A network security access method and device applied to a large model service, equipment and medium
By dividing container groups into workgroups and setting differentiated network access policies, the problem of low network isolation security in Model-as-a-Service is solved, achieving fine-grained network access management and security assurance, and meeting the actual access needs of applications.
Patent Information
- Application Number
- CN202411976213.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-12-19
- Estimated Expiration
- 2044-12-30
AI Technical Summary
In existing technologies, cloud service providers using the Model-as-a-Service approach face challenges in achieving static network isolation outside of applications, including low security or failure to meet actual network access requirements. In particular, when accessing external networks, they cannot simultaneously guarantee the normal operation and security of applications.
By dividing container groups with the same functionality within the same application into corresponding workgroups and setting different network access policies for different workgroups, once the target network access policy is determined, access operations are only performed when the matched access object matches the policy. This includes external network objects, interactive objects outside the container orchestration platform, and internal objects of the container orchestration platform.
It enables finer-grained network access management for applications, which not only meets the actual access needs of different container groups, but also ensures the security of network access, reduces the risk of network attacks, and improves the network security of applications without adding extra overhead.
Smart Images

Figure CN119814446B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of computer, and particularly relates to a network access method and device, equipment and medium. BACKGROUND
[0002] In a cloud computing scenario, a cloud service provider of Model as a Service (MaaS) can provide a large model as a service to a user, and the user hopes that the model related task of the user runs in an isolated network environment, and one task can include a Pod or multiple Pods. In the related art, unified static network isolation outside an application program can be implemented, but the security of the entire application program is very low when the external network is allowed to access, and the network access demand of actual external access cannot be met when the external network is not allowed to access, and needs to be improved. SUMMARY
[0003] In order to solve the above technical problems, the present disclosure provides a network access method, device, equipment and medium.
[0004] The present disclosure provides a network access method, which comprises the following steps:
[0005] obtaining a network access request of a target Pod, wherein the target Pod belongs to a target workgroup, and the target workgroup comprises at least one Pod of the same function of a target application program;
[0006] determining a target network access strategy corresponding to the target workgroup;
[0007] if it is determined that a target access object corresponding to the network access request matches the target network access strategy, performing an access operation between the target Pod corresponding to the network access request and the target access object, wherein the target access object comprises at least one of an external network object, an interactive object of the target Pod outside a container orchestration platform, and an internal object of the container orchestration platform.
[0008] The present disclosure further provides a network access device, which comprises:
[0009] an obtaining module configured to obtain a network access request of a target Pod, wherein the target Pod belongs to a target workgroup, and the target workgroup comprises at least one Pod of the same function of a target application program;
[0010] a determining module configured to determine a target network access strategy corresponding to the target workgroup;
[0011] The execution module is configured to execute an access operation between the target container group corresponding to the network access request and the target access object if it is determined that the target access object corresponding to the network access request matches the target network access policy, wherein the target access object comprises at least one of an external network object, an interactable object of the target container group outside the container orchestration platform, and an internal object of the container orchestration platform.
[0012] The electronic device comprises a processor, a memory for storing executable instructions of the processor, and the processor is configured to read the executable instructions from the memory and execute the instructions to implement the network access method provided by the embodiments of the present disclosure.
[0013] The embodiments of the present disclosure further provide a computer-readable storage medium storing a computer program for executing the network access method provided by the embodiments of the present disclosure.
[0014] The technical solution provided by the embodiments of the present disclosure has the following advantages compared with the prior art: the network access solution provided by the embodiments of the present disclosure obtains a network access request of a target container group, wherein the target container group belongs to a target workgroup, and the target workgroup comprises at least one container group of the same function of a target application program; a target network access policy corresponding to the target workgroup is determined; if it is determined that a target access object corresponding to the network access request matches the target network access policy, an access operation between the target container group corresponding to the network access request and the target access object is executed, wherein the target access object comprises at least one of an external network object, an interactable object of the target container group outside the container orchestration platform, and an internal object of the container orchestration platform. By using the above technical solution, for the network access request of the target container group in the target workgroup of the target application program, the access is allowed when the target network access policy corresponding to the target workgroup matches the target access object corresponding to the target access request. By dividing the container groups with the same function in the same application program into corresponding workgroups and setting different network access policies for different workgroups, since the network access policy can control the access of the external network object, the interactable object, and / or the internal object, the network access management with different isolation degrees is realized for the internal application program with finer granularity, which can meet the actual access requirements of different container groups and guarantee the security of network access. BRIEF DESCRIPTION OF DRAWINGS
[0015] The above and other features, advantages, and aspects of the embodiments of the present disclosure will become more apparent by describing in detail the following specific embodiments with reference to the attached drawings. Throughout the drawings, the same or similar reference numerals refer to the same or similar elements. It should be understood that the drawings are schematic, and the original and elements are not necessarily drawn according to the scale.
[0016] Figure 1 A flowchart of a network access method provided for some embodiments of the present disclosure;
[0017] Figure 2 A schematic diagram of a network access process provided for some embodiments of the present disclosure;
[0018] Figure 3 A schematic diagram of another network access process provided for some embodiments of the present disclosure;
[0019] Figure 4 A schematic diagram of a network access method provided for some embodiments of the present disclosure;
[0020] Figure 5 A schematic diagram of a control plane architecture provided for some embodiments of the present disclosure;
[0021] Figure 6 A schematic diagram of a network access apparatus provided for some embodiments of the present disclosure;
[0022] Figure 7 A schematic diagram of an electronic device provided for some embodiments of the present disclosure. DETAILED DESCRIPTION
[0023] Embodiments of the present disclosure will be described in more detail with reference to the drawings. While certain embodiments of the present disclosure will be shown in the drawings and described below, it will be understood that the present disclosure can be embodied in various forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete, and fully convey the scope of the present disclosure to those skilled in the art. It should be understood that the drawings and embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure.
