Collaborative security defense method, device and computer equipment based on intent-driven edge cloud and central cloud

Through the intent-driven network collaboration of edge cloud and central cloud to generate security defense intentions and services, the problem of limited security resources in cloud-edge collaboration scenarios is solved, and rapid response and efficient security protection are achieved.

CN119652652BActive Publication Date: 2025-10-03CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411969829.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-10-03
Estimated Expiration
2044-12-30

AI Technical Summary

Technical Problem

In cloud-edge collaboration scenarios such as 5G customized networks and MEC, edge-side security resources are limited, making it impossible to quickly identify security attacks and dynamically build protection strategies, resulting in low security protection efficiency.

Method used

The intent-driven network of the edge cloud and the central cloud generates security defense intentions. The edge cloud performs defense operations on its own when resources permit. Otherwise, the central cloud assists in generating and providing defense services, realizing intelligent regulation and dynamic allocation of resources.

Benefits of technology

It improves the security protection efficiency in cloud-edge collaboration scenarios, can quickly respond to security attacks and effectively utilize edge and central cloud resources, thereby improving security protection effects.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119652652B_ABST
    Figure CN119652652B_ABST
Patent Text Reader

Abstract

The present application relates to a collaborative security defense method, apparatus, computer equipment, storage medium and computer program product based on intent-driven edge cloud and central cloud. The method includes: when the edge cloud identifies a security attack, generating an edge cloud security defense intent through the edge cloud's intent-driven network; when the edge cloud resource environment conditions meet the operating environment conditions of the security defense operation and the security resources provided by the edge cloud meet the security resource requirements of the security defense operation, generating an edge cloud security defense service that matches the edge cloud security defense intent through the edge cloud; when the edge cloud resource environment conditions do not meet the operating environment conditions of the security defense operation or the security resources provided by the edge cloud do not meet the security resource requirements of the security defense operation, generating a central cloud security defense intent through the central cloud's intent-driven network and generating a corresponding central cloud security defense service. The use of this method can improve the security protection efficiency of cloud-edge collaborative scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a collaborative security defense method, apparatus, computer equipment, storage medium, and computer program product based on intent-driven edge cloud and central cloud. Background Art

[0002] Due to limited security resources at the edge, cloud-edge collaboration scenarios like 5G customized networks and MEC cannot quickly identify security attacks or dynamically build security protection strategies to respond to sudden attacks such as unknown attacks and large-scale traffic attacks. Furthermore, cloud-edge collaboration scenarios lack a global security protection mechanism, making security protection strategies inefficient to execute and resulting in poor security protection effectiveness.

[0003] Therefore, traditional technologies have the problem of low security protection efficiency in cloud-edge collaboration scenarios. Summary of the Invention

[0004] Based on this, it is necessary to provide an intent-driven edge cloud and central cloud collaborative security defense method, device, computer equipment, computer-readable storage medium and computer program product to address the above technical problems, which can improve the security protection efficiency in cloud-edge collaboration scenarios.

[0005] An intent-driven collaborative security defense approach for edge cloud and central cloud, including:

[0006] When the edge cloud identifies a security attack, the edge cloud's intent-driven network generates an edge cloud security defense intent; the edge cloud security defense intent describes the security defense operations that the edge cloud needs to complete to defend against the security attack;

[0007] When the resource environment conditions of the edge cloud meet the operating environment conditions of the security defense operation and the existing security resources provided by the edge cloud meet the security resource requirements of the security defense operation, an edge cloud security defense service matching the edge cloud security defense intention is generated through the edge cloud; the edge cloud security defense service is used to perform the security defense operation;

[0008] When the resource and environmental conditions of the edge cloud do not meet the operating environment conditions for security defense operations, or the existing security resources provided by the edge cloud do not meet the security resource requirements for security defense operations, the central cloud's intent-driven network generates a central cloud security defense intention and generates a central cloud security defense service that matches the central cloud's security defense intention; the central cloud security defense intention describes the security defense operations that the central cloud needs to complete to assist the edge cloud in defending against security attacks; the central cloud security defense service is used to assist the edge cloud in performing security defense operations.

[0009] In one embodiment, generating a central cloud security defense service that matches a central cloud security defense intention includes:

[0010] Translate edge cloud security defense intent into central cloud security defense strategy through the central cloud;

[0011] The central cloud's security controller provides the edge cloud with central cloud security defense services that match the central cloud's security defense strategy.

[0012] In one embodiment, translating the central cloud security defense intent into a central cloud security defense policy through the central cloud includes:

[0013] The central cloud's intent-driven network is used to translate the central cloud's security defense intent and obtain the initial central cloud security defense strategy;

[0014] Perform format verification on the initial central cloud security defense strategy through the central cloud's intent-driven network to obtain a format verification result;

[0015] If the format verification result is that the format verification passes, the initial central cloud security defense strategy is used as the central cloud security defense strategy.

[0016] In one embodiment, a central cloud security controller provides a central cloud security defense service that matches the central cloud security defense policy to the edge cloud, including:

[0017] Network security functions are instantiated through the central cloud's security controller, and security resources in the central cloud's security resource pool are deployed to provide the edge cloud with central cloud security defense services that match the central cloud's security defense strategy.

[0018] In one embodiment, the method further comprises:

[0019] Collect attack information of security attacks through edge cloud;

[0020] Model the attack information through the central cloud to obtain the attack characteristics of security attacks in various attack dimensions;

[0021] The central cloud determines the security resource requirements for security defense operations based on the attack characteristics of security attacks in each attack dimension.

