A network boundary security stack system

Through layered, embedded, and multi-dimensional integrated security protection design, the traditional boundary protection solutions have solved the problems of numerous equipment, poor expansion capabilities and complex management, and achieved network performance optimization and security improvement, providing a smooth and secure network experience.

CN119743291BActive Publication Date: 2025-07-18CHINESE PEOPLES LIBERATION ARMY UNIT 61660
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202411816679.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-11
Publication Date
2025-07-18
Estimated Expiration
2044-12-11

AI Technical Summary

Technical Problem

Traditional border protection solutions have a wide range of equipment, severe stacking, poor expansion capabilities, and complex management and operation and maintenance, resulting in complex network structure, high costs, reduced performance and increased safety risks.

Method used

The layered, embedded, and multi-dimensional integrated security protection design is adopted, including the boundary access layer, security resource layer, core switching layer and operation and maintenance management and control layer. Combined with unsupervised abnormal detection of network traffic, rapid detection of abnormal abnormality of encrypted traffic, flexible orchestration of service chains and full-scene links, the multi-dimensional refined security control and unified management are achieved.

Benefits of technology

Optimize network performance, reduce data transmission delays and errors, provide a smoother and safe network experience, reduce operation and maintenance complexity, and improve management efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119743291B_ABST
    Figure CN119743291B_ABST
Patent Text Reader

Abstract

The present invention relates to a network boundary security stack system, belonging to the field of network security. The system of the present invention adopts a design scheme of hierarchical, embedded, multi-dimensional integrated security protection; the layering means adopting a software-defined architecture, dividing the system into: a boundary access layer, a security resource layer, a core switching layer, and an operation and maintenance management and control layer; the embedding means that in the multi-source heterogeneous network element pool base of the security resource layer, they are embedded and integrated together at the level of the underlying architecture and data transmission in the business process; the multi-dimensional means that in the core switching area, a service chain flexible orchestration method and a full-scenario link keep-through method are adopted to realize multi-dimensional refined security control of network traffic, break the bondage of one-dimensional traffic processing, enter the multi-dimensional space of traffic, and realize high-speed concurrency of different traffic security processing. The system of the present invention effectively solves the problems existing in the traditional boundary protection scheme by integrating multiple intelligent technologies, and provides a strong guarantee for the security and management efficiency of the network boundary.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security, and particularly relates to a network boundary security stack system. Background Art

[0002] Traditional boundary protection solutions face many challenges when dealing with the current network environment and business requirements, especially in terms of a large number of devices, serious stacking, poor expansion ability, and complex management and operation and maintenance.

[0003] With the continuous expansion of enterprise business and the increasing demand for network security, traditional boundary protection solutions often require the deployment of a large number of security devices, such as firewalls, intrusion detection systems (IDS / IPS), VPN devices, etc. The stacking and redundancy between these devices not only increase the cost of enterprises, but also lead to an increase in the complexity of the network structure, making network management and maintenance more difficult. In addition, due to compatibility and interoperability issues between different devices, it may also lead to a decline in network performance and an increase in security risks.

[0004] Traditional boundary protection solutions often adopt static and fixed network architectures, which are difficult to adapt to the rapidly changing needs of enterprise business. When an enterprise needs to expand the network scale or add new business applications, it often needs to purchase new security devices and reconfigure and deploy them, which not only increases the cost of the enterprise, but also prolongs the business launch cycle. At the same time, due to the poor scalability of traditional solutions, existing network resources and security devices may not be fully utilized, resulting in resource waste and performance bottlenecks.

[0005] Traditional boundary protection solutions require administrators to configure and manage multiple security devices separately, which not only increases the workload of administrators, but also easily leads to configuration errors and security risks. Since the management interfaces and configuration methods of different devices are different, administrators need to master a variety of skills and knowledge to carry out effective management and maintenance. At the same time, with the continuous development and change of enterprise business, security policies and configurations also need to be adjusted and optimized continuously, which makes the management and operation and maintenance work more complex and cumbersome.

[0006] The above problems need to be solved. Summary of the Invention

[0007] (1) Technical Problems to be Solved

[0008] The technical problem to be solved by the present invention is how to provide a network boundary security stack system to solve the problems of traditional boundary protection solutions in terms of a large number of devices, serious stacking, poor expansion ability, and complex management and operation and maintenance.

[0009] (2) Technical Solutions

[0010] To solve the above technical problems, the present invention proposes a network boundary security stack system, which adopts a design scheme of hierarchical, embedded, and multi-dimensional integrated security protection according to the concept of integrated security protection;

[0011] Hierarchical means adopting a software-defined architecture to divide the system into: a boundary access layer, a security resource layer, a core switching layer, and an operation and maintenance management and control layer; the boundary access layer includes next-generation boundary protection devices, and the security resource layer virtualizes the boundary protection devices in the boundary access area into a multi-source heterogeneous network element pool base through network resource virtualization technology, computing resource virtualization technology, and storage resource virtualization technology; the core switching area realizes multi-dimensional refined security control of network traffic; the operation and maintenance management and control layer realizes unified operation and management;

[0012] Embedded means that through integrated design, a network traffic unsupervised anomaly detection method based on an improved Transformer reconstruction model, an encrypted traffic anomaly rapid detection method for plaintext traffic characteristics, and an infrastructure-as-code implementation method for the security resource pool are adopted in the multi-source heterogeneous network element pool base of the security resource layer, and they are integrated together in the business process from the levels of the underlying architecture and data transmission;

[0013] Multi-dimensional means that in the core switching area, a service chain flexible orchestration method and a full-scenario link keep-alive method are adopted to realize multi-dimensional refined security control of network traffic, break the bondage of one-dimensional traffic processing, enter the traffic multi-dimensional space, and realize high-speed concurrency of different traffic security processing;

[0014] Among them, the service chain flexible orchestration method includes: an orchestration method for decrypting traffic service chains based on blockchain and deep reinforcement learning, an optimization method based on software-defined orchestration technology, a unified scheduling method for virtual network elements and physical devices, and an automatic orchestration and deployment method for security service chains based on particle swarm optimization algorithm, and the flexible orchestration of service chains in different situations or scenarios is realized through the above various methods;

[0015] The full-scenario link keep-alive method adopts a multiple intelligent link keep-alive method to ensure that even when faults occur at all levels of the network, the network boundary security stack system can quickly respond and maintain network quality;

[0016] An intelligent security capability unified management method is also provided in the operation and maintenance management and control layer, and the intelligent security capability unified management method enables the system to realize standardized and normalized unified management of multi-category heterogeneous networks.

[0017] (III) Beneficial effects

[0018] The present invention proposes a network boundary security stack system. The present invention designs and implements a next-generation network boundary security stack system, which adopts the above technologies, helps to optimize network performance, reduce latency and errors in data transmission, and thus provides users with a smoother and safer network experience.

[0019] The network boundary security stack system of the present invention effectively solves the problems existing in traditional boundary protection solutions by integrating multiple intelligent technologies, providing strong guarantees for the security and management efficiency of the network boundary. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] Figure 1 It is the overall architecture diagram of the network boundary security stack system of the present invention;

[0021] Figure 2 It is the business traffic forwarding flow chart in a normal scenario;

[0022] Figure 3 It is the schematic diagram of hardware Bypass;

[0023] Figure 4 It is the schematic diagram of software Bypass;

[0024] Figure 5 It is the schematic diagram of service chain Bypass;

[0025] Figure 6 It is the schematic diagram of security network element Bypass;

[0026] Figure 7 It is the initialization flow chart of unified configuration management of network elements;

[0027] Figure 8 It is the flow chart of differential redundancy management of network element configuration;

[0028] Figure 9 It is the technical architecture diagram of service chain orchestration based on software definition;

[0029] Figure 10 It is the NSH data structure diagram;

[0030] Figure 11 It is the schematic diagram of dynamic EFC information synchronization of the service chain;

[0031] Figure 12 It is the diagram of the difference in data transmission paths between network elements across nodes and within nodes;

[0032] Figure 13 It is the path schematic diagram of the round-robin scheduling algorithm based on resource boards in the prior art;

[0033] Figure 14 It is the optimized path diagram of the order-priority scheduling based on resource boards of the present invention;

[0034] Figure 15 It is a flowchart for priority scheduling based on network element ID;

[0035] Figure 16 It is a schematic diagram of the same network element ID running on the same resource board;

[0036] Figure 17 It is a hardware logic architecture diagram of the security stack;

[0037] Figure 18 It is a schematic diagram of the first packet Pkt1 arriving at the system;

[0038] Figure 19 It is a schematic diagram of M1(pushrule1)->R1;

[0039] Figure 20 It is a schematic diagram of Pkt1: R1(rule1 hit)->V1->V2->Port1;

[0040] Figure 21 It is a schematic diagram of subsequent packet forwarding;

[0041] Figure 22 It is a schematic diagram of V2->R1->M1->R2->V3;

[0042] Figure 23 It is a schematic diagram of V2->R1->R2–>V3;

[0043] Figure 24 It is a schematic diagram of the network element after optimization at different resource nodes;

[0044] Figure 25 It is a schematic diagram of the same orchestration of virtual network elements and physical devices;

[0045] Figure 26 It is a schematic diagram of software-defined network classification;

[0046] Figure 27 It is a virtual network element object definition diagram;

[0047] Figure 28 It is a physical network element object definition diagram;

[0048] Figure 29 It is a new network element object definition diagram;

[0049] Figure 30 It is a flowchart for the preservation of the security resource pool infrastructure;

[0050] Figure 31 It is a flowchart for the restoration of the security resource pool infrastructure;

[0051] Figure 32Schematic diagram of an automatic orchestration and deployment method for a security service chain based on a particle swarm algorithm;

[0052] Figure 33 Schematic diagram of the average total bandwidth consumption under three methods;

[0053] Figure 34 Schematic diagram of the success rate of security service chain requests under three methods;

[0054] Figure 35 Comparison chart of the maximum throughput under two models;

[0055] Figure 36 Comparison chart of the maximum number of new connections and concurrent connections under two models. Specific implementation manner

[0056] To make the objectives, content, and advantages of the present invention clearer, the following further describes in detail the specific implementation manner of the present invention with reference to the accompanying drawings and embodiments.

[0057] To solve the problems of traditional boundary protection solutions in aspects such as a large number of devices, serious stacking, poor scalability, and complex management and operation and maintenance, the present invention proposes an innovative network boundary security stack system. The overall architecture of the system is as Figure 1 shown.

[0058] The present invention designs and implements a next-generation network boundary security stack system, which implements next-generation network boundary protection technology. For the next-generation network boundary protection technology, the present invention adopts a design scheme of layered, embedded, and multi-dimensional integrated security protection according to the concept of integrated security protection.