[0024] It should be understood that each of the steps in the method embodiments of the present disclosure can be performed in a different order and / or in parallel. In addition, the method embodiments can include additional steps and / or omit performing the steps shown. The scope of the present disclosure is not limited in this respect.
[0025] The term "comprising" and variations thereof as used herein are open-ended, and mean "including but not limited to". The term "based on" means "based, at least in part, on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Related terms are defined in the description that follows.
[0026] It should be noted that the terms "first", "second", and the like mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not intended to limit the order or interdependence of the functions performed by these devices, modules or units.
[0027] It should be noted that the terms "one", "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that "one or more" should be understood unless otherwise explicitly indicated in the context.
[0028] The names of the messages or information exchanged between the plurality of devices in the embodiments of the present disclosure are only for illustrative purposes, and are not intended to limit the scope of the messages or information.
[0029] In a cloud computing scenario such as a container orchestration platform, uniform static network isolation of application programs can be achieved, but in this isolation mode, in order to ensure the normal use of the application program, the access range needs to be set for the entire application program according to the maximum access range required by the container group in the application program. For example, if there is a container group in the application program that needs to access the external network, the entire application program needs to be allowed to access the external network, and the security of the application program is very low. Or, in order to ensure the security of the application program, the application program can be prohibited from accessing the external network, but at this time the container group that actually has external network access demand in the application program cannot run normally, and the application program also cannot run normally. Or, the entire application program can be allowed to access the external network, and the container groups in the application program can communicate in an encrypted manner. However, the additional overhead of this method is too large, which affects the normal operation of the application program.
[0030] In summary, there is an urgent need for a method that improves the security of application program network access while ensuring the normal operation of the application program.
[0031] In order to solve the above problems, the present disclosure provides a network access method, which will be introduced below in combination with specific embodiments.
[0032] Figure 1 A flowchart of a network access method provided by some embodiments of the present disclosure is shown. The method can be executed by a network access device, and the method can also be executed by a system for managing network access of a target application. The device can be implemented by software and / or hardware, and can be integrated in an electronic device. As shown in the figure, the method includes the following steps. Figure 1
[0033] Step 101, obtaining a network access request of a target container group, wherein the target container group belongs to a target workgroup, and the target workgroup includes at least one container group of the same function of a target application program.
[0034] The target application can be an application (APP) in which the target workgroup is located, and the target application can include one or more workgroups. The application can be a distributed application in model as a service, or the application can be an application deployed based on a custom resource definition (CRD). Alternatively, the application can be an application for processing related data based on a generative model, or the application can be an application for training a generative model. The embodiments do not limit the type of generative model, for example, the generative model can include one or more of a graph-to-text model, a graph reasoning model, a text-to-graph model, a text-to-text model, and a large language model. The large language model can be a natural language processing model that learns the rules, structures, etc. of natural language, understands the meaning of natural language, and generates coherent text with correct grammar and semantics based on the understood meaning.
[0035] The target workgroup can be a workgroup in which the target container group is located, and the target workgroup can include only the target container group, or the target workgroup can include the target container group and one or more container groups having the same function as the target container group. The workgroup can be a collection of container groups divided according to the functions of the container groups, and the workgroup can be the smallest unit for network access policy management in the embodiments of the present disclosure. For example, a workgroup can be a workgroup having a text-to-graph function. It can be understood that if an application is used to implement a task and the task includes multiple subtasks, the container groups in a workgroup in the application can be used to implement the same subtask. The target container group can be a container group currently performing network access, and the target container group can be the initiator of network access or the receiver of network access. The embodiments do not limit the target container group. The container group can be the smallest scheduling and management unit in container technology. The network access request can be a request for network access from the container group to the outside of the container group. The network access request can be initiated by the target container group to the outside of the target container group, or the network access request can be initiated by the outside of the target container group to the target container group. The embodiments do not limit the network access request.
[0036] In some embodiments of the present disclosure, the target application includes multiple workgroups corresponding to multiple functions, and each workgroup includes at least one container group having the same function. In the embodiments, if the target application corresponds to a task, the implementation of the task can be achieved through the cooperation of multiple subtasks, the subtasks can correspond to functions, the target application can correspond to multiple functions, each function can correspond to a workgroup, and the target application can correspond to multiple workgroups. In addition, each workgroup includes one or more container groups. Figure 2This is a schematic diagram of a network access process provided in some embodiments of this disclosure, such as... Figure 2 As shown, visual language model applications can correspond to dialogue management functions, decoding-driven functions, and fill-in-the-blank functions. Dialogue management functions can be implemented through the dialogue management container group in the dialogue management workgroup, decoding-driven functions can be implemented through the decoding-driven container group in the decoding-driven workgroup, and fill-in-the-blank functions can be implemented through the fill-in-the-blank container group in the fill-in-the-blank workgroup.
[0037] Understandably, the structure of container groups within the same application is relatively complex. These container groups can communicate with each other, but the network access requirements of each container group are not the same. For container groups within the same application, one or more container groups can be divided into corresponding workgroups based on their functions. A workgroup includes container groups with the same functions. In this embodiment of the disclosure, a target container group in the target application generates a network access request during operation. The target container group can generate and send a network access request, which is then acquired by a network access device. Alternatively, a network access request for the target container group can be generated on the network, and the network access device acquires this request.
[0038] like Figure 2 As shown, the control plane of the Virtual Private Cloud (VPC) can interact with the data planes of both the Region 1 VPC and the Region 2 VPC. Each data plane can be understood as a cluster. The custom resource visual language model application can be deployed on the data planes of both the Region 1 and Region 2 VPCs. In the Region 1 VPC data plane, the visual language model application includes three different workgroups. The corresponding container groups for these three workgroups can be a dialogue processing container group, a decoding driver container group, and a pre-filling driver container group. The dialogue processing container group can receive requests from outside the data plane and connect to external networks to download images or connect to internal networks to perform resource statistics. The decoding driver container group or the pre-filling container group can receive requests from the dialogue processing container group and process tokens.
