Multi-dimensional constrained security service chain dynamic mapping system and method

Through the multi-dimensional constraints of security service chain dynamic mapping system, the security service chain and resource allocation are dynamically adjusted, which solves the problem that VSF placement in the existing technology fails to fully consider multi-dimensional constraints, and realizes efficient, flexible and secure service chain configuration, reducing operating costs and improving system stability.

CN119814470BActive Publication Date: 2025-05-09QI AN XIN TECHNOLOGY GROUP INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510272074.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-10
Publication Date
2025-05-09
Estimated Expiration
2045-03-10

AI Technical Summary

Technical Problem

The prior art fails to fully consider multi-dimensional constraints such as business type, security equipment capabilities, and security rules when placing virtual security functions (VSFs), resulting in low resource utilization, high operating costs, and insufficient system security and stability.

Method used

A multi-dimensional constraint dynamic mapping system for security service chains is proposed, including model matching unit, resource construction unit, solution deployment unit and solution optimization unit. By dynamically adjusting the security service chain, optimizing resource allocation according to changes in real-time business traffic and resource requirements, ensuring strict compliance with security rule constraints.

Benefits of technology

It realizes more efficient, flexible and secure service chain configuration, improves resource utilization, reduces operating costs, and improves the security and stability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119814470B_ABST
    Figure CN119814470B_ABST
Patent Text Reader

Abstract

A multi-dimensionally constrained security service chain dynamic mapping system and method, input user business configuration and business traffic type of a physical machine to be configured, determine a security service chain; establish static resource constraints for virtual security functions according to resource requirements of different virtual security functions; establish dynamic resource constraints for virtual security functions according to business traffic type of the physical machine to be configured and resource requirements of different virtual security functions that change with traffic; construct a multi-dimensionally constrained security service chain deployment algorithm to obtain a deployment plan for the security service chain on the underlying physical service node; check security dependency constraints, and optimize and adjust the deployment plan for the security service chain on the underlying physical service node. The present invention dynamically adjusts the security service chain to avoid waste of resources and improve utilization; dynamically adjusts the deployment plan according to real-time business traffic and resource demand changes to ensure the success rate of physical deployment; optimizes resource allocation, reduces hardware overhead, and reduces operating costs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cloud computing security services, and in particular to a system and method for dynamically mapping a security service chain with multi-dimensional constraints. Background Art

[0002] Security Service Chain (SSC) is a variety of virtual security services linked in a certain order by NFV / SDN controllers. The process of security service chaining usually includes two steps: first, instantiate the required virtualized security functions (VSFs) on general hardware devices through NFV technology; then, in order to meet the user's requirements for the order of security functions, use SDN technology to direct traffic to different VSFs in a certain order. Compared with traditional security solutions, the security functions provided by SSC are not only more flexible and scalable, but can also be dynamically migrated with cloud services according to demand.

[0003] The first key step to implement a security service chain (SSC) is to deploy its virtualized security function (VSF) on the underlying physical resources, which is called VSF placement. Since VSF is a special type of virtual network function (VNF), VSF placement can be regarded as a special case of VNF placement. VSF placement, like VNF placement, also includes two parts: mapping of VSFs, and mapping of virtual links between VSFs. In addition, the goal of VSF placement is to minimize resource consumption or achieve overall load balancing, which is also the usual goal of VNF placement. There are still some major differences between VSF placement and VNF placement, which are also the focus of current research work. The first is the reachability issue. VNF placement usually does not consider the reachability between physical nodes, which means that traffic from one node can reach any other node in the same connected network. However, in the SDN environment where SSC works, due to the complexity of flow table entries of SDN switches, traffic from one node may not be able to reach another node even if they are in the same connected network. The second difference between VSF placement and VNF placement is the policy conflict issue. VNF placement usually focuses on how to improve resource utilization without considering the policies and policy conflicts of VNFs. However, VSF placement must consider both policy conflicts and resource utilization. This is because VSF needs to process received packets according to specific security policies, which may conflict with the forwarding policies of the underlying SDN switches.