[0059] Layered means adopting a software-defined architecture to divide the system into: a boundary access layer, a security resource layer, a core switching layer, and an operation and maintenance management and control layer, solidifying the internal relationships of the system, simplifying the external relationships of the system, and standardizing the system operation and management mode; the boundary access layer includes next-generation boundary protection devices, and the security resource layer virtualizes the boundary protection devices in the boundary access area into a multi-source heterogeneous network element pool base through network resource virtualization technology, computing resource virtualization technology, and storage resource virtualization technology; the core switching area realizes multi-dimensional refined security control of network traffic; the operation and maintenance management and control layer realizes unified operation and management.

[0060] Embedded means that through an integrated design, a network traffic unsupervised anomaly detection method based on an improved Transformer reconstruction model, an encrypted traffic anomaly fast detection method for plaintext traffic characteristics, and an infrastructure as code implementation method for the security resource pool are adopted in the multi-source heterogeneous network element pool base of the security resource layer, and capabilities such as network access, intrusion detection, anti-virus, WAF protection, access control, and version control are embedded and integrated together at the levels of the underlying architecture and data transmission in the business process;

[0061] Among them, through the infrastructure as code implementation method of the security resource pool, after implementing infrastructure as code in the security resource area, the security resource pool will have the ability to perform rollback for specific network elements and for the entire security resource pool, thereby supporting the security resource pool to quickly stop losses after a failure occurs. At the same time, the security resource pool can also rely on this ability to conveniently restore the fault scene and verify the fault recovery plan in subsequent fault drills.

[0062] Multi-dimensional means that in the core switching area, by adopting service chain flexible orchestration methods, full-scenario link keep-alive methods, multi-level redundant architectures, and high-performance linear extension methods, multi-dimensional refined security control of network traffic is realized, breaking the shackles of one-dimensional traffic processing, entering the multi-dimensional space of traffic, achieving high-speed concurrency of different traffic security processing, and comprehensively improving the processing efficiency of the integrated system. Among them, the multi-level redundant architecture and high-performance linear extension methods adopt existing technologies, and the improvements of the present invention lie in the service chain flexible orchestration method and the full-scenario link keep-alive method;

[0063] The service chain flexible orchestration method includes: an orchestration method for decrypting traffic service chains based on blockchain and deep reinforcement learning, an optimization method based on software-defined orchestration technology, a unified scheduling method for virtual network elements and physical devices, and an automatic orchestration and deployment method for security service chains based on particle swarm algorithm. Through the above various methods, flexible orchestration of service chains in different situations or scenarios is realized.

[0064] The full-scenario link keep-alive method adopts multiple intelligent link keep-alive methods to ensure that even when faults occur at various levels of the network, the boundary security stack system can quickly respond and maintain network quality, thereby ensuring the continuity and stability of critical services.

[0065] In addition, an intelligent security capability unified management method is also provided at the operation and maintenance management and control layer. The intelligent security capability unified management method enables the boundary security stack system to achieve standardized and normalized unified management of multi-category heterogeneous networks. This unified management method not only reduces the complexity and difficulty of operation and maintenance, but also significantly improves the efficiency and ability of management and operation and maintenance, enabling network administrators to more easily cope with various security challenges.

[0066] Among them, the network traffic anomaly detection method based on a reconstructed model (CN202311791348.2), a method for quickly detecting encrypted traffic anomalies based on plaintext traffic characteristics (CN202410347186.1), and an orchestration method for decrypting traffic service chains based on blockchain and deep reinforcement learning (CN202410244760.0) have all applied for patents. The contents of these patents are hereby incorporated into the present invention.

[0067] In summary, these technologies of the present invention help to optimize network performance, reduce latency and errors in data transmission, thereby providing users with a smoother and safer network experience.

[0068] The network boundary security stack system of the present invention effectively solves the problems existing in traditional boundary protection solutions by integrating multiple intelligent technologies, providing strong guarantees for the security and management efficiency of the network boundary.

[0069] Glossary:

[0070] Network element: A device or unit responsible for basic network functions;

[0071] Security network element: A function or unit dedicated to network security-related services;

[0072] Virtual network element: A network unit implemented in a virtualized environment, with flexibility and scalability;

[0073] Security Stack: Generally refers to the collection of all security components and technologies involved in a network architecture, from the lowest infrastructure layer to the highest application layer;

[0074] VNF: Virtual Network Function;

[0075] PNF: Physical Network Function;

[0076] SDN: Software Defined Network;

[0077] SDS: Software Defined Security;

[0078] SC: Service Chain;

[0079] IaC: Infrastructure as Code;

[0080] SFC: Service Function Chaining;

[0081] FW: Firewall;

[0082] IPS: Intrusion Prevention System;

[0083] WAF: WEB Application Firewall;

[0084] AV: Antivirus;

[0085] 1. Full-scenario Link Keep-alive Method

[0086] The full-scenario link keep-alive method provides the full-scenario link keep-alive function through multiple intelligent link keep-alive methods. This method provides comprehensive link protection capabilities to handle various abnormal situations through multiple Bypass mechanisms, including: hardware Bypass, software Bypass, service chain Bypass, and security network element Bypass. While ensuring that customer services are sufficiently protected, it can also guarantee the normal operation of the services.

[0087] The path through which service traffic flows within the network boundary security stack system is divided into four layers: the physical hardware layer, the system platform layer, the sfc service chain layer, and the security network element layer, corresponding to the boundary access layer, the security resource layer, the core switching layer, and the operation and maintenance management and control layer. Among them, multiple security network elements are formed in the operation and maintenance management and control layer after passing through the network boundary security stack of the present invention. There are corresponding Bypass technologies in each layer to handle possible abnormal situations in each layer and abnormal situations that the overall device may encounter.

[0088] When modules such as hardware, system platform, sfc service chain, and security network element fail, Bypass can ensure the normal forwarding of service traffic to ensure that the failure of the security network element does not affect the overall machine service, and the failure of the overall machine does not affect the network quality.

[0089] The normal scenario service traffic forwarding process is as Figure 2 shown:

[0090] Under normal circumstances, the traffic will pass through the physical hardware layer and the system platform layer in sequence to reach the sfc service chain layer; the traffic flowing through the service chain will pass through security network element 1, security network element 2, and security network element 3 in sequence, and then flow out through the system platform layer and the physical hardware layer.

[0091] The hardware Bypass scenario service traffic forwarding process is as Figure 3 shown:

[0092] When the hardware device is powered off or restarted, the hardware Bypass technology will be used to ensure the normal forwarding of service traffic to ensure that the device does not affect the overall machine service. System anomalies will trigger the device to restart, and the hardware layer will be bypassed to ensure the normal forwarding of service traffic. Usually, there is a direct connection line between the input and output of the device. If the device is powered off or restarted, the service traffic will be directly forwarded from the input end to the output end, thus bypassing the hardware layer.

[0093] The software Bypass scenario service traffic forwarding process is as Figure 4 shown:

[0094] When an exception occurs in the system platform layer, i.e., the software layer, such as during device upgrade, the traffic will no longer be forwarded to the system platform layer, that is, the traffic will bypass this layer.

[0095] As Figure 4 shown, under normal circumstances, the traffic flowing through the service chain passes through security network element 1, security network element 2, and security network element 3 in sequence; if the system platform layer is in the process of device upgrade, the system platform layer will be bypassed, and the traffic will be directly forwarded through the physical hardware layer without passing through the system platform layer and its upper layers. This ensures the normal forwarding of service traffic and that the faults of the network elements in the system platform layer do not affect the overall machine service.

[0096] The service chain bypass scenario service traffic forwarding process is as Figure 5 shown:

[0097] If there are no security network elements in the service chain or no security network elements in a normal state, the traffic will bypass the entire service chain and be directly forwarded through the system platform layer to ensure the normal forwarding of service traffic and that it does not affect the overall machine service.

[0098] As Figure 5 shown, under normal circumstances, the traffic flowing through the service chain passes through security network element 1, security network element 2, and security network element 3 in sequence; after detecting that security network element 1, security network element 2, and security network element 3 are all abnormal, this service chain will be bypassed, and the traffic will be directly forwarded through the system platform layer. This ensures the normal forwarding of service traffic and that the faults of the security network elements do not affect the overall machine service.

[0099] The security network element bypass scenario service traffic forwarding process is as Figure 6 shown:

[0100] When a certain security network element fails, the traffic will bypass the abnormal security network element when flowing through various security network elements on the service chain and flow normally through other security network elements on the chain.

[0101] As Figure 6 shown, under normal circumstances, the traffic flowing through the service chain passes through security network element 1, security network element 2, and security network element 3 in sequence; after detecting that security network element 1 is abnormal, the service chain traffic will pass through security network element 2 and security network element 3 in sequence to ensure the normal forwarding of service traffic and that the faults of the security network elements do not affect the overall machine service.

[0102] II. Unified Management Method for Intelligent Security Capabilities

[0103] In actual usage scenarios, multiple categories of security capabilities are required to meet comprehensive security protection needs. To avoid risks brought by a single vendor, heterogeneity within the same category is also an important security requirement. At the same time, to meet the scalability of security capabilities, each security capability is composed of multiple security network elements that jointly provide security services. The number of security network elements will be very large, and individual configuration management will be extremely complex, which will seriously affect the complexity of actual operation and maintenance management and greatly increase the work difficulty of multi-level management personnel. Therefore, an intelligent and automated unified management method for intelligent security capabilities that greatly reduces the complexity and difficulty of operation and maintenance is needed, including: a unified network element configuration management method and a differential redundancy management method for network element configurations.

[0104] The Security Stack contains various security mechanisms, tools, and services designed to protect information systems from various threats. Elements in the security stack may include, but are not limited to, firewalls, intrusion detection / defense systems (IDS / IPS), antivirus software, encryption solutions, identity authentication, and access control systems, etc. The unified network element configuration management module is a functional component in the security stack responsible for managing and configuring all security devices (i.e., security network elements). The goal of the unified network element configuration management module is to uniformly configure and manage security network elements through standardized interfaces, thereby simplifying operations, improving efficiency, and ensuring consistency.

[0105] Specifically, the unified network element configuration management module can be regarded as an important part of the security stack, and it undertakes the following key responsibilities:

[0106] 1. Configuration management: Configure security network elements, including setting, updating, and maintaining security policies.

[0107] 2. Version control: Manage software version upgrades of security network elements to ensure that all devices are running the latest security patches and signature databases.

[0108] 3. Health monitoring: Monitor the operating status of security network elements, and promptly detect and handle potential security issues.

[0109] 4. Fault recovery: Provide fault detection and recovery functions to ensure that problems can be quickly located and repaired when they occur.

[0110] 5. Compliance check: Ensure that all security network elements comply with established security policies and regulatory requirements.

