Network security workload orchestration method, device and product for cloud security
By performing load orchestration in cloud services and connecting to a secure switch via a unified interface, the problem of wasted network security product resources is solved, enabling efficient utilization of server resources and rapid scaling up and down, thus improving deployment efficiency.
Patent Information
- Application Number
- CN202411442358.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-15
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2044-10-15
AI Technical Summary
In cloud services, the uneven allocation of server resources in existing network security products leads to resource waste and makes it difficult to achieve dynamic and flexible scaling up and down.
By acquiring the target configuration information of network security products and the server information of security servers, and using a unified interface to connect to security switches for load balancing, network security products with different network topologies and configuration connection methods can be deployed on the same security server.
It makes full use of server resources, avoids resource waste, supports rapid and flexible product scaling, and improves deployment efficiency and the horizontal scalability of network security products.
Smart Images

Figure CN119363748B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of computer, in particular, to a network security workload orchestration method, device and product for cloud security. BACKGROUND
[0002] The network security product in cloud service can ensure the security of data in the process of transmission and storage, and generally needs to be directly detected and analyzed according to the business traffic of the user, or the business traffic is detected and analyzed after being copied by mirror / splitting.
[0003] In order to meet the requirement of high-performance traffic processing, in the related art, when deploying the workload of the network security product, one or more security servers are deployed for each network security product. However, since the required server resources of each network security product are different, it is easy to cause waste of resources. SUMMARY
[0004] This summary is provided to introduce a selection of concepts, which are further described below in the detailed description. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it used to limit the scope of the claimed subject matter's scope.
[0005] In a first aspect, the present disclosure provides a network security workload orchestration method for cloud security, comprising:
[0006] obtaining target configuration information of at least one network security product corresponding to the cloud service, and obtaining server information of all security servers in a first security server set; wherein the target configuration information comprises the amount of server resources configured for each network security product in the at least one network security product, and the server information comprises the amount of available resources of the all security servers, and different security servers are connected to a security switch corresponding to the cloud service through a unified interface;
[0007] based on the target configuration information and the server information, performing load orchestration on the workload of the at least one network security product.
[0008] In a second aspect, the present disclosure provides a network security workload orchestration device for cloud security, comprising:
[0009] obtain target configuration information of at least one network security product corresponding to the cloud service, and obtain server information of all security servers in the first security server set; wherein the target configuration information comprises a server resource amount configured for each network security product in the at least one network security product, and the server information comprises an available resource amount of the all security servers, different security servers being connected to a security switch corresponding to the cloud service through a unified interface;
[0010] a load arrangement module, configured to arrange a workload of the at least one network security product based on the target configuration information and the server information.
[0011] In a third aspect, the present disclosure provides a computer readable medium having stored thereon a computer program, which, when executed by a processing apparatus, implements the steps of the method in the first aspect.
[0012] In a fourth aspect, the present disclosure provides an electronic device, comprising:
[0013] a storage device having stored thereon a computer program;
[0014] a processing apparatus configured to execute the computer program in the storage device to implement the steps of the method in the first aspect.
[0015] In a fifth aspect, the present disclosure provides a computer program product comprising a computer program, which, when executed by a processor, implements the steps of the method in the first aspect.
[0016] Through the above technical solution, first, target configuration information of at least one network security product corresponding to the cloud service and server information of all security servers in the first security server set are obtained, and then, based on the target configuration information and the server information, a workload of the at least one network security product is arranged. Since different security servers can be connected to a security switch corresponding to the cloud service through a unified interface, the workloads of network security products with different network configurations and connection modes can be deployed to the same security server. In this way, when deploying the workloads of the network security products, the server resources of each security server can be fully utilized, thereby avoiding waste of resources.
[0017] Other features and advantages of the present disclosure will be described in detail in the following detailed description. BRIEF DESCRIPTION OF DRAWINGS
[0018] The above and other features, advantages, and aspects of embodiments of the present disclosure will become more apparent by describing in detail exemplary embodiments thereof with reference to the attached drawings. The same or similar components have the same or similar reference labels. It should be understood that the drawings are not necessarily to scale, with emphasis instead being placed upon illustrating the principles of the embodiments of the present disclosure. In the drawings:
[0019] Figure 1 is a schematic diagram of a cloud service according to an exemplary embodiment of the present disclosure;
[0020] Figure 2 is a flowchart of a network security workload orchestration method according to an exemplary embodiment of the present disclosure;
[0021] Figure 3 is a process diagram of load orchestration and traffic orchestration according to an exemplary embodiment of the present disclosure;
[0022] Figure 4 is a structural block diagram of a network security workload orchestration apparatus according to an exemplary embodiment of the present disclosure;
[0023] Figure 5 is a structural diagram of an electronic device according to an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION
[0024] Embodiments of the present disclosure will be described more fully hereinafter with reference to the accompanying drawings. While several embodiments of the present disclosure have been illustrated and described, it will be appreciated that various changes can be made therein without departing from the spirit and scope of the present disclosure. It is to be understood that the drawings and descriptions are not to be interpreted as limiting the scope of the present disclosure.