[0022] In one embodiment, the central cloud determines the security resource requirements for security defense operations based on the attack characteristics of the security attack in each attack dimension, including:

[0023] Through the central cloud, based on the attack characteristics of security attacks in various attack dimensions, digital twin technology is used to simulate security attacks and simulate the execution of security defense operations;

[0024] The security resources used to perform security defense operations during the simulation process are determined through the central cloud as the security resource requirements of the security defense operations.

[0025] A collaborative security defense device based on intent-driven edge cloud and central cloud, including:

[0026] The intent-driven module is used to generate edge cloud security defense intent through the edge cloud's intent-driven network when the edge cloud identifies a security attack. The edge cloud security defense intent describes the security defense operations that the edge cloud needs to complete to defend against security attacks.

[0027] The edge cloud defense module is used to generate an edge cloud security defense service that matches the edge cloud security defense intention through the edge cloud when the resource environment conditions of the edge cloud meet the operating environment conditions of the security defense operation and the existing security resources provided by the edge cloud meet the security resource requirements of the security defense operation; the edge cloud security defense service is used to perform the security defense operation;

[0028] The central cloud defense module generates a central cloud security defense intention through the central cloud's intention-driven network when the resource and environmental conditions of the edge cloud do not meet the operating environment conditions for security defense operations, or the existing security resources provided by the edge cloud do not meet the security resource requirements for security defense operations, and generates a central cloud security defense service that matches the central cloud security defense intention; the central cloud security defense intention describes the security defense operations that the central cloud needs to complete to assist the edge cloud in defending against the security attacks; the central cloud security defense service is used to assist the edge cloud in performing security defense operations.

[0029] A computer device includes a memory and a processor, wherein the memory stores a computer program and the processor implements the steps of the above method when executing the computer program.

[0030] A computer-readable storage medium stores a computer program, which implements the steps of the above method when executed by a processor.

[0031] A computer program product includes a computer program, and when the computer program is executed by a processor, the steps of the above method are implemented.

[0032] The above-mentioned intent-driven collaborative security defense method, device, computer equipment, storage medium and computer program product of edge cloud and central cloud generate edge cloud security defense intent through the edge cloud's intent-driven network when a security attack is identified at the edge cloud; the edge cloud security defense intent describes the security defense operations that the edge cloud needs to complete to defend against security attacks; when the resource and environmental conditions of the edge cloud meet the operating environment conditions of the security defense operation, and the existing security resources provided by the edge cloud meet the security resource requirements of the security defense operation, an edge cloud security defense service matching the edge cloud security defense intent is generated through the edge cloud; the edge cloud security defense service is used to perform security defense operations; when the resource and environmental conditions of the edge cloud do not meet the operating environment conditions of the security defense operation, or the existing security resources provided by the edge cloud do not meet the security resource requirements of the security defense operation, the central cloud security defense intent is generated through the central cloud's intent-driven network, and a security defense service matching the central cloud security defense intent is generated. Intent-matched central cloud security defense service; central cloud security defense intent describes the security defense operations that the central cloud needs to complete to assist the edge cloud in defending against security attacks; central cloud security defense services are used to assist the edge cloud in performing security defense operations; in this way, when the edge cloud faces a security attack, the edge cloud's intent-driven network can be used to quickly generate edge cloud security defense intents to determine the security defense work that needs to be performed, and accurately and quickly generate edge cloud security defense services when the edge cloud's resource and environmental conditions and the security resources that the edge cloud can provide can support the implementation of security defense operations. When the edge cloud's resource and environmental conditions or the security resources that the edge cloud can provide cannot support the implementation of security defense operations, the central cloud's intent-driven network can be used to quickly generate central cloud security defense intents to assist the edge cloud in performing security defense operations, realizing cloud-edge collaborative defense, which can efficiently help the edge cloud defend against security attacks and improve the security protection efficiency in cloud-edge collaborative scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0034] Figure 1 This is a diagram of an application environment for an intent-driven collaborative security defense method for edge cloud and central cloud in one embodiment;

[0035] Figure 2 1. A flowchart of a collaborative security defense method for edge cloud and central cloud based on intent-driven in one embodiment;

[0036] Figure 3 A flowchart of a collaborative security defense method between edge cloud and central cloud based on intent-driven in one embodiment;

[0037] Figure 4 1 is a flowchart of a collaborative security defense method between edge cloud and central cloud based on intent-driven in another embodiment;

[0038] Figure 5 This is a structural block diagram of a collaborative security defense device based on an intent-driven edge cloud and a central cloud in one embodiment;

[0039] Figure 6 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0040] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0041] Due to limited security resources at the edge, cloud-edge collaboration scenarios like 5G customized networks and MEC cannot quickly identify security attacks and dynamically build security protection strategies to respond to sudden attacks such as unknown attacks and large-scale traffic attacks. Furthermore, due to the lack of a global security protection mechanism, cloud-edge collaboration scenarios suffer from inefficient security policy execution and poor security protection effectiveness.

[0042] The collaborative security defense method for edge cloud and central cloud based on intent-driven provided in the embodiment of the present application can significantly improve the effect of intent-driven network in edge cloud network security protection, evaluate security defense intentions from multiple dimensions, dynamically allocate central cloud and edge cloud security resources, create a safe, flexible and reliable intent-driven security protection mechanism, realize intelligent regulation of security resources, and improve the security protection efficiency of cloud-edge collaborative scenarios.

