An Infrastructure as Code Implementation Method for a Secure Resource Pool
Through the infrastructure as code method, the configuration of the security resource pool is automatically managed, and the complexity of security resource pool settings and management is solved, rapid failure response and configuration rollback are achieved, and the management efficiency and failure recovery capabilities of the security resource pool are improved.
Patent Information
- Application Number
- CN202411817779.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-11
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2044-12-11
AI Technical Summary
In the prior art, the setup and management process of the security resource pool is manual and complex, inefficient and high error rate, making it difficult to deal with complex cyber attacks and security risks.
The Infrastructure as Code (IaC) method is adopted to obtain the infrastructure configuration of the secure resource pool and save it to the version control system to achieve automated management, including the coordinated work of the configuration management module and the infrastructure as code module, supporting configuration version control and rollback.
It realizes automated management of the security resource pool, can quickly roll back to the pre-failure state, supports restoration and recovery plan verification at the fault site, and improves the fault response capability and configuration management efficiency of the security resource pool.
Smart Images

Figure CN119847671B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of computer network security, and particularly relates to a method for implementing Infrastructure as Code (IaC) of a security resource pool. Background Art
[0002] A security resource pool is to use server virtualization technology to run various security components in the form of virtual machines on a host server, and build a proprietary resource pool for outputting security capabilities externally. We can generally understand the security resource pool as a small data center, which includes: computing resources (CPU and memory), network resources (virtualized network switches), storage resources (virtualized shared storage), and security resources (virtualized security network elements). Through the security resource pool technology, various resources are organically integrated together.
[0003] According to the 2023 Thales Data Threat Report, 55% of the organizations that suffered data breaches reported "human error" as the main cause. This situation has been further exacerbated as organizations now face increasingly complex attacks from cybercriminals using various automated tools. As organizations move more of their operations to the cloud, they must also become increasingly aware of the security risks and threats that come with it. Simply having a set of policies that human operators must follow is no longer enough. Traditionally, setting up and managing IT infrastructure is a manual and complex process that is often inconsistent and inefficient due to human error. Therefore, more proactive and automated strategies or methods must be implemented to avoid the above problems.
[0004] The present invention proposes a method for implementing Infrastructure as Code (IaC) of a security resource pool. Infrastructure as Code is a method that draws on code management practices in the software development process and manages infrastructure in a form similar to code management. Summary of the Invention
[0005] (1) Technical Problems to be Solved
[0006] The technical problem to be solved by the present invention is how to provide a method for implementing Infrastructure as Code of a security resource pool to solve the problems that setting up and managing IT infrastructure is a manual and complex process with low efficiency and high error rate.
[0007] (2) Technical Solutions
[0008] To solve the above technical problems, the present invention proposes a method for implementing Infrastructure as Code of a security resource pool, and the method includes the following steps:
[0009] S1. Obtain the infrastructure configuration of the security resource pool and save it to a version control system;
[0010] S2. Load the configuration of the security resource pool from the version control system and deploy it to the security resource pool.
[0011] Further, the S1 specifically includes:
[0012] Step S11. Configure in the security resource pool interface;
[0013] Step S12. The configuration management module sends the configuration to the network elements in the security resource pool;
[0014] Step S13. The configuration management module saves the configuration;
[0015] Step S14. The infrastructure as code module obtains the network element configuration files and topology connection relationship configurations with configuration changes;
[0016] Step S15. The infrastructure as code module saves the complete configuration files and topology connection relationship configurations after the network element changes to the version control system.
[0017] Further, the security resource pool includes: network elements, a configuration management module, an infrastructure as code module, and a version control system.
[0018] Further, the configuration management module reads the configurations of the network elements in the security resource pool, is also used to send the configuration to the network elements, and saves the configuration.
[0019] Further, the infrastructure as code module describes the infrastructure as code text and executes the saving and rollback of network element configurations and topology relationships.
[0020] Further, the version control system is used to save the historical configurations of the network elements. The security resource pool saves the configuration files of all the network elements it contains and the topology connection relationships between the network elements in text form to the version control system.