[0025] It should be understood that various steps in the method embodiments of the present disclosure can be performed in different sequences and / or concurrently. In addition, the method embodiments can include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this regard.
[0026] The term "comprising" and variations thereof as used herein are used inclusively, i.e., "including, but not limited to." The term "based on" means "based, at least in part, on." The term "one embodiment" means "at least one embodiment." The term "another embodiment" means "at least one additional embodiment." The term "some embodiments" means "at least some embodiments." Related definitions are given throughout the description.
[0027] It should be noted that the terms "first", "second", and the like in the present disclosure are merely used to distinguish different devices, modules or units, and do not imply the sequence or interdependence of the functions performed by these devices, modules or units.
[0028] It should be noted that the terms "one", "multiple" in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that "one or more" should be understood unless otherwise explicitly indicated in the context.
[0029] The names of the messages or information exchanged between the plurality of devices in the embodiments of the present disclosure are only for illustrative purposes, and are not intended to limit the scope of the messages or information.
[0030] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the type, use range, use scenario, etc. of the personal information involved in the present disclosure should be informed to the user and the authorization of the user should be obtained through appropriate means according to relevant laws and regulations.
[0031] For example, in response to receiving the active request of the user, the user is sent prompt information to explicitly prompt the user that the operation requested to be performed will require obtaining and using the personal information of the user. Thus, the user can voluntarily choose whether to provide personal information to the software or hardware such as electronic device, application program, server or storage medium, etc. that performs the operation of the technical solutions of the present disclosure according to the prompt information.
[0032] As an optional but non-limiting implementation, in response to receiving the active request of the user, the user is sent prompt information, for example, in the form of a pop-up window, which can present the prompt information in the form of text. In addition, the pop-up window can also carry selection controls for the user to select "agree" or "disagree" to provide personal information to the electronic device.
[0033] It can be understood that the above notification and user authorization process is only illustrative, and does not limit the implementation of the present disclosure. Other ways that meet the relevant laws and regulations can also be applied to the implementation of the present disclosure.
[0034] At the same time, it can be understood that the data involved in the present technical solution (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of the relevant laws and regulations and relevant provisions.
[0035] As Figure 1 shown, first, the Figure 1The nouns appearing in the description are explained. The network gateway is a switch role in the hybrid cloud network architecture for interconnection and interconnection with the user's own switch. The security switch is a switch role specially used for direct connection with network security products. The core switch is a switch role responsible for processing the main data transmission and routing in the network. The security server is a physical server for deploying network security products. The access switch is a switch role for other physical machine interfaces. The DDoS (Distributed Denial of Service) product refers to the network security product of distributed denial of service attack. The NTA (Network Traffic Analysis) product refers to the network intrusion detection technology including feature detection, correlation analysis based on DPI (Deep Packet Inspection, a network packet filtering technology). The FW (Firewall) refers to the cloud firewall security product. The diversion refers to the technology of redirecting network traffic from the original path to a specific security device or service. Mirroring and splitting are two commonly used network packet or traffic replication technologies.
[0036] With reference to the foregoing Figure 1 , the hybrid cloud is deployed in the user's IDC (Internet Data Center) or other independent machine room, and the user decides whether to connect with the public cloud as needed. If not needed, it is used as a private cloud scenario. In the public cloud environment, network security products are usually used in shared clusters for all tenants in the cloud, and in order to meet the needs of large bandwidth and high performance, network security products are usually deployed in clusters and configured according to the network networking and configuration connection mode.
[0037] In the hybrid cloud scenario, the hybrid cloud needs to deploy network security products according to the needs of each user. It should be noted that different network security products using splitting, mirroring, and diversion have different network networking and configuration connection modes. In related technologies, one deployment method is to deploy one or more security servers for each network security product, and one security server is one physical machine. However, since each network security product requires different server resources, it is easy to cause resource waste. Another deployment method is to deploy based on virtual machines, that is, by deploying virtual machines in the security server, the workloads of multiple network security products can be deployed to different virtual machines in the same security server. However, it is also limited by the network networking and configuration connection mode of the network security product. The same security server can only deploy network security products with the same network networking and configuration connection mode, and the virtual machine itself needs to occupy a large amount of resources, and the virtual machine has high difficulty in operation and maintenance when starting, debugging, and fault migration.