[0043] The collaborative security defense method based on the intent-driven edge cloud and central cloud provided in the embodiment of the present application can be applied to Figure 1 In the system architecture shown in Figure 1, the security resource calls of the edge cloud and the central cloud are controlled by the intent policy control layer.

[0044] The intent policy control layer includes an intent collection module, an intent evaluation module, and an intent decision module. The intent collection module is responsible for collecting the security defense intents generated by the edge cloud. The intent evaluation module is responsible for evaluating the effectiveness of the security defense intents generated by the edge cloud based on the collected security intents, intent network status, security status, and other information, including deployment location, network resources, QoS level, etc., to determine whether the intents generated by the edge cloud can meet resource and security requirements. The intent decision module is responsible for linking with the security controller to optimize, adjust, and enhance the security defense intents of the central cloud and edge cloud. If the security resources of the edge cloud cannot meet the security resource requirements of the security defense intent, the security resources of the central cloud will be dynamically allocated as a supplement and enhancement.

[0045] The edge cloud and central cloud each have their own corresponding data collection layer, resource orchestration layer (including security controller), intent-enabling layer, and NFVI (Network Function Virtualization Infrastructure). The central cloud has a centralized security capability pool, providing security services such as image scanning, vulnerability scanning, security testing, baseline verification, web vulnerability scanning, and security auditing. The edge cloud has an edge security capability pool, providing NGFW (Next Generation Firewall, a new type of network security device), WAF (Web Application Firewall), and IPS (Intrusion Prevention System) to different customers.

[0046] In an exemplary embodiment, Figure 2 As shown in the figure, a collaborative security defense method based on intent-driven edge cloud and central cloud is provided. Figure 1 The edge cloud and the central cloud in FIG are taken as an example to illustrate, including the following steps S202 to S206. Among them:

[0047] Step S202: When the edge cloud identifies a security attack, the edge cloud security defense intent is generated by the edge cloud intent-driven network; the edge cloud security defense intent describes the security defense operations that the edge cloud needs to complete to defend against the security attack.

[0048] Among them, security attacks can be network attacks against edge clouds, such as large-scale traffic attacks or distributed denial of service (DDoS) attacks.

[0049] Intent-driven networking, also known as intent-based networking (IBN), allows users to describe desired actions (intents) in concise language. The IBN then translates these intents into policies and leverages automation to establish appropriate configuration and setting changes in complex network environments. This includes steps such as intent acquisition, intent translation, policy validation, intent distribution and execution, and real-time feedback. Intents can be declarative expressions of desired goals, utilities, requirements, and constraints within an information system, defining expectations for service delivery and the behavior of the autonomous management framework and underlying management network. In practical applications, AI models can be used as IDNs, with the natural language text generated by the AI ​​models serving as intents.

[0050] Among them, the edge cloud security defense intent describes the security defense operations that the edge cloud needs to complete to defend against security attacks.

[0051] For example, when the edge cloud faces a distributed denial of service (DDoS) attack, the edge cloud security defense intention can be "intercepting 80% of abnormal traffic from the voice service user side of the edge cloud, and the processing and recovery needs to be completed within 6 hours."

[0052] In practical applications, the intention features of the edge cloud security defense intent can be extracted to intuitively evaluate whether the resource environment conditions of the edge cloud meet the operating environment conditions of the security defense operation. The edge cloud security defense intent can be "intercept 80% of abnormal traffic from the edge cloud voice service user side, and need to complete processing and recovery within 6 hours." The corresponding intention features can include: (1) Business type: voice service; (2) Inter-domain / intra-domain task: intra-domain task; (3) Target object: voice application in the edge cloud domain; (4) Execution operation: intercept abnormal business traffic; (5) Expected result: block 80% of abnormal traffic and reduce the impact on voice service.

[0053] The security defense operation may refer to a security defense action required to be performed to defend against a security attack.

[0054] Optionally, taking the case where the edge cloud faces a distributed denial of service (DDoS) attack as an example, when the edge cloud identifies the security attack as "facing a distributed denial of service (DDoS) attack", the edge cloud's intent-driven network generates the edge cloud security defense intention of "intercepting 80% of abnormal traffic from the edge cloud's voice service user side, and the processing and recovery needs to be completed within 6 hours".

[0055] Step S204: When the resource environment conditions of the edge cloud meet the operating environment conditions of the security defense operation and the existing security resources provided by the edge cloud meet the security resource requirements of the security defense operation, an edge cloud security defense service that matches the edge cloud security defense intention is generated through the edge cloud; the edge cloud security defense service is used to perform security defense operations.

[0056] Among them, the resource and environmental conditions of the edge cloud can be determined by the deployment location of the edge cloud's security equipment, network resources (latency, bandwidth, etc.), QoS level, storage resources (memory), computing resources (CPU), security resources (FW, IPS, IDS, DDoS), etc.

[0057] Among them, the operating environment conditions of security defense operations correspond to the resource environment conditions of the edge cloud. The operating environment conditions of security defense operations can refer to the security equipment, network resources (latency, bandwidth, etc.), QoS levels, storage resources (memory), computing resources (CPU), security resources (FW, IPS, IDS, DDoS), etc. required to perform security defense operations.

[0058] Among them, the existing security resources provided by the edge cloud may refer to the security resources that the edge cloud can currently call.

[0059] The security resource requirements for security defense operations may refer to the security resources required to execute security defense operations.

[0060] Among them, edge cloud security defense service can refer to the security service that the edge cloud can provide to defend against security attacks.

