Firewall verification method and device for software defined network
By obtaining the open flow table when issuing firewall rules by the SDN controller and converting it into a verification process, comparing the state of the firewall rule verification process and the open flow table execution process, the deadlock problem caused by the complex configuration of SDN firewall rules is solved, and accurate verification of firewall rules and network security is achieved.
Patent Information
- Application Number
- CN202510398580.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2045-04-01
AI Technical Summary
The firewall rules in existing software-defined networks (SDNs) are complex in configuration, which can easily cause deadlock problems and affect the normal operation of the network. Inconsistent with the actual execution of the firewall rules and data planes will lead to deadlocks and security vulnerabilities.
By obtaining the open flow table generated during the data flow process when issuing firewall rules in the software-defined network controller, and converting the firewall rules and open flow tables into firewall rules verification processes and open flow table execution processes based on the preset programming language. Compare the consistency of the parallel operation status of these two processes and generate firewall verification results to judge deadlock conditions and rule execution exceptions.
It realizes accurate verification of SDN firewall rules, timely discovers and solves firewall abnormal problems, and improves network security and consistency.
Smart Images

Figure CN119922015A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security, and in particular, to a method and device for verifying a firewall in a software-defined network. Background Art
[0002] With the development of SDN (Software Defined Network) technology, network management has become more flexible and efficient. However, the existing firewall rules in SDN are complex to configure, which can easily cause deadlock problems and affect the normal operation of the network. Therefore, an effective verification system and method are needed to ensure the correct execution of SDN firewall rules and improve the security and consistency of the network.
[0003] Inconsistency between firewall rules and actual execution of the data plane in SDN networks can lead to deadlock and security vulnerabilities, including but not limited to: rules are successfully configured on the controller, but the switch does not execute them correctly. When dynamically updating rules, conflicts between new and old rules can cause network problems.
[0004] Therefore, how to accurately verify the abnormal situation of the firewall is a technical problem that needs to be solved. Summary of the invention
[0005] The purpose of the embodiments of the present application is to provide a firewall verification method for a software-defined network. Through the technical solution of the embodiments of the present application, the effect of accurately verifying abnormal conditions of the firewall can be achieved.
[0006] In a first aspect, an embodiment of the present application provides a firewall verification method for a software-defined network, comprising: when a software-defined network controller issues firewall rules, obtaining an open flow table generated during a data flow process; converting the firewall rules and the open flow table into a firewall rule verification process and an open flow table execution process based on a preset programming language, wherein the firewall rule verification process includes a first conversion module for converting the firewall rule verification process and a firewall rule verification process module for executing the firewall rule verification process, and the open flow table execution process includes a second conversion module for converting the open flow table execution process and an open flow table execution process module for executing the open flow table execution process; comparing the consistency of the parallel operation states of the firewall rule verification process and the open flow table execution process, and generating a firewall verification result, wherein the firewall verification result includes a firewall rule verification result and an open flow table verification result.
[0007] In the above embodiment of the present application, when the software-defined network controller issues firewall rules, by executing the firewall rule verification process based on the firewall rules and the open flow table execution process based on the open flow table in parallel, and comparing the states of the two to determine the deadlock situation, the execution state of the firewall rules in the open flow table can be accurately detected, and the rule execution anomalies can be discovered in time. This method can achieve the effect of accurately verifying the abnormal situation of the firewall.
[0008] In some embodiments, the consistency of the parallel operation status of the firewall rule verification process and the open flow table execution process is compared, and a firewall verification result is generated, including: comparing whether the parallel operation status of the firewall rule verification process and the open flow table execution process are consistent; when the parallel operation status of the firewall rule verification process and the open flow table execution process are inconsistent, generating locking information of the firewall rules and the open flow table.
[0009] In the above embodiments of the present application, the abnormal situation of the firewall is accurately verified by executing the firewall rule verification process based on the firewall rules and the open flow table execution process based on the open flow table in parallel, and comparing the states of the two to determine the deadlock situation.