[0039] Step 102: Determine the target network access policy corresponding to the target workgroup.
[0040] The target network access policy can be the network access policy on which the target workgroup performs network access, and the target network access policy can characterize the network access scope of the container group in the target workgroup.
[0041] In the embodiments of the present disclosure, different container groups can have corresponding network access requirements, and different work groups can have corresponding network access policies. The network access device can determine the target network access policy in various ways, which are not limited in the embodiments. For example, the network access device can obtain the relationship between the work group and the network access policy configured by the administrator, and query the relationship according to the target work group to determine the target network access policy corresponding to the target work group. Alternatively, when the work group is configured with a network isolation label, the network access device can determine the target network access policy according to the network isolation label.
[0042] In some embodiments of the present disclosure, before determining the target network access policy, the network access device can add a corresponding network isolation label to the work group. Specifically, the network access method further includes: in response to a creation operation of a target application program, adding corresponding network isolation labels to a plurality of work groups included in the target application program based on the network isolation relationship library.
[0043] The creation operation can be an operation of creating a target application program, and the creation operation can also include an initial creation of a network access policy. The network access policy is used to specify the network access range or the network isolation range of a work group, and can limit the access object by setting the received entry access range and the sent exit access range. The access object can include at least one of an external network object, an interactive object of a target container group outside the container orchestration platform, and an internal object of the container orchestration platform. The network access policy can be understood as a network access standard, and the network access policy can include an Internet Protocol (IP) address, a Port, and / or an IP address of a network request initiated by a container group for network access, a Port, and / or an IP address of network access received by a container group.
[0044] Optionally, the network isolation relationship library includes a plurality of network access policies and a plurality of network isolation labels having a mapping relationship. Each network access policy has a mapping relationship with a network isolation label. The network isolation label can be used to identify the network isolation level. In the embodiments, the network isolation relationship library can be a database recording the network isolation relationship. The network access policy recorded in the network isolation relationship library can be set according to user demand, which is not limited in the embodiments. One network isolation relationship can be a mapping relationship between one network access policy and one network isolation label. The network access policy and the network isolation label can be one-to-one.
[0045] Optionally, the network isolation tag comprises a plurality of levels, and network isolation tags of different levels correspond to network access policies of different isolation degrees, and the higher the level, the higher the isolation degree of the corresponding network access policy. The level can be a level divided inside the network isolation tag. The isolation degree can represent the isolation degree of the container group and the access object in the network environment. The number of the plurality of levels can be set according to the network environment, user demand, etc., and the embodiment is not limited.
[0046] For example, the plurality of levels can include low, medium, next high, and highest. The network access policy corresponding to the low level can be that there is no network isolation, that is, the container groups in the task group can arbitrarily access each other with network resources; the network access policy corresponding to the medium level can control the ability to access external network objects in the external network of the control plane, the interactive objects of the target container group outside the container orchestration platform, and the internal objects of the container orchestration platform; the network access policy corresponding to the next high level can control the ability to access the interactive objects of the target container group outside the container orchestration platform and the internal objects of the container orchestration platform; and the network access policy corresponding to the highest level can control the ability to access the internal objects of the container orchestration platform or the container groups with the same namespace as the container group and the same application program inside the cluster. The network access policy corresponding to the highest level is the most stringent network access policy, which can be understood as a board isolation policy.
[0047] In the embodiment, the user can perform a creation operation on the target application program, and the network access device creates the target application program in response to the creation operation. In the process of dynamically creating the target application program, the network access device can assign a unique application program identifier (app-id) to the target, and the embodiment does not limit the specific creation method of the target application program. In addition, the network access device can also initialize and create the network isolation relationship library in response to the creation operation, and display the network isolation relationship library to the administrator. The administrator can determine the network access policy adapted to each workgroup in the network isolation relationship library, and perform a tag adding operation on the workgroup according to the network isolation tag corresponding to the network access policy. The network isolation device adds the network isolation tag to the corresponding workgroup in response to the tag adding operation. The tag adding operation can be an operation of adding a network isolation tag, and the embodiment does not limit the tag adding operation.
[0048] For example, for a distributed application in model as a service, different workgroups in the distributed application can be set with corresponding network access policies, thereby effectively reducing the attack surface of network attacks. If the distributed application includes workgroup A, workgroup B, and workgroup C. The network access policy adapted by workgroup A determined by the administrator can be to access external network objects, the network access policy adapted by workgroup B can be to access interactive objects, and the network access policy adapted by workgroup C can be to accept network access sent by container groups in workgroup A and workgroup B. For example, Figure 2 For example, in the data plane of the regional 2 virtual private cloud, the network access policy of the workgroup where the conversation processing container group is located can be to access external network objects, interactive objects, and internal objects. And the network access policies of the decoding driver container group and the pre-filled driver container group are to access internal objects.
[0049] In the above scheme, when creating a target application program, the network isolation tags of the workgroups in the target application program are determined, the network access policies corresponding to the workgroups are briefly represented by the tags, and efficient configuration of the network access policies is achieved.
[0050] In some embodiments of the present disclosure, determining a target network access policy corresponding to a target workgroup includes: obtaining a target network isolation tag corresponding to the target workgroup, and determining a network access policy corresponding to the target network isolation tag as the target network access policy.
[0051] The target network isolation tag can be a network isolation tag corresponding to the target workgroup, and the target network isolation tag can be used to identify the network isolation level corresponding to the target workgroup.
[0052] In this embodiment, the network access device can determine the target network isolation tag configured by the target workgroup, and perform a query operation on the network isolation relationship library according to the target network isolation tag to determine the target network access policy corresponding to the target network access policy. Therefore, the network access policy corresponding to the workgroup is accurately and efficiently determined based on the network isolation tag, and the network access policy can be reused multiple times based on the network isolation tag, thereby saving human resources consumed by repeatedly setting the same network access policy.