[0038] In addition, when the user expands the service, complex and time-consuming network and operation and maintenance configuration, such as network wiring and routing or mirror configuration, need to be performed, so that the dynamic and flexible rapid expansion and the workloads of enabling the network security product cannot be supported.
[0039] Therefore, the present disclosure provides a network security workload orchestration method, device and product for cloud security to solve the above technical problems.
[0040] The embodiments of the present disclosure are further explained and described below with reference to the accompanying drawings.
[0041] Figure 2 is a flowchart of a network security workload orchestration method for cloud security according to an exemplary embodiment of the present disclosure, referring to Figure 2 The method can include the following steps:
[0042] S201: Obtain target configuration information of at least one network security product corresponding to a cloud service, and obtain server information of all security servers in a first security server set; wherein the target configuration information includes the amount of server resources configured for each network security product in the at least one network security product, the server information includes the amount of available resources of all security servers, and different security servers are connected to a security switch corresponding to the cloud service through a unified interface.
[0043] It should be noted that the cloud service includes but is not limited to private cloud, public cloud, hybrid cloud and other architecture cloud services. The server resources include CPU (Central Processing Unit, Central Processing Unit), memory and other resources corresponding to the network security product, which is not limited by the present disclosure.
[0044] For example, unlike the related art which needs to connect the security switch for each network security product and configure specific configuration information, all security servers in the embodiment of the present disclosure are configured as multi-network card models, and the network cards of all security servers are interconnected with the security switch in a standardized and consistent manner, so that specific configuration according to the network security product cluster is not required. That is, all security servers are interconnected with the security switch in a non-discriminatory manner, so that any workload required by the user can be flexibly run on each security server, and the workload of simultaneously running multiple network security products can be supported.
[0045] S202: Based on the target configuration information and the server information, the workload of the at least one network security product is load-orchestrated.
[0046] In a possible manner, the workloads of the at least one network security product are load arranged based on the target configuration information and the server information, including: determining, based on the target configuration information and the server information, a target security server for deploying the workloads of the at least one network security product from all security servers, and deploying the workloads of the at least one network security product to the target security server, where the available resource amount of the target security server is greater than or equal to the server resource amount configured for the at least one network security product.
[0047] For example, the target security server can be one or multiple, and one security server can deploy multiple workloads of one network security product or multiple workloads of different network security products. For example, when the available resource amount of the security server A is greater than or equal to the server resource amount configured for the network security product X, the workloads of the network security product X can be all deployed to the security server A. Or when the available resource amount of the security server A is less than the server resource amount configured for the network security product X, the workloads of the network security product X can be divided into multiple workloads and deployed to multiple security servers including the security server A. Or in order to avoid that the workloads of the network security product X are all unavailable when the security server A is abnormal, when the available resource amount of the security server A is greater than or equal to the server resource amount configured for the network security product X, the workloads of the network security product X can also be divided into multiple workloads and deployed to multiple security servers including the security server A. The specific determination can be based on requirements, and the disclosure does not limit this.
[0048] It should be understood that when performing load arrangement, the target configuration information can also include the number of workloads, etc., which can be configured based on user requirements, and when performing load arrangement, the load arrangement can also be performed in combination with the set load arrangement strategy, and the disclosure does not limit this.
[0049] By using the above method, since different security servers can be connected to the security switches corresponding to the cloud service through a unified interface, the workloads of network security products with different network groupings and connection modes can be deployed to the same security server. In this way, when deploying the workloads of network security products, the server resources of each security server can be fully utilized, thereby avoiding waste of resources.
[0050] For ease of understanding, it is assumed that the workloads of the network security product X include the workload 1 deployed to the security server A, the workload 2 deployed to the security server B, and the workload 3 deployed to the security server C. In subsequent use, when the user needs to perform capacity expansion or reduction of the network security product according to business requirements, workload creation or deletion needs to be performed.
[0051] In a possible implementation, the method further includes: obtaining first configuration update information for a first network security product of the at least one network security product, the first configuration update information configuring a new quantity of server resources for the first network security product, the new quantity of server resources being less than a quantity of server resources configured for the first network security product in the target configuration information; determining, based on the first configuration update information, a first workload to be deleted from a workload of the first network security product; determining a first security server in which the first workload is deployed, and deleting the first workload deployed in the first security server.
[0052] For example, when a user reduces the quantity of server resources allocated to the network security product X according to changes in business requirements, the configuration information for the network security product X can be reconfigured to reduce the quantity of server resources configured for the network security product X. Then, based on the newly configured configuration information, a workload to be deleted and a security server in which the workload is located can be determined, assuming that the workload is workload 1 and the security server is security server A, workload 1 deployed in security server A is deleted. Thus, by simple configuration, quick and flexible product capacity reduction can be achieved according to user requirements.