[0004] Existing security service chains and virtual security function placement methods are used in relatively static cloud computing scenarios, without considering constraints such as business types, security equipment capabilities, and security rules in real scenarios. Although current research focuses on issues such as resource utilization, it is insufficient in terms of VSF placement and business model adaptation, resource consumption coordination, and comprehensive modeling.

[0005] Therefore, the problems existing in the prior art need to be further improved and developed. Summary of the invention

[0006] (I) Purpose of the invention: In order to solve the problems existing in the above-mentioned prior art, the purpose of the present invention is to provide a multi-dimensional constrained security service chain dynamic mapping system and method to solve the problems existing in VSF placement in the prior art, achieve more efficient, flexible and secure service chain configuration, improve resource utilization, reduce operating costs, and enhance system security and stability.

[0007] (II) Technical solution: In order to solve the above technical problems, the present technical solution provides a multi-dimensional constrained security service chain dynamic mapping system, including a model matching unit, a resource construction unit, a solution deployment unit and a solution optimization unit; the model matching unit determines the security service chain according to the user business configuration and business traffic type of the input physical machine to be configured;

[0008] The resource construction unit includes a static resource construction module and a dynamic resource construction module; the static resource construction module establishes static resource constraints for virtual security functions according to resource requirements of different virtual security functions; the dynamic resource construction module obtains dynamic resource constraints for virtual security functions according to the service traffic type of the physical machine to be configured and the resource requirements of different virtual security functions that change with traffic;

[0009] The solution deployment unit constructs a multi-dimensionally constrained security service chain deployment algorithm according to the dynamic resource constraints of the virtual security functions of the physical machine to be configured, and obtains a deployment solution of the security service chain on the underlying physical service node;

[0010] The solution optimization unit checks the security dependency constraints and optimizes and adjusts the deployment solution of the security service chain on the underlying physical service node.

[0011] Preferably, the model matching unit comprises a display input module, through which the user service configuration and service flow of the physical machine to be configured are input to the model matching unit of the multi-dimensional constrained security service chain dynamic mapping system;

[0012] The model matching unit obtains the business model of the physical machine to be configured according to the input user business configuration and business flow, and constructs the logic of the security service chain.

[0013] Preferably, the physical resource constraint sets corresponding to the three physical resource constraints are: , and ,in for , The unit is MB. The unit is GB;

[0014] The static resource constraints required for a specific VSF to run successfully on a physical node are defined as a triple {VC, VM, VD}, where the value range of VC is {0, 1}, the unit of VM is MB, and the unit of VD is GB;

[0015] When an unloaded VSF can be deployed on a physical node When on, meet: .

[0016] Preferably, the dynamic resource constraints of the virtual safety function depend on a time point.

[0017] Preferably, the dynamic resource constraints for a particular VSF are defined as a triple ,in The value range of is {0,1}, The unit is MB. The unit is GB. According to the service deployment parameters or SLA agreement, the value of the resources that the VSF needs to provide under the maximum traffic condition is calculated;

[0018] Therefore, when a VSF is not included in the static resource constraints, it is deployed on a physical node under the maximum deployment bandwidth condition. When on, meet: .

[0019] Preferably, software-defined network technology is used to ensure cloud computing by establishing a dynamically programmable software-defined network and using switch rules to form a data plane traffic plan that complies with security dependency constraints.

[0020] Preferably, the traffic path across physical nodes generated by the security service chain deployment algorithm is the shortest.

[0021] Preferably, the VSF resource constraints to be deployed are: ,in, ;

[0022] From all existing physical nodes, select a set of physical machines C that can simultaneously meet the CPU, memory and other resources required by VSF;

[0023] If the physical machine set C is empty, it means that all current physical nodes cannot accommodate the VSF, and you need to open a physical node or return the service chain deployment failure; if you open a new physical node, initialize its available resources to the initial capacity of the physical node and add it to the physical node resource set;

[0024] If the physical machine set C is not empty, then for each physical node , calculate the deployment fitness parameters and the number of traffic paths across physical nodes : .

[0025] Preferably, among all candidate physical nodes, The lower the value, the higher the priority. The deployment strategy with the lowest value as the second priority selects the physical node and Deployed on superior;

[0026] Update and optimize the physical node resource collection: .

