A secure network element arrangement method, device, equipment and readable storage medium
By integrating security management components into the cloud management platform, receiving and converting security network element orchestration requests, the problem of low security network element orchestration efficiency is solved, enabling efficient orchestration and flexible version upgrades of security network elements, simplifying operation and maintenance, and improving system stability and efficiency.
Patent Information
- Application Number
- CN202411327752.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-23
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2044-09-23
AI Technical Summary
Existing technologies suffer from low efficiency and error-prone nature in security element orchestration, making it impossible to deploy cloud security services efficiently and in compliance with regulations.
By integrating security management components into the cloud management platform, security network element orchestration requests are received, target security vendors are identified, and the requests are converted into vendor-recognizable instructions and sent to the security management components for orchestration. This enables flexible version upgrades and unified management of security network elements, real-time monitoring of virtual machine resources, and unified display of alarm information.
It enables efficient orchestration and flexible version upgrades of security network elements, simplifies operation and maintenance, and improves the efficiency of security network element orchestration and system stability.
Smart Images

Figure CN119182806B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, in particular to a security network element orchestration method and device, equipment and readable storage medium. BACKGROUND
[0002] With the rapid development of cloud computing and big data technology, enterprises gradually migrate to the cloud environment, and the deployment of cloud services becomes the norm. However, along with it comes the increasingly severe information security challenges, such as cloud WAF, load balancing, bastion machine, vulnerability scanning, log auditing and other security services must be efficiently and compliantly deployed to protect the data security of cloud tenants. The traditional way relies on manual creation of virtual machines in the cloud environment and installation and configuration of security network elements one by one, which is low in efficiency and prone to errors.
[0003] Therefore, how to improve the efficiency of security network element orchestration is a technical problem that those skilled in the art urgently need to solve. SUMMARY
[0004] Therefore, the purpose of the present application is to provide a security network element orchestration method, device, equipment and readable storage medium, which solves the technical problem of low efficiency of security network element orchestration in the prior art.
[0005] To solve the above technical problems, the present application provides a security network element orchestration method, comprising:
[0006] receiving a security network element orchestration request;
[0007] determining the target security vendor corresponding to the security network element orchestration request;
[0008] According to the target security vendor, the security network element orchestration request is converted into a target vendor identifiable instruction;
[0009] The target vendor identifiable instruction is sent to the corresponding security management component, so that the security management component orchestrates the security network element based on the target vendor identifiable instruction; wherein each security management component is a component that has integrated security network elements of each security vendor and is deployed in a cloud management platform.
[0010] On the one hand, the security network element orchestration request includes at least one of the following: registration of a security management component to a cloud management platform, life cycle management of a security network element, single sign-on function of a security network element, security network element authorization injection and unified management of security network element authorization.
[0011] On the one hand, determining the target security vendor corresponding to the security network element orchestration request comprises:
[0012] Determine the target security vendor corresponding to the security network element orchestration request according to the vendor in the security network element orchestration request; wherein the security network element orchestration request is a comprehensive instruction request including a security network element orchestration instruction and a vendor, and the security network element orchestration instruction is an instruction for determining an orchestration operation on a complete network element.
[0013] In one aspect, after sending the target vendor identifiable instruction to the corresponding security management component, further comprising:
[0014] Receiving a processing result of the security management component executing the target vendor identifiable instruction;
[0015] Converting the processing result into a set format processing result;
[0016] Determining whether the security network element orchestration is successful based on the set format processing result;
[0017] When it is not successful, determining to perform orchestration processing again based on the target vendor identifiable instruction.
[0018] In one aspect, sending the target vendor identifiable instruction to the corresponding security management component comprises:
[0019] Determining a latest version image of the security network element;
[0020] Sending the latest version image of the security network element to the corresponding security management component to replace a historical version security network element image with the latest version image of the security network element.
[0021] In one aspect, the security network element orchestration method further comprises:
[0022] Real-time monitoring of security network element virtual machine resources;
[0023] Obtaining monitoring information of the security network element virtual machine resources by using a security network element unified operation and maintenance method; wherein the monitoring information of the security network element virtual machine resources includes at least one of central processing unit usage, memory usage, number of disk read-write requests, network interface throughput, disk delay time, and number of attacks;
[0024] Determining threshold information corresponding to each monitoring information of the security network element virtual machine resources;
[0025] Comparing the monitoring information of the security network element virtual machine resources with the respective corresponding threshold information to determine a comparison result;
[0026] When it is determined according to the comparison result that the security network element virtual machine is abnormal, determining to send alarm information to the cloud management platform to enable the cloud management platform to uniformly visually display all the alarm information;
[0027] When it is determined that the security network element virtual machine is normal according to the comparison result, a continuous normal time of the security network element virtual machine is determined, and a security network element virtual machine resource monitoring time period is adjusted according to the continuous normal time.
[0028] In one aspect, after determining the target security vendor corresponding to the security network element orchestration request, the method further includes:
[0029] The cloud resource control instruction is sent to a cloud resource controller, so that the cloud resource controller controls the computing resource, the network resource and the storage resource, creates a virtual machine resource carrying the security network element, configures the virtual machine of the security network element, or recycles the virtual machine resource of the security network element.
[0030] Embodiments of the present application also provide a security network element orchestration device, which includes:
[0031] The security network element orchestration request receiving module is configured to receive a security network element orchestration request.
[0032] The target security vendor determining module is configured to determine a target security vendor corresponding to the security network element orchestration request.