[0053] In a possible implementation, the method further includes: obtaining second configuration update information for a second network security product of the at least one network security product, the second configuration update information configuring a new quantity of server resources for the second network security product, the new quantity of server resources being greater than a quantity of server resources configured for the second network security product in the target configuration information; determining, based on the second configuration update information and the server information, a second workload of the second network security product to be deployed, and determining, from the first set of security servers, a second security server for deploying the second workload; and deploying the second workload to the second security server.
[0054] For example, when a user increases the quantity of server resources allocated to the network security product X according to changes in business requirements, the configuration information for the network security product X can be reconfigured to increase the quantity of server resources configured for the network security product X. Then, based on the newly configured configuration information and the server information, a workload to be deployed and a security server for deploying the workload can be determined, and the newly added workload can be deployed in the determined security server, for example, workload 4 is deployed in security server D. Thus, by simple configuration, quick and flexible product capacity expansion can be achieved according to user requirements.
[0055] Through the above method, without complex and time-consuming network and operation and maintenance configuration, by configuring the quantity of server resources of the network security product, the creation and deletion of the workload can be adaptively performed, and quick and flexible product capacity expansion and reduction can be achieved.
[0056] In a possible manner, determining the second security server for deploying the second workload from the first security server set comprises: in a case that there is a security server in the second security server set for deploying the workload of the second network security product, and an available resource amount of the security server is greater than or equal to a required server resource amount of the second workload, the second security server is determined from the second security server set, and the first security server set includes the second security server set; in a case that there is no security server in the second security server set, and an available resource amount of the security server is greater than or equal to the required server resource amount of the second workload, the second security server is determined from the other security servers in the first security server set except the second security server set.
[0057] For example, continuing to take the workload of the network security product X as an example, the workload includes the workload 1 deployed on the security server A, the workload 2 deployed on the security server B, and the workload 3 deployed on the security server C, in a case that there is at least one security server in the security server A, the security server B, and the security server C, and an available resource amount of the at least one security server is greater than or equal to a required server resource amount of the second workload, the second workload can be deployed to the at least one security server. It should be noted that the second workload can be entirely deployed to one security server in the at least one security server, or the second workload can be divided into multiple workloads and deployed to multiple security servers in the at least one security server, and the present disclosure does not limit this.
[0058] For example, in a case that the sum of the available resource amounts of multiple security servers in the security server A, the security server B, and the security server C is greater than or equal to the required server resource amount of the second workload, the second workload can be divided into multiple workloads and deployed to the multiple security servers.
[0059] For example, in a case that there is no security server in the security server A, the security server B, and the security server C, and the available resource amount of the security server is greater than or equal to the required server resource amount of the second workload, or the sum of the available resource amounts of multiple security servers in the security server A, the security server B, and the security server C is greater than or equal to the required server resource amount of the second workload, one or more security servers can be selected from security servers other than the security server A, the security server B, and the security server C for deploying the second workload, an available resource amount of the selected security server is greater than or equal to the required server resource amount of the second workload, and the selected security server can be an existing security server or a newly deployed security server, and the present disclosure does not limit this.
[0060] That is, in the case that the server resource amount of the original security server deploying the network security product X meets the condition, the expanded workload can be deployed in the original security server. In the case that the server resource amount of the original security server deploying the network security product X does not meet the condition, the expanded workload can be deployed in other security servers, or a new security server is deployed, and the expanded workload is deployed in the new security server.
[0061] Of course, in the case that the server resource amount of the original security server deploying the network security product X meets the condition, the second workload can also be deployed to other security servers, so that the workloads of the network security product X can be deployed separately, and the case that all workloads of the network security product X are unavailable due to the exception of the original security server can be avoided. The specific deployment can be determined according to requirements, and the present disclosure does not limit this.
[0062] It should be understood that when the workload is load-arranged, the load-arrangement can also be performed in combination with the set load-arrangement strategy, and the present disclosure does not limit this.
[0063] In a possible manner, each security server is deployed with a corresponding agent component, and the method further includes: in response to a registration request of the agent component, establishing a communication connection with the agent component. The server information of all security servers in the first security server set is obtained, including: receiving the server information of the corresponding security server sent by each agent component to obtain the server information of all security servers.
[0064] For example, each security server is deployed with a corresponding agent component, and is connected with the network resource security manager, and is configured to receive an instruction issued by the network resource security manager and report server information of the corresponding security server. The network resource security manager is configured to perform load arrangement and issue a corresponding instruction.
[0065] In a possible manner, each security server is deployed with a corresponding agent component, and the workload of the at least one network security product is deployed into the target security server, including: sending a load creation instruction to a target agent component corresponding to the target security server, the load creation instruction being used to instruct the target agent component to deploy the workload of the at least one network security product into the target security server.
