A network isolation method, device, electronic device and storage medium for a cloud phone
By automatically generating and executing isolation task scripts through the cloud phone management platform and combining virtualization technology with Ethernet bridge firewall tools, the problems of security and operation and maintenance complexity in cloud phone network isolation technology are solved, achieving efficient and secure network isolation effects.
Patent Information
- Application Number
- CN202411388626.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-30
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2044-09-30
AI Technical Summary
Existing cloud phone network isolation technology cannot effectively ensure the security of data transmission and storage, and the operation and maintenance operations are complex, resulting in a high risk of network attacks and difficulty in meeting industry compliance.
Through the cloud phone management platform, the isolation service, isolation script and isolation policy of the target cloud device are automatically queried, and the isolation task script is generated and sent. The target cloud device performs network isolation according to the script, and network isolation is achieved by combining virtualization technology and Ethernet bridge firewall tools.
It simplifies operation and maintenance, improves the efficiency and success rate of network isolation, enhances the security of data transmission and storage, and meets industry compliance requirements.
Smart Images

Figure CN119254498B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, in particular to the field of cloud services, and specifically to a network isolation method, device, electronic device, and storage medium for a cloud phone. Background Art
[0002] Cloud phones are mobile phone systems built on cloud servers. Through the server-side chip architecture, they can provide the business services required by cloud phone clients. They are primarily based on the Android system. Currently, cloud phones use the Android operating system and install Android applications.
[0003] Cloud phones run in the cloud and require network isolation technology to ensure that data is protected from leakage risks during transmission and storage, effectively resist various types of network attacks, fully meet industry compliance requirements, and safeguard user data security. Summary of the Invention
[0004] The present disclosure provides a network isolation method, device, electronic device and storage medium for a cloud phone.
[0005] According to one aspect of the present disclosure, a network isolation method for a cloud phone is provided, which is executed by a management platform of the cloud phone, and the method includes:
[0006] Obtain a network isolation task for a target cloud device, and query a database for a target isolation service, a target isolation script, a target configuration file template, and a target isolation policy that match the target cloud device; wherein the target cloud device includes a virtual machine for providing a cloud phone business service;
[0007] Adding the target isolation policy to the target configuration file template to obtain a target configuration file;
[0008] Generate an isolation task script according to the target isolation service, the target isolation script and the target configuration file;
[0009] The isolation task script is sent to the target cloud device, so that the target cloud device performs network isolation according to the isolation task script.
[0010] According to one aspect of the present disclosure, a network isolation method for a cloud phone is provided, which is performed by a cloud device of the cloud phone, wherein the cloud device includes a virtual machine for providing cloud phone business services; the method includes:
[0011] Obtaining an isolation task script for a target cloud device from a cloud phone management platform; wherein the isolation task script is obtained by: adding a target isolation policy to a target configuration file template to obtain a target configuration file; generating the isolation task script based on a target isolation service, a target isolation script, and the target configuration file; wherein the target isolation policy, the target configuration file template, the target isolation service, and the target isolation script are all matched with the target cloud device;
[0012] Perform network isolation according to the isolation task script.
[0013] According to one aspect of the present disclosure, a network isolation device for a cloud phone is provided, which is configured on a management platform of the cloud phone, and includes:
[0014] A script policy query module is used to obtain a network isolation task for a target cloud device and query a database for a target isolation service, target isolation script, target configuration file template, and target isolation policy that matches the target cloud device; wherein the target cloud device includes a virtual machine for providing cloud phone business services;
[0015] A policy adding module, configured to add the target isolation policy to the target configuration file template to obtain a target configuration file;
[0016] A task script generation module, configured to generate an isolation task script according to the target isolation service, the target isolation script, and the target configuration file;
[0017] The task script sending module is used to send the isolation task script to the target cloud device, so that the target cloud device performs network isolation according to the isolation task script.
[0018] According to one aspect of the present disclosure, a network isolation device for a cloud phone is provided, which is configured on a cloud device of the cloud phone, wherein the cloud device includes a virtual machine for providing cloud phone business services; the device includes:
[0019] A task script acquisition module is used to obtain an isolation task script for a target cloud device from a cloud phone management platform; wherein the isolation task script is obtained by: adding a target isolation policy to a target configuration file template to obtain a target configuration file; generating the isolation task script based on a target isolation service, a target isolation script, and the target configuration file; wherein the target isolation policy, the target configuration file template, the target isolation service, and the target isolation script are all matched with the target cloud device;
[0020] A network isolation module is used to perform network isolation according to the isolation task script.
[0021] According to another aspect of the present disclosure, an electronic device is provided, the electronic device comprising:
[0022] at least one processor; and
[0023] a memory communicatively connected to the at least one processor; wherein,
[0024] The memory stores instructions that can be executed by the at least one processor. The instructions are executed by the at least one processor to enable the at least one processor to perform the method provided by any embodiment of the present disclosure.
[0025] According to another aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to enable a computer to execute the method provided by any embodiment of the present disclosure.
[0026] According to another aspect of the present disclosure, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the computer program implements the method provided according to any embodiment of the present disclosure.
[0027] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] The accompanying drawings are used to better understand the present invention and do not constitute a limitation of the present invention.
[0029] Figure 1 This is a flow chart of a network isolation method for a cloud phone provided according to an embodiment of the present disclosure;
[0030] Figure 2a This is a flow chart of another cloud phone network isolation method provided according to an embodiment of the present disclosure;
[0031] Figure 2b This is a schematic diagram of assembling a task script according to an embodiment of the present disclosure;
[0032] Figure 3a This is a flow chart of another network isolation method for a cloud phone provided according to an embodiment of the present disclosure;
[0033] Figure 3b This is a schematic diagram of verifying whether a private policy matches a cloud device according to an embodiment of the present disclosure;
[0034] Figure 3c This is a schematic diagram of network isolation interaction provided according to an embodiment of the present disclosure;
[0035] Figure 4 This is a flow chart of another network isolation method for a cloud phone provided according to an embodiment of the present disclosure;
[0036] Figure 5 This is a structural diagram of a network isolation device for a cloud phone provided according to an embodiment of the present disclosure;
[0037] Figure 6 This is a structural diagram of a network isolation device for a cloud phone provided according to an embodiment of the present disclosure;
[0038] Figure 7 3 is a block diagram of an electronic device used to implement the network isolation method of the cloud phone in the embodiment of the present disclosure. DETAILED DESCRIPTION
[0039] Figure 1 This is a flow chart of a network isolation method for a cloud phone according to an embodiment of the present disclosure. This method is applicable to situations where network isolation is performed on a cloud phone. This method can be performed by a network isolation device of a cloud phone, which can be implemented in software and / or hardware and can be integrated into the management platform of the cloud phone. Figure 1 As shown, the network isolation method of the cloud phone in this embodiment may include:
[0040] S101, obtaining a network isolation task for a target cloud device, and querying a database for a target isolation service, a target isolation script, a target configuration file template, and a target isolation policy that match the target cloud device; wherein the target cloud device includes a virtual machine for providing a cloud phone business service;
[0041] S102, adding the target isolation policy to the target configuration file template to obtain a target configuration file;
[0042] S103, generating an isolation task script according to the target isolation service, the target isolation script and the target configuration file;
[0043] S104: Send the isolation task script to the target cloud device, so that the target cloud device performs network isolation according to the isolation task script.
