxy module in the target virtual machine sends traffic information to the second device.
[0335] Optionally, the device further includes:
[0336] The first information receiving module is used to receive target adjustment information sent by the second device;
[0337] The second adjustment module is used to adjust the adjusted traffic acquisition cycle strategy to the target traffic acquisition cycle strategy according to the target adjustment information.
[0338] The third target monitoring module is used to monitor traffic according to the target traffic acquisition cycle strategy.
[0339] The target adjustment information is generated by the first device when it does not receive an abnormal traffic event notification from the target virtual machine within a preset time period, and then sent to the second device.
[0340] It should be noted that the traffic information acquisition device for the target virtual machine provided in this embodiment of the invention is a device capable of executing the above-described traffic information acquisition method for the target virtual machine. Therefore, all embodiments of the above-described traffic information acquisition method for the target virtual machine are applicable to this device and can achieve the same or similar technical effects.
[0341] like Figure 11 As shown, this embodiment of the invention also provides a traffic information acquisition device, applied to a second device, the device comprising:
[0342] The second receiving module 1101 is used to receive target traffic acquisition periodic update information sent by the first device; the target traffic acquisition periodic update information is generated by the first device based on the abnormal traffic event notification of the target virtual machine;
[0343] The second sending module 1102 is used to send the target traffic acquisition cycle update information to the target virtual machine, so that the target virtual machine adjusts the current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy, and so that the target virtual machine follows the adjusted traffic acquisition cycle strategy.
[0344] Optionally, the device further includes:
[0345] The third policy receiving module is used to receive the initial traffic acquisition period policy corresponding to the virtual machine sent by the first device; the initial traffic acquisition period policy corresponding to the virtual machine is set by the first device.
[0346] The third strategy sending module is used to send the corresponding initial traffic acquisition cycle strategy to the virtual machine so that the virtual machine can perform traffic monitoring according to the initial traffic acquisition cycle strategy.
[0347] The target virtual machine is one of the virtual machines;
[0348] The initial traffic acquisition cycle strategy includes at least one of the following:
[0349] The virtual machine's agent module obtains traffic information from the storage and data retrieval module at an initial interval;
[0350] The virtual machine's agent module sends traffic information to the second device at an initial interval.
[0351] Optionally, the device further includes:
[0352] The second target receiving module is used to receive the security policy corresponding to the virtual machine and the corresponding first traffic acquisition period policy sent by the first device;
[0353] The first target sending module is used to send the corresponding security policy and the corresponding first traffic acquisition cycle policy to the virtual machine, so that the virtual machine can perform traffic monitoring according to the corresponding security policy and the corresponding first traffic acquisition cycle policy.
[0354] The second information receiving module is used to receive abnormal traffic information of the target virtual machine sent by the target virtual machine; the abnormal traffic information of the target virtual machine is obtained by the target virtual machine through traffic monitoring according to the security policy sent by the second device;
[0355] The fourth information sending module is used to send abnormal traffic information of the target virtual machine to the first device, so that the first device generates an abnormal traffic event notification of the target virtual machine based on the abnormal traffic information.
[0356] Wherein, the target virtual machine is one of the virtual machines, and the target traffic acquisition period strategy is a traffic acquisition period strategy in the first traffic acquisition period strategy;
[0357] The first traffic acquisition cycle strategy includes at least one of the following:
[0358] The identity identifier of the virtual machine;
[0359] The period during which the proxy module in the virtual machine obtains traffic information from the storage and data retrieval module;
[0360] The period during which the proxy module in the virtual machine sends traffic information to the second device.
[0361] Optionally, the device further includes:
[0362] The third information receiving module is used to receive target adjustment information sent by the first device;
[0363] The fifth information sending module is used to send the target adjustment information to the target virtual machine, so that the target virtual machine adjusts the adjusted traffic acquisition cycle strategy to the target traffic acquisition cycle strategy according to the target adjustment information, and so that the target virtual machine performs traffic monitoring according to the target traffic acquisition cycle strategy.
[0364] The target adjustment information is generated by the first device when it does not receive an abnormal traffic event notification from the target virtual machine within a preset time period, and then sent to the second device.
[0365] It should be noted that the traffic information acquisition device for the second device provided in the embodiments of the present invention is a device capable of executing the above-described traffic information acquisition method for the second device. Therefore, all embodiments of the traffic information acquisition method for the first device described above are applicable to this device and can achieve the same or similar technical effects.