[0061] Optionally, taking the case where the edge cloud faces a distributed denial of service (DDoS) attack as an example, the effectiveness of the edge cloud security defense intention can be judged based on the deployment location of the edge cloud security device, network resources (latency, bandwidth, etc.), QoS level, storage resources (memory), computing resources (CPU), and security resources (FW, IPS, IDS, DDoS). That is, whether the resource environment conditions of the edge cloud meet the operating environment conditions of the security defense operation. After determining whether the edge cloud security defense intention is effective, it is determined whether the utilization and performance of the CPU, memory, bandwidth and other resources of the anti-DDoS security device currently deployed by the edge cloud can withstand 80% of the DDoS abnormal traffic attacks. That is, whether the existing security resources provided by the edge cloud meet the security resource requirements of the security defense operation. After determining whether the utilization and performance of the CPU, memory, bandwidth and other resources of the anti-DDoS security device currently deployed by the edge cloud can withstand 80% of the DDoS abnormal traffic attacks, an edge cloud security defense service matching the edge cloud security defense intention is generated through the edge cloud. If the resource environment conditions of the edge cloud do not meet the operating environment conditions of the security defense operation or the existing security resources provided by the edge cloud do not meet the security resource requirements of the security defense operation, please refer to the specific instructions of step S206.

[0062] The specific steps of the above-mentioned "generating an edge cloud security defense service that matches the edge cloud security defense intention through the edge cloud" are: translating the edge cloud security defense intention into an edge cloud security defense strategy through the edge cloud's intent enabling layer; generating an edge cloud security defense service that matches the edge cloud security defense strategy through the edge cloud's security controller; and the edge cloud security defense service is used to perform security defense operations.

[0063] Among them, the edge cloud security defense strategy can be a security protection strategy used in the edge cloud to deal with security attacks.

[0064] Among them, the security controller of the edge cloud is located in the resource orchestration layer of the edge cloud, such as Figure 1 As shown, the security controller of the edge cloud executes the corresponding method based on the policy output by the intent decision module of the intent policy control layer.

[0065] Step S206: When the resource environment conditions of the edge cloud do not meet the operating environment conditions of the security defense operation, or the existing security resources provided by the edge cloud do not meet the security resource requirements of the security defense operation, the central cloud's intention-driven network generates a central cloud security defense intention, and generates a central cloud security defense service that matches the central cloud security defense intention; the central cloud security defense intention describes the security defense operation that the central cloud needs to complete to assist the edge cloud in defending against the security attack; the central cloud security defense service is used to assist the edge cloud in performing security defense operations.

[0066] Among them, the central cloud security defense intention describes the security defense operations that the central cloud needs to complete to help the edge cloud defend against security attacks. For example, when the edge cloud faces a distributed denial of service (DDoS) attack, the edge cloud security defense intention can be "intercept 80% of abnormal traffic from the voice service user side of the edge cloud, and complete processing and recovery within 6 hours." The central cloud security defense intention can be "intercept 80% of abnormal traffic for the voice service users of the edge cloud, and complete processing and recovery within 6 hours."

[0067] Among them, the central cloud security defense service can be the security service that the central cloud can provide to help the edge cloud defend against security attacks.

[0068] Optionally, taking the case where the edge cloud faces a distributed denial of service (DDoS) attack as an example, when it is determined that the edge cloud security defense intent is invalid or when it is determined that the CPU, memory, bandwidth and other resource utilization and performance of the anti-DDoS security equipment currently deployed in the edge cloud cannot withstand 80% of the DDoS abnormal traffic attacks, the central cloud can be notified through the intent policy control layer, and the central cloud security defense intent can be generated through the central cloud's intent-driven network, and a central cloud security defense service that matches the central cloud security defense intent can be generated to assist the edge cloud in performing security defense operations.

[0069] In the above-mentioned collaborative security defense method of edge cloud and central cloud based on intent-driven, when a security attack is identified in the edge cloud, the edge cloud security defense intent is generated through the edge cloud's intent-driven network; the edge cloud security defense intent describes the security defense operations that the edge cloud needs to complete to defend against security attacks; when the resource and environmental conditions of the edge cloud meet the operating environment conditions of the security defense operation, and the existing security resources provided by the edge cloud meet the security resource requirements of the security defense operation, the edge cloud security defense service that matches the edge cloud security defense intent is generated through the edge cloud; the edge cloud security defense service is used to perform security defense operations; when the resource and environmental conditions of the edge cloud do not meet the operating environment conditions of the security defense operation, or the existing security resources provided by the edge cloud do not meet the security resource requirements of the security defense operation, the central cloud security defense intent is generated through the central cloud's intent-driven network, and a security defense service is generated. A central cloud security defense service that matches the central cloud security defense intention; the central cloud security defense service is used to assist the edge cloud in performing security defense operations; in this way, when the edge cloud faces a security attack, the edge cloud's intent-driven network can be used to quickly generate edge cloud security defense intentions to determine the security defense work that needs to be performed, and when the edge cloud's resource and environmental conditions and the security resources that the edge cloud can provide can support the implementation of security defense operations, the edge cloud security defense service can be accurately and quickly generated. When the edge cloud's resource and environmental conditions or the security resources that the edge cloud can provide cannot support the implementation of security defense operations, the central cloud's intent-driven network can be used to quickly generate central cloud security defense intentions to assist the edge cloud in performing security defense operations, realizing cloud-edge collaborative defense, which can effectively help the edge cloud defend against security attacks and improve the security protection efficiency in cloud-edge collaborative scenarios.