[0033] The target vendor identifiable instruction determining module is configured to convert the security network element orchestration request into a target vendor identifiable instruction according to the target security vendor.
[0034] The target vendor identifiable instruction sending module is configured to send the target vendor identifiable instruction to a corresponding security management component, so that the security management component orchestrates the security network element based on the target vendor identifiable instruction.
[0035] Embodiments of the present application also provide a security network element orchestration device, which includes:
[0036] The memory is configured to store a computer program.
[0037] The processor is configured to execute the computer program to implement the steps of the above security network element orchestration method.
[0038] Embodiments of the present application also provide a readable storage medium, which stores a computer program.
[0039] Embodiments of the present application also provide a computer program product, which includes a computer program / instruction.
[0040] The embodiment of the present application aims to provide a secure network element arrangement method, device, equipment and readable storage medium, which can solve the technical problem of low efficiency of secure network element arrangement.
[0041] To solve the above technical problem, the embodiment of the present application provides a secure network element arrangement method, which can include: receiving a secure network element arrangement request; determining a target security manufacturer corresponding to the secure network element arrangement request; converting the secure network element arrangement request into a target manufacturer identifiable instruction according to the target security manufacturer; sending the target manufacturer identifiable instruction to a corresponding security management component, so that the security management component arranges the secure network element based on the target manufacturer identifiable instruction; wherein each security management component is a component of the cloud management platform, which has integrated secure network elements of each security manufacturer and is deployed.
[0042] As can be seen from the above technical solution, the beneficial effects of the present application are that: by integrating the secure network element in the security management component, the secure network element does not directly interact with the cloud management platform, which realizes the decoupling of the cloud management platform and the secure network element instance and the security manufacturer level, so that the secure network element can be arranged based on the security management component, which realizes flexible arrangement of the secure network element version, and the arrangement of all secure network elements can be realized, which simplifies the operation and maintenance work and improves the efficiency.
[0043] In addition, the present application also provides a secure network element arrangement device, equipment and readable storage medium, which also has the above beneficial effects. BRIEF DESCRIPTION OF DRAWINGS
[0044] In order to more clearly illustrate the embodiments of the present application, the drawings needed in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0045] Figure 1 A flowchart of a secure network element arrangement method provided by the embodiment of the present application;
[0046] Figure 2 A structural framework schematic diagram of a secure arrangement method provided by the embodiment of the present application;
[0047] Figure 3 A schematic diagram of distributing instructions to corresponding manufacturers provided by the embodiment of the present application;
[0048] Figure 4 A structural schematic diagram of a secure network element arrangement device provided by the embodiment of the present application;
[0049] Figure 5 A structural schematic diagram of a secure network element arrangement provided by the embodiment of the present application. Detailed Implementation
[0050] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of the present invention.
[0051] The terms "comprising" and "having," and any variations thereof, in the specification and accompanying drawings of this invention are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may include steps or units not listed.
[0052] To enable those skilled in the art to better understand the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0053] Next, a flowchart of a security network element orchestration method provided by an embodiment of the present invention will be described in detail. Figure 1 A flowchart of a security network element orchestration method provided in an embodiment of the present invention, the security network element orchestration method may include:
[0054] S101, Receive security network element orchestration request.
[0055] The execution subject of this embodiment is an electronic device. This electronic device can be a computer, mobile phone, cloud platform, etc. This embodiment does not limit the specific security network element orchestration request. The security network element orchestration request in this embodiment can be adding a security network element; or it can be deleting a security network element; or it can be a security network element single sign-on function. This embodiment does not limit the specific format of the security network element orchestration request. For example, the security network element orchestration request in this embodiment can include a security vendor and specific security network element orchestration instructions; or it can be a security network element orchestration request, with the corresponding security network element security vendor identified on the security network element orchestration request. It is understood that this embodiment can assemble the function of receiving security network element orchestration requests into a separate component, for example, as a submodule of the security network element capability standardization engine, responsible for receiving various security network element orchestration requests.
[0056] It needs to be further explained that, in order to improve the efficiency of the security network element arrangement, the above security network element arrangement request can include at least one of the following: registration of a security management component to a cloud management platform, life cycle management of the security network element, single sign-on function of the security network element, security network element authorization injection, and unified management of security network element authorization. In this embodiment, the registration of the security management component to the cloud management platform is a key step to ensure that the enterprise security policy is effectively implemented, and a comprehensive cloud management platform is established to realize centralized management, policy execution, situation awareness and rapid response of cloud security services, which is crucial for maintaining the security of the enterprise's cloud environment. The life cycle management of the security network element in this embodiment refers to the security management and control of the entire process from creation to destruction of the security network element, to ensure that it can maintain security and compliance at each stage. The single sign-on function of the security network element in this embodiment is an important technology in network security management, which allows users to access all mutually trusted application systems after a single authentication in multiple application systems, without the need to repeatedly input login credentials. The single sign-on function of the security network element not only improves user experience, but also reduces the risk of password leakage and enhances system security. The security network element authorization injection in this embodiment refers to injecting code or commands into an application program to obtain permissions or data access. The unified management of security network element authorization in this embodiment refers to centralized management of the authorization operations of various security network elements (such as firewalls, intrusion detection systems, security event management systems, etc.) within an enterprise through a unified security management platform, to ensure that only authorized users can access and operate system resources. The embodiments of the present application provide a variety of security network element arrangement requests, so that the method provided by the present application can complete a variety of security network element arrangement requests, improving the diversity of security network element arrangement.
[0057] S102, determine the target security vendor corresponding to the security network element arrangement request.