[0366] like Figure 12 As shown, this embodiment of the invention also provides a device, which is a first device, including: a processor 1201; and a memory 1203 connected to the processor 1201 via a bus interface 1202. The memory 1203 is used to store programs and data used by the processor 1201 when performing operations, and the processor 1201 calls and executes the programs and data stored in the memory 1203.
[0367] The transceiver 1204 is connected to the bus interface 1202 and is used to receive and send data under the control of the processor 1201. Specifically, the processor 1201 is used to read the program in the memory 1203 and execute the following processes:
[0368] Obtain abnormal traffic event notifications for the target virtual machine; the abnormal traffic event notifications include the identity identifier of the target virtual machine;
[0369] Generate target traffic acquisition periodic update information based on the abnormal traffic event notification;
[0370] The transceiver 1204 performs the following process:
[0371] The target traffic acquisition cycle update information is sent to the second device, so that the second device sends the target traffic acquisition cycle update information to the target virtual machine, and the target virtual machine adjusts the current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy, and the target virtual machine performs traffic monitoring according to the adjusted traffic acquisition cycle strategy.
[0372] Optionally, the processor 1201 is further configured to:
[0373] Set the initial traffic acquisition cycle strategy for the virtual machine;
[0374] The transceiver 1204 is also used for:
[0375] Send the initial traffic acquisition cycle policy corresponding to the virtual machine to the second device, so that the second device sends the corresponding initial traffic acquisition cycle policy to the virtual machine, and the virtual machine performs traffic monitoring according to the initial traffic acquisition cycle policy;
[0376] The target virtual machine is one of the virtual machines;
[0377] The initial traffic acquisition cycle strategy includes at least one of the following:
[0378] The virtual machine's agent module obtains traffic information from the storage and data retrieval module at an initial interval;
[0379] The initial period during which the agent module of the virtual machine sends traffic information to the second device;
[0380] The initial period for the first device to obtain traffic information from the second device.
[0381] Optionally, the processor 1201 is specifically used for:
[0382] Based on the traffic information of the virtual machine sent by the second device, network topology information and the security policy corresponding to the virtual machine are generated;
[0383] Based on the target information and the initial traffic acquisition cycle strategy corresponding to the virtual machine, a first traffic acquisition cycle strategy corresponding to the virtual machine is obtained; the target information includes at least one of the following: the network topology information; the traffic processing volume information of the virtual machine; and the workload information of the second device;
[0384] The transceiver 1204 is specifically used for:
[0385] Send the security policy and the corresponding first traffic acquisition cycle policy of the virtual machine to the second device, so that the second device sends the corresponding security policy and the corresponding first traffic acquisition cycle policy to the virtual machine, and so that the virtual machine performs traffic monitoring according to the corresponding security policy and the corresponding first traffic acquisition cycle policy;
[0386] The processor 1201 is specifically used for:
[0387] Obtain abnormal traffic information of the target virtual machine sent by the second device. The abnormal traffic information is obtained by the target virtual machine through traffic monitoring according to the security policy corresponding to the target virtual machine sent by the second device, and then sent to the second device.
[0388] An abnormal traffic event notification for the target virtual machine is generated based on the abnormal traffic information;
[0389] Wherein, the target virtual machine is one of the virtual machines, and the target traffic acquisition period strategy is a traffic acquisition period strategy in the first traffic acquisition period strategy;
[0390] The first traffic acquisition cycle strategy includes at least one of the following:
[0391] The identity identifier of the virtual machine;
[0392] The period during which the proxy module in the virtual machine obtains traffic information from the storage and data retrieval module;
[0393] The period during which the proxy module in the virtual machine sends traffic information to the second device;
[0394] The period during which the first device obtains traffic information from the second device.
[0395] Optionally, the processor 1201 is specifically used for:
[0396] The initial traffic acquisition cycle strategy corresponding to the virtual machine is updated based on the target information to obtain the first traffic acquisition cycle strategy corresponding to the virtual machine.
[0397] The network topology information includes at least one of the following:
[0398] The type information of the virtual machine; the specification information of the virtual machine.
[0399] Optionally, the target traffic acquisition period strategy includes at least one of the following:
[0400] The period during which the proxy module in the target virtual machine obtains traffic information from the storage and data retrieval module;
[0401] The period during which the proxy module in the target virtual machine sends traffic information to the second device;
[0402] The period during which the first device obtains traffic information from the second device;
[0403] The adjusted traffic acquisition cycle strategy includes at least one of the following:
[0404] The adjusted period for the proxy module in the target virtual machine to obtain traffic information from the storage and data retrieval module;
[0405] The adjusted period for the proxy module in the target virtual machine to send traffic information to the second device;
[0406] The first device obtains the adjusted period of traffic information from the second device.