[0066] For example, the network resource security manager sends the load creation instruction to the target agent component corresponding to the target security server after determining the target security server, and the target agent component deploys the workload into the corresponding target security server after receiving the load creation instruction.
[0067] Correspondingly, when the load is deleted, a load deletion instruction can also be sent to the corresponding proxy component, so that the proxy component deletes the workloads deployed in the corresponding security server based on the load deletion instruction.
[0068] The detailed embodiments are described below with reference to the accompanying drawings.
[0069] As shown in Figure 3 each security server is configured as a multi-network card type, and then the network cards of all security server nodes are interconnected with the security switch in a standardized and consistent manner. Then, the proxy component is deployed in each security server node, and is connected with the network security resource manager. After sending a registration request to the network security resource manager for registration, a communication connection is established, so that subsequent instructions, server information of the security server, and state information of the workloads deployed on the security server, etc. can be received. The present disclosure does not limit this. It should be understood that the process of adding a new security server is consistent with the above process, and the present disclosure will not be repeated here.
[0070] Continuing to refer to Figure 3 , the network security resource manager can perform load orchestration according to the configuration information of the network security product and the server information reported by the proxy component, generate a load orchestration instruction based on the load orchestration result, and send the load orchestration instruction to the corresponding proxy component. The load orchestration instruction can be a load creation instruction or a load deletion instruction. The load orchestration result includes the workloads that need to be created or deleted and the corresponding security server, and the configuration information of the network security product is determined based on user demand.
[0071] Further, the proxy component executes the creation, deletion, etc. of the workloads according to the load orchestration instruction, so that the workloads of the network security product can run or exit running on the security server in an adaptive manner, realizing fast and flexible product deployment and scaling.
[0072] In a possible manner, the method further includes: obtaining a running state of the workloads of the at least one network security product, performing traffic orchestration on the at least one network security product based on the running state, generating a traffic orchestration instruction, and the traffic orchestration instruction is used to indicate the traffic of the at least one network security product allocated to each workload; and sending the traffic orchestration instruction to a traffic orchestration manager, so that the traffic orchestration manager sends the traffic orchestration instruction to a security switch, and the security switch is used to schedule the traffic of the at least one network security product to the corresponding workload for security testing according to the traffic orchestration instruction.
[0073] For example, as Figure 3As shown, the network security resource manager can obtain the running state of the workloads in the corresponding security server through the proxy component, and then perform traffic arrangement on the network security product based on the running state, generate traffic arrangement instructions, send the traffic arrangement instructions to the traffic arrangement manager, and the traffic arrangement manager sends the traffic arrangement instructions to the security switch, so that the security switch schedules the traffic of the network security product to the corresponding workload based on the traffic arrangement instructions for security testing, including flow diversion, mirroring, and traffic load balancing, etc., which are not limited by the present disclosure.
[0074] It should be noted that load arrangement and traffic arrangement can be performed by a central manager with load arrangement and traffic arrangement functions, or load arrangement and traffic arrangement can be performed by different managers, etc., which are not limited by the present disclosure.
[0075] Through the above method, all security servers of the cloud service can be interconnected with the security switch without difference, and each security server can flexibly create and manage various workloads and traffic arrangements according to user needs. In addition, it also supports the simultaneous running of the workloads of multiple network security products, ensuring the traffic load balancing between different network security products. Not only meets the processing needs of high-performance traffic data, but also enhances the horizontal expansion capability of the network security product and improves the deployment efficiency.
[0076] Based on the same concept, the present disclosure provides a network security workload arrangement device for cloud security, as shown in Figure 4 As shown, the network security workload arrangement device 400 comprises:
[0077] The acquisition module 401 is configured to acquire target configuration information of at least one network security product corresponding to a cloud service, and acquire server information of all security servers in a first security server set; wherein the target configuration information comprises server resource quantity configured for each network security product in the at least one network security product, and the server information comprises available resource quantity of the all security servers, and different security servers are connected to a security switch corresponding to the cloud service through a unified interface;
[0078] The load arrangement module 402 is configured to perform load arrangement on the workloads of the at least one network security product based on the target configuration information and the server information.
[0079] Optionally, the network security workload arrangement device 400 further comprises:
[0080] The first obtaining sub-module is configured to obtain first configuration update information for a first network security product in the at least one network security product, wherein a new server resource amount configured for the first network security product in the first configuration update information is less than a server resource amount configured for the first network security product in the target configuration information;
[0081] The first determining module is configured to determine, based on the first configuration update information, a first workload to be deleted from workloads of the first network security product;
[0082] The deleting module is configured to determine a first security server in which the first workload is deployed, and delete the first workload deployed in the first security server.