[0044] The cloud phone management platform is used to centrally manage and control cloud devices. It can be a PaaS (Platform as a Service) platform. PaaS provides a foundational platform, including application design, development, testing, and hosting. Users can develop customized applications and products based on this platform.
[0045] The cloud device for a cloud phone can be an ARM (array) server. An ARM server is an ARM processor computing board installed within a computer chassis. Each computing board is a minimal, independently operating system consisting of an ARM processor chip, memory, eMMC (embedded MultiMediaCard) storage, a network interface card, and other physical hardware. Multiple ARM processors can be installed within a single chassis, interconnected via Ethernet and communicating with the outside world.
[0046] Multiple virtual machines can be created on a cloud phone's cloud device. Each virtual machine has an independent operating system installed as a cloud phone instance and is provided to users. Specifically, the operating system is installed on the cloud device's physical hardware, and virtualization software is installed on the operating system. This virtualization software is used to partition the physical hardware into multiple virtual machines, each with its own independent operating system and applications deployed. The virtualization software abstracts the physical hardware into a logical resource pool and allocates it to each virtual machine as needed. Each virtual machine can independently use its own virtual hardware resources without interfering with others.
[0047] In the embodiment of the present disclosure, the target cloud device is a cloud device that needs to be isolated from the network. The isolation service isolate.service, the isolation script isolate.sh and the target configuration file template sys.ini can be maintained on the cloud phone's management platform. The isolation service, isolation script and configuration file template may have multiple versions, and the latest version is used by default. Taking into account version compatibility issues, some cloud devices may be bound to a specified version of the isolation service, isolation script and configuration file template instead of the latest version. That is to say, if the target cloud device has a specified version of the isolation service, isolation script and configuration file template, the specified version of the isolation service, isolation script and configuration file template is queried from the database as the target isolation service, target isolation script and target configuration file template; otherwise, the latest version of the isolation service, isolation script and configuration file template is queried from the database as the target isolation service, target isolation script and target configuration file template.
[0048] In the cloud phone management platform, operations and maintenance personnel can create, update, and clear various isolation policies. These policies can include network isolation rules such as the network segment, IP address, and port number to be isolated. Isolation policies can include public policies applicable to all cloud devices and private policies applicable to some cloud devices. Both public and private policies can have multiple versions. The public policy defaults to the latest version. To ensure version compatibility, some cloud devices can be bound to a specific version of the public policy.
[0049] For private policies, there must be a bound customer account. If the customer account is a platform account, a sub-customer account under the customer account can also be bound. The sub-customer account can be called a user group. The private policies of different sub-customer accounts under the same customer account can be different. For example, different private cloud services can be provided. By determining a customer account or a sub-customer account to which a private policy is bound, all cloud devices belonging to the customer account and the sub-customer account are bound to the private policy. There is no need to configure private policies for each cloud device under the same customer account or the same sub-customer account, thereby simplifying the operations of operation and maintenance personnel and improving the processing efficiency of network isolation. Moreover, in the process of maintaining the rules to be isolated, multiple rule values can be continuously entered in a single window of the rules to be isolated. For example, multiple IPs can be continuously entered in a single IP window, and different IPs are separated by line breaks or specific characters, thereby further simplifying operation and maintenance operations.
[0050] Exemplarily, in response to a network isolation task for a target cloud device, the target isolation task, target isolation script, target configuration file template, and target isolation policy bound to the target cloud device are queried from the database; the target isolation policy is added to the target configuration file template to obtain the target configuration file. It should be noted that the isolation policy may include necessary policy items and optional policy items, the values of necessary policy items cannot be empty, and the values of optional policy items can be flexibly adjusted as needed. If any one of the target isolation task, target isolation script, or target configuration file template is missing, or any necessary policy item in the target isolation policy is missing, the network isolation task will be abnormally terminated.
[0051] Among them, the target configuration file is a parameter of the target isolation script, and the target isolation service is used to call the target isolation script when the target cloud device is started. Exemplarily, the target isolation service, target isolation script and target configuration file are assembled into an isolation task script, and the isolation task script is sent to the target cloud device, so that the target cloud device performs network isolation according to the target isolation service, target isolation script and target configuration file in the isolation task script. By automatically querying the target isolation service, target isolation script, target configuration file template and target isolation policy that match the target isolation task from the database; adding the target isolation policy to the target configuration file template to obtain a target configuration file containing the target isolation policy, that is, containing the target isolation rules; assembling the target isolation service, target isolation script and target configuration file to obtain the isolation task script, and sending the isolation task script to the target cloud device, it can not only simplify the operation of the operation and maintenance personnel, improve the efficiency and accuracy of the target cloud device in obtaining the target isolation service, target isolation script and target isolation policy, but also maintain the integrity and consistency between the target isolation service, target isolation script and target isolation policy, avoid the missing of necessary policy items in the target isolation service, target isolation script and target isolation policy, and thus improve the success rate of the network isolation task.
[0052] The technical solution provided by the embodiment of the present disclosure automatically queries the target isolation service, target isolation script, target configuration file template and target isolation policy that match the target isolation task from the database; adds the target isolation policy to the target configuration file template to obtain the target isolation policy; assembles the target isolation service, target isolation script and target configuration file to obtain the isolation task script, and sends the isolation task script to the target cloud device. This can not only simplify the operations of the operation and maintenance personnel, improve the efficiency and accuracy of the target cloud device in obtaining the target isolation service, target isolation script and target isolation policy, but also improve the success rate of network isolation tasks.
[0053] In an optional embodiment, after sending the isolation task script to the target cloud device, it also includes: obtaining the network isolation result of the target cloud device; wherein, the network isolation result of the target cloud device is obtained by performing a network test on the target cloud device; according to the network isolation result, determining the total number of devices that need to be isolated and the number of successful devices that have been isolated; and calculating the coverage rate of the network isolation based on the number of successful devices and the total number of devices.
[0054] In the disclosed embodiment, the target cloud device can also perform a structural check on the executed network isolation task to obtain a network isolation result, which can be either in line with expectations or not. For example, each rule to be isolated is obtained from the target configuration file; each rule to be isolated is tested, for example, the ping network connectivity detection command can be used to test the reachability of the network segment and IP, and the telnet remote login command can be used to test the open status of the port, and it is determined whether the test result matches the rule to be isolated. If it matches all the rules to be isolated, the network isolation result of the target cloud device is successful; otherwise, the network isolation result of the target cloud device is failed. The cloud phone management platform obtains the network isolation result from each target cloud device; the total number of target cloud devices is counted to obtain the total number of devices that need to be isolated, the number of successful target cloud devices is counted to obtain the number of successful devices, and the ratio of the number of successful devices to the total number of devices is used as the coverage of the network isolation. By determining and displaying the number of successful devices, the total number of devices and the coverage, the management platform facilitates an intuitive understanding of the completion status of network isolation, and facilitates timely discovery and repair of potential security vulnerabilities in the case of low coverage.