[0407] Optionally, the processor 1201 is further configured to:
[0408] If no abnormal traffic event notification is received from the target virtual machine within a preset time period, target adjustment information is generated;
[0409] The transceiver 1204 is also used for:
[0410] The target adjustment information is sent to the second device, so that the second device sends the target adjustment information to the target virtual machine, and the target virtual machine adjusts the adjusted traffic acquisition cycle policy to the target traffic acquisition cycle policy according to the target adjustment information, so that the target virtual machine performs traffic monitoring according to the target traffic acquisition cycle policy.
[0411] Among them, Figure 12 In this context, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 1201) and memory (memory 1203). The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. A bus interface provides a user interface 1205. A transceiver 1204 may be multiple elements, including transmitters and receivers, providing units for communicating with various other devices over a transmission medium. Processor 1201 is responsible for managing the bus architecture and general processing, and memory 1203 may store data used by processor 1201 during operation.
[0412] This invention also provides a virtual machine, which is a target virtual machine, including: a processor; and a memory connected to the processor via a bus interface, the memory being used to store programs and data used by the processor when performing operations, and the processor calling and executing the programs and data stored in the memory.
[0413] The transceiver is connected to the bus interface and is used to receive and send data under the control of the processor.
[0414] It should be noted that the virtual machine provided in this embodiment of the invention is similar to... Figure 12 The structure of the first device shown is similar, and will not be described in detail here.
[0415] Specifically, the processor is used to read the program from the memory, and the transceiver performs the following processes:
[0416] Receive target traffic acquisition periodic update information sent by the second device;
[0417] The processor performs the following procedures:
[0418] The current target traffic acquisition cycle strategy is adjusted based on the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy; traffic monitoring is then performed based on the adjusted traffic acquisition cycle strategy.
[0419] The target traffic acquisition periodic update information is generated by the first device based on the abnormal traffic event notification of the target virtual machine.
[0420] Optionally, the target traffic acquisition period strategy includes at least one of the following:
[0421] The period during which the proxy module in the target virtual machine obtains traffic information from the storage and data retrieval module;
[0422] The period during which the proxy module in the target virtual machine sends traffic information to the second device;
[0423] The adjusted traffic acquisition cycle strategy includes at least one of the following:
[0424] The adjusted period for the proxy module in the target virtual machine to obtain traffic information from the storage and data retrieval module;
[0425] The adjusted period for the proxy module in the target virtual machine to send traffic information to the second device.
[0426] Optionally, the system receives the initial traffic acquisition periodicity policy corresponding to the target virtual machine sent by the second device, wherein the initial traffic acquisition periodicity policy corresponding to the target virtual machine is set by the first device and sent to the second device.
[0427] The processor is also used for:
[0428] Traffic monitoring is performed based on the initial traffic acquisition cycle strategy corresponding to the target virtual machine;
[0429] The initial traffic acquisition period strategy corresponding to the target virtual machine includes at least one of the following:
[0430] The initial period during which the proxy module of the target virtual machine obtains traffic information from the storage and data retrieval module;
[0431] The initial period during which the agent module of the target virtual machine sends traffic information to the second device.
[0432] Optionally, the transceiver is further configured to:
[0433] The system receives a security policy and a corresponding first traffic acquisition cycle policy for the target virtual machine sent by the second device. The security policy for the target virtual machine is generated by the first device based on the traffic information of the target virtual machine and sent to the second device. The first traffic acquisition cycle policy for the target virtual machine is generated by the first device based on network topology information and an initial traffic acquisition cycle policy and sent to the second device. The network topology information is generated by the first device based on the traffic information of the virtual machine.
[0434] The processor is also used for:
[0435] Traffic monitoring is performed based on the security policy and the corresponding first traffic acquisition cycle policy of the target virtual machine.
[0436] The transceiver is also used for:
[0437] When abnormal traffic information of the target virtual machine is obtained by traffic monitoring according to the security policy, the abnormal traffic information of the target virtual machine is sent to the second device, so that the second device sends the abnormal traffic information of the target virtual machine to the first device, and the first device generates an abnormal traffic event notification of the target virtual machine based on the abnormal traffic information of the target virtual machine.