[0111] Through this module, administrators can more conveniently centrally manage each security network element in the security stack without having to log in to each device separately for operations. This not only improves work efficiency but also reduces the risk of security vulnerabilities caused by manual configuration errors.

[0112] Therefore, it can be said that the network element unified configuration management module is a core management component in the security stack. Through standardized interface specifications, it realizes the effective management and control of security network elements, thereby enhancing the stability and security of the entire security architecture.

[0113] 2.1 Network Element Unified Configuration Management Method:

[0114] To this end, the core functions of each type of security network element can be abstracted, and the important common parameters can be refined. At the same time, the common parameters must also meet the configuration logics of each manufacturer. Through this method, the interface specifications for each type of security capability are formulated. Based on these interface specifications, the corresponding configuration management functions for each type of security network element are developed and executed by the network element unified configuration management module in the security stack. These management functions are further divided into security capability configuration functions and security network element upgrade management functions. The former provides the management of security capabilities, and the latter manages the network elements themselves, such as version upgrade, patch package upgrade, feature library upgrade, and so on.

[0115] Among them,

[0116] The common parameters include:

[0117] Interface type - the network interface standards supported by the device.

[0118] Security policy - including but not limited to ACL rules, signature libraries, certificate management, etc.

[0119] Logging - supports the logging and auditing of events.

[0120] Upgrade management - version update, patch package installation, feature library update, etc.

[0121] Authentication mechanism - the supported authentication methods.

[0122] Performance metrics - processing speed, maximum concurrent connection number, etc.

[0123] The interface specifications include:

[0124] To specify the core functions of each type of security network element and their common parameters, and to formulate interface specifications based on this, the following aspects need to be considered to design the main interfaces:

[0125] 1. Authentication Interface (Authentication API)

[0126] - Function: Used to verify the identity of users or systems.

[0127] - Parameters: username, password, token, or other authentication credentials.

[0128] - Examples: OAuth2, JWT (JSON Web Tokens), etc.

[0129] 2. Configuration Management API

[0130] - Function: Allows adding, deleting, or modifying configuration items on a security device.

[0131] - Parameters: Configuration file, configuration entry, expiration date, etc.

[0132] - Examples: Configuring firewall rules, updating the IPS rule base.

[0133] 3. Logging and Reporting API

[0134] - Function: Collects security event logs and generates reports.

[0135] - Parameters: Log level, log message, report format, etc.

[0136] - Example: Sending logs to a centralized log server via Syslog.

[0137] 4. Monitoring and Alerting API

[0138] - Function: Monitors the status of a security device and issues warnings when an anomaly occurs.

[0139] - Parameters: Threshold settings, alert conditions, notification methods, etc.

[0140] - Example: Setting an alert to trigger when the CPU usage exceeds 80%.

[0141] 5. Software Update API

[0142] - Function: Manages firmware or software updates.

[0143] - Parameters: Update package URL, version number, checksum, etc.

[0144] - Example: Automatically downloading and installing the latest version of the IPS feature library.

[0145] 6. Health Check API

[0146] - Function: Periodically checks the operating status of the device.

[0147] - Parameters: Check frequency, check items, return status code, etc.

[0148] - Example: Periodically pinging the device to ensure connectivity.

[0149] 7. Policy Management API

[0150] -Functionality: Create, edit and delete security policies.

[0151] -Parameters: policy name, policy rule set, effective time, etc.

[0152] - Example: Adding a new firewall rule via API call.

[0153] 8. Remote Management API

[0154] - Functionality: Allows remote access and management of devices.

[0155] -Parameters: remote management port, encryption method, session management, etc.

[0156] - Example: Use of SSH or Telnet protocol.

[0157] Through these interface specifications, the unified configuration management module of network elements can achieve consistent management of different security devices, improve management efficiency, and reduce the complexity caused by differences between devices. At the same time, these interfaces need to follow open standard protocols, such as RESTful API, to facilitate integration with other systems and services.

[0158] like Figure 7 As shown in the figure, by analyzing the product startup process of each category and manufacturer, the device startup is divided into several stages: startup stage, system ready stage, and configuration ready stage. The unified configuration management module of network elements has different interactions with security network elements at different stages, and the tasks that security network elements need to do at different stages are also different. For example, only in the final configuration ready stage can traffic be directed to the security network element for security protection. If traffic is directed in advance, it may cause traffic interruption or fail to provide security protection services. After the security network element is started, the unified configuration management module of network elements will start to detect the API interface of the security network element. When the security network element enters the system ready stage, it will return a ready message to the unified configuration management module of network elements. At this time, the unified configuration management module of network elements will identify the category of security network elements, security manufacturers and other information, and decide to use the corresponding API interface to send the corresponding configuration to the security network element. After all configurations are sent successfully, the security network element enters the configuration ready stage. At this point, the unified configuration management module of network elements notifies the traffic diversion module to start diverting traffic to the security network element for security protection according to the corresponding service chain and diversion strategy.

[0159] 2.2 Differentiated redundancy management method for network element configuration:

[0160] The network element configuration differential redundancy management process refers to a set of management mechanisms designed to ensure the high availability and fault tolerance of a system in a distributed or multi-node environment. This mechanism typically uses multiple components or services with the same function to ensure that in the event of a component failure, other components can seamlessly take over its workload. The following are some key components of the network element configuration differential redundancy management process and their introductions:

[0161] 1. Redundancy Configuration

[0162] - Describe how to deploy multiple security network elements or modules with the same function to ensure that when one fails, other instances can continue to provide services.

[0163] - Parameters involved may include redundancy level, failover strategy, etc.

[0164] 2. Health Monitoring

[0165] - Monitor the health status of each network element in real time and detect any problems that may cause service interruption.

[0166] - Key parameters include heartbeat interval, fault detection time, etc.

[0167] 3. Fault Detection

[0168] - Automatically discover and report single points of failure, including hardware failures, software errors, or configuration issues.

[0169] - Parameters may include error codes, fault types, recovery suggestions, etc.

[0170] 4. Failover

[0171] - When the primary system detects a fault, it can automatically redirect traffic to the standby system.

[0172] - Parameters may include switchover trigger conditions, switchover time window, verification after switchover, etc.

[0173] 5. Load Balancing

[0174] - Distribute the workload among multiple redundant components to ensure that no single component is overloaded.

[0175] - Parameters may include load algorithms, weight distribution, selection of healthy nodes, etc.

[0176] 6. Recovery Management

[0177] - After a failure, provide an automatic or manual recovery mechanism to help the affected components resume normal operation.

[0178] - Parameters may include recovery priority, recovery steps, recovery verification, etc.

[0179] 7. Data Synchronization

[0180] - Ensure that the data of all redundant components is consistent, especially in stateful services.

[0181] - Parameters may include synchronization frequency, synchronization method, consistency guarantee measures, etc.

[0182] As Figure 8 shown, the key steps of the dissimilar redundant management process

[0183] 1. Define the redundancy policy: Determine which security network elements need redundant configuration and the level of redundancy.

[0184] 2. Implement health monitoring: Deploy tools or services to continuously monitor the health status of each network element.

[0185] 3. Set up a fault detection mechanism: Define the specific methods and triggering conditions for fault detection.

[0186] 4. Configure the failover plan: Design how the standby node can quickly take over the service when the primary node fails.

[0187] 5. Load balancing strategy: Develop load balancing rules to distribute requests to each network element in the optimal way.

[0188] 6. Establish a recovery plan: Prepare a detailed recovery process to resume normal operation as soon as possible after the fault is resolved.

[0189] 7. Ensure data consistency: Take measures to ensure data synchronization and consistency among all redundant components.

[0190] Through such a dissimilar redundant management process, the reliability and stability of the entire system can be significantly improved, the risk of single point of failure can be reduced, and thus the overall service quality can be enhanced.

[0191] III. Optimization Methods Based on Software-Defined Orchestration Technology

[0192] The optimization method based on software-defined orchestration technology is an innovative optimization method to improve the overall security capability and processing performance of security orchestration devices in the business network. The optimization method based on software-defined orchestration technology simplifies the traffic path design among multiple security network elements and improves the efficiency of information transmission. It has the characteristics of less resource occupancy and higher transmission performance in terms of transmission efficiency compared with traditional orchestration technology.

[0193] As shown Figure 9 in the figure is the complete data packet processing flow of the security capability orchestration device in the service network. In this processing flow, the security orchestration device in the core switching area receives the packet, and the device processes it based on its own orchestration capabilities, matches the service chain, and according to its own design, forwards the data packet to each security network element on the service chain in sequence. After all security network elements have completed processing, the security orchestration device sends a signal to end the processing flow.

[0194] With the increasing traffic in the service network, in order to prevent the security orchestration device from becoming a performance bottleneck in the link, it is crucial to improve the overall transmission and processing performance of the device. Analyzing from Figure 9 it, the factors affecting the overall processing performance in the orchestration network consist of the following points: data packet size, data path length, security network element performance, physical hardware performance, etc.

[0195] When the processing capabilities of network elements and physical hardware are the same, the optimization method based on software-defined orchestration technology mainly optimizes the data packet size and data path length.

[0196] The method based on software-defined orchestration technology has the following advantages: flexible external networking access mode; flexible internal VNF access mode, including series connection, three-layer, and bypass modes; support for fine-grained traffic orchestration based on policies; support for load balancing and probing; and high-performance traffic processing capabilities.

[0197] 3.1 Optimization of data encapsulation technology:

[0198] The standard service chain is defined in RFC7665, but only a general idea is defined in the RFC, not a detailed implementation method, so it leaves room for each manufacturer to implement privately. Basically, by creating a logical tunnel for data, the data is passed to each forwarding node of the SFC on the service chain. In fact, each SFC forwarding node is independent and does not have global SFC information. In this way, it is necessary to encapsulate a Network Service Header (NSH, defined in RFC8300) on the data header to find the next destination node of the data. Such encapsulation and decapsulation operations will reduce the processing capabilities of the device; at the same time, when the number of service chain nodes is large, the number of encapsulation layers will increase accordingly, which may cause the data packet length to exceed the MTU of the interface, resulting in a series of fragmentation-related problems. As Figure 10 shown

[0199] Due to the need to use the relatively new NSH protocol, each node device on the SFC path also needs to support the NSH protocol to ensure data circulation, which requires relatively high network capabilities for all node devices. Moreover, the path for reverse traffic also needs to be defined to ensure that the data passes through each node in the reverse order, and the configuration difficulty is relatively large. Once the SFC is modified, the configurations on the relevant nodes need to be modified accordingly.

[0200] The service chain based on the software-defined orchestration technology method distributes traffic through a centrally managed traffic diversion platform. The SFC is defined on the traffic diversion platform, and various VNFs and PNFs can be included in the SFC. Dynamic forwarding flow tables are stored on the corresponding resource servers for fast distribution of intermediate traffic. For the data that needs to pass through the SFC, the traffic diversion platform directly forwards the original data packets to the corresponding SFC node devices. Since the data is not modified, there is no need to add special protocol processing on the node devices, so it has wide adaptability.