[0027] The multi-dimensional constrained security service chain dynamic mapping method is applicable to the multi-dimensional constrained security service chain dynamic mapping system, specifically including:

[0028] Step 1: Enter the user service configuration and service traffic type of the physical machine to be configured, and determine the security service chain;

[0029] Step 2: Establish static resource constraints for virtual security functions based on resource requirements of different virtual security functions;

[0030] Step 3: According to the business traffic type of the physical machine to be configured and the resource requirements of different virtual security functions that change with the traffic, the dynamic resource constraints of the virtual security functions are obtained;

[0031] Step 4: According to the dynamic resource constraints of the virtual security functions of the physical machine to be configured, a multi-dimensionally constrained security service chain deployment algorithm is constructed to obtain a deployment plan for the security service chain on the underlying physical service node;

[0032] Step 5: Check security dependency constraints and optimize the deployment plan of the security service chain on the underlying physical service nodes.

[0033] (III) Beneficial effects: The present invention provides a multi-dimensional constrained security service chain dynamic mapping system and method. First, by dynamically adjusting the security service chain, the system takes full account of changes in business traffic and resource requirements, avoids waste of resources, and improves the utilization rate of physical servers. Secondly, the system dynamically adjusts the deployment plan according to changes in real-time business traffic and resource requirements, and strictly abides by security rules and constraints, effectively ensuring the success rate of SSC physical deployment. Finally, by optimizing resource allocation, it reduces unnecessary hardware overhead, waste of resources, and frequent migration of virtual VSFs, thereby reducing the operating cost of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 It is a structural schematic diagram of the multi-dimensional constrained security service chain dynamic mapping system of the present invention;

[0035] Figure 2 It is a flowchart of the steps of the dynamic mapping method of the multi-dimensionally constrained security service chain of the present invention;

[0036] Figure 3 The following are schematic diagrams of two deployment schemes for security service chains. DETAILED DESCRIPTION

[0037] The present invention is further described in detail below in conjunction with preferred embodiments. More details are elaborated in the following description to facilitate a full understanding of the present invention. However, the present invention can obviously be implemented in a variety of other ways different from the description. Those skilled in the art can make similar generalizations and deductions based on actual application situations without violating the connotation of the present invention. Therefore, the protection scope of the present invention should not be limited by the content of this specific embodiment.

[0038] The accompanying drawings are schematic diagrams of embodiments of the present invention. It should be noted that the drawings are only examples and are not drawn to scale, and should not be used to limit the actual protection scope of the present invention.

[0039] A dynamic mapping system for security service chains with multi-dimensional constraints, such as Figure 1 As shown, it includes a model matching unit, a resource construction unit, a solution deployment unit and a solution optimization unit. The model matching unit includes a display input module, the display input module inputs the user service configuration and service traffic type of the physical machine to be configured; the model matching unit determines the security service chain according to the input user service configuration and service traffic type of the physical machine to be configured.

[0040] The resource construction unit includes a static resource construction module and a dynamic resource construction module; the static resource construction module establishes static resource constraints for virtual security functions according to resource requirements of different virtual security functions. The dynamic resource construction module obtains dynamic resource constraints for virtual security functions according to the service traffic type of the physical machine to be configured and the resource requirements of different virtual security functions that change with traffic.

[0041] The solution deployment unit constructs a multi-dimensionally constrained security service chain deployment algorithm according to the dynamic resource constraints of the virtual security functions of the physical machine to be configured, and obtains a deployment solution for the security service chain on the underlying physical service node.

[0042] The solution optimization unit checks the security dependency constraints and optimizes and adjusts the deployment solution of the security service chain on the underlying physical service node.

[0043] The multi-dimensional constrained security service chain dynamic mapping method is applicable to the multi-dimensional constrained security service chain dynamic mapping system, such as Figure 2 As shown, the specific steps include:

[0044] Step 1: Enter the user service configuration and service traffic type of the physical machine to be configured, and determine the security service chain.

[0045] Step 2: Establish static resource constraints for virtual security functions based on resource requirements of different virtual security functions.