[0058] This embodiment does not limit the specific way of determining the target security vendor corresponding to the security network element arrangement request. For example, this embodiment can determine the target security vendor from the vendor part in the security network element arrangement request; or this embodiment can also determine the target security vendor according to the vendor identifier carried by the security network element arrangement request. The reason why this embodiment determines the target security vendor is to convert the specific operation instructions for the security network element in the security network element arrangement request into instructions that the vendor can recognize.
[0059] It needs to be further explained that, in order to improve the efficiency of the manufacturer determination, the above-mentioned determination of the target security manufacturer corresponding to the security network element arrangement request can include: determining the target security manufacturer corresponding to the security network element arrangement request according to the manufacturer in the security network element arrangement request; wherein the security network element arrangement request is a comprehensive instruction request including a security network element arrangement instruction and a manufacturer, and the security network element arrangement instruction is an instruction for determining the arrangement operation of the complete network element. This embodiment can directly determine the target security manufacturer according to the manufacturer in the security network element arrangement request, thereby improving the accuracy of the determination of the target security manufacturer.
[0060] It needs to be further explained that, after determining the target security manufacturer corresponding to the security network element arrangement request, the cloud resource controller can be instructed to control the computing resources, network resources and storage resources to create virtual machine resources carrying the security network element, configure the virtual machine of the security network element, or recycle the virtual machine resources of the security network element. At this time, after the manufacturer is determined, the security network element corresponding to the manufacturer can be determined, so that the virtual machine resources are dynamically created, configured and optimized by the cloud resource controller, thereby effectively supporting the operation of the security network element. This centralized and automated resource management method not only improves the efficiency of resource use, but also enhances the security and reliability of the system.
[0061] S103, converting the security network element arrangement request into a target manufacturer recognizable instruction according to the target security manufacturer.
[0062] This embodiment can use a separate component to realize the function of converting the security network element arrangement request into a target manufacturer recognizable instruction according to the target security manufacturer, for example, the name of the component can be a security service management capability driver plug-in sub-module, so that it can be connected and interacted with different security manufacturers.
[0063] S104, sending the target manufacturer recognizable instruction to the corresponding security management component to arrange the security network element based on the target manufacturer recognizable instruction; wherein each security management component is a component that has integrated the security network element of each security manufacturer and is deployed in the cloud management platform.
[0064] The security management component in this embodiment is responsible for the actual management of its security network element, and the cloud management platform only interacts with the security management component of each manufacturer, thereby reducing the functional coupling between the cloud management platform and the security network element. This embodiment does not limit the specific method of deploying the security network element in the cloud management platform, for example, this embodiment can deploy the security network element in the cloud management platform in a containerized manner; or this embodiment can also deploy the security network element in the cloud management platform in a virtual machine manner.
[0065] It needs to be further explained that in order to realize the upgrade of the security network element, the above sending the target manufacturer identifiable instruction to the corresponding security management component can include: determining the latest version image of the security network element;
[0066] Sending the latest version image of the security network element to the corresponding security management component to replace the historical version security network element image with the latest version image of the security network element. This embodiment sends the latest version image of the security network element to the corresponding security management component, so that the security management component can upgrade the security network element according to the latest version image of the security network element.
[0067] It needs to be further explained that in order to improve the experience of the user, after sending the target manufacturer identifiable instruction to the corresponding security management component, it can further include:
[0068] S1: receiving a processing result of the security management component executing the target manufacturer identifiable instruction;
[0069] S2: format conversion is performed on the processing result to obtain a set format processing result;
[0070] S3: determining whether the security network element orchestration is successful based on the set format processing result;
[0071] S4: when it is unsuccessful, determining to re-orchestrate based on the target manufacturer identifiable instruction.
[0072] This embodiment does not limit the specific processing result. For example, the processing result in this embodiment can be orchestration success; or the processing result can also be orchestration failure; or the processing result can also be orchestration after cleaning up the memory. This embodiment receives the processing result of the security management component executing the target manufacturer identifiable instruction, so as to determine whether the security network element orchestration instruction is successfully executed based on the processing result, and if not, re-orchestrate in time, thereby preventing the security network element orchestration from failing and improving the experience of the user.
[0073] It needs to be further explained that the above-mentioned security network element arrangement method can further include: monitoring the security network element virtual machine resources in real time; obtaining the monitoring information of the security network element virtual machine resources by using the security network element unified operation and maintenance method; wherein the monitoring information of the security network element virtual machine resources includes at least one of central processing unit usage, memory usage, number of disk read-write requests, network interface throughput, disk delay time and attack times; determining the threshold information corresponding to the monitoring information of each security network element virtual machine resource; comparing the monitoring information of the security network element virtual machine resources with the respective corresponding threshold information to determine the comparison result; when it is determined that the security network element virtual machine is abnormal according to the comparison result, it is determined that the alarm information is sent to the cloud management platform, so that the cloud management platform uniformly visualizes all the alarm information; when it is determined that the security network element virtual machine is normal according to the comparison result, the continuous normal time of the security network element virtual machine is determined, and the security network element virtual machine resource monitoring time period is adjusted according to the continuous normal time.