[0010] In some embodiments, after comparing the consistency of the parallel operation states of the firewall rule verification process and the open flow table execution process and generating the firewall verification results, it also includes: generating a log and issuing an alarm based on the lock information, wherein the log includes error rules and node information of the firewall rule verification process and the open flow table.
[0011] In the above-mentioned embodiments, the present application can promptly issue an alarm when there is an abnormality in the firewall, thereby discovering and resolving the abnormality problem of the firewall.
[0012] In some embodiments, when a software-defined network controller issues firewall rules, an open flow table generated during the data flow process is obtained, including: when the software-defined network controller controls multiple nodes to transmit data, the firewall rules issued by the controller and the open flow table generated during the data transmission process are obtained, wherein the application scenarios of the software-defined network controller controlling multiple nodes to transmit data include: enterprise internal network firewalls to protect enterprise data and resource scenarios, data center network traffic transmission to protect network isolation and security policies between different users, verification of whether the firewall set by each user is executed correctly during cloud computing, and verification of firewall rules in the software-defined network during telecommunications network communication data transmission.
[0013] In the above embodiments of the present application, there may be multiple scenarios for firewall verification of the present application, and accurate verification of firewall rules and exceptions may be achieved in different scenarios through the dual-process verification method of the present application.
[0014] In some embodiments, firewall rules and open flow tables are converted into firewall rule verification processes and open flow table execution processes based on a preset programming language, including: selecting a preset script file and placing it in a preset configuration file; executing the script corresponding to the programming language in the configuration file to obtain the firewall rule verification process and the open flow table execution process.
[0015] In the above embodiments of the present application, a script may be set in advance through a programming language to directly obtain the firewall rule verification process and the open flow table execution process to facilitate subsequent verification of the dual processes.
[0016] In a second aspect, an embodiment of the present application provides a firewall verification device for a software-defined network, including: An acquisition module, used to acquire the open flow table generated during the data flow process when the software-defined network controller issues firewall rules; A conversion module, used to convert the firewall rules and the open flow table into a firewall rule verification process and an open flow table execution process based on a preset programming language, wherein the firewall rule verification process includes a first conversion module for converting the firewall rule verification process and a firewall rule verification process module for executing the firewall rule verification process, and the open flow table execution process includes a second conversion module for converting the open flow table execution process and an open flow table execution process module for executing the open flow table execution process; The verification module is used to compare the consistency of the parallel operation states of the firewall rule verification process and the open flow table execution process, and generate a firewall verification result, wherein the firewall verification result includes a firewall rule verification result and an open flow table verification result.
[0017] Optionally, the verification module is specifically used to: Compare the parallel operation states of the firewall rule verification process and the open flow table execution process to see if they are consistent; When the parallel operation states of the firewall rule verification process and the open flow table execution process are inconsistent, locking information of the firewall rule and the open flow table is generated.
[0018] Optionally, the device further comprises: The alarm module is used to generate a log and issue an alarm according to the lock information after the verification module compares the consistency of the parallel operation status of the firewall rule verification process and the open flow table execution process and generates a firewall verification result, wherein the log includes the error rules and node information of the firewall rule verification process and the open flow table.
[0019] Optionally, the acquisition module is specifically used to: When a software-defined network controller controls multiple nodes to transmit data, the firewall rules issued by the controller and the open flow table generated during the data transmission process are obtained. The application scenarios of the software-defined network controller controlling multiple nodes to transmit data include: enterprise internal network firewall protection of enterprise data and resource scenarios, data center network traffic transmission protection of network isolation and security policies between different users, verification of whether the firewall set by each user is correctly executed during cloud computing, and verification of firewall rules in the software-defined network during telecommunications network communication data transmission.
[0020] Optionally, the conversion module is specifically used for: Select the preset script file and place it in the preset configuration file; Execute the script corresponding to the programming language in the configuration file to obtain the firewall rule verification process and the open flow table execution process.
[0021] In a third aspect, an embodiment of the present application provides an electronic device, comprising a processor and a memory, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps in the method provided in the first aspect are performed.