[0438] The target virtual machine is one of the virtual machines;
[0439] The first traffic acquisition cycle strategy includes at least one of the following:
[0440] The identity identifier of the target virtual machine;
[0441] The period during which the proxy module in the target virtual machine obtains traffic information from the storage and data retrieval module;
[0442] The period during which the proxy module in the target virtual machine sends traffic information to the second device.
[0443] Optionally, the transceiver is further configured to:
[0444] Receive target adjustment information sent by the second device;
[0445] The processor is also used for:
[0446] The adjusted traffic acquisition cycle strategy is adjusted to the target traffic acquisition cycle strategy based on the target adjustment information.
[0447] The target adjustment information is generated by the first device when it does not receive an abnormal traffic event notification from the target virtual machine within a preset time period, and then sent to the second device.
[0448] This invention also provides a device, which is a second device, comprising: a processor; and a memory connected to the processor via a bus interface, the memory being used to store programs and data used by the processor during operation, and the processor calling and executing the programs and data stored in the memory.
[0449] The transceiver is connected to the bus interface and is used to receive and send data under the control of the processor.
[0450] It should be noted that the second device provided in this embodiment of the invention is similar to... Figure 12 The structure of the first device shown is similar, and will not be described in detail here.
[0451] Specifically, the processor is used to read the program from the memory, and the transceiver performs the following processes:
[0452] The system receives target traffic acquisition periodic update information sent by a first device; the target traffic acquisition periodic update information is generated by the first device based on abnormal traffic event notifications from the target virtual machine.
[0453] Send the target traffic acquisition cycle update information to the target virtual machine so that the target virtual machine can adjust its current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information, thereby obtaining an adjusted traffic acquisition cycle strategy, and enabling the target virtual machine to operate according to the adjusted traffic acquisition cycle strategy.
[0454] Optionally, the transceiver is further configured to:
[0455] The system receives the initial traffic acquisition periodic policy for each virtual machine sent by the first device; the initial traffic acquisition periodic policy for each virtual machine is set by the first device.
[0456] Send the corresponding initial traffic acquisition cycle policy to the virtual machine so that the virtual machine can perform traffic monitoring according to the initial traffic acquisition cycle policy;
[0457] The target virtual machine is one of the virtual machines;
[0458] The initial traffic acquisition cycle strategy includes at least one of the following:
[0459] The virtual machine's agent module obtains traffic information from the storage and data retrieval module at an initial interval;
[0460] The virtual machine's agent module sends traffic information to the second device at an initial interval.
[0461] Optionally, the transceiver is further configured to:
[0462] Receive the security policy corresponding to the virtual machine and the corresponding first traffic acquisition period policy sent by the first device;
[0463] Send the corresponding security policy and the corresponding first traffic acquisition cycle policy to the virtual machine so that the virtual machine can perform traffic monitoring according to the corresponding security policy and the corresponding first traffic acquisition cycle policy.
[0464] The system receives abnormal traffic information of the target virtual machine sent by the target virtual machine; the abnormal traffic information of the target virtual machine is obtained by the target virtual machine through traffic monitoring based on the security policy sent by the second device.
[0465] Send abnormal traffic information of the target virtual machine to the first device, so that the first device generates an abnormal traffic event notification of the target virtual machine based on the abnormal traffic information;
[0466] Wherein, the target virtual machine is one of the virtual machines, and the target traffic acquisition period strategy is a traffic acquisition period strategy in the first traffic acquisition period strategy;
[0467] The first traffic acquisition cycle strategy includes at least one of the following:
[0468] The identity identifier of the virtual machine;
[0469] The period during which the proxy module in the virtual machine obtains traffic information from the storage and data retrieval module;
[0470] The period during which the proxy module in the virtual machine sends traffic information to the second device.
[0471] Optionally, the transceiver is further configured to:
[0472] Receive target adjustment information sent by the first device;
[0473] Send the target adjustment information to the target virtual machine, so that the target virtual machine adjusts the adjusted traffic acquisition cycle policy to the target traffic acquisition cycle policy according to the target adjustment information, and so that the target virtual machine performs traffic monitoring according to the target traffic acquisition cycle policy;
[0474] The target adjustment information is generated by the first device when it does not receive an abnormal traffic event notification from the target virtual machine within a preset time period, and then sent to the second device.
[0475] In addition, specific embodiments of the present invention also provide a computer-readable storage medium having a computer program stored thereon, wherein when the program is executed by a processor, it implements the steps in the traffic information acquisition method for a first device as described above, or implements the steps in the traffic information acquisition method for a target virtual machine as described above, or implements the steps in the traffic information acquisition method for a second device as described above.