[0070] In one embodiment, generating a central cloud security defense service that matches the central cloud security defense intention includes: translating the central cloud security defense intention into a central cloud security defense policy through the central cloud; and providing the edge cloud with a central cloud security defense service that matches the central cloud security defense policy through the central cloud's security controller.

[0071] Among them, the central cloud security defense strategy can be a security protection strategy used in the central cloud to deal with security attacks.

[0072] Optionally, taking the case where the edge cloud faces a distributed denial of service (DDoS) attack as an example, when it is determined that the edge cloud security defense intention is invalid or when it is determined that the CPU, memory, bandwidth and other resource utilization and performance of the anti-DDoS security equipment currently deployed in the edge cloud cannot withstand 80% of the DDoS abnormal traffic attacks, the central cloud can be notified through the intent policy control layer, and the central cloud security defense intention can be generated through the intent enabling layer of the central cloud. The central cloud security defense intention is then translated into a central cloud security defense policy through the central cloud, and then the central cloud security controller provides the edge cloud with a central cloud security defense service that matches the central cloud security defense policy to assist the edge cloud in performing security defense operations.

[0073] In this embodiment, the central cloud security defense intention is translated into the central cloud security defense intention through the central cloud; the central cloud security controller provides the edge cloud with a central cloud security defense service that matches the central cloud security defense strategy; in this way, the central cloud security defense strategy can be accurately and quickly generated through the central cloud, and then the corresponding central cloud security defense service can be called through the central cloud security controller to efficiently assist the edge cloud in defending against security attacks, prevent the edge cloud from being unable to defend against security attacks, and improve the security protection efficiency in the cloud-edge collaboration scenario.

[0074] In one of the embodiments, the central cloud security defense intent is translated into a central cloud security defense policy through the central cloud, including: translating the central cloud security defense intent through the intent-driven network of the central cloud to obtain an initial central cloud security defense policy; formatting the initial central cloud security defense policy through the intent-driven network of the central cloud to obtain a format verification result; when the format verification result is that the format verification passes, using the initial central cloud security defense intent as the central cloud security defense policy.

[0075] Among them, the initial central cloud security defense intention may refer to the result obtained after format conversion of the central cloud security defense intention.

[0076] The format verification result may refer to whether the format of the translated central cloud security defense intent is correct, or whether the key fields are correct.

[0077] Optionally, the central cloud security defense intent is translated through the central cloud's intent-driven network to obtain an initial central cloud security defense strategy. Then, the format of the initial central cloud security defense strategy is verified through the central cloud's intent-driven network to determine whether the format of the initial central cloud security defense intent is correct. If not, it needs to be re-translated. If correct, the initial central cloud security defense strategy is determined as the central cloud security defense strategy to ensure that the translated central cloud security defense strategy can match the configured security defense strategy.

[0078] In this embodiment, the central cloud security defense intent is translated through the intent-driven network of the central cloud to obtain an initial central cloud security defense strategy; the initial central cloud security defense strategy is format-verified through the intent-driven network of the central cloud to obtain a format verification result; when the format verification result is that the format verification passes, the initial central cloud security defense strategy is used as the central cloud security defense strategy; in this way, the translation, verification, and policy configuration and distribution of the central cloud security defense intent can be completed through the intent-driven network of the central cloud, thereby improving the generation efficiency and accuracy of the security defense strategy.

[0079] In one embodiment, the central cloud's security controller provides the edge cloud with a central cloud security defense service that matches the central cloud's security defense policy, including: instantiating network security functions through the central cloud's security controller, and deploying security resources in the central cloud's security resource pool to provide the edge cloud with a central cloud security defense service that matches the central cloud's security defense policy.

[0080] Among them, the security controller of the central cloud is located in the resource orchestration layer of the central cloud, such as Figure 1 As shown, the security controller of the central cloud executes the corresponding method based on the policy output by the intent decision module of the intent policy control layer.

[0081] Among them, the network security function may refer to a function of defending against security attacks.

[0082] The central cloud security resource pool can refer to the security resource pool corresponding to the central cloud, which can be found in Figure 1 The centralized security capability pool shown in the figure corresponds to the edge cloud, which also has a corresponding security resource pool. Figure 1 The edge security capability pool shown.

[0083] Optionally, taking the case where the edge cloud faces a distributed denial of service (DDoS) attack as an example, the network security function is instantiated through the security controller of the central cloud, and the security resources in the central cloud security resource pool are deployed to provide the edge cloud with a central cloud security defense service that matches the central cloud security defense strategy, which can be an anti-DDoS service, to perform security defense operations.

[0084] In this embodiment, the network security function is instantiated through the security controller of the central cloud, and the security resources in the central cloud security resource pool are deployed to provide the edge cloud with a central cloud security defense service that matches the central cloud security defense strategy. The security resources of the central cloud can be allocated to provide security defense services for the edge cloud, thereby improving the collaborative security defense efficiency of the edge cloud and the central cloud.

[0085] In one embodiment, the method further includes: collecting attack information of security attacks through the edge cloud; modeling the attack information through the central cloud to obtain attack characteristics of the security attacks in each attack dimension; and determining the security resource requirements of the security defense operation based on the attack characteristics of the security attacks in each attack dimension through the central cloud.

[0086] The attack information may be information recording attack situations of security attacks.

[0087] Among them, the attack dimension can refer to the attack target location, attack duration, attack impact range, attack path restoration, threat intelligence, number of high- and medium-risk security incident alarms, and the proportion of high- and medium-risk security incident alarms corresponding to the security attack.