[0053] Step 103, if it is determined that the target access object corresponding to the network access request matches the target network access policy, performing an access operation between the target container group corresponding to the network access request and the target access object, wherein the target access object includes at least one of an external network object, an interactive object of a target container group outside the container orchestration platform, and an internal object of the container orchestration platform.
[0054] The target access object can be an object that performs network interaction with the target container group. In some embodiments of the present disclosure, the target access object includes an ingress access object or an egress access object. The ingress access object can be an object that initiates a network access request. The egress access object can be an object that receives a network access request, which can be understood as an object that is accessed. The access operation can be an access operation between the target container group and the target access object. The access operation can include an operation in which the target container group accesses the target access object, or an operation in which the target access object accesses the target container group. The Extranet object can be an object located in an external network, which can be a network outside the container orchestration platform where the target container group is located, and can be understood as the Internet or an open network that allows public access, which is also referred to as the Extranet.
[0055] The interactable object of the target container group outside the container orchestration platform can be an object that does not belong to the management range of the container orchestration platform where the target container group is located, but can interact with the target container group in some way. For example, the interactable object can include resources, servers, or databases in the same Virtual Private Cloud (VPC) as the target container group outside the container orchestration platform. The interactable object can be an object that is pre-divided for the target container group outside the container orchestration platform, for example, the interactable object can be an object in a specific intranet outside the container orchestration platform. The present embodiment does not limit the functions implemented by the interactable object, for example, the interactable object can be used to implement auditing services, Video on Demand (VOD) services, etc. Based on the interactable object, the range of network access to objects outside the container orchestration platform can be controlled while the network access is implemented.
[0056] The internal object of the container orchestration platform can be an object located in an Intranet of the container orchestration platform, which can be a network environment constructed in the container orchestration platform. The present embodiment does not limit the internal object, for example, Figure 3 Another schematic diagram of a network access process provided by some embodiments of the present disclosure is shown in FIG. 6. The internal object can be a Model Proxy in Figure 3 The target container group can interact with the Model Proxy.
[0057] In the embodiments of the present disclosure, after determining the target network access policy, the network access device can perform an access operation between the target container group and the target access object according to a network location where the target access object corresponding to the network access request is located, if the network location matches the target network access policy. If the network location does not match the target network access policy, the network access device can reject the access operation between the target container group and the target access object.
[0058] In some embodiments of the present disclosure, determining that the target access object corresponding to the network access request matches the target network access policy includes: matching object information of the target access object corresponding to the network access request with entry access information and exit access information included in the target network access policy; and if the matching result is that the object information of the target access object is included in the entry access information or the exit access information, determining that the target access object matches the target network access policy.
[0059] The object information can be used to record a network location where the target access object is located, and the object information can include an Internet protocol address, a port, and the like of the network location where the target access object is located. The entry access information can be used to record a receiving range when the target container group receives a network access, and can be understood as a range of external access that the target container group can receive. The exit access information can be used to record an access range when the target container group performs a network access to the outside, and can be understood as a range of access that the target container group can initiate to the outside.
[0060] In the present embodiment, the network access device can determine object information of the target access object according to the network access request. If the network access request is received by the target container group, the network access device can match the object information with the entry access information. If the object information is included in the entry access information, it is determined that the target access object matches the target network access policy successfully. If the object information is not included in the entry access information, it is determined that the target access object matches the target network access policy unsuccessfully. If the network access request is sent by the target container group, the network access device can match the object information with the exit access information. If the object information is included in the exit access information, it is determined that the target access object matches the target network access policy successfully. If the object information is not included in the exit access information, it is determined that the target access object matches the target network access policy unsuccessfully.
[0061] In the above scheme, for different scenarios of initiating a network access request and receiving a network access request by the target container group, whether the target access object matches the corresponding network access policy is determined through corresponding access information, so that the network access method can cover multiple network scenarios of initiating a request and receiving a request.
[0062] In some embodiments of the present disclosure, the access operation between the target container group corresponding to the network access request and the target access object is performed, including: when the network access request is from the entry access object, the network access request is sent to the target container group to perform the access operation of the entry access object; when the network access request is from the target container group, the network access request is sent to the exit access object to perform the access operation of the target container group.
[0063] In the present embodiment, after determining that the object information of the target access object is included in the entry access information, if the network access request is sent from the entry access object to the target container group, the network access request is sent to the target container group to realize the access operation of the entry access object to the target container group. After determining that the object information of the target access object is included in the exit access information, if the network access request is sent from the target container group to the exit access object, the network access request is sent to the exit access object to realize the operation of the target container group to the exit access object. Thus, the execution of the access operation is realized in the case that the network access strategy allows the network access.
[0064] As shown in Figure 3 , the graph-to-text application and the text-to-graph application can be deployed through the custom resource. The deployed application programs such as the graph-to-text application and the text-to-graph application can receive or send traffic to the model agent, and the model agent can be the control plane. The graph-to-text application can include a graph-to-text workgroup and a corresponding inference workgroup, the graph-to-text workgroup includes a graph-to-text container group, and the inference workgroup includes multiple inference container groups. The text-to-graph application can include a text-to-graph workgroup and a corresponding inference workgroup, the text-to-graph workgroup includes a text-to-graph container group, and the inference workgroup includes multiple inference container groups. In addition, other custom resource applications or deployment applications can be used to provide headless inference services, the other custom resource applications or deployment applications include an inference workgroup, and the inference workgroup includes multiple inference container groups, and the inference container groups can directly receive traffic from the model agent. In addition, if there are multiple application programs, the container groups in different application programs do not directly communicate, for example, the container groups in the graph-to-text application do not directly communicate with the container groups in the text-to-graph application, that is, there is network isolation between the two kinds of container groups.