[0201] In a certain case, for remote resource nodes, the traffic diversion platform will send the dynamic RFC information related to the SFC to the relevant resource nodes, and the resource nodes will directly perform data forwarding between network elements according to the RFC information.

[0202] Such a design not only reduces the requirements for network elements, as long as they can process ordinary type protocol data, but also ensures the processing speed. The data packets processed by each node in the SFC are all original data, without the need for encapsulation and decapsulation operations. The node devices only need to support the layer-2 transparent mode, which improves the orchestration processing performance within the service chain. As Figure 11 、 12 shown.

[0203] 3.2 Optimization of Network Element Allocation Method

[0204] Based on the optimization of the network element allocation and scheduling algorithm, different security network elements on the service chain can be allocated to the same resource node as much as possible, so as to effectively reduce the data transmission loss between network elements of the service chain. From the perspective of the data transmission path, the physical network data link path length and the virtual network data link path length are reduced.

[0205] The security network elements are scheduled to the resource boards in the resource nodes using the resource board round-robin scheduling algorithm.

[0206] The resource board round-robin scheduling algorithm is as follows:

[0207] The defined SFC service chain is FW->IPS->Waf->AV. FW is usually a firewall, IPS is an intrusion prevention system, Waf is a WEB application firewall, and AV is an antivirus software.

[0208] In the prior art, each network element group randomly selects a network element from within its own group based on load balancing to forward the traffic in the SFC. As Figure 13 shown, there will be a situation where the traffic of an SFC forwarding chain needs to pass through different resource boards. If we pursue more optimized SFC service chain forwarding performance, it is necessary to prioritize enabling the forwarding of network elements within the same SFC service chain to be directly completed locally, reducing cross-resource board forwarding for the same service chain.

[0209] The optimized scheduling policy based on the order of resource boards first is as Figure 14 shown:

[0210] The same security network element group will be sent to all resource nodes. Since the security network element group IDs within the same security network element group are the same, but the security network element IDs are different, a policy of creating security network elements within each security network element group and performing priority scheduling based on the security network element ID is adopted. As Figure 15 shown.

[0211] As Figure 15 shown, the method includes the following steps:

[0212] S31. The Web issues a network element creation request;

[0213] S32. The configuration management module assigns a network element ID to this network element; if the assignment is successful, execute S33, if the assignment fails, execute S37;

[0214] S33. Perform network element scheduling; obtain the resource board node by taking the remainder of the network element ID % the number of resource boards;

[0215] S34. Determine whether the available resources of this resource board are sufficient. If so, execute S36; otherwise, execute S35;

[0216] S35. Based on Robin, select a certain resource board node from the remaining resource board nodes, and after finding a resource node that meets the specification conditions, execute S36;

[0217] S36. Perform resource scheduling response processing;

[0218] S37. Determine whether the scheduling is successful. If not, the creation of the network element fails. If so, continue to execute the remaining process of creating the network element.

[0219] After the scheduling algorithm, it is ensured that network elements with the same security network element ID among different network element groups are preferentially scheduled on the same resource board to meet the local priority policy for network element forwarding in the same SFC service chain. Based on the above scheduling algorithm, under the condition of sufficient resources on the resource board, it is preferentially ensured that network elements with the same security network element ID run on the same resource board. As Figure 16 shown:

[0220] As Figure 16 shown, after the optimized scheduling, the algorithm makes the network elements of the same color have the same network element ID and are distributed on the same resource board. There are 2 service chains shown in the figure: SFC1: FW -> IPS -> WAF -> AV; SFC2: IPS -> WAF -> AV.

[0221] 3.3 Service Chain Scheduling Optimization

[0222] The security stack performs refined traffic orchestration on the user's service traffic. That is, for the traffic that hits the service chain policy, it needs to be scheduled to different virtual security network elements for processing according to the logical order predefined by the user. Therefore, the service chain scheduling ability of the shunt platform is crucial for realizing the functions of the service chain.

[0223] In traditional chassis devices, one resource board can only correspond to one network element, such as a firewall resource board, an intrusion prevention resource board, etc., resulting in more resource consumption in service chain network element scheduling. The service chain scheduling optimization based on software definition can enable one resource board to carry network elements with multiple different security capabilities and support flexible scheduling, improving resource scheduling performance.

[0224] The hardware logic architecture of the security stack is as Figure 17 shown:

[0225] Among them, the main control board M1 plays the role of the shunt platform (the two main control boards M1 / M2 are deployed in a master-backup manner, and only M1 is discussed here), the resource boards R1 / R2 / … / Rn play the role of resource nodes (only R1 / R2 are discussed), and the switching boards S1 / S2 play the role of traffic load balancing (only S1 is discussed).

[0226] The shunt platform M1 is the management entry of the entire security stack, and users configure security policies and service chain policies on it. When the user adds a new virtual network element, the management plane of the shunt platform will refer to the resource occupancy of each resource node to select a suitable resource node for deployment. For example, in the above figure, the virtual network elements V1 / V2 are deployed on the resource node R1, and the virtual network elements V3 / V4 are deployed on the resource node R2. When selecting a resource node, for the virtual network elements belonging to the same service chain, the same resource node will be allocated as much as possible to reduce the scheduling overhead between virtual network elements.

[0227] As a distributed system composed of multiple hardware boards, the shunt platform M1 has a global perspective, knows the distribution of all traffic and the complete definition of the service chain policy, and pushes the forwarding flow table to the resource node based on the policy matching situation;

[0228] The resource nodes R1 / R2 are only the executors of the forwarding policy and rely on the forwarding flow table to forward the packets to the virtual network elements.

[0229] The switching board S1 is responsible for load balancing the incoming traffic to prevent a single resource node from becoming a performance bottleneck. The hash algorithm of the switching board is usually L3 hash or L4 hash, so the packets of each flow will be assigned to the same resource node (R1 or R2) for processing.

[0230] 1) The network element is on the same resource node

[0231] Based on the software-defined service chain scheduling method, when the first packet Pkt1 of a certain flow (denoted as Flow1) arrives at the system, the switching board S1 load-balances it to the resource board R1. Since the flow table of R1 is empty and it doesn't know how to process this packet, it redirects it to the traffic splitting platform M1 for processing.

[0232] This process can be expressed as: Pkt1: S1 -> R1 (rule miss) -> M1. As Figure 18 shown.

[0233] M1 receives the packet Pkt1 of flow Flow1 and performs the standard L2 / L3 forwarding process. During the process of matching the service chain policy, it is found that the packet hits the service chain Chain 1: V1 -> V2, that is, it needs to pass through two virtual network elements V1 and V2, and both of these network elements are on R1. So M1 issues the following forwarding flow table to R1:

[0234] Rule1: Flow1: V1 -> V2 -> Port1; (where Port1 is the outgoing interface for L2 / L3 forwarding)

[0235] The meaning of the rule is:

[0236] a. Schedule the packets that hit F1 to be processed by the virtual network element V1;

[0237] b. For the traffic processed by the virtual network element V1, continue to schedule it to the virtual network element V2;

[0238] c. After the traffic processed by the virtual network element V2, the service chain scheduling process ends and the forwarding process also ends, and it can be directly sent from Port1.

[0239] M1 issues Rule1 to R1, and this process can be expressed as: Pkt1: M1 (pushrule1) -> R1. As Figure 19 shown.

[0240] Then, M1 schedules the packet back to R1 for processing again, performing the forwarding actions of V1->V2->Port1: First, the packet is sent to V1. After V1 finishes processing, it is sent to V2. After V2 finishes processing, it is forwarded from Port1. This process is recorded as: Pkt1: R1(rule1hit)->V1->V2->Port1; as Figure 20 shown.

[0241] When the subsequent packets Pkt2 / Pkt3 / Pktn of Flow1 arrive, first, S1 ensures that the packets are hashed to the same resource board R1. Second, since R1 already contains the forwarding information of Flow1, it can process the forwarding of Flow1 normally without the direct participation of M1. This process is recorded as: Pkt2 / Pkt3: S1->R1(rule1 hit)->V1->V2->Port1. As Figure 21 shown.

[0242] Based on the advantages of software-defined service chain scheduling, it is ensured that the network elements belonging to the same service chain are distributed on the same resource nodes; the scheduling between network elements can be completed within the resource nodes without the need to go through the shunt platform M1 for processing, greatly reducing the pressure on the shunt platform M1 and avoiding the waste of internal bandwidth of the chassis.

[0243] 2) Security network elements on different resource nodes

[0244] For the case where the service chain spans multiple resource nodes, such as Chain2: V1->V2->V3->V4, the virtual network elements are distributed on two resource nodes, R1 and R2 (of course, the management plane will try to ensure that V1 / V2 / V3 / V4 are deployed together). After V2 on R1 finishes processing, there are two options:

[0245] a. In the prior art, the next node V3 is not on the current resource node R1. R1 does not know the distribution of non-local network elements and needs to schedule the packet back to the shunt platform M1, which is then relayed by M1 and scheduled to R2; …->V2->R1->M1->R2->V3->…, as Figure 22 shown.

[0246] b. In the optimized service chain resource scheduling method, when M1 issues the flow table to R1, it knows that the next network element of V2 is on the non-local resource node R2 and can reflect this information in the forwarding entry. For example, Rule2: Flow2: V1->V2->R1->R2, where R1 does not need to know how R2 schedules the remaining part of the service chain; …->V2->R1->R2–>V3->… As Figure 23 shown.

[0247] The optimized service chain resource scheduling method can save one more message scheduling. As Figure 24 shown.

[0248] 3.4 In-network Function Verification

[0249] The in-network verification solution in the prior art is as follows:

[0250] 1) All messages are scheduled to the shunt platform M1 (i.e., the resource board does not participate in load balancing);

[0251] 2) The shunt node matches the service chain policy Chain1: V1->V2. The first network element is on R1 and is scheduled to R1 for processing;

[0252] 3) After R1 receives the message and processes it through V1, it is scheduled back to M1;

[0253] 4) After M1 receives the message and continues to process the second network element, which is still on R1, it is scheduled to R1 for processing;

[0254] 5) After R1 receives the message and processes it through V2, it is scheduled back to M1;

[0255] 6) After M1 receives the message, Chain1 ends, and L2 / L3 forwarding is performed. Port1 is selected as the egress to send out;

[0256] 7) The subsequent messages repeat steps 1) to 6).