[0074] The embodiment first needs to obtain key monitoring information from each secure network element virtual machine resource. These monitoring information includes but is not limited to central processing unit (CPU) usage, memory usage, number of disk read and write requests, network interface throughput, disk delay time, and number of attacks, etc. These data are key indicators for evaluating system performance and security. For the monitoring information of each secure network element virtual machine resource, the corresponding threshold information needs to be set. These thresholds are obtained according to system performance requirements, security standards and historical data analysis, which are used to judge whether the system is in normal state. For example, the normal threshold of CPU usage may be set to 70%, which means that the system load is too high. Compare the obtained monitoring information of the secure network element virtual machine resource with the corresponding threshold information to determine the current running state of the system. The comparison result will directly reflect whether there is a potential problem or abnormality in the system. According to the comparison result, when the behavior of the secure network element virtual machine is found to be abnormal, alarm information needs to be generated. These alarm information contains key information such as specific description of abnormality, occurrence time, possible impact range, etc. The generated alarm information is sent to the cloud management platform. The cloud management platform is responsible for unified management and visualization display of all alarm information, so that the administrator can quickly understand the problems existing in the system and take corresponding measures. On the cloud management platform, all alarm information will be displayed in a visual form, such as charts, dashboards, etc., which facilitates the administrator to monitor the system state in real time and timely discover and solve problems. The embodiment will monitor the virtual resources of the secure network element, prevent the secure network element virtual machine resources from being abnormal, and cause the secure network element to be unable to use, and when the real-time monitoring of the secure network element virtual machine resources is just started, the monitoring time period of the secure network element virtual machine resources will be adjusted when it is determined that the continuous normal time exceeds a certain length of time. The adjustment of the monitoring period is based on the evaluation of the continuous normal time, which can more flexibly allocate monitoring resources, so as to optimize the performance of the monitoring system while ensuring security. For example, if a secure network element virtual machine has not appeared abnormal situation for a month, the interval time of monitoring check can be appropriately prolonged (increased to once every minute) to reduce the pressure of the system. Such adjustment not only can improve the efficiency of monitoring work, but also can avoid unnecessary waste of resources. The embodiment realizes the unified operation and maintenance management of the secure network element virtual machine resources, improves the efficiency and accuracy. Through real-time monitoring and rapid response, system failures can be effectively prevented and reduced, and the stable operation of the system is ensured. At the same time, unified visualization display enables the administrator to more intuitively understand the system state, providing strong support for decision-making.
[0075] It needs to be further explained that when there are multiple security network elements that need to be arranged, the above sending the target manufacturer identifiable instruction to the corresponding security management component can include: determining an arrangement order of the security network elements according to real-time network states, security requirements and performance data of the security network elements of each manufacturer, sending the target manufacturer identifiable instruction and the arrangement order of the security network elements to the security management component, so that the security management component arranges according to the arrangement order of the security network elements, and ensures that the use efficiency of resources is optimized while meeting the security requirements. The embodiment does not limit the specific real-time network state. For example, the real-time network state in the embodiment can be the type of network attack, at which time the arrangement order of the security network elements that can defend against the attack can be selected as the first level, or the real-time network state in the embodiment can also be network performance, at which time the security network elements that can be quickly installed can be selected as the first level. The security requirements of the embodiment are user-defined requirements, and the embodiment does not limit the specific security requirements. For example, the security requirements of the embodiment can be specific defenses that need to be implemented. The performance data of the security network elements of each manufacturer in the embodiment indicates the advantages and characteristics of each manufacturer in their respective security fields. For example, when a DDoS (Distributed Denial of Service) attack is detected, the algorithm can preferentially arrange network element devices with DDoS defense functions. The embodiment enables the security network elements to be arranged in order, preventing resource preemption.
[0076] It needs to be further explained that the embodiment can also collect real-time data from the security network elements, including performance indicators, fault information, etc., predict potential security problems through machine learning analysis, and dynamically adjust the arrangement strategy to prevent or mitigate security incidents.
[0077] The security network element arrangement method provided by the embodiment of the application can include: S101, receiving a security network element arrangement request; S102, determining a target security manufacturer corresponding to the security network element arrangement request; S103, converting the security network element arrangement request into a target manufacturer identifiable instruction according to the target security manufacturer; S104, sending the target manufacturer identifiable instruction to a corresponding security management component, so that the security management component arranges the security network elements based on the target manufacturer identifiable instruction; wherein each security management component is a component that has integrated the security network elements of each security manufacturer and is deployed in a cloud management platform. The embodiment of the application integrates the security network elements in the security management component, so that the security network elements do not directly interact with the cloud management platform, realizes decoupling of the cloud management platform and the security network element instances and the security manufacturer level, and thus the security network elements can be arranged based on the security management component, realizing flexible upgrade and configuration management of the security network element version, and all security network element arrangements can be realized, simplifying operation and maintenance work and improving the efficiency of security network element arrangement.
[0078] In order to make the application more convenient to understand, please refer to the specificFigure 2 , Figure 2 The structural framework of the security arrangement method provided by the embodiment of the present application is shown in the figure, and can specifically include:
[0079] As shown in the figure, Figure 2 The embodiment of the present application integrates security management components of different manufacturers and designs a security capability standardization engine submodule and a security service management capability driving plug-in submodule of a cloud management platform, the cloud management platform implements the issuing and management functions of security network elements through the security management components of different manufacturers, and the decoupling of the cloud management platform and the security network element instance and the security manufacturer management level is realized without direct interaction with the security network element instance, the security network element version flexible upgrade and configuration management of the cloud management platform can be realized through the standardization and low coupling design, and the unified operation and maintenance of the network element is realized through the collection of network element virtual machine resource monitoring information by the unified operation and maintenance submodule of the security network element and the reporting of network element alarm information through the standard SNMP protocol.