[0022] In a fourth aspect, an embodiment of the present application provides a readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps in the method provided in the first aspect are performed.
[0023] Other features and advantages of the present application will be described in the subsequent description, and in part will become apparent from the description, or will be understood by implementing the embodiments of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0025] Figure 1 A flowchart of a software-defined network firewall verification method provided in an embodiment of the present application; Figure 2 A schematic block diagram of an SDN firewall application verification system provided in an embodiment of the present application; Figure 3 A schematic diagram of an interactive method for SDN controller and firewall verification provided in an embodiment of the present application; Figure 4A schematic block diagram of a firewall verification device for a software-defined network provided in an embodiment of the present application; Figure 5 A schematic diagram of the structure of a firewall verification device for a software-defined network provided in an embodiment of the present application. DETAILED DESCRIPTION
[0026] The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application usually described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present application.
[0027] It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.
[0028] First, some terms involved in the embodiments of the present application are explained to facilitate understanding by those skilled in the art.
[0029] Firewall Policy: Specifies the conditions for allowing or prohibiting network access, such as determining how to handle data packets (allowing them to pass or discarding them) based on the source IP, destination IP, etc.
[0030] Open Flow Table: A rule table used by switches in an SDN network to forward data packets. It is issued by the SDN controller and determines the direction of data packets in the network.
[0031] Process: In this patent, it refers to the FW process based on firewall rules (first process) and the PATH process based on the open flow table (second process), which are used to process data packets and determine the execution status of rules.
[0032] Synchronization: A coordination mechanism between the FW process and the PATH process to ensure consistency in processing data packets, such as synchronization through event in signals.
[0033] Software Defined Network (SDN) is a new network innovation architecture proposed by the Clean-Slate research group of Stanford University in the United States. It is a way to implement network virtualization. Its core technology OpenFlow separates the control plane from the data plane of network devices, thereby achieving flexible control of network traffic, making the network more intelligent, and providing a good platform for innovation of core networks and applications.
[0034] ACL rules are specific rules in the access control list (ACL) that are used to control network traffic and access rights. ACL rules consist of a series of conditional statements, which can include the source address, destination address, port number, etc. of the message. By configuring these rules, you can filter and control network traffic to ensure that only messages that meet specific conditions can pass.
[0035] FW process usually refers to the firewall process. In the field of network security, FW is the abbreviation of Firewall, which stands for firewall. A firewall is a security system used to protect computers or network devices from unauthorized access or attacks. It prevents malware, viruses or hacker attacks by monitoring and controlling network traffic, and helps administrators implement access control policies and regulate network behavior.
[0036] The PATH process is an environment variable in the operating system, which is mainly used to specify the path where the operating system searches for executable files when executing commands. When a user enters a command in the terminal, the system searches for the executable file of the command in the PATH and then executes the corresponding operation.
[0037] QoS rules (Quality of Service Rules) refer to the rules formulated in communication networks to ensure the quality of data transmission.
[0038] This application is applied to the scenario of firewall verification. The specific scenario is to convert firewall rules and open flow tables through a preset programming language, compare the obtained FW process with the PATH process in parallel operation status, generate information on whether a deadlock occurs between the two, and then realize the firewall verification process.
[0039] With the development of SDN (Software Defined Network) technology, network management has become more flexible and efficient. However, the existing firewall rules in SDN are complex to configure, which can easily cause deadlock problems and affect the normal operation of the network. Therefore, an effective verification system and method are needed to ensure the correct execution of SDN firewall rules and improve the security and consistency of the network. Inconsistency between firewall rules and actual execution of the data plane in SDN networks can lead to deadlock and security vulnerabilities, including but not limited to: the rules are successfully configured in the controller, but the switch is not correctly executed. When dynamically updating rules, conflicts between new and old rules cause network problems.