[0046] Step 3: According to the business traffic type of the physical machine to be configured and the resource requirements of different virtual security functions that change with the traffic, the dynamic resource constraints of the virtual security functions are obtained.

[0047] Step 4: According to the dynamic resource constraints of the virtual security functions of the physical machine to be configured, a multi-dimensional constrained security service chain deployment algorithm is constructed to obtain a deployment plan for the security service chain on the underlying physical service node.

[0048] Step 5: Check security dependency constraints and optimize the deployment plan of the security service chain on the underlying physical service nodes.

[0049] More specifically, the step 1 specifically includes:

[0050] The model matching unit includes a display input module, through which manual input is performed and displayed. The display input module can be an electronic display screen, a liquid crystal display screen, etc., and is not specifically limited here.

[0051] The user business configuration and business flow of the physical machine to be configured are input into the model matching unit of the multi-dimensional constrained security service chain dynamic mapping system through the display input module. The model matching unit obtains the business model of the physical machine to be configured based on the input user business configuration and business flow, thereby constructing the logic of the security service chain.

[0052] The business model of the physical machine to be configured refers to the business specifically deployed on the cloud, such as cloud storage, portal site, or audio and video business.

[0053] The Security Service Chain (SSC) is composed of a set of ordered VSF (Virtual Security Function) instances. The set of virtual security functions in the security service chain is .

[0054] The virtual security function is a security service form that uses virtualization technology software to deploy traditional network security devices or functions (such as firewalls, intrusion detection systems, VPN gateways, etc.) in general hardware or container environments. Table 1 shows common VSF device examples.

[0055] Table 1 Common VSF devices

[0056]

[0057] More specifically, the step 2 specifically includes:

[0058] According to the security capability type of the physical machine to be configured, a static resource constraint of the virtual security function is established. The static resource constraint of the virtual security function reflects the basic resource requirements of the VSF, thereby affecting the static resource dependency of the deployed physical machine.

[0059] Cloud computing physical nodes form an interconnected physical network using an undirected graph Among them, the physical node set where the VSF virtual network security function node can be placed .

[0060] Before deploying on a physical node, the virtual security function VSF needs to consider whether the resources of different underlying physical nodes meet the operating resource requirements, such as CPU, memory, and disk. That is, the minimum resource requirement of VSF cannot exceed the upper limit of the available resources of a physical node. Therefore, three physical resource constraints are mainly considered, namely CPU utilization, available memory capacity, and available disk capacity. The corresponding physical resource constraint sets are expressed as , and ,in The value range is , The unit is MB. The unit is GB.

[0061] Different types of VSFs have different functions, which are reflected in the significant differences in the consumption of memory, CPU and disk resources. The qualitative analysis is shown in Table 2. Therefore, the static resource constraints required for a specific VSF to run successfully on a physical node are defined as a triple {VC, VM, VD}. Similarly, the value range of VC is {0, 1}, the unit of VM is MB, and the unit of VD is GB.

[0062] Table 2 Virtual security function types and resource consumption

[0063]

[0064] Therefore, the static resource constraints of the virtual security function are as shown in formula (1). When an unloaded (i.e., unconfigured) VSF can be deployed on a physical node When you are on the Internet, you must meet the following requirements:

[0065] (1).

[0066] More specifically, the step 3 is as follows:

[0067] According to the business traffic type of the physical machine to be configured and the static resource constraints of the virtual security function, the dynamic resource constraints of the virtual security function of the physical machine to be configured are established. The dynamic resource constraints of the virtual security function mainly consider that when different business traffic is configured on a time scale, it will depend on the time point, thereby affecting the dynamic resource dependency of the deployed physical machine.

[0068] In cloud computing, different types of businesses often show periodic changes in requests or traffic. The so-called "periodicity" can be either daily peaks and troughs, or regular fluctuations during a week, a quarter, or certain holidays or commercial promotions. For example, general users have fixed routines, so different time periods, such as early morning, daytime or nighttime, will show obvious differences in visit volume; e-commerce sites will see a sharp increase in traffic in a short period of time during large promotional nodes, such as "Double Eleven", "618" or holidays, while the overall level is relatively low during weekday nights or non-promotional periods; the game business is relatively busy on weekends and holidays, but relatively less in the early morning or during weekdays.