[0065] And, Figure 3The network isolation tags corresponding to the Chinese-to-text workgroup and the text-to-graph workgroup can be intermediate, and the network isolation tags corresponding to the inference container group can be the highest. Inside the same application program, a dynamic isolation strategy can be used to pass through the traffic between the internal container groups, where passing through can be understood as allowing the transmission of traffic. Specifically, the network access device can add an application program identifier to all container groups under the same application program instance, the application program identifiers of the container groups of the same application program are the same, and the network intercommunication of the container groups of the same application program can be realized based on the application program identifier.
[0066] The network access scheme provided by the embodiments of the present disclosure provides a network access request of a target container group, wherein the target container group belongs to a target workgroup, and the target workgroup includes at least one container group of the same function of a target application program; a target network access strategy corresponding to the target workgroup is determined; if it is determined that a target access object corresponding to the network access request matches the target network access strategy, an access operation between the target container group corresponding to the network access request and the target access object is performed, wherein the target access object includes at least one of an external network object, an interactive object of a target container group outside the container orchestration platform, and an internal object of the container orchestration platform. By using the above technical solution, the network access request of the target container group in the target workgroup of the target application program is allowed to access when the network access strategy corresponding to the target workgroup matches the target access object corresponding to the target access request. By dividing the container groups with the same function in the same application program into corresponding workgroups and setting different network access strategies for different workgroups, since the network access strategy can control the access of the external network object, the interactive object, and / or the internal object, the network access management with different isolation degrees of finer granularity is realized inside the application program, which can meet the actual access needs of different container groups and also guarantee the security of network access. In addition, the granularity of network access control is finer than the application program and coarser than the container group, so that the security in the network access process is efficiently guaranteed while meeting the normal network access needs of the application program at a proper granularity, and the network security of the target application program is improved based on smaller resource consumption.
[0067] In the embodiments of the present disclosure, different workgroups of the same application program are provided with corresponding network access strategies. However, communication needs to be performed between different workgroups. For example, if there are workgroup A and workgroup B in the application program, the network access strategy of workgroup A includes access to external network objects, and workgroup B does not have the access right. However, workgroup B can communicate with workgroup A, and although theoretically workgroup B can access external network objects through workgroup A. However, from an engineering perspective, only when workgroup A and workgroup B are both attacked, the controlled external network access can be performed, and the security of network access is improved compared with the related art. In addition, for this case, the network access device can limit the access operation of workgroup A through network detection and the like, and further reduce the risk of network access.
[0068] In some embodiments of the present disclosure, the network access method further includes: performing network access detection and / or label anomaly detection on a target application program to-be-detected container group, wherein the to-be-detected container group belongs to a to-be-detected workgroup, and the to-be-detected workgroup corresponds to a network access strategy supporting access to external network objects and interactive objects.
[0069] The detection program can be used to detect whether the to-be-detected container group is abnormal. The to-be-detected workgroup can be a workgroup containing the to-be-detected container group. The to-be-detected container group can be a container group to be detected for network access and / or label anomaly detection. The to-be-detected container group can be a container group authorized to access external network objects and interactive objects.
[0070] The network access detection can be used to detect whether the network access process of the to-be-detected container group is abnormal. This embodiment does not limit the abnormal access, for example, the abnormal access can include one or more of access to an abnormal Internet protocol address, access to an abnormal port, and access to an abnormal resource. Taking the abnormal access as access to an abnormal resource as an example, the network access detection can determine whether the type of the resource transmitted in the access process belongs to a target type. The target type can be the type of the resource transmitted in the actual running of the to-be-detected container group. The actual running can be understood as the running of the to-be-detected container group without security anomalies. This embodiment does not limit the resource type, for example, the resource type can include pictures, videos, audios, and the like. Taking the to-be-detected container group as a visual language model container group as an example, the target type corresponding to the visual language model container group can be a picture type. Through the network access detection, it can be detected whether the traffic sent and / or received by the to-be-detected container group is abnormal.
[0071] In this embodiment, the network access device can perform network access detection on the to-be-tested container group through the detection program, and if the network access detection is not passed, an abnormal network access warning is issued. Specifically, taking detection of access to abnormal resources as an example, the network access device can detect whether the resource type of the resource transmitted in the actual running process of the to-be-tested container group belongs to the target type, and if yes, it is determined that the to-be-tested container group passes the network access detection, otherwise, it is determined that the to-be-tested container group fails to pass the network access detection, and a corresponding warning is issued. For example, the target type corresponding to the visual language model container group can be a picture type, and if the resource type of the resource transmitted by the visual language model container group is not a picture type, it is determined that the container group fails to pass the network access detection.
[0072] The label anomaly detection can be used to detect whether the access range corresponding to the network isolation label of the to-be-tested working group matches the target access range, and the target access range can be the network range required to be accessed in the actual running process of the to-be-tested container group in the to-be-tested working group. Through the label anomaly detection, closer detection can be performed on the to-be-tested working group that supports access to external network objects and / or interactive objects.
[0073] In this embodiment, the network access device can perform label anomaly detection on the to-be-tested container group through the detection program, and if the network access detection is not passed, an abnormal label warning is issued. Specifically, the network access device can detect whether the access range of the network isolation label corresponding to the to-be-tested container group belongs to the target access range, and if yes, it is determined that the to-be-tested container group passes the label anomaly detection, otherwise, it is determined that the to-be-tested container group fails to pass the label anomaly detection, and a corresponding warning is issued. For example, for a container group that implements pure reasoning, access to internal objects can meet the access requirements of the normal running of the to-be-tested container group, and thus the corresponding target access range can be internal objects. If the access range corresponding to the network isolation label includes interactive objects or external network objects, it is determined that the to-be-tested container group fails to pass the label anomaly detection. Thus, it is determined through detection whether the network isolation label is added according to the actual needs of the to-be-tested working group.
[0074] Optionally, the network access device can also perform detection analysis on the traffic data sent by the to-be-tested container group through the data loss prevention program.