[0021] Further, the security resource pool further includes a code comparison tool, which is used to compare the configurations of the security resource pool at different time points to check what changes have occurred.
[0022] Further, the S2 specifically includes the following steps:
[0023] Step S21. Select at what time point in the security resource pool interface to roll back the configuration and execute the rollback operation;
[0024] Step S22. The infrastructure as code module pulls the configuration files and topology connection relationship configurations of the network elements on the specified date from the version control system and sends them to the configuration management module;
[0025] Step S23. The configuration management module sends the configuration to the network elements in the security resource pool;
[0026] Step S24: The configuration management module saves the configuration.
[0027] Further, in step S21, either a specific network element is selected to perform a rollback or the entire security resource pool is selected for rollback.
[0028] Further, in step S21, after a failure occurs in the security resource pool, a certain point in time before the failure is selected for rollback.
[0029] (III) Beneficial effects
[0030] The present invention proposes a method for implementing infrastructure as code for a security resource pool. After the infrastructure as code is implemented in the security resource pool, the security resource pool will have the ability to perform rollbacks for specific network elements and for the entire security resource pool, thereby supporting the security resource pool to quickly stop losses after a failure occurs. At the same time, the security resource pool can also rely on this ability to conveniently restore the fault scene and verify the fault recovery plan in subsequent fault drills.
[0031] The security resource pool adopting the infrastructure as code implementation method can obtain the following benefits:
[0032] 1. It helps to roll back the security resource pool to the state before the failure occurs.
[0033] 2. It can restore the security resource pool to the configuration state at a specified time.
[0034] 3. It can conveniently use a code comparison tool to compare the security resource pool configurations at different time points to see what changes have occurred. Description of the drawings
[0035] Figure 1 It is the infrastructure preservation process of the security resource pool of the present invention;
[0036] Figure 2 It is the infrastructure recovery process of the security resource pool of the present invention. Detailed implementation manners
[0037] To make the objectives, contents, and advantages of the present invention clearer, the following further describes in detail the specific implementation manners of the present invention with reference to the drawings and embodiments.
[0038] Using the infrastructure as code module, the security resource pool can save the configuration files of all network elements it contains and the topological connection relationships between network elements in text form to a version control system, forming an infrastructure configuration library of the security resource pool.
[0039] IaC: Infrastructure as Code (Infrastructure as Code)
[0040] The present invention discloses a method for implementing infrastructure as code for a security resource pool, including two processes:
[0041] S1. Obtain the infrastructure configuration of the security resource pool and save it to the version control system;
[0042] S2. Load the configuration of the security resource pool from the version control system and deploy it to the security resource pool.
[0043] (1). The process of obtaining the infrastructure configuration of the security resource pool and saving it to the version control system is as follows (the flowchart is as Figure 1 shown):
[0044] Step S11. Configure on the security resource pool interface;
[0045] Step S12. The configuration management module sends the configuration to the network elements in the security resource pool;
[0046] Step S13. The configuration management module saves the configuration;
[0047] The security resource pool includes: network elements, a configuration management module, an infrastructure as code module, and a version control system;
[0048] The configuration management module is used to read the configuration of the network elements in the security resource pool, and is also used to send the configuration to the network elements and save the configuration;
[0049] The infrastructure as code module is used to describe the infrastructure as code text, and execute the saving and rollback of network element configuration and topological relationship;
[0050] The version control system is used to save the historical configuration of the network elements; the security resource pool can save the configuration files of all the network elements it contains and the topological connection relationships between the network elements in text form to the version control system.
[0051] Step S14. The infrastructure as code module obtains the network element configuration files with configuration changes and the topological connection relationship configuration;
[0052] Step S15. The infrastructure as code module saves the complete network element configuration file after change and the topological connection relationship configuration to the version control system.
[0053] Furthermore, the security resource pool further includes a code comparison tool, which is used to compare the configurations of the security resource pool at different time points to check what changes have occurred.
[0054] (2). The process of loading the configuration of the security resource pool from the version control system and deploying it to the security resource pool is as follows (the flowchart is as Figure 2 shown):
[0055] Step S21: Select the time point to which the configuration is to be rolled back on the security resource pool interface and perform the rollback operation;
[0056] Furthermore, select specific network elements to perform the rollback;
[0057] Furthermore, select the entire security resource pool for rollback.