[0476] In the several embodiments provided in this application, it should be understood that the disclosed methods and apparatus can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0477] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can be physically comprised separately, or two or more units can be integrated into one unit. The integrated unit described above can be implemented in hardware or in the form of hardware plus software functional units.
[0478] The integrated units implemented as software functional units described above can be stored in a computer-readable storage medium. These software functional units, stored in a storage medium, include several instructions that cause a computer device (which may be a personal computer, server, or network device, etc.) to execute some steps of the transmission and reception methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0479] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for acquiring traffic information, characterized in that, Applied to a first device, the method includes: Obtain notifications of abnormal traffic events from the target virtual machine; Generate target traffic acquisition periodic update information based on the abnormal traffic event notification; Send the target traffic acquisition cycle update information to the second device, so that the second device sends the target traffic acquisition cycle update information to the target virtual machine, and so that the target virtual machine adjusts the current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy, and so that the target virtual machine performs traffic monitoring according to the adjusted traffic acquisition cycle strategy. The step of obtaining abnormal traffic event notifications from the target virtual machine includes: Based on the traffic information of the virtual machine sent by the second device, network topology information and the security policy corresponding to the virtual machine are generated; Based on the target information and the initial traffic acquisition cycle strategy corresponding to the virtual machine, a first traffic acquisition cycle strategy corresponding to the virtual machine is obtained; the target information includes at least one of the following: the network topology information; the traffic processing volume information of the virtual machine; and the workload information of the second device; Send the security policy and the corresponding first traffic acquisition cycle policy of the virtual machine to the second device, so that the second device sends the corresponding security policy and the corresponding first traffic acquisition cycle policy to the virtual machine, and so that the virtual machine performs traffic monitoring according to the corresponding security policy and the corresponding first traffic acquisition cycle policy; Obtain abnormal traffic information of the target virtual machine sent by the second device. The abnormal traffic information is obtained by the target virtual machine through traffic monitoring according to the security policy corresponding to the target virtual machine sent by the second device, and then sent to the second device. An abnormal traffic event notification for the target virtual machine is generated based on the abnormal traffic information; Wherein, the target virtual machine is one of the virtual machines, and the target traffic acquisition period strategy is a traffic acquisition period strategy in the first traffic acquisition period strategy; The first traffic acquisition cycle strategy includes: The identity identifier of the virtual machine; The period during which the proxy module in the virtual machine obtains traffic information from the storage and data retrieval module; The period during which the proxy module in the virtual machine sends traffic information to the second device; The period during which the first device obtains traffic information from the second device.
2. The method for obtaining traffic information according to claim 1, characterized in that, Before obtaining the abnormal traffic event notification of the target virtual machine, the method further includes: Configure the initial traffic acquisition cycle strategy for the virtual machine; Send the initial traffic acquisition cycle policy corresponding to the virtual machine to the second device, so that the second device sends the corresponding initial traffic acquisition cycle policy to the virtual machine, and the virtual machine performs traffic monitoring according to the initial traffic acquisition cycle policy; The target virtual machine is one of the virtual machines; The initial traffic acquisition cycle strategy includes at least one of the following: The virtual machine's agent module obtains traffic information from the storage and data retrieval module at an initial interval; The initial period during which the agent module of the virtual machine sends traffic information to the second device; The initial period for the first device to obtain traffic information from the second device.
3. The method for obtaining traffic information according to claim 1, characterized in that, The step of obtaining the first traffic acquisition cycle strategy corresponding to the virtual machine based on the target information and the initial traffic acquisition cycle strategy corresponding to the virtual machine includes: The initial traffic acquisition cycle strategy corresponding to the virtual machine is updated based on the target information to obtain the first traffic acquisition cycle strategy corresponding to the virtual machine. The network topology information includes at least one of the following: The type information of the virtual machine; the specification information of the virtual machine.
4. The method for obtaining traffic information according to claim 1, characterized in that, The target traffic acquisition cycle strategy includes at least one of the following: The period during which the proxy module in the target virtual machine obtains traffic information from the storage and data retrieval module; The period during which the proxy module in the target virtual machine sends traffic information to the second device; The period during which the first device obtains traffic information from the second device; The adjusted traffic acquisition cycle strategy includes at least one of the following: The adjusted period for the proxy module in the target virtual machine to obtain traffic information from the storage and data retrieval module; The adjusted period for the proxy module in the target virtual machine to send traffic information to the second device; The first device obtains the adjusted period of traffic information from the second device.