[0080] 1) Security management component: each security manufacturer provides a security management component, which is deployed in a containerized manner to the container base of the cloud management platform, and each security management component of the security manufacturer is responsible for the actual management of its security network element, the cloud management platform only interacts with the security management component of each manufacturer, and the functional coupling between the cloud management platform and the security network element is reduced;
[0081] The security network element instance of manufacturer A in the embodiment includes WAF (firewall), log audit, bastion host, and other network elements.
[0082] 2) Containerized deployment of security management component: the security management components of different manufacturers are deployed in a containerized manner, and run in the cloud management platform management node based on a pod (container), which simplifies the network topology of the cloud platform;
[0083] 3) Security network element capability standardization engine submodule: the security capability standardization engine layer of the cloud management platform defines the security atomic capabilities (i.e. the function requests used by each security network element) required by the security cloud management platform network element, including the registration of the security management component to the cloud management platform, the life cycle management (CRUD) of the security network element, the single sign-on function of the security network element, the security network element authorization injection, the unified management of security authorization, etc., and the functions can be extended as needed;
[0084] 4) Security service management capability driving plug-in sub-module: different drives defined by the cloud management platform driving layer interact with the security management components of different security manufacturers, the driving layer serves as a conversion layer between the security capability standardization engine sub-module and the security management components provided by the manufacturers, responsible for converting the operation instructions (such as creating a security network element) of the security capability standardization engine sub-module into instructions or APIs (interfaces) recognizable by different manufacturer security management components, and converting the differentiated messages fed back by different manufacturer security management component interfaces into messages in the format required by the security capability standardization engine sub-module;
[0085] 5) Security network element image management sub-module: there are different security network element virtual machine images of different manufacturers, when a network element image needs to be upgraded, a new image can be registered to the security network element image management sub-module to realize on-demand version upgrade of the network element; when upgrading is needed, the security network element capability standardization engine sub-module creates a security network element, pulls the image from the security network element image management sub-module, and sends the instructions to the security service management capability driving plug-in sub-module (plugin) and to the security management component.
[0086] 6) Standardized interface and manufacturer neutrality: the security network element adopts a security manufacturer master version (the master version can be understood as a basic version, which is used by each version of the security network element), without customized interface development, but through the security management component provided by the manufacturer to interface with the cloud management platform, the cloud management platform and the security network element are decoupled, and the security network element can be upgraded immediately with the manufacturer version;
[0087] 7) Security network element unified operation and management sub-module: for the security network element virtual machine instance, the CPU (central processing unit), memory, hard disk, network card and the like are monitored in real time; at the same time, the alarms generated by the security network element itself are collected to the cloud platform monitoring alarm, so that the user can grasp the running state of the network element in a timely manner (the security network element generates an alarm and pushes it to the cloud management platform, and the cloud management platform displays unified alarms).
[0088] In order to make the application more convenient to understand, the security arrangement method provided by the embodiment of the application can specifically include the following steps:
[0089] Step one: the user operates through the security capability interaction layer, or interacts with the third-party system outside the cloud management platform, and determines the security network element arrangement request.
[0090] Step two: after receiving the security network element arrangement request, the security capability standardization engine sub-module analyzes the security network element arrangement, obtains the corresponding manufacturer, and calls the corresponding driving program.
[0091] The security capability standardization engine submodule in the embodiment is a standard capability definition layer, defines standard security atomic capabilities for a security capability interaction layer in an upper layer to call, and shields differences between security management components of different security vendors in a bottom layer. When the security capability standardization engine submodule interacts with the security service management capability driving plug-in submodule, the security capability standardization engine submodule delivers a security atomic capability operation instruction to the driving layer in a comprehensive instruction mode of <atomic operation instruction, vendor>, and the driving layer identifies a target security vendor security management plug-in to be operated through the comprehensive instruction. The standard security atomic capabilities include: security vendor security management component registration, security network element life cycle management (security network element addition, deletion, modification, and query), security network element single sign-on, security network element authorization injection, security network element unified authorization management (unified authorization tracking, unified authorization display, and unified authorization deletion), and the like. Meanwhile, the security capability standardization engine submodule interacts with the security network element mirror management submodule, pulls a virtual machine image of a corresponding security network element from the security network element mirror management submodule when performing an atomic operation of adding a security network element, and uses the virtual machine image to create a virtual machine resource that carries the security network element. The security capability standardization engine submodule interacts with a cloud resource controller, is responsible for delivering cloud resource related instructions to the cloud resource controller when performing atomic operations such as adding, deleting, modifying, and querying a security network element, and controls computing, network, storage, and other cloud basic resources of the cloud resource controller to create a virtual machine resource that carries the security network element, and configures the virtual machine of the security network element or recycles the virtual machine resource of the security network element.
[0092] Step three, the security service management capability driving plug-in submodule converts the standardized security atomic operation instruction into an instruction recognizable by each vendor security management component and delivers the instruction to perform related operations of the security network element. As shown in Figure 3 Figure 3 A schematic diagram for distributing an instruction to a corresponding vendor is provided in the embodiment. The security atomic capability driving adapter of the security service management capability driving plug-in submodule receives a comprehensive instruction delivered by the security capability standardization engine submodule, for example, <create a security network element, A> parses the comprehensive instruction to identify that the atomic instruction is an A vendor security network element asset creation instruction, and then the security atomic capability driving adapter forwards the instruction to a corresponding vendor driving plug-in. After receiving the atomic instruction, the corresponding vendor driving plug-in is responsible for converting the atomic instruction into an instruction recognizable by a corresponding vendor security management component and delivering the instruction to the security management component of the corresponding vendor. The driving plug-in of the security service management capability driving plug-in submodule is designed in a pluggable mode, can be extended according to actual needs, and when a security management component of a bottom layer vendor is added, only a corresponding driving plug-in needs to be added to realize decoupling with the upper layer standardization engine layer.