[0069] Therefore, since the resource consumption of virtual security functions by requests or traffic of different magnitudes varies continuously, it is very likely that resource preemption or resource exhaustion will occur on the running physical nodes, thus affecting the normal operation of all virtual security functions on the physical nodes and causing the deployment of the security service chain to fail. Therefore, the dynamic resource constraint of a specific VSF is defined as a triple .in The value range of is {0,1}, The unit is MB. The unit is GB.

[0070] Obviously, These are dynamically changing values, and their values ​​are closely related to the requests or traffic that are occurring. The determination is based on the worst case estimate, that is, the maximum bandwidth allocated to the service Specifically, before deploying different types of services, according to the service deployment parameters or SLA (Service Level Agreement) agreement, the value of the resources that VSF needs to provide under the maximum traffic is calculated to ensure that the deployment of the security service chain can run effectively on the underlying physical nodes under the maximum bandwidth allocated by the service.

[0071] Therefore, the dynamic resource constraint of the virtual security function is as shown in formula (2). When a VSF is not included in the static resource constraint, it can be deployed on a physical node under the condition of maximum deployment bandwidth. When you are on the Internet, you must meet the following requirements:

[0072] (2).

[0073] More specifically, step 4 specifically includes:

[0074] A multi-dimensionally constrained security service chain deployment algorithm is constructed to solve a deployment solution that can be used for the underlying physical service nodes. The deployment of the security service chain must meet security dependency constraints to ensure that data flows pass through multiple virtual security functions in order. At the same time, network topology constraints require that traffic transmission across physical nodes be minimized to reduce bandwidth usage.

[0075] The security service chain is a specific function combination with sequential dependencies constructed by a series of virtual security functions according to the generation logic to ensure that data and network traffic are fully protected in the cloud environment. This chain structure means that before the data flow reaches the final destination, it must pass through multiple virtual security functions in the agreed order to ensure that each virtual security function can detect or filter specific potential threats, that is, meet specific order constraints. In actual deployment, the combination of virtual security functions requires, on the one hand, the selection of specific function combinations for actual business traffic, and on the other hand, it is necessary to ensure that the processing of actual business traffic complies with security dependency constraints so as to ensure the effectiveness of the overall security function. According to different business needs, the design of the security service chain is generally different, because each business has different requirements for security, performance, and traffic processing. As shown in Table 3, some typical business scenarios and their corresponding security service chains, that is, security service chains are closely related to specific businesses. In other words, during physical deployment, the constructed security service chain deployment algorithm also needs to meet security dependency constraints.

[0076] Table 3 Common SSC examples

[0077]

[0078] Usually, software-defined networking (SDN) technology is used to ensure this in cloud computing, that is, by establishing a dynamically programmable software-defined network and using switch rules to form a data plane traffic plan that complies with security dependency constraints. However, using SDN technology alone will lead to a potential problem, causing business traffic to be transmitted across physical nodes unnecessarily, thereby causing additional bandwidth usage. Figure 3As shown in the figure, for the security service chain A → B → C, the security service chain deployment scheme 2 is better than the security service chain deployment scheme 1. The reason is that for the same service traffic, under the condition of satisfying the security constraints, the security service chain deployment scheme 1 needs to be transmitted back and forth between physical nodes twice, resulting in additional traffic transmission across physical nodes, while the security service chain deployment scheme 2 only needs one transmission across physical nodes. Therefore, the network topology constraint requires that the traffic path across physical nodes generated by the security service chain deployment algorithm is the shortest, that is, the fewer traffic paths across physical nodes generated by the security service chain deployment algorithm, the better.

[0079] More specifically, step 5 specifically includes:

[0080] The VSF deployment problem is abstractly defined as deploying all VSF instances in a specific security service chain on multiple underlying physical nodes in sequence, while ensuring resource requirements and satisfying multi-dimensional constraints, improving the overall utilization of the security service chain deployment and minimizing resource fragmentation and the number of physical machines used. However, considering the multi-dimensional resource constraints, a simple single-dimensional "packaging" strategy is not enough to meet actual needs. Therefore, it is necessary to optimize and adjust according to the actual usage.