[0055] Figure 2a This is a flow chart of another cloud phone network isolation method provided according to an embodiment of the present disclosure. In this embodiment, the cloud phone network isolation method is executed by the cloud phone management platform. Figure 2a The network isolation method of the cloud phone in this embodiment may include:
[0056] S201, obtaining a network isolation task for a target cloud device, and querying a database for a target isolation service, a target isolation script, a target configuration file template, and a target isolation policy that match the target cloud device; wherein the target cloud device includes a virtual machine for providing a cloud phone business service;
[0057] S202, adding the target isolation policy to the target configuration file template to obtain a target configuration file;
[0058] S203, obtaining a target path directory of the executable script in the target cloud device, adding the target path directory to the target isolation service, and obtaining a target isolation service containing the target path directory;
[0059] S204, using a preset encoding format to encode the target configuration file, the target isolation service containing the target path directory, and the target isolation script respectively;
[0060] S205, merging the encoding results to obtain the isolation task script;
[0061] S206: Send the isolation task script to the target cloud device, so that the target cloud device performs network isolation according to the isolation task script.
[0062] In the embodiment of the present disclosure, the management platform also maintains a path directory of executable scripts in each cloud device, wherein the path directory of the executable scripts is determined according to the version of the operating system in the cloud device. For example, the path directory of the executable scripts in some cloud devices is / data / local / init_sh / , and the path directory of the executable scripts in some cloud devices is ~~ / data / local / container / script / ~~. The preset encoding format is different from the original encoding format in the target isolation service, target isolation script, and target isolation file, that is, the preset encoding is an encoding format other than the original encoding format in the target isolation service, target isolation script, and target isolation file. For example, the preset encoding format may be Base64 format. Base64 is a representation method for binary data based on 64 printable characters, and is mainly used to transmit or store binary data in situations where text data needs to be processed.
[0063] Figure 2b This is a schematic diagram of an assembly of a task script provided according to an embodiment of the present disclosure. Figure 2b After the management platform queries the database for the target isolation service, target isolation script, target configuration file template, and target isolation policy that match the target cloud device, the target isolation policy is added to the target configuration file template to obtain the target configuration file; the target path directory of the executable script in the target cloud device can be obtained, and the target path directory is added to the target isolation service to obtain the target isolation service containing the target path directory. The target isolation service, target isolation script, and target configuration file containing the target path directory are respectively encoded into a preset encoding format, for example, using Base64 format to obtain each encoding result; each encoding result is loaded into the template of the isolation task script to obtain a merged isolation task script. By adding the target path directory to the target isolation service, the target isolation service can use the target path directory to call the target isolation script; by encoding the target isolation service, target isolation script and target configuration file containing the target path directory in the same encoding format to obtain each encoding result, and then assembling each encoding result, compared to directly assembling the target isolation service, target isolation script and target configuration file containing the target path directory, it can avoid conflicts in the meaning of characters during the assembly process due to the different original encoding formats in the target isolation service, target isolation script and target configuration file containing the target path directory, thereby improving the quality of the isolation task script.
[0064] In an optional embodiment, a target isolation service containing a target path directory is used to obtain the target isolation script and the target configuration file from the target path directory when the target cloud device is started, and execute the target isolation script according to the target configuration file to perform network isolation.
[0065] Exemplarily, after the target cloud device obtains the isolation task script from the management platform, it can use a preset decoding format to decode the isolation task script to obtain a target isolation service, a target isolation script and a target configuration file containing a target path directory; wherein, the target isolation script and the target configuration file can be located under the target path directory of the target cloud device. When the target cloud device is started, the target path directory is accessed through the target isolation service, the target isolation script is pulled up from the target path directory, the target configuration file is read as a parameter of the target isolation script, and the target isolation script is executed. Among them, the target isolation script can be an encapsulation method for writing the isolation rules in the target configuration file into the Ethernet bridge firewall tool of the Linux system, such as the ebtables plug-in, to perform network isolation. Among them, the ebtables plug-in is a tool for configuring the Ethernet bridge firewall, which works at the data link layer (MAC layer) and is mainly used to filter data packets at the data link layer.
[0066] In an optional embodiment, the target isolation strategy includes at least the following public strategy: the IP addresses of public cloud services that are allowed to be used and the IP network segments that are prohibited to be used; the target isolation strategy also includes the following private strategy: the IP addresses of private cloud services that are allowed to be used; the public strategy also includes at least one of the risk ports of public cloud services and the risk ports of cloud devices.
[0067] Among them, the target isolation strategy includes at least the following public strategies: the IP address of the public cloud service that is allowed to be used, namely X86_IP, which is used to provide cloud phone services; and the IP network segment that is prohibited to be used, namely DROP_IP, such as the IP segment of the cloud phone. In addition, the target isolation strategy may also include the following private strategies: the IP address of the private cloud service that is allowed to be used, namely X86_IP_CUSTOMER, which is used to provide private cloud services corresponding to customer accounts, such as cloud gaming customer accounts that can provide game streaming services, cloud gaming live broadcasts and other private cloud services. The public strategy may also include at least one of the following: the risk port of the public cloud service, namely X86_DANGEROUS_PORT, which is used to isolate some ports of the public cloud service, or the risk port of the cloud device, namely DANGEROUS_PORT, which is used to isolate the risk port of the cloud device.
[0068] Configuration policies can be managed as public and private policies. Public policies include X86_IP, X86_DANGEROUS_PORT, DANGEROUS_PORT, and DROP_IP; private policies include X86_IP_CUSTOMER. X86_IP and DROP_IP are required policy items, while the others are optional. Furthermore, the target isolation policy can also include the virtual machine's IP address, VM_IP, to determine connectivity between the cloud device and its virtual machines. This configuration is the virtual machine IP address of each cloud device and can be retrieved from the database. It is a private policy for the cloud device.
[0069] Exemplarily, at least X86_IP and DROP_IP matching the target cloud device are queried from the database, and at least one of X86_DANGEROUS_PORT, DANGEROUS_PORT, X86_IP_CUSTOMER or VM_IP matching the target cloud device can also be queried from the database to obtain the target isolation policy. Figure 2b The target configuration file template can contain target isolation policies that match the target cloud device: X86_IP, DROP_IP, X86_DANGEROUS_PORT, DANGEROUS_PORT, X86_IP_CUSTOMER, and VM_IP. By directly querying the target isolation policy from the database for each isolation rule, compared to manually editing isolation rules, this can avoid the inefficiency and risk of human error caused by manual editing, thereby improving the efficiency and security of network isolation.
[0070] According to the technical solution provided by the embodiments of the present disclosure, the management platform of the cloud phone adds the target path directory of the executable script in the target cloud device to the target isolation service, so that the target isolation service uses the target path directory to call the target isolation script; and by encoding the target isolation service, target isolation script and target configuration file containing the target path directory in the same encoding format to obtain each encoding result, and then assembling each encoding result, it is possible to avoid conflicts during the assembly process, thereby improving the quality of the isolation task script.
[0071] In an optional embodiment, obtaining the network isolation task for the target cloud device includes: when a change is detected in at least one of the isolation services, isolation scripts or isolation policies bound to any cloud device, using the cloud device as the target cloud device and generating a network isolation task for the target cloud device.