[0075] Figure 4 A schematic diagram of a network access method provided by some embodiments of the present disclosure is as follows, Figure 4As shown, first, the network isolation relationship library of the target application is initialized. Specifically, the network isolation relationship library can be preconfigured with a correspondence between network access policies and network isolation labels, which can include levels such as low, medium, sub-high, high, and the like. Further, the corresponding network isolation labels are added to the workgroups in the target application program, realizing the configuration of the corresponding network for different workgroups. Further, after the target application program is deployed, the network access policies of each workgroup in the target application program take effect. Specifically, the detection program detects the to-be-detected container group in the application program, which includes: detecting the network access of the container group corresponding to the medium network isolation label and the sub-high network isolation label; detecting whether the medium network isolation label and the sub-high network isolation label are incorrectly identified on the to-be-detected workgroup; logging the operation of the network isolation label, and periodically automatically detecting or manually detecting the log. Further, the application program is terminated, which can be understood as the destruction of the application program.
[0076] In the above scheme, the network behavior of the container group in the workgroup with a relatively loose network isolation degree is detected through network access detection, and the risk caused after the container group is broken into is traced back in a timely manner. Through label anomaly detection, the network isolation label of the workgroup is effectively and dynamically detected, and the probability of abuse of the network isolation label with a relatively loose network isolation is reduced. Moreover, the change of the network isolation label is recorded in the security log, so that the change of the network isolation label can be traced back.
[0077] Next, the network access method in the embodiments of the present disclosure will be further described through a specific example. The application program of the network access method can provide corresponding services based on the control plane, Figure 5 An architecture schematic diagram of a control plane is provided for some embodiments of the present disclosure. The model of the data plane can be a service, realizing model as a service. The data plane can mainly undertake large models of various model providers, and then provide inference, fine-tuning and other services using these models. Essentially, model as a service is platform as a service (PaaS).
[0078] Among them, the data plane depends on infrastructure as a service (IaaS), and the data plane can have a corresponding software stack. The software stack can be deployed as a service container group on the governed cloud server (ECS) node, and will be scheduled according to the scheduler in response to the scheduling of the user. Figure 5There are multiple user pod groups (User Pod) and service pod groups (Service Pod) in the middle cloud server virtual machine (Elastic Compute Service Virtual Machine, ECS VM).
[0079] Generally, the related tasks of model as a service can be divided into inference tasks and training tasks (for example, dynamic fine-tuning tasks), etc. There are three roles in the task, namely, cloud service providers, model providers, and users.
[0080] Specifically, the cloud service provider provides cloud services (for example, infrastructure as a service or platform as a service) to serve different entities of model providers. The model provider owns a large model and uses the cloud service provider to build its own inference task and other services. The user runs the application provided by the cloud service provider and the model provider. The user has corresponding network environment isolation requirements for the model provider and the cloud service provider. Specifically, when the user obtains model as a service from the cloud service provider, the user hopes that his task can run in a secure sandbox or an isolated network environment. The secure sandbox can achieve security enhancement from the aspects of computing, network, storage, etc. The secure sandbox can be designed based on the protection mechanism of privacy or confidential computing. The network access method provided by the embodiments of the present disclosure can be applied in the secure sandbox.
[0081] In some embodiments of the present disclosure, the network access method can include: first, for a distributed application of model as a service, setting corresponding network access strategies for different work groups in the application, thereby effectively reducing the attack surface. For example, if the application includes three work groups, work group A, work group B, and work group C. Work group A can access external network objects, work group B can access interactive objects, and work group C can receive network access from work group A and work group B. Specifically, a plurality of network access strategies can be predefined, and when the application is started, the work group is configured with a corresponding network isolation label. For different network isolation labels, corresponding network access strategies are provided.
[0082] Further, the container groups in the work group with the middle-level network isolation label and the container groups in the work group with the next-high-level network isolation label are detected more closely. Specifically, it can be detected whether the above-mentioned container groups have abnormal traffic, and the traffic of the above-mentioned container groups is detected by a data loss prevention program.
[0083] Further, in the container orchestration platform, it is detected whether the work groups of each application program add network isolation labels according to the corresponding requirements of the work groups. If an abnormal network isolation label is found, the network isolation label is timely alarmed and processed.
[0084] The network access scheme provided in this disclosure, based on network isolation between container groups of different applications, allows for more granular network access policy settings for workgroups within a single application, resulting in high network security for the application during normal operation. Furthermore, while meeting the needs of Model-as-a-Service (MAS) in update and iteration dimensions, it still provides a high level of network isolation protection, preventing user data from being leaked outside the security sandbox and improving network security.
[0085] Figure 6 This is a schematic diagram of the structure of a network access device provided in some embodiments of this disclosure. This device can be implemented by software and / or hardware and is generally integrated into an electronic device. For example... Figure 6 As shown, the device includes:
[0086] The acquisition module 601 is used to acquire network access requests for a target container group, wherein the target container group belongs to a target workgroup, and the target workgroup includes at least one container group with the same function of the target application.
[0087] The determining module 602 is used to determine the target network access policy corresponding to the target workgroup;
[0088] The execution module 603 is configured to execute an access operation between the target container group and the target access object corresponding to the network access request if it is determined that the target access object corresponding to the network access request matches the target network access policy. The target access object includes at least one of an external network object, an interactive object of the target container group outside the container orchestration platform, and an internal object of the container orchestration platform.
[0089] In some embodiments of this disclosure, the target application includes multiple workgroups corresponding to multiple functions, each workgroup includes at least one container group with the same function, and the network access device further includes:
[0090] An add module is used to add corresponding network isolation tags to multiple workgroups included in the target application in response to the creation operation of the target application, based on the network isolation relation library.
[0091] In some embodiments of this disclosure, the network isolation relationship library includes multiple network access policies and multiple network isolation labels with mapping relationships, wherein each network access policy has a mapping relationship with one of the network isolation labels.