[0257] In this solution, M1 is very likely to become the performance bottleneck of the system. Moreover, the same message has to be scheduled back and forth in the system multiple times. The longer the service chain, the greater the additional scheduling overhead, the more serious the waste of hardware bandwidth, and the more seriously it affects the overall performance of the machine. Comparison of the resource scheduling before and after the optimization of the solution design:

[0258] Table 1 Comparison of Service Chain Scheduling Before and After Optimization

[0259]

[0260]

[0261] IV. Unified Scheduling Method Based on Virtual Network Elements and Physical Devices

[0262] The unified scheduling method for virtual network elements and physical devices is an innovative method mainly proposed to solve the problem of the inability to uniformly orchestrate and schedule virtual network elements and physical devices. Compared with the current situation where traditional orchestration technologies can only separately orchestrate virtual network elements or only physical devices, this method can abstract both virtual network elements and physical devices into a new type of security service object, enabling users to ignore the two device forms and only focus on their security protection capabilities. They can be flexibly combined using service chains, greatly reducing the operation and maintenance complexity. Moreover, it can make use of existing equipment and solve the problem that some devices do not have a virtualized form.

[0263] As Figure 25 shown, virtual network elements need to be connected to the corresponding virtual network at the time of creation and then orchestrated and used, while physical devices need to be wired in the physical network and are not related to the virtual network. To simultaneously orchestrate physical devices in the physical network and virtual network elements in the virtual network to form a virtual-real hybrid service chain, it is necessary to reclassify and define the network, sort out and analyze the use of virtual network elements and physical devices, define the characteristics of physical network elements, and then conduct compatibility analysis and design in combination with how to uniformly orchestrate the service chain.

[0264] 4.1 Definition of Physical Network Elements

[0265] To design and define physical network elements, it is necessary to first sort out the main deployment and use methods of physical security devices in the network. Physical security devices in the business network are mainly divided into two-layer access and three-layer access. For the service chain of three-layer access, generally, devices are strung together based on routing, and traffic is transmitted to physical security devices through policy-based routing. Since this access method requires corresponding three-layer networks and IPs for physical security devices to logically string the physical security devices into a service chain, this method is complex and inflexible to use. If you want to adjust the composition of the service chain during the process, it is even more difficult to achieve. Therefore, three-layer access is basically not considered. Two-layer access is more flexible and convenient, divided into series access and bypass access. Different physical security devices may use different access methods. Combining with the unified use of compatible virtual network elements, the situation of software-defined networks is sorted out.

[0266] As Figure 26 shown, the network is defined as four types: internal management network, business network, service chain series network, service chain bypass (mirror) network. The interfaces are also divided into four types: internal management interface, business network interface, series interface (a pair), bypass (mirror) interface.

[0267] This four-category division of the network is based on different demand scenarios.

[0268] Internal Management Network: The internal management network is an internal management network that is not perceived externally and is used to manage VNFs, including passwordless jump, VNF configuration initialization (network), and centralized management, etc. This network is mandatory for virtual network elements and not required for physical network elements.

[0269] Service Network: The service network is a network service network connected to users and is mainly used to actively provide security services based on a three-layer network. For example, the vulnerability scanning system connects to the customer's service network through this network for scanning, etc. This network is mandatory for virtual network elements and not required for physical network elements, and there can be multiple. For each service network, there will be an interface in the VNF connected to it.

[0270] Service Chain Serial Network: The service chain serial network is used to orchestrate network elements and form a logically serial network. The reason why the service chain does not require routing for serialization is that it is connected in series with multiple VNFs through a layer-2 access method, and does not need to be like other service chain implementation methods that achieve the effect of a single service chain by configuring multiple three-layer networks and combining policy routing. This network is selected according to the usage method of the network elements. Network elements that require security protection on the serial chain need to be configured.

[0271] Service Chain Bypass Network: The service chain bypass network is specifically used for traffic mirroring, which is used to copy the specified traffic and distribute it to bypass auditing, analysis, and statistical network elements in the adjacent chain of the service chain. This network is also selected according to the usage method of the network elements. Network elements that require statistical analysis on the bypass chain need to be configured.

[0272] According to the above four types of network definitions, there are also corresponding four types of interfaces.

[0273] Internal Management Interface: The internal management network is mandatory for virtual network elements, so there must be an internal management interface in the VNF, which is the default first interface, in DHCP mode. After startup, it will automatically obtain an internal network IP, which will be used for passwordless jump and RESTAPI configuration issuance, etc., while physical network elements do not require it. The internal management interface is the Figure 26 e0 interface in the network element in

[0274] Service Network Interface: Since the service network is mandatory for virtual network elements and there is at least one, for each corresponding service network in the VNF, there will be an interface. Service-type VNFs will provide relevant security protection through this network, such as vulnerability scanning, SSLVPN, etc., and physical network elements also do not require it. The service network interface is the Figure 26 e1 interface in the VNF in

[0275] Serial Interface: If a network element is to be arranged in the serial chain of a service chain, the serial network needs to be selected when creating or defining the network element. There will be a pair of interfaces corresponding in the virtual network element, while the physical network element needs to select a pair of interfaces on the physical device as the serial interface. These two interfaces are required to be assigned to a bridge for layer-2 transmission, with one interface for incoming traffic and the other for outgoing traffic. The service chain orchestration engine will, according to the traffic steering policy and the service chain policy, send the specified traffic to the incoming serial interface of the corresponding network element in sequence. For the traffic received from the outgoing serial interface, the next network element will be found according to the service chain policy, and the above actions will be repeated until the traffic is processed by the last network element in the serial chain of the service chain and then forwarded. The serial interface is Figure 26 the e2 and e3 interfaces in the VNF of

[0276] Bypass Interface: If a VNF is to be arranged in the bypass chain of a service chain, the bypass network needs to be selected when creating or defining the network element. There will be an additional corresponding interface in the VNF, while the physical network element needs to select an interface on the physical device as the bypass interface. The interface needs to be set to the bypass mode to be able to receive and process the mirrored traffic. The service chain orchestration engine will, according to the traffic steering policy and the service chain policy, copy the specified traffic and send it to the bypass interface of each network element in the bypass chain. The bypass interface is Figure 26 the e4 interface in the VNF of

[0277] Based on the above definitions and analyses, there are significant differences between physical network elements and virtual network elements. Physical network elements only care about the networks and interfaces for serial or bypass services and can be directly managed by the service chain without any custom development on the physical devices, achieving a better effect of making use of existing resources.

[0278] 4.2 Service Chain Unified Orchestration Method

[0279] Based on the differences between virtual network elements and physical network elements, it is necessary to abstract these two types of objects, extract the attributes in the intersection of the two types of objects, and form a new common network element object. For the service chain function, it is necessary to change to orchestrating this new network element object instead of using the previous virtual network element object and physical network element object, without distinguishing whether the orchestrated object is a virtual network element or a physical network element. When performing traffic distribution, only care about the serial or bypass interfaces of the network element object, so as to achieve a compatible effect.

[0280] For example Figure 27 , in addition to the attributes of some of its own characteristics, a virtual network element also includes network-related attributes, which include internal management network, service network, serial network, bypass network, and the corresponding interface information of the corresponding network, etc.

[0281] For example Figure 28, the attributes of physical network elements are fewer than those of virtual network elements. In addition to their own characteristics, they also include network-related attributes, such as only series network, bypass network, and corresponding interface information of the corresponding network.

[0282] Such as Figure 29 , both virtual network element objects and physical network element objects are ultimately converted into new network element objects. This object extracts and retains the attributes of the intersection part, and refines the four types of networks and the corresponding four types of interfaces to form independent interface objects. After the service chain references the new network element object, the compatibility of virtual and physical network elements has been completed. In subsequent use, there is no need to consider the relevant differences. Only need to define the required virtual and physical network elements, and they can be directly referenced in the service chain to form a virtual-real hybrid service chain to achieve the corresponding security protection effect, with simple operation and high flexibility.

[0283] V. Infrastructure as Code Implementation Method for Security Resource Pool

[0284] Using the infrastructure as code module, the security resource pool can save the configuration files of all network elements it contains and the topological connection relationships between network elements in text form to the version control system, forming an infrastructure configuration library for the security resource pool.

[0285] The present invention discloses an infrastructure as code implementation method for a security resource pool, including two processes:

[0286] S51. Obtain the infrastructure configuration of the security resource pool and save it to the version control system;

[0287] S52. Load the configuration of the security resource pool from the version control system and deploy it to the security resource pool.

[0288] 5.1. The process of obtaining the infrastructure configuration of the security resource pool and saving it to the version control system is as follows (the flowchart is as Figure 30 shown):

[0289] Step S511. Configure on the security resource pool interface;

[0290] Step S512. The configuration management module issues the configuration to the network elements in the security resource pool;

[0291] Step S513. The configuration management module saves the configuration;

[0292] The security resource pool includes: network elements, a configuration management module, an infrastructure as code module, and a version control system;

[0293] The configuration management module is used to read the configuration of the network elements in the security resource pool, and is also used to issue the configuration to the network elements and save the configuration;

[0294] An Infrastructure as Code module is used to describe infrastructure as code text, and perform network element configuration, preservation and rollback of topological relationships;

[0295] A version control system is used to save the historical configurations of network elements; the security resource pool can save the configuration files of all network elements it contains and the topological connection relationships between network elements in text form to the version control system.

[0296] Step S514: The Infrastructure as Code module obtains the network element configuration file with configuration changes and the topological connection relationship configuration;

[0297] Step S515: The Infrastructure as Code module saves the complete configuration file of the network element after the change and the topological connection relationship configuration to the version control system.

[0298] Furthermore, the security resource pool also includes a code comparison tool, which is used to compare the configurations of the security resource pool at different time points to check what changes have occurred.

[0299] 5.2 The process of loading the configuration of the security resource pool from the version control system and deploying it to the security resource pool is as follows (the flowchart is as Figure 31 shown):

[0300] Step S521: Select at the security resource pool interface the time point to which the configuration is to be rolled back and perform the rollback operation;

[0301] Furthermore, select specific network elements to perform the rollback;

[0302] Furthermore, select the entire security resource pool for rollback.

[0303] Furthermore, after a failure occurs in the security resource pool, select a certain time point before the failure for rollback.

[0304] Step S522: The Infrastructure as Code module pulls the configuration files of network elements and the topological connection relationship configuration on a specified date from the version control system and sends them to the configuration management module;

[0305] Step S523: The configuration management module issues the configuration to the network elements in the security resource pool;

[0306] Step S524: The configuration management module saves the configuration.

[0307] After the present invention implements Infrastructure as Code in the security resource pool, the security resource pool will have the ability to perform rollback for specific network elements and for the entire security resource pool, thereby supporting the security resource pool to quickly stop losses after a failure occurs. At the same time, the security resource pool can also rely on this ability to conveniently restore the fault scene and verify the fault recovery plan in subsequent fault drills.