[0072] For example, a listener can be used to monitor the isolation services, isolation scripts, and isolation policies of each cloud device, i.e., the isolation rules in the isolation policy, to see if there are any changes. If any change is detected for any cloud device, such as a version update of the isolation service or isolation script of the cloud device, or an update of at least one of X86_IP, DROP_IP, X86_DANGEROUS_PORT, DANGEROUS_PORT, X86_IP_CUSTOMER, and VM_IP, the cloud device is used as the target cloud device, and a network isolation task is generated for the target cloud device. By automatically triggering the network isolation task when changes are detected in the isolation service, isolation script, or isolation policy of the cloud device through automated monitoring, failures caused by delays in the network isolation task are avoided, further improving the efficiency and security of network isolation.
[0073] In an optional embodiment, obtaining the network isolation task for the target cloud device includes: obtaining the network isolation task for the target cloud device based on the isolation task information entered in the isolation task page; wherein the isolation task information includes the identification of the target cloud device, the version of the target isolation service, the version of the target isolation script and the version of the target isolation policy.
[0074] For example, it also supports operation and maintenance personnel to manually trigger network isolation tasks. Under special circumstances, operation and maintenance personnel can enter isolation task information in the isolation task page. The isolation task information may include the identification of the target cloud device, such as the IP of the target cloud device, the version of the target isolation service, the version of the target isolation script, and the version of the target isolation policy. Accordingly, the version of the target isolation service, the version of the target isolation script, and the version of the target isolation policy are used to query the target isolation service, target isolation script, and target isolation policy from the database. The two mechanisms of automatic triggering and manual triggering of the listener can more flexibly meet the needs of implementing network isolation.
[0075] Figure 3a This is a flow chart of another cloud phone network isolation method provided according to an embodiment of the present disclosure. In this embodiment, the cloud phone network isolation method is executed by the cloud phone management platform. Figure 3a The network isolation method of the cloud phone in this embodiment may include:
[0076] S301, obtaining a network isolation task for a target cloud device, and querying a database for a target isolation service, a target isolation script, a target configuration file template, and a target isolation policy that match the target cloud device; wherein the target cloud device includes a virtual machine for providing a cloud phone business service;
[0077] Among them, the target isolation strategy includes at least the following public strategies: the IP addresses of public cloud services that are allowed to be used and the IP network segments that are prohibited to be used; the target isolation strategy also includes the following private strategies: the IP addresses of private cloud services that are allowed to be used; the public strategy also includes at least one of the risk ports of public cloud services and the risk ports of cloud devices.
[0078] S302, when the target isolation policy includes a target private policy, obtaining a first customer account bound to the target private policy;
[0079] S303: If the first customer account is a platform account, obtain a first sub-customer account bound to the target private policy;
[0080] S304, obtaining a second customer account to which the target cloud device belongs. If the second customer account is a platform account, obtaining a second sub-customer account to which the target cloud device belongs;
[0081] At step S305, if the first customer account and the second customer account are consistent, and the first sub-customer account and the second sub-customer account are consistent, then it is determined that the target private policy verification has passed, and the process continues with step S306; otherwise, it is determined that the target private policy verification is abnormal, and the network isolation task ends.
[0082] S306, adding the target isolation policy to the target configuration file template to obtain a target configuration file;
[0083] S307, generating an isolation task script according to the target isolation service, the target isolation script and the target configuration file;
[0084] S308: Send the isolation task script to the target cloud device, so that the target cloud device performs network isolation according to the isolation task script.
[0085] Exemplarily, in response to a network isolation task for a target cloud device, the management platform queries the database for a target isolation service, target isolation script, target configuration file template, and target isolation policy that matches the target cloud device. If the target isolation policy includes a target private policy, i.e., if the target isolation policy includes the IP address of the corresponding private cloud service, the management platform may also verify the customer account corresponding to the target cloud device with the customer account corresponding to the target private policy.
[0086] For example, the first customer account pre-bound to the target private policy during creation can be obtained. If the first customer account is a platform account, the first sub-customer account pre-bound to the target private policy during creation, such as the first user group, can also be obtained. Furthermore, the second customer account belonging to the target cloud device, i.e., the second customer account belonging to the cloud phone in the target cloud device, can be obtained. If the second customer account is a platform account, the second sub-customer account belonging to the corresponding cloud phone, such as the second user group, can also be obtained. The first customer account and the second customer account are compared to see if they are consistent, and the first sub-customer account and the second sub-customer account are consistent. If they are consistent, the target private policy verification is determined to have passed; otherwise, a verification error is determined. Furthermore, if the first customer account is a non-platform account, the second customer account belonging to the target cloud device can be obtained and the first customer account and the second customer account are compared to see if they are consistent. If they are consistent, the target private policy verification is determined to have passed; otherwise, a verification error is determined. By verifying the customer account corresponding to the target cloud device with the customer account corresponding to the target private policy, if the verification passes, the operation of adding the target isolation policy to the target configuration file template is triggered to continue executing the network isolation task. If the verification error occurs, the network isolation task is terminated and task failure feedback is provided to the user.
[0087] In an optional embodiment, the method further includes: during the update of any private policy, obtaining the identifiers of each cloud device to be bound entered on the update page of the private policy; determining whether each cloud device to be bound belongs to a third customer account based on the identifiers of each cloud device to be bound; if they all belong to the third customer account, and the third customer account is a platform account, determining whether all cloud phones under each cloud device to be bound belong to a third sub-customer account; if they all belong to the third sub-customer account, determining whether the third customer account is consistent with the fourth customer account bound to the private policy, and whether the third sub-customer account is consistent with the fourth sub-customer account bound to the private policy; if they are consistent, the verification passes; otherwise, the verification fails.
[0088] When the operation and maintenance personnel updates the private policy on the management platform, they can verify the customer account corresponding to the updated private policy and the customer account corresponding to the cloud device to be bound.
[0089] For example, during the update process of any private policy, the identifiers of each cloud device to be bound, such as the IP addresses of each cloud device to be bound, are obtained from the operation and maintenance personnel in the update page of the private policy. Figure 3b, verify each cloud device to be bound to the private policy: S31, determine whether the IP of each cloud device to be bound belongs to the same customer account. If not, jump to execute S37, that is, the verification is abnormal; if they belong to the same customer account, continue to execute S32, obtain the third customer account to which they belong, and determine whether the third customer account is a platform account; if it is a platform account, continue to execute S33, determine whether the IP of each cloud device to be bound belongs to the same sub-customer account, that is, the same user group; if they do not belong to the same user group, the verification is abnormal; if they belong to the same user group, continue to execute S34, obtain the third sub-customer account to which they belong, and determine whether the third customer account is consistent with the fourth customer account bound to the private policy, and whether the fourth sub-customer account is consistent with the fourth sub-customer account bound to the private policy; if they are consistent, continue to execute S35, that is, the verification is passed; otherwise, jump to execute S37, that is, the verification is abnormal. If the third customer account is a non-platform account, the process jumps to S36 to determine whether the third customer account is consistent with the fourth customer account bound to the private policy. If they are consistent, the process jumps to S35, indicating a successful verification. Otherwise, the process jumps to S37, indicating a failed verification. If the verification is successful, the private policy update is allowed; if the verification is a failed verification, the private policy update is rejected.
[0090] During the process of updating the private policy, by verifying the customer account corresponding to the updated private policy and the customer account corresponding to the cloud device to be bound, the matching between the private policy and the bound cloud device can be further improved, thereby improving the security of subsequent network isolation of the bound cloud device.