5. The method for obtaining traffic information according to claim 1, characterized in that, The method further includes: If no abnormal traffic event notification is received from the target virtual machine within a preset time period, target adjustment information is generated; The target adjustment information is sent to the second device, so that the second device sends the target adjustment information to the target virtual machine, and the target virtual machine adjusts the adjusted traffic acquisition cycle policy to the target traffic acquisition cycle policy according to the target adjustment information, so that the target virtual machine performs traffic monitoring according to the target traffic acquisition cycle policy.
6. A method for acquiring traffic information, characterized in that, Applied to the target virtual machine, the method includes: Receive target traffic acquisition periodic update information sent by the second device; The current target traffic acquisition cycle strategy is adjusted based on the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy; traffic monitoring is then performed based on the adjusted traffic acquisition cycle strategy. The target traffic acquisition periodic update information is generated by the first device based on the abnormal traffic event notification of the target virtual machine; Before receiving the target traffic acquisition periodic update information sent by the second device, the method further includes: The system receives a security policy and a corresponding first traffic acquisition cycle policy for the target virtual machine sent by the second device. The security policy for the target virtual machine is generated by the first device based on the traffic information of the target virtual machine and sent to the second device. The first traffic acquisition cycle policy for the target virtual machine is generated by the first device based on network topology information and an initial traffic acquisition cycle policy and sent to the second device. The network topology information is generated by the first device based on the traffic information of the virtual machine. Traffic monitoring is performed based on the security policy and the corresponding first traffic acquisition cycle policy of the target virtual machine. When abnormal traffic information of the target virtual machine is obtained by traffic monitoring according to the security policy, the abnormal traffic information of the target virtual machine is sent to the second device, so that the second device sends the abnormal traffic information of the target virtual machine to the first device, and the first device generates an abnormal traffic event notification of the target virtual machine based on the abnormal traffic information of the target virtual machine. The target virtual machine is one of the virtual machines; The first traffic acquisition cycle strategy corresponding to the target virtual machine includes: The identity identifier of the target virtual machine; The period during which the proxy module in the target virtual machine obtains traffic information from the storage and data retrieval module; The period during which the proxy module in the target virtual machine sends traffic information to the second device.
7. The method for obtaining traffic information according to claim 6, characterized in that, The target traffic acquisition cycle strategy includes at least one of the following: The period during which the proxy module in the target virtual machine obtains traffic information from the storage and data retrieval module; The period during which the proxy module in the target virtual machine sends traffic information to the second device; The adjusted traffic acquisition cycle strategy includes at least one of the following: The adjusted period for the proxy module in the target virtual machine to obtain traffic information from the storage and data retrieval module; The adjusted period for the proxy module in the target virtual machine to send traffic information to the second device.
8. The method for obtaining traffic information according to claim 6, characterized in that, Before receiving the target traffic acquisition periodic update information sent by the second device, the method further includes: The system receives the initial traffic acquisition period policy corresponding to the target virtual machine sent by the second device, wherein the initial traffic acquisition period policy corresponding to the target virtual machine is set by the first device and sent to the second device. Traffic monitoring is performed based on the initial traffic acquisition cycle strategy corresponding to the target virtual machine; The initial traffic acquisition period strategy corresponding to the target virtual machine includes at least one of the following: The initial period during which the proxy module of the target virtual machine obtains traffic information from the storage and data retrieval module; The initial period during which the agent module of the target virtual machine sends traffic information to the second device.
9. The method for obtaining traffic information according to claim 6, characterized in that, The method further includes: Receive target adjustment information sent by the second device; The adjusted traffic acquisition cycle strategy is adjusted to the target traffic acquisition cycle strategy based on the target adjustment information. Traffic monitoring is performed according to the target traffic acquisition cycle strategy; The target adjustment information is generated by the first device when it does not receive an abnormal traffic event notification from the target virtual machine within a preset time period, and then sent to the second device.