[0093] Step four, the operation result of the security atomic capability executed by the vendor security management component is returned to the security capability standardization engine submodule through the vendor driver plug-in, and after processing in a unified format, the security capability standardization engine submodule is notified, and the result feedback is completed.
[0094] Step five, after the security network element is created successfully, the security network element reports alarm data of a system thereof to the security network element unified operation and maintenance submodule through a standard SNMP protocol (simple network management protocol), and meanwhile, the security network element unified operation and maintenance submodule collects monitoring information (CPU, memory, storage and the like) of a virtual machine resource bearing the security network element, so as to realize unified monitoring and alarm of the security network element.
[0095] Step six, different security network element images of different vendors are stored through the security network element image management submodule, the security network element capability standardization engine submodule interacts with the security network element image management submodule to pull the image of the corresponding security network element of the corresponding vendor to create the virtual machine resource bearing the security network element when the security network element is created; when it is needed to upgrade the version of the security network element, the image of the new version is directly uploaded to the security network element image management submodule and replaces the corresponding image of the old version, so that the rapid iterative upgrade of the version of the security network element can be realized.
[0096] The embodiment of the application defines the unified security network element life cycle management, authorization management and the like standard security atomic capability through the security capability standardization engine submodule, realizes the decoupling of the standardization security atomic capability of the cloud management platform standardization engine submodule and the security management capability of the bottom layer different security vendors through the standardized interface and the driver plug-in submodule, interacts with the security management component of the security vendor through the driver plug-in, converts the differentiating instructions of different security vendors into the standard instructions recognizable by the cloud management platform, simultaneously defines the pluggable driver plug-in of different security vendors, can flexibly interface different security vendors on demand, only needs to develop the corresponding driver plug-in to interface the new vendor, and greatly reduces the integration workload. Overall, the cloud management platform simplifies the automatic allocation and management process of the security network element instance of the cloud tenant, realizes the standardization adaptation of the cloud management platform and the network element.
[0097] The security network element arrangement device provided by the embodiment of the application is described below, and the security network element arrangement device described below can be correspondingly referred to the security network element arrangement method described above.
[0098] Figure 4 The structure diagram of the security network element arrangement device provided by the embodiment of the application can specifically include:
[0099] The security network element arrangement request receiving module 100 is used for receiving the security network element arrangement request.
[0100] The target security vendor determination module 200 is configured to determine a target security vendor corresponding to the security network element orchestration request.
[0101] The target vendor identifiable instruction determination module 300 is configured to convert the security network element orchestration request into a target vendor identifiable instruction according to the target security vendor.
[0102] The target vendor identifiable instruction sending module 400 is configured to send the target vendor identifiable instruction to a corresponding security management component, so that the security management component orchestrates a security network element based on the target vendor identifiable instruction. Each security management component is a component of the cloud management platform, which has integrated security network elements of each security vendor and is deployed in the cloud management platform.
[0103] Further, based on the above embodiments, the security network element orchestration request includes at least one of the following: registration of a security management component to the cloud management platform, lifecycle management of a security network element, single sign-on function of a security network element, security network element authorization injection, and unified management of security network element authorization.
[0104] Further, based on any of the above embodiments, the target security vendor determination module 200 can include:
[0105] A target security vendor determination unit is configured to determine the target security vendor corresponding to the security network element orchestration request according to a vendor in the security network element orchestration request. The security network element orchestration request is a comprehensive instruction request including a security network element orchestration instruction and a vendor. The security network element orchestration instruction is an instruction for determining an orchestration operation of a complete network element.
[0106] Further, based on any of the above embodiments, the security network element orchestration apparatus can further include:
[0107] A processing result determination module is configured to receive a processing result of the security management component executing the target vendor identifiable instruction.
[0108] A format conversion module is configured to perform format conversion on the processing result to obtain a set-format processing result.
[0109] A judgment module is configured to determine whether the security network element orchestration is successful based on the set-format processing result.
[0110] A re-orchestration module is configured to, when the orchestration is not successful, determine to re-orchestrate based on the target vendor identifiable instruction.
[0111] Further, based on any of the above embodiments, the target vendor identifiable instruction sending module 400 can include:
[0112] A security network element latest version image determination unit is configured to determine a security network element latest version image.
[0113] A security network element updating unit is configured to send the security network element latest version image to a corresponding security management component to replace a historical version security network element image with the security network element latest version image.
[0114] Further, based on any of the above embodiments, the security network element orchestration apparatus can further include:
[0115] A resource monitoring module is configured to monitor security network element virtual machine resources in real time.
[0116] A monitoring information acquisition module is configured to acquire monitoring information of security network element virtual machine resources by using a security network element unified operation and maintenance method, wherein the monitoring information of the security network element virtual machine resources includes at least one of central processing unit usage, memory usage, the number of disk read / write requests, network interface throughput, disk delay time, and the number of attacks.
[0117] A threshold information determination module is configured to determine threshold information corresponding to the monitoring information of each of the security network element virtual machine resources.
[0118] A comparison result determination module is configured to compare the monitoring information of the security network element virtual machine resources with the respective corresponding threshold information to determine a comparison result.
[0119] An alarm information sending module is configured to determine to send alarm information to the cloud management platform to enable the cloud management platform to uniformly visually display all alarm information when it is determined according to the comparison result that the security network element virtual machine is abnormal.