[0308] The security resource pool adopting the infrastructure-as-code implementation method can obtain the following benefits:

[0309] 1. It helps to roll back the security resource pool to the state before the failure occurs when a failure occurs;

[0310] 2. It can restore the security resource pool to the configuration state at a specified time;

[0311] 3. It can conveniently use code comparison tools to compare the security resource pool configurations at different time points and view what changes have occurred.

[0312] VI. Automatic Orchestration and Deployment Method of Security Service Chain Based on Particle Swarm Algorithm

[0313] Through programmable preprocessing settings for network traffic in the virtualized environment, the present invention can complete two-way support for the automatic orchestration of virtualized security service chains, obtain the best combination of security service chain policies through particle swarm algorithm model matching, and implement and deploy the security service chain based on the best match, continuously optimizing and adjusting to complete the automatic orchestration process.

[0314] Aiming at the problem of high bandwidth consumption in the process of automatic orchestration of virtualized security service chains, the optimal solution is obtained by setting constraint conditions, which not only effectively improves the request success rate, but also reduces the bandwidth consumption and improves the efficiency and effective transmission ability of the orchestration algorithm.

[0315] The present invention proposes an automatic orchestration and deployment method of security service chain based on particle swarm algorithm. The data transmission process is designed by using the particle swarm algorithm model to improve the programmability of the service chain and realize two-way support for the automatic orchestration of virtualized security service chains. Aiming at the problem of high bandwidth consumption in the process of automatic orchestration of virtualized security service chains, the optimal solution is extracted by preprocessing sample parameters and setting sample parameters, which not only effectively improves the request success rate, but also reduces the bandwidth consumption and improves the effective transmission ability.

[0316] 6.1. Preprocessing of Sample Parameters

[0317] Through programmable preprocessing settings for network traffic in the virtualized environment, two-way support for the automatic orchestration of virtualized security service chains can be completed. However, in the process of automatic orchestration, multiple constraint conditions need to be considered, including:

[0318] The request volume on the security service chain must be less than or equal to the resources that the corresponding physical node can provide;

[0319] The bandwidth request volume also needs to be less than or equal to the bandwidth provided on the virtual link;

[0320] There can only be one mapping between the virtual link and the actual physical path;

[0321] Meanwhile, in order to reduce the bandwidth consumption during the automatic orchestration of the virtual environment security service chain, the present invention sets the minimum total bandwidth as the optimal solution for automatic orchestration.

[0322] 6.2. Sample Parameter Setting and Extraction

[0323] For the extraction of sample parameters, it is first necessary to complete the setting of feature sample parameters. In a certain embodiment, the physical topology structure of the virtualized environment includes a main core layer switch, and the numbers of other switches in the aggregation layer and the edge layer are defined as N (5) and M (40) respectively. The specific setting of the sample parameters is shown in Table 2. The total number of requests for the virtualized link is set at Z (500 times). To ensure the authenticity of the sample results, K (20 times) of tests are conducted under the same parameters. The number of virtual network functions on the security service chain is increased from 1 to 20 in sequence according to the number of tests, and the number of requests each time is set to 20.

[0324] Table 2 Test Sample Parameter Settings

[0325]

[0326]

[0327] 6.3. Automatic Orchestration Deployment Model Design

[0328] After obtaining the test sample parameters in the virtualized environment, for the security protection design of the virtualized network, it is necessary to establish an automatic orchestration deployment model. According to the security service requirements of the upper-layer users and the automatic architecture service chain strategy, the virtual security network element protection function is realized, and the data stream being transmitted is safely scheduled into the virtual security network element to achieve the security protection of the transmission sequence.

[0329] The present invention proposes a method for automatically orchestrating and deploying a security service chain based on the particle swarm algorithm, and the specific process is as follows:

[0330] Step S61: Initialize the particle swarm of the automatic orchestration deployment model, and randomly generate a group of particles. Each particle represents a possible policy combination, also known as an orchestration solution.

[0331] Step S62: Calculate the fitness: According to the evaluation function (fitness function) of the problem, calculate the fitness value of each particle. This value can be the direct output of the fitness function or may require certain conversion (such as taking the opposite number to adapt to the maximization problem).

[0332] Step S63: Evaluate the fitness of each particle according to the predetermined fitness function.

[0333] Step S64: Record the position of the particle with the best fitness in the particle swarm, i.e., the global optimal solution. Update the velocity and position of each particle by considering the individual historical optimal position and the global optimal position.

[0334] Step S65: Repeat Step S62 to Step S64 until the termination condition is met, and obtain the position of the particle with the best fitness. This position is the optimal solution, corresponding to the best combination of security service chain policies.

[0335] Step S66: Deploy and adjust the security service chain according to the best policy combination represented by the optimal solution, continuously optimize and adjust, and complete the automatic orchestration process.

[0336] Among them, the implementation method of the fitness function is as follows:

[0337] In the function optimization problem, the fitness function usually directly adopts the objective function. For example, in the problem of finding the minimum value, the smaller the objective function value, the higher the fitness of the particle. The present invention designs a binary optimization function, sets the objective function as f(x,y) = x 2 +y 2 , and we need to find the minimum value of this function. In this problem, we directly use the objective function as the fitness function, and the function formula is defined as follows:

[0338] Fitness(x,y) = x 2 +y 2

[0339] Among them, x and y represent two input variables. The present invention comprehensively considers the number of user requests in the security service chain orchestration and the bandwidth consumption in the orchestration process as the measurement indicators of fitness. Therefore, the input variable of x is defined as the number of user requests, and the input variable of y is defined as the bandwidth consumption. The particle swarm algorithm will evaluate the position of each particle according to this fitness function and guide the particle to move to the area with a smaller fitness value, so as to find the minimum value of the function.

[0340] The automatic orchestration and deployment model of the virtualized environment security service chain can automatically implement the orchestration of service chain policies and the automatic deployment of virtual security network elements, safely schedule the data flow into the corresponding virtual security network elements for security protection, improve the reliability of security protection, and reduce the management workload. Two key problems need to be solved in this process:

[0341] 1) Solve the policy conflict problem in the automatic orchestration of the virtualized environment security service chain;

[0342] 2) Solve the problem of optimizing network traffic scheduling.

[0343] To solve the above two problems, the present invention designs an automatic orchestration and deployment model of the security service chain based on the particle swarm algorithm, asFigure 32 As shown, it further includes: a policy conflict decision node, a network traffic scheduling node, and a security resource pool;

[0344] In the case of conflicts in automatic orchestration decisions, the policy conflict decision node first provides network security protection services for business traffic automatically through an open policy scheduling interface. However, affected by different front and back policies, there may well be certain conflicts between execution actions. At this time, the best policy combination obtained based on the particle swarm algorithm is used to automatically coordinate and manage the relationships between various services, enabling the policy conflict decision node to correctly orchestrate network flow transmission according to the priorities of the security service chain, eliminating conflicts in the environment, reducing network congestion, thereby reducing the CPU load and the CPU utilization rate. At the same time, the scheduling optimization decision results are transmitted to the corresponding network traffic scheduling node.

[0345] The network traffic scheduling node is responsible for analyzing and managing the virtualized security network elements in the security resource pool, effectively realizing the automatic monitoring of the load information of the network elements, outputting the corresponding security traffic scheduling configuration according to the security service chain orchestration policy, parsing the types of security network elements, evaluating the best solution for policy scheduling from the scheduling optimization decision results of the policy conflict decision node, and automatically transmitting the actual configured security traffic scheduling information policy to the virtualized security network elements in the security resource pool through a message queue to achieve the directional processing of data traffic.

[0346] The message queue uses asynchronous communication. The sender in the security resource pool (traffic incoming direction, generally referring to the source IP address of network traffic) sends messages to the queue without waiting for the response of the receiver (traffic outgoing direction, generally referring to the destination IP address of network traffic), so the response speed of the security service chain can be improved.

[0347] 6.4. Comparison and Training of Sample Parameters

[0348] Based on the extracted sample parameters, experimental data analysis is carried out on the average total bandwidth consumption of the zero-touch network orchestration method, the real-time seamless orchestration method, and the method adopted in this project. In the experiment, the same physical topology structure is input into the virtualized environment, the same number of security service chain requests are made for the three methods, and the average total bandwidth consumption of the three algorithms is compared. The calculation process of the average total bandwidth consumption is shown in the following formula:

[0349]

[0350] Among them, D represents the total data volume, and T represents the data transmission time. The specific situation is as Figure 32 shown.

[0351] According to Figure 33It can be seen that although the operation process of the zero-touch network orchestration method is relatively simple and can greatly improve the efficiency of the orchestration algorithm, the corresponding average total bandwidth consumption is relatively high, and the consumption is much greater than that of the real-time seamless orchestration method and the method of this project. The change of the present invention is more stable compared with the zero-touch network orchestration method and the real-time seamless orchestration method. In the process of the increasing number of requests for the security service chain in the virtualization environment by users, the average total bandwidth consumption of the present invention can be stably maintained within a certain level range. This is mainly because in the process of automatically orchestrating the service chain of the present invention, minimizing the total bandwidth is set as the automatic orchestration goal, reducing the total average bandwidth consumption in the process of automatically orchestrating the security service chain of the virtual environment, and ensuring that the average total bandwidth consumption can be stably maintained within a certain level range.

[0352] Experimental comparative analysis is carried out on the request success rates under different algorithm conditions. In the test, the same physical topology is input to the virtual link to ensure that the number of requests for the security service chain of the three methods is the same, and experimental analysis and comparison are carried out on the request success rates of the zero-touch network orchestration method, the real-time seamless orchestration method and the present invention. The calculation formula of the request success rate is shown as follows:

[0353]

[0354] Among them, Nc represents the number of successful requests, and N1 represents the total number of requests. The specific experimental results are as Figure 34 shown. It can be seen from the experimental results that the request success rate of the user security service chain corresponding to the zero-touch network orchestration method is much lower than that of the real-time seamless orchestration method and the present invention. Comparing the zero-touch network orchestration method and the present invention, it can be seen that as the number of requests for the security service chain by cloud network users increases, the request success rate of the present invention can remain stable and is always higher than that of the zero-touch network orchestration method. This shows that the present invention can effectively improve the request success rate of users to a certain extent while saving bandwidth consumption, and realize better automatic orchestration of the service chain. The reason for the analysis is that through the dynamic scheduling of service nodes by the security service chain automatic orchestration and deployment model based on the particle swarm algorithm, and at the same time using the real-time feedback results, the failure rate of the system is effectively reduced, thereby improving the request success rate.

[0355] 6.5. Verification by real network data test

[0356] Through extracting about 500 Gbps traffic of real data of a certain telecom user for comparative test verification, under the precondition of adopting the same physical topology, the security service chain automatic orchestration and deployment model based on the particle swarm algorithm is compared and tested with the traditional SDN-based traffic scheduling model. The test results are obtained by the tester respectively recording the maximum throughput, the maximum number of new connections and the maximum number of concurrent connections that can be reached under the two models, as shown in Figure 35 、 36 shown.