10. A method for acquiring traffic information, characterized in that, Applied to a second device, the method includes: The system receives target traffic acquisition periodic update information sent by a first device; the target traffic acquisition periodic update information is generated by the first device based on abnormal traffic event notifications from the target virtual machine. Send the target traffic acquisition cycle update information to the target virtual machine so that the target virtual machine can adjust the current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy, and make the target virtual machine follow the adjusted traffic acquisition cycle strategy. Before receiving the target traffic acquisition periodic update information sent by the first device, the method further includes: Receive the security policy corresponding to the virtual machine and the corresponding first traffic acquisition period policy sent by the first device; Send the corresponding security policy and the corresponding first traffic acquisition cycle policy to the virtual machine so that the virtual machine can perform traffic monitoring according to the corresponding security policy and the corresponding first traffic acquisition cycle policy. The system receives abnormal traffic information of the target virtual machine sent by the target virtual machine; the abnormal traffic information of the target virtual machine is obtained by the target virtual machine through traffic monitoring based on the security policy sent by the second device. Send abnormal traffic information of the target virtual machine to the first device, so that the first device generates an abnormal traffic event notification of the target virtual machine based on the abnormal traffic information; Wherein, the target virtual machine is one of the virtual machines, and the target traffic acquisition period strategy is a traffic acquisition period strategy in the first traffic acquisition period strategy; The first traffic acquisition cycle strategy includes: The identity identifier of the virtual machine; The period during which the proxy module in the virtual machine obtains traffic information from the storage and data retrieval module; The period during which the proxy module in the virtual machine sends traffic information to the second device.
11. The method for acquiring traffic information according to claim 10, characterized in that, Before receiving the target traffic acquisition periodic update information sent by the first device, the method further includes: The system receives the initial traffic acquisition period policy corresponding to the virtual machine sent by the first device; the initial traffic acquisition period policy corresponding to the virtual machine is set by the first device. Send the corresponding initial traffic acquisition cycle policy to the virtual machine so that the virtual machine can perform traffic monitoring according to the initial traffic acquisition cycle policy; The target virtual machine is one of the virtual machines; The initial traffic acquisition cycle strategy includes at least one of the following: The virtual machine's agent module obtains traffic information from the storage and data retrieval module at an initial interval; The virtual machine's agent module sends traffic information to the second device at an initial interval.
12. The method for acquiring traffic information according to claim 10, characterized in that, The method further includes: Receive target adjustment information sent by the first device; Send the target adjustment information to the target virtual machine, so that the target virtual machine adjusts the adjusted traffic acquisition cycle policy to the target traffic acquisition cycle policy according to the target adjustment information, and so that the target virtual machine performs traffic monitoring according to the target traffic acquisition cycle policy; The target adjustment information is generated by the first device when it does not receive an abnormal traffic event notification from the target virtual machine within a preset time period, and then sent to the second device.
13. A traffic flow information acquisition device, characterized in that, Applied to a first device, the device includes: The first acquisition module is used to acquire abnormal traffic event notifications of the target virtual machine; The first processing module is used to generate target traffic acquisition periodic update information based on the abnormal traffic event notification. The first sending module is used to send the target traffic acquisition cycle update information to the second device, so that the second device sends the target traffic acquisition cycle update information to the target virtual machine, and so that the target virtual machine adjusts the current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy, and so that the target virtual machine performs traffic monitoring according to the adjusted traffic acquisition cycle strategy. The first acquisition module includes: The first processing unit is configured to generate network topology information and a security policy corresponding to the virtual machine based on the traffic information of the virtual machine sent by the second device. The second processing unit is configured to obtain a first traffic acquisition cycle strategy corresponding to the virtual machine based on the target information and the initial traffic acquisition cycle strategy corresponding to the virtual machine; the target information includes at least one of the following: the network topology information; the traffic processing volume information of the virtual machine; and the workload information of the second device. The first sending unit is configured to send the security policy and the corresponding first traffic acquisition cycle policy of the virtual machine to the second device, so that the second device sends the corresponding security policy and the corresponding first traffic acquisition cycle policy to the virtual machine, and the virtual machine performs traffic monitoring according to the corresponding security policy and the corresponding first traffic acquisition cycle policy. The first acquisition unit is used to acquire abnormal traffic information of the target virtual machine sent by the second device. The abnormal traffic information is obtained by the target virtual machine through traffic monitoring according to the security policy corresponding to the target virtual machine sent by the second device, and then sent to the second device. The third processing unit is used to generate an abnormal traffic event notification for the target virtual machine based on the abnormal traffic information. Wherein, the target virtual machine is one of the virtual machines, and the target traffic acquisition period strategy is a traffic acquisition period strategy in the first traffic acquisition period strategy; The first traffic acquisition cycle strategy includes: The identity identifier of the virtual machine; The period during which the proxy module in the virtual machine obtains traffic information from the storage and data retrieval module; The period during which the proxy module in the virtual machine sends traffic information to the second device; The period during which the first device obtains traffic information from the second device.