[0058] Furthermore, after a failure occurs in the security resource pool, select a time point before the failure for rollback.
[0059] Step S22: The infrastructure-as-code module pulls the configuration file and topology connection relationship configuration of the network elements on the specified date from the version control system and sends them to the configuration management module;
[0060] Step S23: The configuration management module issues the configuration to the network elements in the security resource pool;
[0061] Step S24: The configuration management module saves the configuration.
[0062] After the infrastructure-as-code is implemented in the security resource pool in the present invention, the security resource pool will have the ability to perform rollback for specific network elements and for the entire security resource pool, thereby supporting the security resource pool to quickly stop losses after a failure occurs. At the same time, the security resource pool can also rely on this ability to conveniently restore the fault scene and verify the fault recovery plan in subsequent fault drills.
[0063] The security resource pool adopting the infrastructure-as-code implementation method can obtain the following benefits:
[0064] 1. It helps to roll back the security resource pool to the state before the failure occurs when a failure occurs;
[0065] 2. It can restore the security resource pool to the configuration state at the specified time;
[0066] 3. It can conveniently use a code comparison tool to compare the security resource pool configurations at different time points to check what changes have occurred.
[0067] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and deformations can be made, and these improvements and deformations should also be regarded as the protection scope of the present invention.
Claims
1. A method for implementing infrastructure as code for a secure resource pool, characterized in that, The method includes the following steps: S1. Obtain the infrastructure configuration of the security resource pool and save it to the version control system; S2. Load the configuration of the security resource pool from the version control system and deploy it to the security resource pool; Wherein, The specific steps of S1 include: Step S11. Configure on the security resource pool interface; Step S12. The configuration management module sends the configuration to the network elements in the security resource pool; Step S13. The configuration management module saves the configuration; Step S14. The infrastructure-as-code module obtains the network element configuration files and topology connection relationship configurations with configuration changes; Step S15. The infrastructure-as-code module saves the complete configuration files and topology connection relationship configurations after the network element changes to the version control system; The specific steps of S2 include the following steps: Step S21. Select the time point to which the configuration is to be rolled back on the security resource pool interface and perform the rollback operation; Step S22. The infrastructure-as-code module pulls the configuration files and topology connection relationship configurations of the network elements on the specified date from the version control system and sends them to the configuration management module; Step S23. The configuration management module sends the configuration to the network elements in the security resource pool; Step S24. The configuration management module saves the configuration.
2. The infrastructure as code implementation method of the security resource pool according to claim 1, characterized in that, The security resource pool includes: network elements, a configuration management module, an infrastructure-as-code module, and a version control system.
3. The infrastructure as code implementation method of the security resource pool according to claim 2, characterized in that, The configuration management module reads the configurations of the network elements in the security resource pool, is also used to send the configuration to the network elements, and saves the configuration.
4. The infrastructure as code implementation method of the security resource pool according to claim 2, wherein, The infrastructure-as-code module describes the infrastructure as code text and performs the saving and rollback of network element configurations and topology relationships.
5. The infrastructure as code implementation method of the security resource pool according to claim 2, characterized in that, The version control system is used to save the historical configurations of the network elements. The security resource pool saves the configuration files of all the network elements it contains and the topology connection relationships between the network elements in text form to the version control system.
6. The infrastructure as code implementation method of the security resource pool according to claim 2, characterized in that The security resource pool further includes a code comparison tool for comparing the configurations of the security resource pool at different time points to check what changes have occurred.
7. The infrastructure as code implementation method of the security resource pool according to claim 1, characterized in that In step S21, select specific network elements to perform the rollback or select the entire security resource pool for rollback.
8. The infrastructure as code implementation method of the security resource pool according to claim 1, characterized in that, In step S21, after a failure occurs in the security resource pool, select a certain time point before the failure for rollback.
Citation Information
Patent Citations
Fault recovery method and device and computer readable storage medium
CN114095964A
DevOps infrastructure management method, device, equipment and medium
CN117170687A