[0081] The VSF deployment algorithm has the following characteristics:

[0082] The deployment of VSFs needs to be placed in the order of specific security service chains. It is impossible to predict other security service chain deployment requests in advance, and it is impossible to pre-sort all VSFs to be deployed. Therefore, the VSF deployment algorithm needs to be completed online.

[0083] VSF deployment complies with atomicity, that is, resource requirements are indivisible, and all resources required by VSF, such as CPU, memory, and hard disk, must be met before they can be deployed on a physical machine.

[0084] The VSF deployment algorithm should minimize the number of physical machines used, or deploy as many VSFs as possible on a fixed number of physical machines.

[0085] Therefore, the online VSF deployment algorithm of the present invention is designed using the heuristic Best-Fit strategy, that is, all physical machines that can accommodate the VSF in the security service chain to be deployed are evaluated, and the "most suitable" physical machine for VSF is selected. For multi-dimensional resources, "most suitable" can be understood as minimizing the gap between the remaining resources and the VSF requirements and minimizing the number of traffic paths across physical nodes to reduce resource fragmentation and improve resource utilization.

[0086] The core logic of the VSF online heuristic deployment solution is as follows:

[0087] The physical node resource set is: (3).

[0088] VSF to be deployed , whose resource constraints are: ,in,

[0089] (4).

[0090] Among all existing physical nodes, select a set C of physical machines that can simultaneously meet the CPU, memory, etc. required by VSF.

[0091] If the physical machine set C is empty, it means that all current physical nodes cannot accommodate the VSF, and you need to open a physical node or return the service chain deployment failure. If you open a new physical node, initialize its available resources to the initial capacity of the physical node and add it to the physical node resource set.

[0092] If the physical machine set C is not empty, then for each physical node , calculate a deployment fitness parameter and the number of traffic paths across physical nodes :

[0093] (5).

[0094] Among all candidate physical nodes, The lower the value, the higher the priority. The deployment strategy with the lowest value as the second priority selects the physical node and Deployed on superior.

[0095] Update and optimize the physical node resource collection, namely:

[0096] (6).

[0097] The multi-dimensionally constrained security service chain dynamic mapping system and method of the present invention firstly dynamically adjusts the service chain, fully considers the changes in business flow and resource requirements, avoids resource waste, and improves the utilization rate of physical servers. Secondly, according to the changes in real-time business flow and resource requirements, the deployment plan is dynamically adjusted, and the security rule constraints are strictly observed, effectively ensuring the success rate of SSC physical deployment. Finally, by optimizing resource allocation, unnecessary hardware overhead, resource waste and frequent migration of virtual VSF are reduced, thereby reducing the operating cost of the system.

[0098] The above content is an explanation of the preferred embodiments of the present invention, which can help those skilled in the art to more fully understand the technical solution of the present invention. However, these embodiments are merely illustrative, and it cannot be determined that the specific implementation methods of the present invention are limited to the description of these embodiments. For ordinary technicians in the technical field to which the present invention belongs, without departing from the concept of the present invention, several simple deductions and transformations can be made, which should be regarded as belonging to the protection scope of the present invention.

Claims

1. A multi-dimensional constrained security service chain dynamic mapping system, characterized by: It includes a model matching unit, a resource construction unit, a solution deployment unit and a solution optimization unit; the model matching unit determines the security service chain according to the user business configuration and business traffic type of the input physical machine to be configured; The resource construction unit includes a static resource construction module and a dynamic resource construction module; the static resource construction module establishes static resource constraints for virtual security functions according to resource requirements of different virtual security functions; the dynamic resource construction module obtains dynamic resource constraints for virtual security functions according to the service traffic type of the physical machine to be configured and the resource requirements of different virtual security functions that change with traffic; The solution deployment unit constructs a multi-dimensionally constrained security service chain deployment algorithm according to the dynamic resource constraints of the virtual security functions of the physical machine to be configured, and obtains a deployment solution of the security service chain on the underlying physical service node; The solution optimization unit checks the security dependency constraints and optimizes and adjusts the deployment solution of the security service chain on the underlying physical service node.