[0092] In some embodiments of the present disclosure, the network isolation label comprises a plurality of levels, and different levels of the network isolation label correspond to network access policies of different isolation degrees, and the higher the level is, the higher the isolation degree of the corresponding network access policy is.
[0093] In some embodiments of the present disclosure, the determining module 602 specifically comprises:
[0094] The target network isolation label corresponding to the target workgroup is acquired, and a network access policy corresponding to the target network isolation label is determined as a target network access policy.
[0095] In some embodiments of the present disclosure, the determination that the target access object corresponding to the network access request matches the target network access policy comprises:
[0096] The object information of the target access object corresponding to the network access request is matched with ingress access information and egress access information included in the target network access policy.
[0097] If the matching result is that the object information of the target access object is included in the ingress access information or the egress access information, it is determined that the target access object matches the target network access policy.
[0098] In some embodiments of the present disclosure, the target access object comprises an ingress access object or an egress access object, and the execution of an access operation between the target container group corresponding to the network access request and the target access object comprises:
[0099] When the network access request comes from the ingress access object, the network access request is sent to the target container group to execute the access operation of the ingress access object.
[0100] When the network access request comes from the target container group, the network access request is sent to the egress access object to execute the access operation of the target container group.
[0101] In some embodiments of the present disclosure, the network access device further comprises:
[0102] The detecting module is configured to perform network access detection and / or label anomaly detection on a to-be-detected container group of the target application program, wherein the to-be-detected container group belongs to a to-be-detected workgroup, and the to-be-detected workgroup corresponds to a network access policy supporting access to external network objects and interactive objects.
[0103] The network access device provided in the embodiments of the present disclosure can execute the network access method provided in any of the embodiments of the present disclosure, and has the corresponding function modules and beneficial effects of the execution method.
[0104] The embodiment of the present disclosure provides a computer program product comprising computer programs / instructions which, when executed by a processor, implement the steps of the network access method described above.
[0105] Figure 7 A structural diagram of an electronic device provided by some embodiments of the present disclosure is shown.
[0106] Reference will now be made in detail to Figure 7 which shows a structural diagram of an electronic device 700 suitable for use in implementing embodiments of the present disclosure. The electronic device 700 in embodiments of the present disclosure can include, but is not limited to, a mobile terminal such as a mobile phone, a notebook computer, a digital broadcast receiver, a PDA (Personal Digital Assistant), a PAD (Tablet Personal Computer), a PMP (Portable Multimedia Player), a car terminal (e.g., a car navigation terminal), and the like, as well as a stationary terminal such as a digital TV, a desktop computer, and the like. Figure 7 The electronic device shown is merely an example and should not impose any limitation on the functions and use range of embodiments of the present disclosure.
[0107] As shown in Figure 7 , the electronic device 700 can include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 701 which can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 702 or loaded from a storage device 708 into a random access memory (RAM) 703. Various programs and data required for the operation of the electronic device 700 are also stored in the RAM 703. The processing device 701, the ROM 702, and the RAM 703 are connected to each other through a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0108] Generally, the following devices can be connected to the I / O interface 705: an input device 706 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, and the like; an output device 707 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, and the like; a storage device 708 including, for example, a magnetic tape, a hard disk, and the like; and a communication device 709. The communication device 709 can allow the electronic device 700 to communicate wirelessly or by wire with other devices to exchange data. Although Figure 7 The electronic device 700 is shown with various devices, but it should be understood that all of the devices shown are not required, and that more or fewer devices can alternatively be implemented.
[0109] In particular, according to embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as a computer software program. For example, embodiments of the present disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for executing the methods illustrated by the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network by the communication device 709, or installed from the storage device 708, or installed from the ROM 702. When the computer program is executed by the processing device 701, the above-mentioned functions defined in the network access method of the embodiments of the present disclosure are executed.
[0110] It should be noted that the computer-readable medium described above in the present disclosure can be a computer-readable signal medium or a computer-readable storage medium or any combination thereof. The computer-readable storage medium may, for example, be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or apparatus, or any suitable combination thereof. More specific examples of the computer-readable storage medium can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus, or device. In the present disclosure, the computer-readable signal medium can include a data signal propagated in a baseband or as a carrier wave in a propagated data signal, in which a computer-readable program code is carried. Such a propagated data signal can take many forms, including but not limited to, an electromagnetic signal, an optical signal, or any suitable combination thereof. The computer-readable signal medium can also be any computer-readable medium that is not a computer-readable storage medium and that can be used to carry or store a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained in the computer-readable medium can be transmitted by any suitable medium, including but not limited to, a wire, an optical fiber, an RF (radio frequency) or the like, or any suitable combination thereof.
[0111] In some embodiments, the client, server, or other computing machines utilized by the embodiments can communicate over any current known or future developed network protocol, such as the HyperText Transfer Protocol (HTTP), and can be interconnected with any form or medium of digital data communication (for example, a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), the Internet, and peer-to-peer networks (for example, ad hoc peer-to-peer networks), as well as any current known or future developed network.
[0112] The computer-readable medium described above can be included in the electronic device described above; alternatively, the computer-readable medium can exist as a standalone entity.
[0113] The computer-readable medium described above carries one or more programs that, when executed by the electronic device, cause the electronic device to: acquire a network access request of a target container group, wherein the target container group belongs to a target workgroup, and the target workgroup includes at least one container group of the same function of a target application program; determine a target network access policy corresponding to the target workgroup; and if it is determined that a target access object corresponding to the network access request matches the target network access policy, perform an access operation between the target container group corresponding to the network access request and the target access object, wherein the target access object includes at least one of an external network object, an interactable object of the target container group outside a container orchestration platform, and an internal object of the container orchestration platform.
[0114] Computer program code for carrying out operations of the present disclosure can be written in any of one or more programming languages, including but not limited to object oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network ("LAN") or a wide area network ("WAN"), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0115] The computer program product of the first aspect can include one or more non-transitory computer-readable media storing instructions that, when executed, cause one or more processors to perform the operations of the method of the first aspect. The computer program product of the first aspect can include a computer-readable medium storing instructions that, when executed, cause one or more processors to perform the operations of the method of the first aspect.