[0091] The technical solution provided by the embodiment of the present disclosure verifies the customer account corresponding to the target cloud device and the customer account corresponding to the target private policy. If the verification is successful, it triggers the operation of adding the target isolation policy to the target configuration file template to continue executing the network isolation task; if the verification is abnormal, the network isolation task is terminated and feedback to the user indicates that the task execution failed.
[0092] In an optional embodiment, the method also includes: if a recycling operation of a cloud phone under any customer account is monitored, the customer account to which the recycled cloud phone belongs is obtained, and the private policy corresponding to the cloud phone is updated; if a sub-customer account change operation of each cloud device in any customer account is monitored, the sub-customer account to which each cloud device in the customer account belongs is updated, and the private policy associated with the sub-customer account is updated.
[0093] For example, when a customer account expires, the cloud phone of the customer account can be recycled, and the private policy bound to the cloud phone can be updated, such as updating the customer account, sub-customer account, etc. bound to the private policy. For example, when the sub-customer account of each cloud phone in a customer account is changed, that is, when the user groups of each cloud phone in the customer account are re-grouped, the sub-customer account to which each cloud phone belongs can be updated, and the private policy associated with the sub-customer account can be updated synchronously. The above processing can synchronously update the corresponding private policy when the cloud phone is recycled or the user group is changed, thereby improving the accuracy of the private policy. Moreover, when the private policy is updated, the cloud device bound to the private policy can also trigger a network isolation task.
[0094] In an optional implementation, the method further includes: if a new operation or migration operation of the public cloud service is monitored, updating the IP address of the public cloud service.
[0095] For example, if a public cloud service adds a new network segment or undergoes a network segment migration, the public cloud service's IP address can be updated simultaneously, thereby improving the accuracy of the public cloud service's IP address. Furthermore, if the public cloud service's IP address is updated, network isolation tasks can be triggered for cloud devices bound to the public cloud service's IP address.
[0096] refer to Figure 3c Operations and maintenance personnel and other users can maintain network isolation services, network isolation scripts, and various network isolation policies. The management platform stores these services, scripts, and policies in a database. Users can manually trigger network isolation tasks, or the listener can trigger network isolation tasks for any cloud device if it detects changes to the network isolation service, script, or policy of that cloud device.
[0097] In response to the network isolation task, the management platform queries the database for the target network isolation service, target network isolation script, and target network isolation policy that match the target cloud device. If the target network isolation service and target network isolation script are not missing, the necessary policy items in the target network isolation policy are not missing, and the target isolation policy has a target private policy, the customer account corresponding to the target cloud device and the customer account corresponding to the target private policy can be verified. If the verification passes, the target network isolation service, target network isolation script, and target network isolation policy are transmitted to the target cloud device, so that the target cloud device implements network isolation, and the implementation result of the network isolation is tested to obtain the network isolation result. The management platform obtains the network isolation result from the target cloud device, records the network isolation result, and records the successfully implemented target network isolation service, target network isolation script, and target network isolation policy.
[0098] Figure 4 This is a flow chart of a network isolation method for a cloud phone provided according to an embodiment of the present disclosure. This method is applicable to situations where network isolation is performed on a cloud phone. This method can be executed by a network isolation device for a cloud phone, which can be implemented in software and / or hardware and can be integrated into a cloud device of the cloud phone. The cloud device includes at least two virtual machines, which are used to provide cloud phone business services, that is, to provide a cloud phone instance through a virtual machine. Figure 4 As shown, the network isolation method of the cloud phone in this embodiment may include:
[0099] S401, obtaining an isolation task script for a target cloud device from a cloud phone management platform; wherein the isolation task script is obtained by: adding a target isolation policy to a target configuration file template to obtain a target configuration file; generating the isolation task script based on a target isolation service, a target isolation script, and the target configuration file; wherein the target isolation policy, the target configuration file template, the target isolation service, and the target isolation script are all matched with the target cloud device;
[0100] S402, performing network isolation according to the isolation task script and obtaining the actual version used by each virtual machine from the cloud device of the cloud phone.
[0101] In the case where the local cloud device obtains the isolation task script from the management platform, the local cloud device is the target cloud device that needs to be network isolated. Among them, the isolation task script can be obtained in the following way: the management platform queries the target isolation task, target isolation script, target configuration file template and target isolation policy bound to the target cloud device from the database; the target isolation policy is added to the target configuration file template to obtain the target configuration file. The target configuration file is a parameter of the target isolation script, and the target isolation service is used to call the target isolation script when the target cloud device is started. The target isolation service, target isolation script and target configuration file are assembled into an isolation task script. In addition, the target cloud device performs network isolation according to the target isolation service, target isolation script and target configuration file in the isolation task script.
[0102] The technical solution provided by the embodiment of the present disclosure obtains the isolation task script from the management platform, performs network isolation according to the target isolation service, target isolation script, and target configuration file in the isolation task script, thereby improving the efficiency and accuracy of the target cloud device in obtaining the target isolation service, target isolation script, and target isolation strategy, and can also improve the success rate of the network isolation task.
[0103] In an optional embodiment, the network isolation is performed according to the isolation task script, including: using a preset decoding format to decode the isolation task script to obtain the target isolation service, the target isolation script and the target configuration file; when started, starting the target isolation service to obtain the target isolation script and the target configuration file from the target path directory; wherein, the target path directory is the path directory of the executable script in the target cloud device; and executing the target isolation script according to the target configuration file to perform network isolation.
[0104] Exemplarily, after the target cloud device obtains the isolation task script from the management platform, it can use a preset decoding format to decode the isolation task script to obtain a target isolation service, a target isolation script and a target configuration file containing a target path directory; wherein, the target isolation script and the target configuration file can be located under the target path directory of the target cloud device. When the target cloud device is started, the target path directory is accessed through the target isolation service, the target isolation script is pulled up from the target path directory, the target configuration file is read as a parameter of the target isolation script, and the target isolation script is executed. Among them, the target isolation script can be an encapsulation method for writing the isolation rules in the target configuration file into the Ethernet bridge firewall tool of the Linux system, such as the ebtables plug-in, to perform network isolation. Among them, the ebtables plug-in is a tool for configuring the Ethernet bridge firewall, which works at the data link layer (MAC layer) and is mainly used to filter data packets at the data link layer. Exemplarily, the target cloud device can obtain the network isolation result through the following processing: in the target cloud device, use the ebtables-L command to check whether the necessary rules exist, especially check DROP_IP; in any cloud phone of the target cloud device, use the ping command to test the implementation results of the configuration policies X86_IP, DROP_IP, and X86_IP_CUSTOMER; in the target cloud device, ping the cloud phone to see if it is connected to test the implementation results of the configuration policy VM_IP; in any cloud phone of the target cloud device, use the telnet command to test the implementation results of the configuration policies X86_DANGROUS_PORT and DANGROUS_PORT.