[0357] Test conclusion: By adopting the automatic orchestration technology of the security service chain based on the particle swarm algorithm, compared with the traditional SDN-based traffic scheduling technology, the improvement rate of traffic scheduling and detection performance in the virtualization environment reaches up to 65%, solving the problems of insufficient performance, complex management, and too low efficiency existing in the traditional traffic diversion and service chain orchestration technology.

[0358] The present invention proposes an automatic orchestration and deployment method of a security service chain based on the particle swarm algorithm. The particle swarm algorithm model is used to design the data transmission process, improving the programmability of the service chain and realizing two-way support for the automatic orchestration of the virtualization security service chain. Aiming at the problem of high bandwidth consumption in the process of automatic orchestration of the virtualization security service chain, the optimal solution is obtained by setting constraint conditions, which not only effectively improves the request success rate, but also reduces the bandwidth consumption and improves the ability of effective transmission.

[0359] By adopting the automatic orchestration and deployment technology of the security service chain based on the particle swarm algorithm of the present invention, compared with the traditional SDN-based traffic scheduling technology, the improvement rate of traffic scheduling and detection performance in the virtualization environment reaches up to 65%, solving the problems of insufficient performance, complex management, and too low efficiency existing in the traditional traffic diversion and service chain orchestration technology.

[0360] In summary, the present invention designs and implements a next-generation network boundary security stack system. By adopting the above technology, it helps to optimize network performance, reduce the delay and error of data transmission, and thus provide a smoother and safer network experience for users.

[0361] The network boundary security stack system of the present invention effectively solves the problems existing in the traditional boundary protection scheme by integrating multiple intelligent technologies, providing a strong guarantee for the security and management efficiency of the network boundary.

[0362] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and deformations can still be made, and these improvements and deformations should also be regarded as the protection scope of the present invention.

Claims

1. A network boundary security stack system, characterized in that Based on the concept of integrated security protection, the system adopts a design scheme of hierarchical, embedded, and multi-dimensional integrated security protection; Hierarchical means adopting a software-defined architecture, dividing the system into: a boundary access layer, a security resource layer, a core switching layer, and an operation and maintenance management and control layer; the boundary access layer includes next-generation boundary protection devices, and the security resource layer virtualizes the boundary protection devices in the boundary access area into a multi-source heterogeneous network element pool base through network resource virtualization technology, computing resource virtualization technology, and storage resource virtualization technology; the core switching area realizes multi-dimensional refined security control of network traffic; the operation and maintenance management and control layer realizes unified operation and management; Embedded means that through integrated design, in the multi-source heterogeneous network element pool base of the security resource layer, network traffic unsupervised anomaly detection based on an improved Transformer reconstruction model, encrypted traffic anomaly rapid detection of plaintext traffic characteristics, and infrastructure as code implementation of the security resource pool are integrated together at the underlying architecture and data transmission levels in the business process; Multi-dimensional means that in the core switching area, flexible service chain orchestration and full-scenario link keep-alive are adopted to realize multi-dimensional refined security control of network traffic, break the bondage of one-dimensional traffic processing, enter the multi-dimensional traffic space, and realize high-speed concurrency of different traffic security processing; Among them, flexible service chain orchestration includes: decrypted traffic service chain orchestration based on blockchain and deep reinforcement learning, optimization based on software-defined orchestration technology, unified scheduling based on virtual network elements and physical devices, and automatic orchestration and deployment of security service chains based on particle swarm algorithms, realizing flexible orchestration of service chains in different situations or scenarios through the above various methods; Full-scenario link keep-alive adopts multiple intelligent link keep-alive to ensure that when faults occur at all levels of the network, the boundary security stack system can also respond quickly and maintain network quality; In the operation and maintenance management and control layer, unified management of intelligent security capabilities is also provided, and unified management of intelligent security capabilities enables the system to realize standardized and normalized unified management of multi-category heterogeneous networks.

2. The network boundary security stack system according to claim 1, characterized in that, Full-scenario link keep-alive provides comprehensive link protection capabilities to handle various abnormal situations through multiple Bypass mechanisms, including: hardware Bypass, software Bypass, service chain Bypass, and security network element Bypass.

3. The network boundary security stack system according to claim 2, wherein When the hardware device is powered off or restarted, the hardware Bypass technology will be used to ensure the normal forwarding of service traffic and ensure that the device does not affect the overall machine business; a direct connection line is set between the input and output of the hardware device. If the device is powered off or restarted, the service traffic will be directly forwarded from the input end to the output end, thus bypassing the hardware layer.

4. The network boundary security stack system according to claim 2, wherein If the system platform layer is being upgraded, the system platform layer will be bypassed, and the traffic will be directly forwarded through the physical hardware layer without flowing through the system platform layer and its upper layers; this ensures the normal forwarding of service traffic and ensures that it does not affect the overall machine business.

5. The network boundary security stack system according to claim 2, wherein If there is no security network element in the service chain or no security network element is in a normal state, the traffic will bypass the entire service chain and be directly forwarded through the system platform layer, thus ensuring the normal forwarding of service traffic and ensuring that it does not affect the overall machine business.

6. The network boundary security stack system according to claim 2, wherein When a certain security network element fails, when traffic flows through various security network elements on the service chain, it will bypass the abnormal security network element and flow normally through other security network elements on the chain.

7. The network boundary security stack system according to claim 1, wherein Unified management of intelligent security capabilities includes: unified network element configuration management module and differential redundancy management of network element configuration. The unified network element configuration management module is responsible for managing and configuring all security devices in the security stack. The unified network element configuration management module uniformly configures and manages security network elements through standardized interfaces.

8. The network boundary security stack system according to claim 7, characterized in that, The unified network element configuration management module abstracts the core functions of each type of security network element, extracts important common parameters, and the common parameters also need to meet the configuration logics of each manufacturer. Then, it formulates the interface specifications for each type of security capability, and develops the corresponding configuration management functions based on each type of security network element based on these interface specifications, which are executed by the unified network element configuration management module in the security stack. These management functions are further divided into security capability configuration functions and security network element upgrade management functions.

9. The network boundary security stack system according to claim 8, wherein The common parameters include: interface type, security policy, logging, upgrade management, authentication mechanism, and performance metrics; the interface specifications include: authentication interface, configuration management interface, logging and reporting interface, monitoring and alert interface, software update interface, health check interface, policy management interface, and remote management interface.

10. The network boundary security stack system according to claim 7, characterized in that, Differential redundancy management of network element configuration uses multiple components with the same function to ensure that in the event of a failure of one component, other components can seamlessly take over its workload, including: redundant configuration, health monitoring, fault detection, failover, load balancing, recovery management, and data synchronization processes.

11. The network boundary security stack system according to claim 10, wherein The key steps of differential redundancy management of network element configuration include: Defining redundancy policies: determining which security network elements require redundant configuration and the level of redundancy; Implementing health monitoring: deploying tools or services to continuously monitor the health status of each network element; Setting up a fault detection mechanism: clarifying the specific methods and triggering conditions for fault detection; Configuring a failover plan: designing how the standby node can quickly take over the service when the primary node fails; Load balancing strategy: formulating load balancing rules to allocate requests to each network element in an optimal manner; Establishing a recovery plan: preparing a detailed recovery process to resume normal operation as soon as possible after the fault is resolved; Ensuring data consistency: taking measures to ensure data synchronization and consistency among all redundant components.

12. The network boundary security stack system according to claim 1, characterized in that, Optimization based on software-defined orchestration technology includes: Optimization of data encapsulation technology: traffic is distributed through a centrally managed traffic splitting platform. SFC is defined on the traffic splitting platform, and dynamic forwarding flow tables are stored on the corresponding resource servers for fast distribution of intermediate traffic; for data that needs to pass through the SFC, the traffic splitting platform directly forwards the original data packets to the corresponding SFC node devices. Since the data is not modified, no special protocol processing needs to be added to the node devices. Optimization of network element allocation method: By optimizing the network element allocation scheduling algorithm, different security network elements on the service chain are allocated to the same resource node. From the perspective of the data transmission path, the physical network data link path length and the virtual network data link path length are reduced. Service Chain Scheduling Optimization: The shunt platform is the management entry of the entire security stack, where users configure security policies and service chain policies; the shunt platform has a global perspective, knows the distribution of all traffic, as well as the complete definition of service chain policies, and pushes forwarding flow tables to resource nodes based on policy matching; resource nodes are the executors of forwarding policies and rely on forwarding flow tables to forward packets to virtual network elements; the switching board is responsible for load balancing the incoming traffic to avoid a single resource node becoming a performance bottleneck.

13. The network boundary security stack system according to claim 12, wherein Under the condition that the processing capabilities of network elements and physical hardware are the same, the optimization based on software-defined orchestration technology optimizes the packet size and data path length.

14. The network boundary security stack system according to claim 12, wherein When optimizing the network element allocation method, the security network elements are scheduled to the resource boards in the resource nodes using the round-robin scheduling algorithm based on the resource boards; the same security network element group will be sent to a resource node. Since the security network element group IDs within the same security network element group are the same, but the security network element IDs are different, a policy of creating security network elements within each security network element group and performing priority scheduling based on the security network element IDs is adopted.

15. The network boundary security stack system according to claim 12, characterized in that, When optimizing service chain scheduling, when network elements are on the same resource node, When the first packet Pkt1 of a certain flow Flow1 arrives at the system, the switching board S1 load-balances it to the resource board R1; since the flow table of R1 is empty and doesn't know how to handle this packet, it redirects it to the shunt platform M1 for processing; this process is represented as: Pkt1: S1 -> R1 (rule miss) -> M1; The shunt platform M1 receives the packet Pkt1 of flow Flow1 and performs the standard L2 / L3 forwarding process; during the process of matching the service chain policy, it is found that the packet hits the service chain Chain 1: V1->V2, that is, it needs to pass through two virtual network elements V1 and V2, and both of these network elements are on R1; so the shunt platform M1 will send the following forwarding flow table to R1: Rule1: Flow1: V1 -> V2-> Port1; Port1 is the L2 / L3 forwarding output interface. The shunt platform M1 sends Rule1 to R1, and this process is represented as: Pkt1: M1 (push rule1) -> R1; The shunt platform M1 schedules the packet back to R1 for processing again, and executes the forwarding action of V1->V2->Port1: first, send the packet to V1, after V1 finishes processing, send it to V2, and after V2 finishes processing, forward it from Port1; This process is recorded as: Pkt1: R1(rule1hit) -> V1 -> V2 -> Port1; When subsequent packets Pkt2, Pkt3, …, Pktn of Flow1 arrive, first, S1 ensures that the packets are hashed to the same resource board R1. Second, since R1 already contains the forwarding information of Flow1, it can process the forwarding of Flow1 normally without the direct participation of the traffic splitting platform M1. This process is denoted as: Pkt2, Pkt3, …, Pktn: S1 -> R1(rule1 hit) -> V1 -> V2 -> Port1.