2. The multi-dimensional constrained security service chain dynamic mapping system according to claim 1 is characterized in that: The model matching unit includes a display input module, through which the user service configuration and service flow of the physical machine to be configured are input to the model matching unit of the multi-dimensional constrained security service chain dynamic mapping system; The model matching unit obtains the business model of the physical machine to be configured according to the input user business configuration and business traffic, and constructs the logic of the security service chain.

3. The multi-dimensional constrained security service chain dynamic mapping system according to claim 1 is characterized in that: The physical resource constraint sets corresponding to the three physical resource constraints are: , and ,in The value range is , The unit is MB. The unit is GB; the three physical resource constraints are CPU utilization, memory available capacity and disk available capacity; The static resource constraints required for a specific VSF to run successfully on a physical node are defined as a triple {V C ,V M ,V D }, where V C The value range is {0,1}, V M The unit is MB, V D The unit is GB; When an unloaded VSF can be deployed on a physical node When on, meet: .

4. The multi-dimensional constrained security service chain dynamic mapping system according to claim 1 is characterized in that: The dynamic resource constraints of virtual security functions depend on the time point.

5. The multi-dimensional constrained security service chain dynamic mapping system according to claim 3 or 4, characterized in that: The dynamic resource constraints of a specific VSF are defined as a triple { },in The value range of is {0,1}, The unit is MB. The unit is GB. According to the service deployment parameters or SLA agreement, the value of the resources that the VSF needs to provide under the maximum traffic condition is calculated; Therefore, when a VSF is not included in the static resource constraints, it is deployed on a physical node under the maximum deployment bandwidth condition. When on, meet: .

6. The multi-dimensional constrained security service chain dynamic mapping system according to claim 1 is characterized in that: In cloud computing, software-defined network technology is used to ensure this by establishing a dynamically programmable software-defined network and using switch rules to form a data plane traffic plan that complies with security dependency constraints.

7. The multi-dimensional constrained security service chain dynamic mapping system according to claim 6 is characterized in that: The security service chain deployment algorithm produces the shortest traffic path across physical nodes.

8. The multi-dimensional constrained security service chain dynamic mapping system according to claim 1 is characterized in that: The VSF resource constraints to be deployed are: ,in, ; From all existing physical nodes, select a set of physical machines C that can simultaneously meet the CPU, memory, and disk resources required by VSF; If the physical machine set C is empty, it means that all current physical nodes cannot accommodate the VSF, and you need to open a physical node or return the service chain deployment failure; if you open a new physical node, initialize its available resources to the initial capacity of the physical node and add it to the physical node resource set; If the physical machine set C is not empty, then for each physical node , calculate the deployment fitness parameters and the number of traffic paths across physical nodes : .

9. The multi-dimensional constrained security service chain dynamic mapping system according to claim 8 is characterized in that: Among all candidate physical nodes, The lower the value, the higher the priority. The deployment strategy with the lowest value as the second priority selects the physical node and Deployed on superior; Update and optimize the physical node resource collection: .

10. A method for dynamic mapping of a security service chain with multi-dimensional constraints, applicable to a dynamic mapping system for a security service chain with multi-dimensional constraints, characterized in that: Specifically include: Step 1: Enter the user service configuration and service traffic type of the physical machine to be configured, and determine the security service chain; Step 2: Establish static resource constraints for virtual security functions based on resource requirements of different virtual security functions; Step 3: According to the business traffic type of the physical machine to be configured and the resource requirements of different virtual security functions that change with the traffic, the dynamic resource constraints of the virtual security functions are obtained; Step 4: According to the dynamic resource constraints of the virtual security functions of the physical machine to be configured, a multi-dimensionally constrained security service chain deployment algorithm is constructed to obtain a deployment plan for the security service chain on the underlying physical service node; Step 5: Check security dependency constraints and optimize the deployment plan of the security service chain on the underlying physical service nodes.

Citation Information

Patent Citations

  • Method for constructing safety service of reconfigurable network

    CN104092668A

  • Network safety service architecture based on safety service chain and realization method thereof

    CN108881207A