[0105] Figure 5 This is a schematic diagram of the structure of a network isolation device for a cloud phone provided according to an embodiment of the present disclosure. The device is suitable for isolating the network of a cloud phone. The device can be integrated into the management platform of the cloud phone. Figure 5 As shown, the network isolation device 500 of the cloud phone in this embodiment may include:
[0106] The script policy query module 510 is used to obtain a network isolation task for a target cloud device and query a database for a target isolation service, target isolation script, target configuration file template, and target isolation policy that matches the target cloud device; wherein the target cloud device includes a virtual machine for providing cloud phone business services;
[0107] A policy adding module 520 is configured to add the target isolation policy to the target configuration file template to obtain a target configuration file;
[0108] A task script generation module 530 is configured to generate an isolation task script according to the target isolation service, the target isolation script, and the target configuration file;
[0109] The task script sending module 540 is used to send the isolation task script to the target cloud device, so that the target cloud device performs network isolation according to the isolation task script.
[0110] In an optional implementation, the task script generation module 530 includes:
[0111] A directory adding unit is used to obtain a target path directory of the executable script in the target cloud device, and add the target path directory to the target isolation service to obtain a target isolation service containing the target path directory;
[0112] A script strategy encoding unit, configured to encode the target configuration file, the target isolation service containing the target path directory, and the target isolation script respectively using a preset encoding format;
[0113] The task script generating unit is used to merge the encoding results to obtain the isolation task script.
[0114] In an optional embodiment, a target isolation service containing a target path directory is used to obtain the target isolation script and the target configuration file from the target path directory when the target cloud device is started, and execute the target isolation script according to the target configuration file to perform network isolation.
[0115] In an optional embodiment, the target isolation strategy includes at least the following public strategy: the IP addresses of public cloud services that are allowed to be used and the IP network segments that are prohibited to be used; the target isolation strategy also includes the following private strategy: the IP addresses of private cloud services that are allowed to be used; the public strategy also includes at least one of the risk ports of public cloud services and the risk ports of cloud devices.
[0116] In an optional embodiment, the network isolation device 500 of the cloud phone further includes a script policy verification module, and the script policy verification module includes:
[0117] A first customer account unit, configured to obtain a first customer account bound to a target private policy when the target isolation policy includes a target private policy;
[0118] A first sub-customer account unit, configured to obtain the first sub-customer account bound to the target private policy when the first customer account is a platform account;
[0119] A second customer account unit, configured to obtain a second customer account to which the target cloud device belongs, and if the second customer account is a platform account, obtain a second sub-customer account to which the target cloud device belongs;
[0120] A script policy verification unit is used to determine that the target private policy verification has passed if the first customer account and the second customer account are consistent, and the first sub-customer account and the second sub-customer account are consistent, and trigger the operation of adding the target isolation policy to the target configuration file template.
[0121] In an optional embodiment, the network isolation device 500 of the cloud phone further includes a private policy verification module, which is specifically configured to:
[0122] During the update process of any private policy, obtain the identifier of each cloud device to be bound entered on the update page of the private policy;
[0123] determining, based on the identifiers of the cloud devices to be bound, whether the cloud devices to be bound all belong to a third customer account;
[0124] If they all belong to the third customer account, and the third customer account is a platform account, then determine whether all cloud phones under each cloud device to be bound belong to the third sub-customer account;
[0125] If both belong to the third sub-customer account, determining whether the third customer account and the fourth customer account bound to the private policy are consistent, and whether the third sub-customer account and the fourth sub-customer account bound to the private policy are consistent;
[0126] If they are consistent, the verification passes; otherwise, the verification fails.
[0127] In an optional embodiment, the network isolation device 500 of the cloud phone further includes:
[0128] A first policy update module is configured to obtain the customer account to which the recycled cloud phone belongs and update the private policy corresponding to the cloud phone if a recycling operation of the cloud phone under any customer account is detected;
[0129] The second policy update module is used to update the sub-customer accounts of each cloud device in any customer account and update the private policy associated with the sub-customer account if a change operation on the sub-customer accounts of each cloud device in any customer account is detected.
[0130] In an optional embodiment, the network isolation device 500 of the cloud phone further includes:
[0131] The third policy update module is configured to update the IP address of the public cloud service if a new operation or migration operation of the public cloud service is detected.
[0132] In an optional implementation, the script policy query module 510 is specifically configured to:
[0133] When a change is detected in at least one of the isolation service, isolation script, or isolation policy bound to any cloud device, the cloud device is used as the target cloud device and a network isolation task is generated for the target cloud device; or
[0134] According to the isolation task information entered in the isolation task page, the network isolation task for the target cloud device is obtained; wherein the isolation task information includes the identification of the target cloud device, the version of the target isolation service, the version of the target isolation script and the version of the target isolation policy.
[0135] In an optional embodiment, the network isolation device 500 of the cloud phone further includes an isolation result module, which is specifically configured to:
[0136] Obtaining a network isolation result of the target cloud device; wherein the network isolation result of the target cloud device is obtained by performing a network test on the target cloud device;
[0137] Determine the total number of devices that need to be isolated and the number of successfully isolated devices based on the network isolation result;
[0138] The coverage rate of network isolation is calculated based on the number of successful devices and the total number of devices.
[0139] The network isolation device for a cloud phone provided by an embodiment of the present invention can execute the network isolation method for a cloud phone provided by any embodiment of the present invention, and has functional modules and beneficial effects corresponding to the execution method.
[0140] Figure 6 This is a schematic diagram of the structure of a network isolation device for a cloud phone according to an embodiment of the present disclosure. The device is suitable for isolating the network of a cloud phone. The device can be integrated into the cloud device of the cloud phone; the cloud device includes a virtual machine for providing cloud phone business services. Figure 6As shown, the network isolation device 600 of the cloud phone in this embodiment may include:
[0141] The task script acquisition module 610 is used to obtain the isolation task script of the target cloud device from the cloud phone management platform; wherein the isolation task script is obtained by adding the target isolation policy to the target configuration file template to obtain the target configuration file; generating the isolation task script according to the target isolation service, the target isolation script and the target configuration file; the target isolation policy, the target configuration file template, the target isolation service and the target isolation script are all matched with the target cloud device;
[0142] The network isolation module 620 is used to perform network isolation according to the isolation task script.
[0143] In an optional implementation, the network isolation module 620 includes:
[0144] A decoding unit, configured to decode the isolation task script using a preset decoding format to obtain the target isolation service, the target isolation script, and the target configuration file;
[0145] A script startup unit, configured to, when started, start the target isolation service to obtain the target isolation script and the target configuration file from a target path directory; wherein the target path directory is a path directory of executable scripts in the target cloud device;
[0146] A network isolation unit is used to execute the target isolation script according to the target configuration file to perform network isolation.
[0147] The network isolation device for a cloud phone provided by an embodiment of the present invention can execute the network isolation method for a cloud phone provided by any embodiment of the present invention, and has functional modules and beneficial effects corresponding to the execution method.
[0148] In the technical solutions disclosed herein, the acquisition, storage, and application of user personal information involved comply with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0149] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0150] Figure 7 3 is a block diagram of an electronic device used to implement the network isolation method of the cloud phone in the embodiment of the present disclosure.