14. A traffic flow information acquisition device, characterized in that, Applied to a target virtual machine, the apparatus includes: The first receiving module is used to receive target traffic acquisition periodic update information sent by the second device; The first adjustment module is used to adjust the current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy. The first monitoring module is used to monitor traffic according to the adjusted traffic acquisition cycle strategy. The target traffic acquisition periodic update information is generated by the first device based on the abnormal traffic event notification of the target virtual machine; The device further includes: The first target receiving module is configured to receive the security policy and the corresponding first traffic acquisition cycle policy of the target virtual machine sent by the second device. The security policy of the target virtual machine is generated by the first device based on the traffic information of the target virtual machine and sent to the second device. The first traffic acquisition cycle policy of the target virtual machine is generated by the first device based on the network topology information and the initial traffic acquisition cycle policy and sent to the second device. The network topology information is generated by the first device based on the traffic information of the virtual machine. The second target monitoring module is used to perform traffic monitoring based on the security policy corresponding to the target virtual machine and the corresponding first traffic acquisition cycle policy. The second information sending module is used to send the abnormal traffic information of the target virtual machine to the second device when abnormal traffic information of the target virtual machine is obtained by traffic monitoring according to the security policy, so that the second device sends the abnormal traffic information of the target virtual machine to the first device, and the first device generates an abnormal traffic event notification of the target virtual machine based on the abnormal traffic information of the target virtual machine. The target virtual machine is one of the virtual machines; The first traffic acquisition cycle strategy corresponding to the target virtual machine includes: The identity identifier of the target virtual machine; The period during which the proxy module in the target virtual machine obtains traffic information from the storage and data retrieval module; The period during which the proxy module in the target virtual machine sends traffic information to the second device.
15. A traffic flow information acquisition device, characterized in that, Applied to a second device, the device includes: The second receiving module is used to receive target traffic acquisition periodic update information sent by the first device; the target traffic acquisition periodic update information is generated by the first device based on the abnormal traffic event notification of the target virtual machine; The second sending module is used to send the target traffic acquisition cycle update information to the target virtual machine, so that the target virtual machine can adjust the current target traffic acquisition cycle strategy according to the target traffic acquisition cycle update information to obtain the adjusted traffic acquisition cycle strategy, and make the target virtual machine follow the adjusted traffic acquisition cycle strategy. The device further includes: The second target receiving module is used to receive the security policy corresponding to the virtual machine and the corresponding first traffic acquisition period policy sent by the first device; The first target sending module is used to send the corresponding security policy and the corresponding first traffic acquisition cycle policy to the virtual machine, so that the virtual machine can perform traffic monitoring according to the corresponding security policy and the corresponding first traffic acquisition cycle policy. The second information receiving module is used to receive abnormal traffic information of the target virtual machine sent by the target virtual machine; the abnormal traffic information of the target virtual machine is obtained by the target virtual machine through traffic monitoring according to the security policy sent by the second device; The fourth information sending module is used to send abnormal traffic information of the target virtual machine to the first device, so that the first device generates an abnormal traffic event notification of the target virtual machine based on the abnormal traffic information. Wherein, the target virtual machine is one of the virtual machines, and the target traffic acquisition period strategy is a traffic acquisition period strategy in the first traffic acquisition period strategy; The first traffic acquisition cycle strategy includes: The identity identifier of the virtual machine; The period during which the proxy module in the virtual machine obtains traffic information from the storage and data retrieval module; The period during which the proxy module in the virtual machine sends traffic information to the second device.
16. An electronic device, wherein the electronic device is a first device, comprising: A transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; characterized in that, when the processor executes the program or instructions, it implements the steps of the traffic information acquisition method as described in any one of claims 1 to 5.
17. A virtual machine, wherein the virtual machine is a target virtual machine, comprising: A transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; characterized in that, when the processor executes the program or instructions, it implements the steps of the traffic information acquisition method as described in any one of claims 6 to 9.
18. An electronic device, wherein the electronic device is a second device, comprising: A transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; characterized in that, when the processor executes the program or instructions, it implements the steps of the traffic information acquisition method as described in any one of claims 10 to 12.
19. A readable storage medium having a program or instructions stored thereon, characterized in that, When the program or instructions are executed by the processor, they implement the steps in the traffic information acquisition method as described in any one of claims 1 to 5, or implement the steps in the traffic information acquisition method as described in any one of claims 6 to 9, or implement the steps in the traffic information acquisition method as described in any one of claims 10 to 12.
Citation Information
Patent Citations
Method and system for traffic guidance
CN107846470A
Safety protection system, method and equipment and storage medium
CN109995794A