[0088] The attack feature may refer to the analysis result corresponding to the attack dimension.

[0089] To facilitate understanding by those skilled in the art, the following Table 1 exemplarily provides attack features corresponding to each attack dimension.

[0090] Table 1

[0091]

[0092] Optionally, attack information of security attacks is collected through the edge cloud, and then the attack information is modeled through the central cloud to obtain the attack characteristics of the security attacks in each attack dimension. The central cloud then evaluates the security resource requirements of security defense operations based on the attack characteristics of the security attacks in each attack dimension.

[0093] In practical applications, Table 1 can be used to determine the security resource requirements for security defense operations. Implementing security defense operations requires an interception bandwidth of 50 Mbps. Before determining the security resource requirements for security defense operations, it is necessary to model and analyze the existing security resources of the edge cloud and the central cloud. As shown in Table 2 below, the edge cloud currently has one firewall deployed with an interception bandwidth of 10 Mbps, while the central cloud currently has ten anti-DDoS devices deployed with an interception bandwidth of 1000 Mbps. Since implementing security defense operations requires an interception bandwidth of 50 Mbps, and the edge cloud already has one firewall deployed with an interception bandwidth of 10 Mbps, the existing security resources of the edge cloud are insufficient to support the implementation of security defense operations.

[0094] Table 2

[0095]

[0096] In this embodiment, attack information of security attacks is collected through the edge cloud; the attack information is modeled through the central cloud to obtain the attack characteristics of the security attacks in each attack dimension; the security resource requirements of the security defense operation are determined by the central cloud based on the attack characteristics of the security attacks in each attack dimension; in this way, the security resources required for the edge cloud security defense intention can be evaluated through central cloud modeling, which is conducive to accurately and quickly determining the gap between the security resources required for the edge cloud security defense intention and the existing security resources of the edge cloud, thereby quickly determining whether it is necessary to use the security resources of the central cloud.

[0097] In one embodiment, the central cloud determines the security resource requirements for security defense operations based on the attack characteristics of security attacks in each attack dimension, including: simulating security attacks and simulating the execution of security defense operations based on the attack characteristics of security attacks in each attack dimension using digital twin technology through the central cloud; and determining the security resources used to perform security defense operations during the simulation process as the security resource requirements for security defense operations through the central cloud.

[0098] Optionally, the central cloud can simulate security attacks based on the attack characteristics of security attacks in each attack dimension, and simulate the execution of security defense operations using digital twin technology or simulation technology. The central cloud can determine the security resources used to perform security defense operations during the simulation as the security resource requirements for security defense operations.

[0099] In this embodiment, the central cloud uses digital twin technology to simulate security attacks based on the attack characteristics of security attacks in various attack dimensions, and simulates the execution of security defense operations; the central cloud determines the security resources used to perform security defense operations during the simulation as the security resource requirements of the security defense operations; in this way, the security resource requirements of the security defense operations can be accurately and quickly determined, which is conducive to accurately evaluating whether it is necessary to use the security resources of the central cloud to assist the edge cloud in defending against security attacks.

[0100] Figure 3 A flowchart of a collaborative security defense method based on intent-driven edge cloud and central cloud is provided as an example. The flowchart covers the technical solutions of the above embodiments and needs to be implemented through Figure 1 The intent collection module, intent evaluation module, and intent decision module in the intent strategy control layer shown in the figure work together to complete the task. Specifically, they include:

[0101] The intent collection module collects the security defense intent generated by the edge cloud based on the intent-driven network;

[0102] The intent assessment module evaluates the effectiveness of the edge cloud security defense intent based on the edge cloud's deployment location (security domain), network resources (latency, bandwidth, etc.), QoS level, storage resources (memory), computing resources (CPU), and security resources (FW, IPS, IDS, DDoS). This means determining whether the edge cloud's resource and environmental conditions meet the operating environment conditions for security defense operations.

[0103] When the edge cloud security defense intent is valid, the edge cloud security defense intent is translated, verified, and policy configuration is issued. The network security function is instantiated through the edge cloud security controller NFV, and the corresponding security service is provided through the edge security capability pool.

[0104] When the edge cloud security defense intent is invalid, the intent decision module enables the central cloud to extract the edge cloud attack characteristics and attack patterns based on the security information collected by the edge cloud, analyze and judge the attack source, attack method, and attack path. The central cloud models and evaluates the gap between the security resources required for the edge cloud security defense intent and the existing security resources of the edge cloud (see Table 1 and Table 2 above). The central cloud security defense intent is then generated through the central cloud intent enabling layer, and the central cloud security defense intent is translated, verified, and policy configured and issued. Finally, the network security function is instantiated through the central cloud security controller, and the security resources of the centralized security capability pool are deployed to provide security services for the edge cloud.

[0105] In this way, this application can evaluate the gap between the security resources required for edge cloud security defense intentions and existing security resources through central cloud security modeling, and generate central cloud security defense intentions based on the security resources of the central cloud, thereby dispatching the security resources of the central cloud to help the edge cloud perform security defense, making up for the lack of edge cloud computing capabilities and security defense capabilities, and effectively improving cloud-edge collaborative security and edge cloud security protection capabilities. This application is based on intent-driven networking, with small architectural changes, easy implementation and good scalability. It can be embedded in the intent-driven network access and calling process in a modular manner, and is compatible with single-domain intent-driven security defense.