[0151] Figure 7A schematic block diagram of an example electronic device 700 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0152] like Figure 7 As shown, the electronic device 700 includes a computing unit 701, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 702 or a computer program loaded from a storage unit 708 into a random access memory (RAM) 703. Various programs and data required for the operation of the electronic device 700 can also be stored in the RAM 703. The computing unit 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0153] Multiple components in the electronic device 700 are connected to the I / O interface 705, including an input unit 706, such as a keyboard, a mouse, etc.; an output unit 707, such as various types of displays, speakers, etc.; a storage unit 708, such as a magnetic disk, an optical disk, etc.; and a communication unit 709, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 709 allows the electronic device 700 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0154] The computing unit 701 can be a variety of general-purpose and / or specialized processing components with processing and computing capabilities. Some examples of the computing unit 701 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units that run machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The computing unit 701 performs the various methods and processes described above, such as the network isolation method of the cloud phone. For example, in some embodiments, the network isolation method of the cloud phone can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as the storage unit 708. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 700 via the ROM 702 and / or the communication unit 709. When the computer program is loaded into the RAM 703 and executed by the computing unit 701, one or more steps of the network isolation method of the cloud phone described above can be performed. Alternatively, in other embodiments, the computing unit 701 can be configured to perform the network isolation method of the cloud phone by any other appropriate means (e.g., by means of firmware).
[0155] Figure 7 A schematic block diagram of an example electronic device 700 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0156] like Figure 7 As shown, the electronic device 700 includes a computing unit 701, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 702 or a computer program loaded from a storage unit 708 into a random access memory (RAM) 703. Various programs and data required for the operation of the electronic device 700 can also be stored in the RAM 703. The computing unit 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0157] Multiple components in the electronic device 700 are connected to the I / O interface 705, including an input unit 706, such as a keyboard, a mouse, etc.; an output unit 707, such as various types of displays, speakers, etc.; a storage unit 708, such as a magnetic disk, an optical disk, etc.; and a communication unit 709, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 709 allows the electronic device 700 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0158] The computing unit 701 can be a variety of general-purpose and / or specialized processing components with processing and computing capabilities. Some examples of the computing unit 701 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units that run machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The computing unit 701 performs the various methods and processes described above, such as the network isolation method of the cloud phone. For example, in some embodiments, the network isolation method of the cloud phone can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as the storage unit 708. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 700 via the ROM 702 and / or the communication unit 709. When the computer program is loaded into the RAM 703 and executed by the computing unit 701, one or more steps of the network isolation method of the cloud phone described above can be performed. Alternatively, in other embodiments, the computing unit 701 can be configured to perform the network isolation method of the cloud phone by any other appropriate means (e.g., by means of firmware).
[0159] Various embodiments of the systems and techniques described above can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0160] The program code for implementing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flow chart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0161] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0162] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0163] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with embodiments of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.
[0164] A computer system may include a client and a server. The client and server are generally remote from each other and typically interact through a communication network. The client-server relationship arises through computer programs running on the respective computers and having a client-server relationship with each other. The server may be a cloud server, a server in a distributed system, or a server integrated with a blockchain.
[0165] Artificial intelligence (AI) is the study of how computers can simulate certain human thought processes and intelligent behaviors (such as learning, reasoning, thinking, and planning). It encompasses both hardware and software technologies. AI hardware technologies generally include sensors, specialized AI chips, cloud computing, distributed storage, and big data processing. AI software technologies primarily encompass computer vision, speech recognition, natural language processing, machine learning / deep learning, big data processing, and knowledge graphs.
[0166] Cloud computing refers to a technology system that provides network access to elastically scalable shared pools of physical or virtual resources. These resources can include servers, operating systems, networks, software, applications, and storage devices, and can be deployed and managed on-demand in a self-service manner. Cloud computing technology provides efficient and powerful data processing capabilities for the application of technologies such as artificial intelligence and blockchain, as well as for model training.
[0167] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved. This is not a limitation herein.
[0168] The above specific embodiments do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the scope of protection of this disclosure.
Claims
1. A network isolation method for a cloud phone, executed by a cloud phone management platform, comprising: Obtain a network isolation task for a target cloud device, and query a database for a target isolation service, a target isolation script, a target configuration file template, and a target isolation policy that match the target cloud device; wherein the target cloud device includes a virtual machine for providing a cloud phone business service; Adding the target isolation policy to the target configuration file template to obtain a target configuration file; Generate an isolation task script according to the target isolation service, the target isolation script and the target configuration file; Sending the isolation task script to the target cloud device, so that the target cloud device performs network isolation according to the isolation task script; The step of generating an isolation task script according to the target isolation service, the target isolation script, and the target configuration file includes: Obtain a target path directory of the executable script in the target cloud device, add the target path directory to the target isolation service, and obtain a target isolation service containing the target path directory; Using a preset encoding format, respectively encode the target configuration file, the target isolation service containing the target path directory, and the target isolation script; The encoding results are combined to obtain the isolation task script.
2. The method according to claim 1, wherein The target isolation service containing the target path directory is used to obtain the target isolation script and the target configuration file from the target path directory when the target cloud device is started, and execute the target isolation script according to the target configuration file to perform network isolation.
3. The method according to claim 1, wherein The target isolation strategy includes at least the following public strategies: the IP addresses of public cloud services that are allowed to be used and the IP segments that are prohibited to be used; the target isolation strategy also includes the following private strategies: the IP addresses of private cloud services that are allowed to be used; the public strategy also includes at least one of the risk ports of public cloud services and the risk ports of cloud devices.
4. The method according to any one of claims 1 to 3, before adding the target isolation policy to the target configuration file template, further comprising: In a case where the target isolation policy includes a target private policy, obtaining a first customer account bound to the target private policy; In the case where the first customer account is a platform account, obtaining a first sub-customer account bound to the target private policy; Obtaining a second customer account to which the target cloud device belongs. If the second customer account is a platform account, obtaining a second sub-customer account to which the target cloud device belongs; If the first customer account and the second customer account are consistent, and the first sub-customer account and the second sub-customer account are consistent, it is determined that the target private policy verification passes, and an operation of adding the target isolation policy to the target configuration file template is triggered.
5. The method according to any one of claims 1 to 3, further comprising: During the update process of any private policy, obtain the identifier of each cloud device to be bound entered on the update page of the private policy; determining, based on the identifiers of the cloud devices to be bound, whether the cloud devices to be bound all belong to a third customer account; If they all belong to the third customer account, and the third customer account is a platform account, then determine whether all cloud phones under each cloud device to be bound belong to the third sub-customer account; If both belong to the third sub-customer account, determining whether the third customer account and the fourth customer account bound to the private policy are consistent, and whether the third sub-customer account and the fourth sub-customer account bound to the private policy are consistent; If they are consistent, the verification passes; otherwise, the verification fails.
6. The method according to claim 3, further comprising: If a recycling operation of a cloud phone under any customer account is detected, the customer account to which the recycled cloud phone belongs is obtained and the private policy corresponding to the cloud phone is updated; If a change operation is detected on the sub-customer accounts of each cloud device in any customer account, the sub-customer accounts belonging to each cloud device in the customer account will be updated, and the private policy associated with the sub-customer account will be updated.
7. The method according to claim 3, further comprising: If a new operation or migration operation of a public cloud service is monitored, the IP address of the public cloud service is updated.
8. The method according to claim 1, wherein The task of obtaining network isolation for the target cloud device includes: When a change is detected in at least one of the isolation service, isolation script, or isolation policy bound to any cloud device, the cloud device is used as the target cloud device and a network isolation task is generated for the target cloud device; or According to the isolation task information entered in the isolation task page, the network isolation task for the target cloud device is obtained; wherein the isolation task information includes the identification of the target cloud device, the version of the target isolation service, the version of the target isolation script and the version of the target isolation policy.