[0083] Optionally, the network security workload arrangement apparatus 400 further comprises:
[0084] The second obtaining sub-module is configured to obtain second configuration update information for a second network security product in the at least one network security product, wherein a new server resource amount configured for the second network security product in the second configuration update information is greater than a server resource amount configured for the second network security product in the target configuration information;
[0085] The second determining module is configured to determine, based on the second configuration update information and the server information, a second workload of the second network security product to be deployed, and determine, from the first security server set, a second security server for deploying the second workload;
[0086] The deploying sub-module is configured to deploy the second workload into the second security server.
[0087] Optionally, the second determining module is configured to:
[0088] In a case where, in a second security server set in which workloads of the second network security product are deployed, there is a security server with an available resource amount greater than or equal to a server resource amount required by the second workload, the second security server is determined from the second security server set, and the first security server set comprises the second security server set;
[0089] In a case where, in the second security server set, there is no security server with an available resource amount greater than or equal to a server resource amount required by the second workload, the second security server is determined from other security servers in the first security server set except the second security server set.
[0090] Optionally, the network security workload arrangement apparatus 400 further comprises:
[0091] a third obtaining sub-module, configured to obtain a running state of a workload of the at least one network security product, perform traffic orchestration on the at least one network security product based on the running state, and generate a traffic orchestration instruction, the traffic orchestration instruction being used to instruct a traffic of the at least one network security product allocated to each workload;
[0092] a sending module, configured to send the traffic orchestration instruction to a traffic orchestration manager, so that the traffic orchestration manager issues the traffic orchestration instruction to a security switch, and the security switch is used to schedule the traffic of the at least one network security product to a corresponding workload for security testing according to the traffic orchestration instruction.
[0093] Optionally, each of the security servers is deployed with a corresponding agent component, and the load orchestration apparatus 400 further comprises:
[0094] a connecting module, configured to establish a communication connection with the agent component in response to a registration request of the agent component;
[0095] The obtaining module 401 is configured to:
[0096] receive server information of a corresponding security server sent by each of the agent components, and obtain the server information of all the security servers.
[0097] Optionally, the load orchestration module 402 is configured to:
[0098] determine a target security server for deploying a workload of the at least one network security product from all the security servers based on the target configuration information and the server information, and deploy the workload of the at least one network security product into the target security server, wherein an available resource amount of the target security server is greater than or equal to a server resource amount configured for the at least one network security product.
[0099] Optionally, each of the security servers is deployed with a corresponding agent component, and the load orchestration module 402 is configured to:
[0100] send a load creation instruction to a target agent component corresponding to the target security server, the load creation instruction being used to instruct the target agent component to deploy the workload of the at least one network security product into the target security server.
[0101] Based on the same idea, the disclosure further provides a computer readable medium having a computer program stored thereon, the program being executed by a processing device to implement the steps of the network security workload orchestration method for cloud security.
[0102] Based on the same idea, the embodiments of the present disclosure further provide an electronic device, which can include:
[0103] a storage device having stored thereon a computer program;
[0104] a processing device configured to execute the computer program in the storage device to implement the steps of the network security workload orchestration method for cloud security described above.
[0105] Based on the same idea, the embodiments of the present disclosure further provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the network security workload orchestration method for cloud security described above.
[0106] Reference will now be made to the drawings, in which Figure 5 , which shows a structural schematic diagram of an electronic device 500 suitable for implementing the embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure can include, but is not limited to, mobile terminals such as mobile phones, notebook computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Personal Computers), PMPs (Portable Multimedia Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), and the like, as well as fixed terminals such as digital TVs, desktop computers, and the like. Figure 5 The electronic device shown is merely an example and should not impose any limitation on the functions and use range of the embodiments of the present disclosure.
[0107] As shown in Figure 5 , the electronic device 500 can include a processing device (such as a central processor, a graphics processor, etc.) 501, which can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 502 or programs loaded from a storage device 508 into a random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the electronic device 500 are also stored. The processing device 501, the ROM 502, and the RAM 503 are connected to each other through a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.
[0108] Generally, the following devices can be connected to the I / O interface 505: input devices 506 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, and the like; output devices 507 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, and the like; storage devices 508 including, for example, a magnetic tape, a hard disk, and the like; and communication devices 509. The communication devices 509 can allow the electronic device 500 to communicate with other devices wirelessly or by wire to exchange data. Although Figure 5 Electronic device 500 is shown with various means, but it is understood that not all of the shown means need be implemented or present. More or less means can alternatively be implemented or present.
[0109] In particular, according to embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as a computer software program. For example, embodiments of the present disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods illustrated by the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication means 509, or installed from storage means 508, or installed from ROM 502. When the computer program is executed by processing means 501, the above-mentioned functions defined in the methods of embodiments of the present disclosure are performed.