[0120] A time period adjustment module is configured to determine a continuous normal time of the security network element virtual machine when it is determined according to the comparison result that the security network element virtual machine is normal, and to adjust a security network element virtual machine resource monitoring time period according to the continuous normal time.
[0121] Further, based on any of the above embodiments, the security network element orchestration apparatus can further include:
[0122] A resource control module is configured to send cloud resource instructions to a cloud resource controller to enable the cloud resource controller to control computing resources, network resources, and storage resources, to create virtual machine resources carrying security network elements, to change configurations of the virtual machine of the security network element, or to recycle the virtual machine resources of the security network element.
[0123] It should be noted that the order of the modules and units in the security network element orchestration apparatus described above can be changed without affecting the logic.
[0124] Figure 4 The description of the features in the corresponding embodiments can be referred to Figure 4 The related description of the corresponding embodiments will not be repeated here.
[0125] The security network element arrangement device provided by the embodiment of the application can include: a security network element arrangement request receiving module 100, configured to receive a security network element arrangement request; a target security manufacturer determining module 200, configured to determine a target security manufacturer corresponding to the security network element arrangement request; a target manufacturer identifiable instruction determining module 300, configured to convert the security network element arrangement request into a target manufacturer identifiable instruction according to the target security manufacturer; and a target manufacturer identifiable instruction sending module 400, configured to send the target manufacturer identifiable instruction to a corresponding security management component, so that the security management component arranges security network elements based on the target manufacturer identifiable instruction. Each security management component is a component of a cloud management platform, in which each security manufacturer's security network element has been integrated. The security network elements are not directly interacted with the cloud management platform by being integrated in the security management component, which realizes decoupling of the cloud management platform and the security network element instance and the security manufacturer level, so that the security network elements can be arranged based on the security management component, security network element version flexible upgrading and configuration management are realized, and the arrangement of all security network elements can be realized, which simplifies operation and maintenance work and improves the efficiency of security network element arrangement.
[0126] Next, a security network element arrangement device provided by the embodiment of the application is introduced. The security network element arrangement device described below can be correspondingly referred to the security network element arrangement method described above.
[0127] Figure 5 A structural schematic diagram of the security network element arrangement provided by the embodiment of the application is shown in FIG. 1, which includes a memory 60 for storing a computer program. Figure 5
[0128] A processor 61 is configured to execute the computer program to realize the steps of the security network element arrangement method of the above-described embodiment.
[0129] The security network element arrangement device provided by the embodiment of the application can include but is not limited to a smart phone, a tablet computer, a notebook computer, a desktop computer, and the like.
[0130] The processor 61 can include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 61 can be implemented in at least one of a hardware form of a digital signal processing (DSP), a field-programmable gate array (FPGA), a programmable logic array (PLA). The processor 61 can also include a main processor and a coprocessor. The main processor is a processor for processing data in an awake state, also known as a central processing unit (CPU). The coprocessor is a low-power processor for processing data in a standby state. In some embodiments, the processor 61 can be integrated with a graphics processing unit (GPU) that is responsible for rendering and drawing content required to be displayed by the display screen. In some embodiments, the processor 61 can further include an artificial intelligence (AI) processor for processing computing operations related to machine learning.
[0131] The memory 60 can include one or more computer-readable storage media that can be non-transitory. The memory 60 can further include a high-speed random access memory, and a nonvolatile memory such as one or more disk storage devices, flash storage devices. In this embodiment, the memory 60 is at least used to store the following computer program 601, wherein the computer program is loaded and executed by the processor 61, and can implement the related steps of the security network element orchestration method disclosed in any of the preceding embodiments. In addition, the resources stored by the memory 60 can further include an operating system 602 and data 603, etc., and the storage manner can be temporary storage or permanent storage. The operating system 602 can include Windows, Unix, Linux, etc. The data 603 can include, but is not limited to, security network element orchestration data, etc.
[0132] In some embodiments, the security network element orchestration device can further include a display screen 62, an input / output interface 63, a communication interface 64, a power supply 65, and a communication bus 66.
[0133] Those skilled in the art can understand that, Figure 5 The structure shown in the figure does not constitute a limitation on the security network element orchestration device, and can include more or fewer components than those shown in the figure.
[0134] It can be understood that if the security network element arrangement method in the above embodiments is implemented in the form of a software function unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and performs all or part of the steps of the method of each embodiment of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (Read-Only Memory, ROM), a random access memory (Random Access Memory, RAM), an electrically erasable programmable ROM, a register, a hard disk, a removable magnetic disk, a CD-ROM, a magnetic disk or an optical disk, and various media that can store program codes.
[0135] Based on this, the embodiment of the present application further provides a computer readable storage medium, and the computer readable storage medium stores a computer program. The computer program is executed by a processor to implement the steps of the above security network element arrangement method.
[0136] The embodiment of the present application further provides a computer program product, which includes computer programs / instructions. The computer programs / instructions are executed by a processor to implement the steps of the above security network element arrangement method.
[0137] The above describes in detail the security network element arrangement method, device, equipment and readable storage medium provided by the embodiment of the present application. The embodiments in the specification are described in a progressive manner, and each embodiment mainly describes the difference from other embodiments. The same and similar parts of each embodiment can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the related parts can be referred to the method part.