9. The method according to claim 1, after sending the isolation task script to the target cloud device, further comprising: Obtaining a network isolation result of the target cloud device; wherein the network isolation result of the target cloud device is obtained by performing a network test on the target cloud device; Determine the total number of devices that need to be isolated and the number of successfully isolated devices based on the network isolation result; The coverage rate of network isolation is calculated based on the number of successful devices and the total number of devices.
10. A network isolation method for a cloud phone, performed by a cloud device of the cloud phone, wherein the cloud device includes a virtual machine for providing cloud phone business services; the method comprises: Obtaining an isolation task script for a target cloud device from a cloud phone management platform; wherein the isolation task script is obtained by: adding a target isolation policy to a target configuration file template to obtain a target configuration file; generating the isolation task script based on a target isolation service, a target isolation script, and the target configuration file; wherein the target isolation policy, the target configuration file template, the target isolation service, and the target isolation script are all matched with the target cloud device; Perform network isolation according to the isolation task script; Wherein, performing network isolation according to the isolation task script includes: Using a preset decoding format, decoding the isolation task script to obtain the target isolation service, the target isolation script and the target configuration file; When started, the target isolation service is started to obtain the target isolation script and the target configuration file from the target path directory; wherein the target path directory is the path directory of the executable script in the target cloud device; Execute the target isolation script according to the target configuration file to perform network isolation.
11. A network isolation device for a cloud phone, configured on a cloud phone management platform, comprising: A script policy query module is used to obtain a network isolation task for a target cloud device and query a database for a target isolation service, target isolation script, target configuration file template, and target isolation policy that matches the target cloud device; wherein the target cloud device includes a virtual machine for providing cloud phone business services; A policy adding module, configured to add the target isolation policy to the target configuration file template to obtain a target configuration file; A task script generation module, configured to generate an isolation task script according to the target isolation service, the target isolation script, and the target configuration file; A task script sending module is used to send the isolation task script to the target cloud device, so that the target cloud device performs network isolation according to the isolation task script; The task script generation module includes: A directory adding unit is used to obtain a target path directory of the executable script in the target cloud device, and add the target path directory to the target isolation service to obtain a target isolation service containing the target path directory; A script strategy encoding unit, configured to encode the target configuration file, the target isolation service containing the target path directory, and the target isolation script respectively using a preset encoding format; The task script generating unit is used to merge the encoding results to obtain the isolation task script.
12. The device according to claim 11, wherein The target isolation service containing the target path directory is used to obtain the target isolation script and the target configuration file from the target path directory when the target cloud device is started, and execute the target isolation script according to the target configuration file to perform network isolation.
13. The device according to claim 11, wherein The target isolation strategy includes at least the following public strategies: the IP addresses of public cloud services that are allowed to be used and the IP segments that are prohibited to be used; the target isolation strategy also includes the following private strategies: the IP addresses of private cloud services that are allowed to be used; the public strategy also includes at least one of the risk ports of public cloud services and the risk ports of cloud devices.
14. The apparatus according to any one of claims 11 to 13, further comprising a script policy verification module, wherein the script policy verification module comprises: A first customer account unit, configured to obtain a first customer account bound to a target private policy when the target isolation policy includes a target private policy; A first sub-customer account unit, configured to obtain the first sub-customer account bound to the target private policy when the first customer account is a platform account; A second customer account unit, configured to obtain a second customer account to which the target cloud device belongs, and if the second customer account is a platform account, obtain a second sub-customer account to which the target cloud device belongs; A script policy verification unit is used to determine that the target private policy verification has passed if the first customer account and the second customer account are consistent, and the first sub-customer account and the second sub-customer account are consistent, and trigger the operation of adding the target isolation policy to the target configuration file template.
15. The apparatus according to any one of claims 11 to 13, further comprising a private policy verification module, wherein the private policy verification module is specifically configured to: During the update process of any private policy, obtain the identifier of each cloud device to be bound entered on the update page of the private policy; determining, based on the identifiers of the cloud devices to be bound, whether the cloud devices to be bound all belong to a third customer account; If they all belong to the third customer account, and the third customer account is a platform account, then determine whether all cloud phones under each cloud device to be bound belong to the third sub-customer account; If both belong to the third sub-customer account, determining whether the third customer account and the fourth customer account bound to the private policy are consistent, and whether the third sub-customer account and the fourth sub-customer account bound to the private policy are consistent; If they are consistent, the verification passes; otherwise, the verification fails.
16. The apparatus according to claim 13, further comprising: A first policy update module is configured to obtain the customer account to which the recycled cloud phone belongs and update the private policy corresponding to the cloud phone if a recycling operation of the cloud phone under any customer account is detected; The second policy update module is used to update the sub-customer accounts of each cloud device in any customer account and update the private policy associated with the sub-customer account if a change operation on the sub-customer accounts of each cloud device in any customer account is detected.
17. The apparatus according to claim 13, further comprising: The third policy update module is configured to update the IP address of the public cloud service if a new operation or migration operation of the public cloud service is detected.
18. The device according to claim 11, wherein The script strategy query module is specifically used to: When a change is detected in at least one of the isolation service, isolation script, or isolation policy bound to any cloud device, the cloud device is used as the target cloud device, and a network isolation task is generated for the target cloud device; or, According to the isolation task information entered in the isolation task page, the network isolation task for the target cloud device is obtained; wherein the isolation task information includes the identification of the target cloud device, the version of the target isolation service, the version of the target isolation script and the version of the target isolation policy.
19. The apparatus according to claim 11, further comprising an isolation result module, wherein the isolation result module is specifically configured to: Obtain the network isolation result of the target cloud device; wherein, The network isolation result of the target cloud device is obtained by performing a network test on the target cloud device; Determine the total number of devices that need to be isolated and the number of successfully isolated devices based on the network isolation result; The coverage rate of network isolation is calculated based on the number of successful devices and the total number of devices.
20. A network isolation device for a cloud phone, configured on a cloud device of the cloud phone, wherein the cloud device includes a virtual machine for providing cloud phone business services; the device comprises: A task script acquisition module is used to obtain an isolation task script for a target cloud device from a cloud phone management platform; wherein the isolation task script is obtained by: adding a target isolation policy to a target configuration file template to obtain a target configuration file; generating the isolation task script based on a target isolation service, a target isolation script, and the target configuration file; wherein the target isolation policy, the target configuration file template, the target isolation service, and the target isolation script are all matched with the target cloud device; A network isolation module, configured to perform network isolation according to the isolation task script; The network isolation module includes: A decoding unit, configured to decode the isolation task script using a preset decoding format to obtain the target isolation service, the target isolation script, and the target configuration file; A script startup unit, configured to, when started, start the target isolation service to obtain the target isolation script and the target configuration file from a target path directory; wherein the target path directory is a path directory of executable scripts in the target cloud device; A network isolation unit is used to execute the target isolation script according to the target configuration file to perform network isolation.
21. An electronic device comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 10.
22. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to make a computer execute the method according to any one of claims 1-10.
23. A computer program product comprising a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 10.
Citation Information
Patent Citations
Virtual machine generation method and system
CN107729117A