[0110] It should be noted that the computer-readable medium described above in the present disclosure can be a computer-readable signal medium or a computer-readable storage medium or any combination thereof. The computer-readable storage medium, for example, can be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or apparatus, or any suitable combination thereof. More specific examples of the computer-readable storage medium can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program used by or in connection with an instruction execution system, apparatus, or device. In the present disclosure, the computer-readable signal medium can include a data signal propagated in baseband or propagated as a carrier wave in a propagated data signal, in which the computer-readable program code is carried. Such a propagated data signal can take a variety of forms, including but not limited to electro-magnetic, optical, or any suitable combination thereof. The computer-readable signal medium can also be any computer-readable medium that is not a computer-readable storage medium and that can be used to carry or store program code used by or in connection with an instruction execution system, apparatus, or device. Program code contained in the computer-readable medium can be transmitted using any suitable medium, including but not limited to wire, cable, optical fiber, RF (radio frequency), etc., or any suitable combination thereof.
[0111] In some embodiments, communications can be conducted using any currently known or future developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communications (e.g., communications networks) of any form or medium, including, for example, local area networks ("LANs"), wide area networks ("WANs"), internetworks (e.g., the Internet), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future developed networks.
[0112] The computer readable medium described above can be included in the electronic device described above; or can exist separately from the electronic device and be not assembled into the electronic device.
[0113] The computer readable medium described above carries one or more programs, when the one or more programs are executed by the electronic device, cause the electronic device to: acquire target configuration information of at least one network security product corresponding to a cloud service, and acquire server information of all security servers in a first security server set; wherein the target configuration information includes a server resource amount configured for each network security product in the at least one network security product, and the server information includes an available resource amount of the all security servers, different security servers are connected to a security switch corresponding to the cloud service through a unified interface; based on the target configuration information and the server information, load orchestration is performed on a working load of the at least one network security product.
[0114] Computer program code for carrying out operations of the present disclosure can be written in any one or combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network ("LAN") or a wide area network ("WAN"), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0115] The computer program product of the first aspect can include one or more non-transitory computer-readable media storing instructions that, when executed, cause one or more processors to perform the operations of the first aspect. The computer program product of the first aspect can include a non-transitory computer-readable medium storing code that, when executed, causes a computer to perform operations for the first aspect.
[0116] The modules involved in the embodiments of the present disclosure can be implemented in the form of software, or can be implemented in the form of hardware. In some cases, the name of the module does not constitute a limitation on the module itself.
[0117] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, non-limiting examples of exemplary types of hardware logic components that can be used include field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SOCs), complex programmable logic devices (CPLDs), etc.
[0118] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable storage media can include, without limitation, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of machine-readable storage media can include one or more lines of electrical wire, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or Flash memory), optical fiber, portable compact disc read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination of the foregoing.
[0119] The above description merely illustrates the preferred embodiment of the disclosure and a principle of applied technologies. It should be understood by those skilled in the art that the disclosed range of the disclosure is not limited to the technical solutions formed by the specific combinations of the technical features described above, and should also cover other technical solutions formed by the combinations of the technical features described above or their equivalent features without departing from the disclosed concept. For example, the technical solutions formed by the mutual replacement of the above-described features and the technical features with similar functions disclosed in the disclosure (but not limited to) can be formed.
[0120] Furthermore, although each operation is depicted in a particular order, this should not be understood as requiring the operations to be performed in the particular order shown or in a sequential order. In certain circumstances, multitasking and parallel processing can be advantageous. Likewise, although specific implementation details are included in the above discussion, these should not be interpreted as limiting the scope of the disclosure. Certain features described in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment can also be implemented separately or in any suitable subcombination. It will be appreciated that various features described herein can form part of a larger system, can be implemented in a distributed system, or can form part of a larger system that is implemented in a distributed manner.
[0121] Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are merely illustrative of the example forms of implementing the claims. As to the devices in the above-described embodiments, the specific manner in which the various modules perform operations has been described in detail in the embodiments related to the method, and will not be described here in detail.