16. The network boundary security stack system according to claim 12, wherein When optimizing service chain scheduling and the security network element is at different resource nodes When the traffic splitting platform M1 issues a flow table to R1 and knows that the next network element of V2 is on a non-local resource node R2, it reflects this information in the forwarding entry. Rule2: Flow2: V1 -> V2 -> R1 -> R2, and R1 directly schedules the packet to R2 after processing.

17. The network boundary security stack system according to claim 1, wherein Unified scheduling based on virtual network elements and physical devices includes: physical network element definition and unified service chain orchestration; Physical network element definition: The network is defined into four types: internal management network, service network, service chain tandem network, and service chain bypass network; the interfaces are also divided into four types: internal management interface, service network interface, tandem interface, and bypass interface; physical network elements only care about the networks and interfaces for tandem or bypass services. Unified service chain orchestration: Based on the differences between virtual network elements and physical network elements, abstract the two types of objects, extract the attributes of the intersection part of the two types of objects, and form a new common network element object; for service chain functions, orchestrate this new network element object, no longer using the previous virtual network element object and physical network element object, without distinguishing whether the orchestrated is a virtual network element or a physical network element. When performing traffic distribution, only care about the tandem or bypass interfaces of the network element object.

18. The network boundary security stack system according to claim 17, wherein The internal management network is a network for internal management, not perceived externally, used to manage VNFs, including passwordless jump, VNF configuration initialization, and centralized management. This network is mandatory for virtual network elements and not required for physical network elements. The service network is a network for connecting to user network services, used to actively provide security services based on a three-layer network. This network is mandatory for virtual network elements and not required for physical network elements. There are multiple service networks, and each service network will have an interface connected to it within the VNF. The service chain tandem network is used to orchestrate network elements and form a logically tandem network. The reason why the service chain does not require routing for tandem is that multi-VNF tandem is achieved through a layer-2 access method; this network is selected according to the usage method of network elements, and network elements that require security protection on the tandem chain need to be configured. Service chain bypass network: The service chain bypass network is used for traffic mirroring, used to copy specified traffic and distribute it to bypass auditing, analysis, and statistics network elements in the bypass chain of the service chain; this network is selected according to the usage method of network elements, and network elements that require statistical analysis on the bypass chain need to be configured.

19. The network boundary security stack system according to claim 18, wherein Internal management interface: The internal management network is mandatory for virtual network elements. Therefore, there must be an internal management interface in the VNF, which is the first interface by default and in DHCP mode. After startup, it will automatically obtain an internal network IP, which will be used for passwordless jump and REST API configuration distribution. Physical network elements do not require this. Service network interface: Since the service network is mandatory for virtual network elements and there is at least one, there will be one interface in the VNF for each corresponding service network. Service-oriented VNFs will provide relevant security protection through this interface. Physical network elements also do not require this. Series interface: If a network element is to be arranged in the series chain of a service chain, the series network needs to be selected when creating or defining the network element. There will be a pair of interfaces corresponding in the virtual network element, while physical network elements need to select a pair of interfaces on the physical device as series interfaces. These two interfaces are required to be assigned to a bridge for layer 2 transmission, with one interface for incoming and one for outgoing. The service chain orchestration engine will, according to the traffic diversion strategy and service chain strategy, send the specified traffic to the incoming series interfaces of the corresponding network elements in sequence. For the traffic received from the outgoing series interfaces, it will find the next network element according to the service chain strategy and repeat the above actions until the traffic is processed by the last network element in the series chain of the service chain and then forwarded. Bypass interface: If a VNF is to be arranged in the bypass chain of a service chain, the bypass network needs to be selected when creating or defining the network element. There will be an additional corresponding interface in the VNF, while physical network elements need to select an interface on the physical device as the bypass interface. The interface needs to be set to bypass mode to be able to receive and process the mirrored traffic. The service chain orchestration engine will, according to the traffic diversion strategy and service chain strategy, copy the specified traffic and send it to the bypass interfaces of each network element in the bypass chain.

20. The network boundary security stack system according to claim 19, wherein The abstraction of two types of objects includes: In addition to some attributes of its own characteristics, virtual network elements also include network-related attributes, which include the internal management network, service network, series network, bypass network, and the corresponding interface information of the corresponding networks. In addition to its own characteristics, physical network elements also include network-related attributes, which only include the series network, bypass network, and the corresponding interface information of the corresponding networks.

21. The network boundary security stack system according to claim 20, wherein Virtual network element objects and physical network element objects are finally converted into new network element objects, which extract and retain the intersecting part of the attributes and refine the four types of networks and the corresponding four types of interfaces to form independent interface objects. After the service chain references the new network element objects, the compatibility of virtual and physical network elements has been completed. In subsequent use, there is no need to consider the relevant differences. Only need to define the required virtual and physical network elements and directly reference them in the service chain to form a virtual-real hybrid service chain.

22. The network boundary security stack system according to claim 1, wherein, The infrastructure as code implementation of the security resource pool includes: S51. Obtain the infrastructure configuration of the security resource pool and save it to the version control system; S52. Load the configuration of the security resource pool from the version control system and deploy it to the security resource pool.

23. The network boundary security stack system according to claim 22, wherein The specific content of S51 includes: Step S511. Configure on the security resource pool interface; Step S512: The configuration management module issues configurations to network elements in the security resource pool; Step S513: The configuration management module saves the configurations; Step S514: The infrastructure as code module obtains the network element configuration files and topology connection relationship configurations where the configurations have changed; Step S515: The infrastructure as code module saves the complete network element configuration files and topology connection relationship configurations after the changes to the version control system.

24. The network boundary security stack system according to claim 23, characterized in that, The security resource pool includes: network elements, a configuration management module, an infrastructure as code module, and a version control system; The configuration management module reads the configurations of network elements in the security resource pool, is also used to issue configurations to network elements, and saves the configurations; The infrastructure as code module describes the infrastructure as code text, and performs the saving and rollback of network element configurations and topology relationships; The version control system is used to save the historical configurations of network elements. The security resource pool saves the configuration files of all network elements it contains and the topology connection relationships between network elements in text form to the version control system.

25. The network boundary security stack system according to claim 23, wherein The specific steps of S52 are as follows: Step S521: Select the time point to which the configuration is to be rolled back on the security resource pool interface and perform the rollback operation; Step S522: The infrastructure as code module pulls the network element configuration files and topology connection relationship configurations of the specified date from the version control system and sends them to the configuration management module; Step S523: The configuration management module issues configurations to network elements in the security resource pool; Step S524: The configuration management module saves the configurations.

26. The network boundary security stack system according to claim 25, wherein Select specific network elements to perform rollback or select the entire security resource pool for rollback.

27. The network boundary security stack system according to claim 1, wherein The automatic orchestration and deployment of the security service chain based on the particle swarm algorithm includes the following steps: Step S61: The automatic orchestration and deployment model initializes the particle swarm and randomly generates a set of particles. Each particle represents a policy combination, also known as an orchestration solution; Step S62: Calculate the fitness: According to the fitness function, calculate the fitness value of each particle. The fitness function is: where x and y represent two input variables. The input variable x is defined as the number of user requests, and the input variable y is defined as the bandwidth consumption; The particle swarm algorithm will evaluate the position of each particle according to this fitness function and guide the particles to move to the area with a smaller fitness value, so as to find the minimum value of the fitness function; Step S63: Perform fitness evaluation on each particle according to the predetermined fitness function; Step S64: Record the position of the particle with the best fitness in the particle swarm, that is, the global optimal solution; update the speed and position of each particle by considering the individual historical optimal position and the global optimal position; Step S65: Repeat steps S62 to S64 until the termination condition is met, and obtain the position of the particle with the best fitness. This position is the optimal solution, corresponding to the best security service chain policy combination; Step S66: According to the best policy combination represented by the optimal solution, deploy and adjust the security service chain, continuously optimize and adjust, and complete the automatic orchestration process.

28. The network boundary security stack system according to claim 27, wherein Before the step S1, it further includes: a sample parameter preprocessing process. Specifically, through programmable preprocessing settings for network traffic in a virtualized environment, two-way support for automatic orchestration of virtualized security service chains is completed.

29. The network boundary security stack system according to claim 27, wherein During the automatic orchestration process, multiple constraint conditions need to be considered, including: the request volume on the security service chain must be less than or equal to the resources that the corresponding physical node can provide; the bandwidth request volume also needs to be less than or equal to the bandwidth provided on the virtual link; there can only be one mapping between the virtual link and the actual physical path.

30. The method for automatically orchestrating and deploying a security service chain based on a particle swarm algorithm according to claim 27, wherein The automatic orchestration deployment model further includes: a policy conflict decision node, a network traffic scheduling node, and a security resource pool; In the case of conflicts in automatic orchestration decisions, the policy conflict decision node first provides network security protection services for business traffic automatically through an open policy scheduling interface; affected by different front and back policies, resulting in conflicts between execution actions, at this time, the best policy combination obtained based on the particle swarm algorithm is used to automatically coordinate and manage the relationships between various services, so that the policy conflict decision node correctly orchestrates network flow transmission according to the priority of the security service chain; the policy conflict decision node also transmits the scheduling optimization decision result to the corresponding network traffic scheduling node; The network traffic scheduling node is responsible for analyzing and managing virtualized security network elements in the security resource pool, realizing automatic monitoring of the load information of the network elements, outputting corresponding security traffic scheduling configurations according to the security service chain orchestration strategy, parsing the types of security network elements, evaluating the best solution for policy scheduling from the scheduling optimization decision result of the policy conflict decision node, and automatically transmitting the security traffic scheduling information policy of the actual configuration to the virtualized security network elements in the security resource pool through a message queue to achieve directional processing of data traffic; The message queue adopts an asynchronous communication method. The sender in the security resource pool sends the message to the queue without waiting for the response of the receiver, improving the response speed of the security service chain.

Citation Information

Patent Citations

  • An unsupervised anomaly detection method for network traffic based on improved Transformer reconstruction model

    CN117768207B

  • Decryption traffic service chain arrangement method based on block chain and deep reinforcement learning

    CN118158078A

  • Fast detection method for encrypted traffic based on combination of plaintext traffic features and ciphertext traffic features

    CN118337416A

  • An agnostic system acting as a service for traffic management and cybersecurity in virtualized network environments.

    BR102018002209A2

  • Endogenous security programmable network system

    CN116112304A