[0106] In another embodiment, Figure 4 As shown in the figure, a collaborative security defense method based on intent-driven edge cloud and central cloud is provided. Figure 1 The edge cloud and central cloud in the example are used to illustrate the process, including the following steps:

[0107] Step S402: When the edge cloud identifies a security attack, the edge cloud security defense intent is generated by the edge cloud intent-driven network; the edge cloud security defense intent describes the security defense operations that the edge cloud needs to complete to defend against the security attack.

[0108] Step S404: When the resource environment conditions of the edge cloud meet the operating environment conditions of the security defense operation and the existing security resources provided by the edge cloud meet the security resource requirements of the security defense operation, an edge cloud security defense service that matches the edge cloud security defense intention is generated through the edge cloud; the edge cloud security defense service is used to perform security defense operations.

[0109] Step S406: When the resource environment conditions of the edge cloud do not meet the operating environment conditions of the security defense operation, or the existing security resources provided by the edge cloud do not meet the security resource requirements of the security defense operation, the central cloud's intention-driven network generates a central cloud security defense intention; the central cloud security defense intention describes the security defense operations that the central cloud needs to complete to assist the edge cloud in defending against security attacks.

[0110] Step S408: The central cloud security defense intention is translated into a central cloud security defense strategy through the central cloud.

[0111] Step S410, providing the edge cloud with a central cloud security defense service that matches the central cloud security defense policy through the central cloud security controller; the central cloud security defense service is used to assist the edge cloud in performing security defense operations.

[0112] It should be noted that the specific limitations of the above steps can be found in the specific limitations of an intent-driven collaborative security defense method for edge cloud and central cloud.

[0113] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0114] Based on the same inventive concept, the embodiment of the present application also provides an intent-driven edge cloud and central cloud collaborative security defense device for implementing the above-mentioned intent-driven edge cloud and central cloud collaborative security defense method. The implementation solution provided by the device is similar to the implementation solution described in the above-mentioned method. Therefore, the specific limitations in the embodiments of one or more intent-driven edge cloud and central cloud collaborative security defense devices provided below can be found in the above-mentioned limitations on the intent-driven edge cloud and central cloud collaborative security defense method, which will not be repeated here.

[0115] In an exemplary embodiment, Figure 5 As shown, a collaborative security defense device for edge cloud and central cloud based on intent-driven is provided, including: an intent-driven module 502, an edge cloud defense module 504 and a central cloud defense module 506, wherein:

[0116] A generation module 502 is configured to generate an edge cloud security defense intent through an edge cloud intent-driven network when the edge cloud identifies a security attack; the edge cloud security defense intent describes the security defense operations that the edge cloud needs to perform to defend against the security attack;

[0117] The judgment module 504 is configured to generate, through the edge cloud, an edge cloud security defense service that matches the edge cloud security defense intent, if the resource environment conditions of the edge cloud meet the operating environment conditions of the security defense operation and the existing security resources provided by the edge cloud meet the security resource requirements of the security defense operation; the edge cloud security defense service is used to perform the security defense operation;

[0118] The central cloud defense module 506 is used to generate a central cloud security defense intention through the central cloud's intention-driven network and generate a central cloud security defense service that matches the central cloud security defense intention when the resource environment conditions of the edge cloud do not meet the operating environment conditions of the security defense operation, or the existing security resources provided by the edge cloud do not meet the security resource requirements of the security defense operation; the central cloud security defense intention describes the security defense operations that the central cloud needs to complete to assist the edge cloud in defending against security attacks; the central cloud security defense service is used to assist the edge cloud in performing the security defense operation.

[0119] In one embodiment, the central cloud defense module 506 is specifically used to translate the central cloud security defense intention into a central cloud security defense policy through the central cloud; and provide the edge cloud with a central cloud security defense service that matches the central cloud security defense policy through the central cloud security controller.

[0120] In one embodiment, the central cloud defense module 506 is further used to translate the central cloud security defense intent through the central cloud's intent-driven network to obtain an initial central cloud security defense strategy; perform format verification on the initial central cloud security defense strategy through the central cloud's intent-driven network to obtain a format verification result; and when the format verification result is that the format verification passes, the initial central cloud security defense strategy is used as the central cloud security defense strategy.

[0121] In one embodiment, the central cloud defense module 506 is specifically used to instantiate network security functions through the central cloud's security controller and deploy security resources in the central cloud's security resource pool to provide the edge cloud with central cloud security defense services that match the central cloud's security defense strategy.

[0122] In one embodiment, the device also includes: a modeling module for collecting attack information of security attacks through the edge cloud; modeling the attack information through the central cloud to obtain attack characteristics of security attacks in each attack dimension; and determining the security resource requirements of security defense operations based on the attack characteristics of security attacks in each attack dimension through the central cloud.

[0123] In one of the embodiments, the modeling module is specifically used to simulate security attacks and simulate the execution of security defense operations based on the attack characteristics of security attacks in various attack dimensions through the central cloud using digital twin technology; and the security resources used to perform security defense operations during the simulation process are determined through the central cloud as the security resource requirements of the security defense operations.

[0124] Each module in the above-mentioned intent-driven edge cloud and central cloud collaborative security defense device can be implemented in whole or in part through software, hardware, or a combination thereof. Each of the above modules can be embedded in or independent of the processor in the computer device in hardware form, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each of the above modules.

[0125] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 6As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store collaborative security defense data based on intent-driven edge cloud and central cloud. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it realizes a collaborative security defense method based on intent-driven edge cloud and central cloud.