Claims
1. A network security workload orchestration method for cloud security, characterized in that, The method includes: Obtain target configuration information for at least one network security product corresponding to the cloud service, and obtain server information for all security servers in the first set of security servers; wherein, the target configuration information includes the amount of server resources configured for each network security product in the at least one network security product, and the server information includes the available resources of all security servers, different security servers are connected to the security switch corresponding to the cloud service through a unified interface, and the same security server can deploy network security products with different network topologies and / or configured connection methods; Based on the target configuration information and the server information, a target security server for deploying the workload of the at least one network security product is determined from all the security servers, and the workload of the at least one network security product is deployed to the target security server. The number of target security servers is one or more, and the available resources of the target security server are greater than or equal to the server resources configured for the at least one network security product. The method further includes: The system obtains the operating status of the workload of the at least one network security product, performs traffic orchestration on the at least one network security product based on the operating status, and generates a traffic orchestration instruction. The traffic orchestration instruction is used to indicate the traffic of the at least one network security product allocated to each workload. The traffic orchestration instruction is sent to the traffic orchestration manager, so that the traffic orchestration manager issues the traffic orchestration instruction to the security switch. The security switch is used to schedule the traffic of the at least one network security product to the corresponding workload for security testing according to the traffic orchestration instruction.
2. The network security workload orchestration method for cloud security according to claim 1, characterized in that, The method further includes: Obtain first configuration update information for a first network security product among the at least one network security products, wherein the new server resource amount configured for the first network security product in the first configuration update information is less than the server resource amount configured for the first network security product in the target configuration information. Based on the first configuration update information, determine the first workload to be deleted from the workload of the first network security product; Identify the first security server where the first workload is deployed, and remove the first workload deployed on the first security server.
3. The network security workload orchestration method for cloud security according to claim 1 or 2, characterized in that, The method further includes: Obtain second configuration update information for the second network security product among the at least one network security product, wherein the new server resource amount configured for the second network security product in the second configuration update information is greater than the server resource amount configured for the second network security product in the target configuration information; Based on the second configuration update information and the server information, the second workload of the second network security product to be deployed is determined, and the second security server for deploying the second workload is determined from the first set of security servers. The second workload is deployed to the second security server.
4. The network security workload orchestration method for cloud security according to claim 3, characterized in that, The step of determining a second security server from the first set of security servers for deploying the second workload includes: If, in the second set of security servers where the workload of the second network security product is deployed, there exists a security server with available resources greater than or equal to the server resources required by the second workload, the second security server is determined from the second set of security servers, wherein the first set of security servers includes the second set of security servers. If there is no secure server in the second set of secure servers with available resources greater than or equal to the server resources required by the second workload, the second secure server shall be determined from the other secure servers in the first set of secure servers excluding the second set of secure servers.
5. The network security workload orchestration method for cloud security according to claim 1 or 2, characterized in that, Each of the security servers is deployed with a corresponding proxy component, and the method further includes: In response to the registration request of the proxy component, a communication connection is established with the proxy component; The step of obtaining server information for all security servers in the first set of security servers includes: Receive server information of the corresponding security server sent by each of the proxy components to obtain server information of all the security servers.
6. The network security workload orchestration method for cloud security according to claim 1 or 2, characterized in that, Each of the aforementioned security servers is deployed with a corresponding proxy component, and the deployment of the workload of the at least one network security product to the target security server includes: A load creation instruction is sent to the target proxy component corresponding to the target security server. The load creation instruction is used to instruct the target proxy component to deploy the workload of the at least one network security product to the target security server.
7. A network security workload orchestration apparatus for cloud security, characterized in that, The device includes: The acquisition module is used to acquire target configuration information of at least one network security product corresponding to the cloud service, and to acquire server information of all security servers in the first set of security servers; wherein, the target configuration information includes the amount of server resources configured for each network security product in the at least one network security product, the server information includes the available resources of all security servers, different security servers are connected to the security switch corresponding to the cloud service through a unified interface, and the same security server can deploy network security products with different network topologies and / or configured connection methods; The load orchestration module is used to determine, based on the target configuration information and the server information, a target security server for deploying the workload of the at least one network security product from all the security servers, and to deploy the workload of the at least one network security product to the target security server. The number of target security servers is one or more, and the available resources of the target security server are greater than or equal to the server resources configured for the at least one network security product. The device further includes: The third acquisition submodule is used to acquire the operating status of the workload of the at least one network security product, perform traffic orchestration on the at least one network security product based on the operating status, and generate traffic orchestration instructions. The traffic orchestration instructions are used to indicate the traffic of the at least one network security product allocated to each workload. The sending module is used to send the traffic orchestration instruction to the traffic orchestration manager, so that the traffic orchestration manager can issue the traffic orchestration instruction to the security switch. The security switch is used to schedule the traffic of the at least one network security product to the corresponding workload for security testing according to the traffic orchestration instruction.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the program implements the steps of the method described in any one of claims 1-6.
9. An electronic device, characterized in that, include: A memory on which computer programs are stored; A processor for executing the computer program in the memory to implement the steps of the method according to any one of claims 1-6.
10. A computer program product, comprising a computer program, characterized in that, When executed by a processor, the computer program implements the steps of the method described in any one of claims 1-6.
Citation Information
Patent Citations
Web application deployment method and device
CN107992547A