[0138] The skilled person can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in electronic hardware, computer software or a combination of the two. In order to clearly show the interchangeability of hardware and software, the components and steps of each example have been described in the above description. Whether the functions are executed in hardware or software depends on the specific application and design constraints of the technical solutions. The skilled person can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0139] The above describes in detail the method, device, equipment and readable storage medium for the safe network element arrangement provided by the present application. The principle and implementation mode of the present application are described by applying specific examples, and the above description of the examples is only used to help understand the method of the present application and its core idea. It should be pointed out that, for ordinary skilled persons in the technical field, some improvements and modifications can be made to the present application without departing from the principle of the present application, and these improvements and modifications also fall within the protection scope of the claims of the present application.
Claims
1. A method for arranging security network elements, characterized in that, The method comprises the following steps: receiving a security network element orchestration request; the security network element orchestration request comprises at least one of the following: security management component registration to a cloud management platform, life cycle management of a security network element, single sign-on function of a security network element, security network element authorization injection, and unified management of security network element authorization; determining a target security vendor corresponding to the security network element orchestration request; converting the security network element orchestration request into a target vendor identifiable instruction according to the target security vendor; sending the target vendor identifiable instruction to a corresponding security management component, so that the security management component orchestrates a security network element based on the target vendor identifiable instruction; each security management component is a component that has integrated security network elements of each security vendor and is deployed on a cloud management platform; security management components of different vendors are deployed in containers and run in the containers on the cloud management platform management node; wherein sending the target vendor identifiable instruction to the corresponding security management group comprises: determining an orchestration sequence of the security network element according to real-time network state, security requirements, and performance data of security network elements of each vendor, sending the target vendor identifiable instruction and the orchestration sequence of the security network element to the security management component, so that the security management component orchestrates according to the orchestration sequence of the security network element.
2. The method of claim 1, wherein, determining a target security vendor corresponding to the security network element orchestration request comprises: determining the target security vendor corresponding to the security network element orchestration request according to the vendor in the security network element orchestration request; wherein the security network element orchestration request is a comprehensive instruction request comprising a security network element orchestration instruction and a vendor, and the security network element orchestration instruction is an instruction for determining orchestration operations on a complete network element. 3.The method of claim 1 or 2, wherein, after sending the target vendor identifiable instruction to the corresponding security management component, the method further comprises: receiving a processing result of the target vendor identifiable instruction executed by the security management component; format-converting the processing result to obtain a set-format processing result; determining whether the security network element orchestration is successful based on the set-format processing result; when it is unsuccessful, determining to re-orchestrate based on the target vendor identifiable instruction.
4. The method of claim 1, wherein, sending the target vendor identifiable instruction to the corresponding security management component comprises: determining a latest version image of the security network element; sending the latest version image of the security network element to the corresponding security management component to replace a historical version security network element image with the latest version image of the security network element.
5. The method of claim 1, wherein, The security network element orchestration method further comprises: real-time monitoring of security network element virtual machine resources; obtaining monitoring information of the security network element virtual machine resources by using a security network element unified operation and maintenance method; wherein the monitoring information of the security network element virtual machine resources comprises at least one of the following: central processing unit usage, memory usage, number of disk read-write requests, network interface throughput, disk delay time, and number of attacks; determining threshold information corresponding to each monitoring information of the security network element virtual machine resources; comparing the monitoring information of the security network element virtual machine resources with the respective corresponding threshold information to determine a comparison result; When it is determined that the security network element virtual machine is abnormal according to the comparison result, it is determined to send alarm information to the cloud management platform, so that the cloud management platform uniformly visualizes all the alarm information; When it is determined that the security network element virtual machine is normal according to the comparison result, the continuous normal time of the security network element virtual machine is determined, and the security network element virtual machine resource monitoring time period is adjusted according to the continuous normal time.
6. The method of claim 1, wherein, After determining the target security vendor corresponding to the security network element arrangement request, further comprising: The cloud resource controller is instructed to control the computing resource, the network resource and the storage resource, to create the virtual machine resource bearing the security network element, to configure the virtual machine of the security network element, or to recycle the virtual machine resource of the security network element.
7. A secure network element orchestration apparatus, characterized in that, Comprise: The security network element arrangement request receiving module is used for receiving the security network element arrangement request; The security network element arrangement request comprises at least one of the security management component registration to the cloud management platform, the life cycle management of the security network element, the single sign-on function of the security network element, the security network element authorization injection and the unified management of the security network element authorization; The target security vendor determination module is used for determining the target security vendor corresponding to the security network element arrangement request; The target vendor identifiable instruction determination module is used for converting the security network element arrangement request into the target vendor identifiable instruction according to the target security vendor; The target vendor identifiable instruction sending module is used for sending the target vendor identifiable instruction to the corresponding security management component, so that the security management component arranges the security network element based on the target vendor identifiable instruction; wherein each security management component is a component integrated with the security network element of each security vendor and deployed in the cloud management platform; the security management components of different vendors are containerized deployed and run in the cloud management platform management node based on the container; The target vendor identifiable instruction is sent to the corresponding security management group, comprising: determining the arrangement order of the security network element according to the real-time network state, the security demand and the performance data of the security network element of each vendor, sending the target vendor identifiable instruction and the arrangement order of the security network element to the security management component, so that the security management component arranges according to the arrangement order of the security network element.
8. A secure network element orchestration device, comprising: Comprise: The memory is used for storing the computer program; The processor is used for executing the computer program to realize the steps of the security network element arrangement method in any one of claims 1 to 6.
9. A readable storage medium, characterized by, The computer program is stored on the readable storage medium, and the computer program is executed by the processor to realize the steps of the security network element arrangement method in any one of claims 1 to 6.
Citation Information
Patent Citations
CT cloud and edge cloud security platform
CN118432835A