[0126] Those skilled in the art will understand that Figure 6 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0127] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program. When the computer program is executed by the processor, the processor performs the steps of the above-mentioned method for collaborative security defense between edge cloud and central cloud based on intent-driven collaboration. The steps of the method for collaborative security defense between edge cloud and central cloud based on intent-driven collaboration can be the steps of the method for collaborative security defense between edge cloud and central cloud based on intent-driven collaboration in each of the above-mentioned embodiments.

[0128] In one embodiment, a computer-readable storage medium is provided, storing a computer program. When executed by a processor, the computer program causes the processor to perform the steps of the above-mentioned method for collaborative security defense between edge cloud and central cloud based on intent-driven operation. The steps of the method for collaborative security defense between edge cloud and central cloud based on intent-driven operation can be the steps of the method for collaborative security defense between edge cloud and central cloud based on intent-driven operation in each of the above-mentioned embodiments.

[0129] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the processor executes the steps of the above-mentioned method for collaborative security defense between edge cloud and central cloud based on intent-driven operation. The steps of the method for collaborative security defense between edge cloud and central cloud based on intent-driven operation can be the steps of the method for collaborative security defense between edge cloud and central cloud based on intent-driven operation in each of the above-mentioned embodiments.

[0130] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned embodiments. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), data processing logic devices based on quantum computing, and the like.

[0131] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0132] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A collaborative security defense method based on intent-driven edge cloud and central cloud, characterized in that: The method comprises: When the edge cloud identifies a security attack, the edge cloud security defense intent is generated through the edge cloud's intent-driven network; the edge cloud security defense intent describes the security defense operations that the edge cloud needs to complete to defend against the security attack; When the resource environment conditions of the edge cloud meet the operating environment conditions of the security defense operation and the existing security resources provided by the edge cloud meet the security resource requirements of the security defense operation, an edge cloud security defense service matching the edge cloud security defense intention is generated by the edge cloud; the edge cloud security defense service is used to perform the security defense operation; When the resource environment conditions of the edge cloud do not meet the operating environment conditions of the security defense operation, or the existing security resources provided by the edge cloud do not meet the security resource requirements of the security defense operation, the central cloud's intention-driven network generates a central cloud security defense intention, and generates a central cloud security defense service that matches the central cloud security defense intention; the central cloud security defense intention describes the security defense operation that the central cloud needs to complete to assist the edge cloud in defending against the security attack; the central cloud security defense service is used to assist the edge cloud in performing the security defense operation.

2. The method according to claim 1, characterized in that The generating of a central cloud security defense service matching the central cloud security defense intention includes: Translating the central cloud security defense intention into a central cloud security defense strategy through the central cloud; The central cloud security controller provides the edge cloud with a central cloud security defense service that matches the central cloud security defense strategy.

3. The method according to claim 2, characterized in that The translating the central cloud security defense intention into a central cloud security defense strategy through the central cloud includes: The central cloud security defense intent is translated through the central cloud's intent-driven network to obtain an initial central cloud security defense strategy; Performing format verification on the initial central cloud security defense policy through the central cloud's intent-driven network to obtain a format verification result; When the format verification result is that the format verification is passed, the initial central cloud security defense strategy is used as the central cloud security defense strategy.

4. The method according to claim 2, characterized in that The providing, by the security controller of the central cloud, a central cloud security defense service matching the central cloud security defense policy for the edge cloud, includes: The network security function is instantiated through the security controller of the central cloud, and the security resources in the central cloud security resource pool are deployed to provide the edge cloud with a central cloud security defense service that matches the central cloud security defense strategy.

5. The method according to claim 1, wherein The method further comprises: Collecting attack information of the security attack through the edge cloud; Modeling the attack information through the central cloud to obtain the attack characteristics of the security attack in each attack dimension; The central cloud determines the security resource requirements of the security defense operation based on the attack characteristics of the security attack in each attack dimension.

6. The method according to claim 5, characterized in that The determining, by the central cloud, the security resource requirements of the security defense operation based on the attack characteristics of the security attack in each attack dimension includes: Using the central cloud, based on the attack characteristics of the security attack in each attack dimension, the digital twin technology is used to simulate the security attack and simulate the execution of the security defense operation; The security resources used to perform the security defense operation during the simulation process are determined by the central cloud as the security resource requirements of the security defense operation.

7. A security defense device based on the collaboration of edge cloud and central cloud driven by intent, characterized in that: The device comprises: An intent-driven module is configured to generate an edge cloud security defense intent through the edge cloud's intent-driven network when the edge cloud identifies a security attack; the edge cloud security defense intent describes the security defense operations that the edge cloud needs to perform to defend against the security attack; An edge cloud defense module is configured to generate, through the edge cloud, an edge cloud security defense service that matches the edge cloud security defense intention, if the resource environment conditions of the edge cloud meet the operating environment conditions of the security defense operation and the existing security resources provided by the edge cloud meet the security resource requirements of the security defense operation; the edge cloud security defense service is configured to execute the security defense operation; The central cloud defense module generates a central cloud security defense intention through the central cloud's intention-driven network and generates a central cloud security defense service that matches the central cloud security defense intention when the resource environment conditions of the edge cloud do not meet the operating environment conditions of the security defense operation, or the existing security resources provided by the edge cloud do not meet the security resource requirements of the security defense operation; the central cloud security defense intention describes the security defense operation that the central cloud needs to complete to assist the edge cloud in defending against the security attack; the central cloud security defense service is used to assist the edge cloud in performing the security defense operation.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Trust management method based on integrated learning in ocean cloud edge collaborative network

    CN117614983A

  • Security and resiliency for cloud to edge deployments

    US20240022609A1