[0116] The units described in the embodiments of the present disclosure can be implemented by software, or by hardware, or by a combination of software and hardware. In some cases, the names of the units do not constitute a limitation on the units themselves.
[0117] The functions described in this document can be implemented in part or in whole in hardware, firmware, software, or any combination thereof. For example, one or more hardware logic components can be used to perform the functions. Examples of hardware logic components can include programmable logic devices, application-specific integrated circuits, and the like. With software, implementing the functions can be stored as one or more instructions on a non-transitory computer-readable medium such as RAM memory, flash memory, ROM memory, EEP ROM memory, registers, or a remote storage device.
[0118] In the context of the present disclosure, a machine-readable medium can be a tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include but is not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium can include a tangible, non-transitory memory, such as one or more of a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0119] It can be understood that, before using the technical solutions disclosed in the embodiments of the present disclosure, the type of information involved in the present disclosure, the use range, the use scenario, etc. should be informed to the user and the authorization of the user should be obtained through appropriate means according to relevant laws and regulations.
[0120] The above description is merely the preferred embodiments of the present disclosure and the explanation of the applied technical principles. It should be understood by those skilled in the art that the disclosed scope of the present disclosure is not limited to the technical solutions formed by the specific combinations of the above technical features, and should also cover other technical solutions formed by the combinations of the above technical features or their equivalent features without departing from the above disclosed concept. For example, the technical solutions formed by the mutual replacement of the above features and the technical features disclosed in the present disclosure (but not limited to) having similar functions.
[0121] In addition, although each operation is described in a particular order, this should not be understood as requiring the operations to be performed in the specific order shown or in a sequential order. In certain circumstances, multitasking and parallel processing can be advantageous. Similarly, although several implementation details are included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Certain features described in the context of separate embodiments can also be combined in a single embodiment. Conversely, various features described in the context of a single embodiment can also be implemented separately or in any suitable subcombination in multiple embodiments.
[0122] Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.
Claims
1. A network security access method applied to a large model service, characterized in that, The method comprises: obtaining a network access request of a target container group, the network access request being a request for the target container group to access a network outside the target container group, wherein the target container group belongs to a target work group, and the target work group comprises at least one container group of the same function of a target application program; determining a target network access policy corresponding to the target work group, the target network access policy representing a network access range of the container groups in the target work group; if it is determined that a target access object corresponding to the network access request matches the target network access policy, performing an access operation between the target container group corresponding to the network access request and the target access object, wherein the target access object comprises at least one of an external network object, an interactable object of the target container group outside a container orchestration platform, and an internal object of the container orchestration platform.
2. The method of claim 1, wherein, The target application program comprises a plurality of work groups corresponding to a plurality of functions, and each work group comprises at least one container group of the same function. The method further comprises: in response to a creation operation of the target application program, adding corresponding network isolation labels to the plurality of work groups included in the target application program based on a network isolation relationship library.
3. The method of claim 2, wherein, The network isolation relationship library comprises a plurality of network access policies and a plurality of network isolation labels having a mapping relationship, and each network access policy has a mapping relationship with a network isolation label.
4. The method of claim 2, wherein, The network isolation labels comprise a plurality of levels, and different levels of network isolation labels correspond to network access policies of different isolation degrees, and the higher the level, the higher the isolation degree of the corresponding network access policy.
5. The method of claim 2, wherein, Determining the target network access policy corresponding to the target work group comprises: obtaining a target network isolation label corresponding to the target work group, and determining a network access policy corresponding to the target network isolation label as the target network access policy.
6. The method of claim 1, wherein, Determining that the target access object corresponding to the network access request matches the target network access policy comprises: matching object information of the target access object corresponding to the network access request with entry access information and exit access information included in the target network access policy; if the matching result is that the object information of the target access object is included in the entry access information or the exit access information, it is determined that the target access object matches the target network access policy.
7. The method of claim 1, wherein, The target access object comprises an entry access object or an exit access object, and the execution of the access operation between the target container group corresponding to the network access request and the target access object comprises: when the network access request comes from the entry access object, sending the network access request to the target container group to perform the access operation of the entry access object; when the network access request comes from the target container group, sending the network access request to the exit access object to perform the access operation of the target container group.
8. The method of claim 1, wherein, The method further comprises: The target application program is detected container group is carried out network access detection and / or label exception detection, wherein the container group to be detected belongs to the working group to be detected, and the working group to be detected corresponds to the network access policy supporting access to external network objects and interactive objects.
9. A network security access device applied to a large model service, characterized in that, Comprise: The acquisition module is used for acquiring the network access request of the target container group, and the network access request is the request of the target container group and the outside of the target container group for network access, wherein the target container group belongs to the target working group, and the target working group comprises at least one container group of the same function of the target application program; The determination module is used for determining the target network access policy corresponding to the target working group, and the target network access policy represents the network access range of the container group in the target working group; The execution module is used for if it is determined that the target access object corresponding to the network access request matches the target network access policy, executing the access operation between the target container group corresponding to the network access request and the target access object, wherein the target access object comprises at least one of the external network object, the interactive object of the target container group outside the container orchestration platform and the internal object of the container orchestration platform.
10. An electronic device, comprising: The electronic device comprises: A processor; A memory for storing executable instructions of the processor; The processor is used for reading the executable instructions from the memory and executing the instructions to realize the network security access method applied to the large model service in any one of the above claims 1-8.
11. A computer readable storage medium, characterized in that, The storage medium stores a computer program, and the computer program is used for executing the network security access method applied to the large model service in any one of the above claims 1-8.
Citation Information
Patent Citations
Container environment safety protection method, device and equipment and storage medium
CN116015875A
Network access method, device, equipment and medium
CN119071071A