[0040] To this end, the present application obtains the open flow table generated in the data flow process when the software-defined network controller issues the firewall rules; based on the preset programming language, the firewall rules and the open flow table are converted into a firewall rule verification process and an open flow table execution process, wherein the firewall rule verification process includes a first conversion module for converting the firewall rule verification process and a firewall rule verification process module for executing the firewall rule verification process, and the open flow table execution process includes a second conversion module for converting the open flow table execution process and an open flow table execution process module for executing the open flow table execution process; compare the consistency of the parallel operation state of the firewall rule verification process and the open flow table execution process, and generate a firewall verification result, wherein the firewall verification result includes the firewall rule verification result and the open flow table verification result. When the software-defined network controller issues the firewall rules, by executing the firewall rule verification process based on the firewall rules and the open flow table execution process based on the open flow table in parallel, and comparing the states of the two to determine the deadlock situation, the execution state of the firewall rules in the open flow table can be accurately detected, and the rule execution anomalies can be discovered in time. This method can achieve the effect of accurately verifying the abnormal situation of the firewall.
[0041] In an embodiment of the present application, the execution entity may be a software-defined network firewall verification device in a software-defined network firewall verification system. In actual applications, the software-defined network firewall verification device may be electronic devices such as terminal devices and servers, which are not limited here.
[0042] Combine the following Figure 1 The firewall verification method of the software defined network in the embodiment of the present application is described in detail.
[0043] Please see Figure 1 , Figure 1 A flowchart of a firewall verification method for a software-defined network provided in an embodiment of the present application, such as Figure 1 The firewall verification methods for software-defined networks shown include: Step 110: When the software-defined network controller sends firewall rules, an open flow table generated during the data flow process is obtained.
[0044] Among them, firewall rules can be obtained through historically stored firewall rules, or they can be obtained by manually uploading after the user compiles them. The data can be the internal network firewall of the enterprise to protect enterprise data and resources, the network isolation and security policies between different users of the data center network traffic transmission to protect the firewall data and telecommunications network communication data set by each user during cloud computing, etc., but the present application is not limited to this. The open flow table includes the nodes where the data flows, the type of data, the specific content of the data, and whether the data flows normally when the data flows through each node. At the same time, the software-defined network controller can also be responsible for determining the forwarding and data packet processing rules, and sending the data packet processing rules to the SDN switch, and can also control the SDN network according to security, QoS and other rules.
[0045] In some embodiments of the present application, when a software-defined network controller issues firewall rules, an open flow table generated during the data flow process is obtained, including: when the software-defined network controller controls multiple nodes to transmit data, the firewall rules issued by the controller and the open flow table generated during the data transmission process are obtained, wherein the application scenarios of the software-defined network controller controlling multiple nodes to transmit data include: enterprise internal network firewalls to protect enterprise data and resource scenarios, data center network traffic transmission to protect network isolation and security policies between different users, verification of whether the firewall set by each user is executed correctly during cloud computing, and verification of firewall rules in the software-defined network during telecommunications network communication data transmission.
[0046] In the above process, the firewall verification scenarios of the present application can be multiple, and the accurate verification of firewall rules and exceptions can be achieved in different scenarios through the dual-process verification method of the present application.
[0047] Among them, the multiple nodes can be the nodes that data needs to pass through when flowing in any application scenario.
[0048] Step 120: Convert the firewall rules and the open flow table into a firewall rule verification process and an open flow table execution process based on a preset programming language.
[0049] Among them, the firewall rule verification process includes a first conversion module for converting the firewall rule verification process (FW process) and a firewall rule verification process module for executing the firewall rule verification process, and the open flow table execution process includes a second conversion module for converting the open flow table execution process (PATH process) and an open flow table execution process module for executing the open flow table execution process. The FW process module can also receive firewall-related signals, such as synchronization signals for receiving data information, firewall rule signals, and signals indicating whether the firewall is abnormal, etc. The PATH process module can also send firewall-related information and transmit data packets, such as synchronization signals for sending data information, firewall rule signals, and signals indicating whether the firewall is abnormal, etc. The programming language can be obtained by relevant personnel according to the programming language required by this application.
[0050] Specifically, Figure 1 The method shown can be Figure 1 The system shown is executed.
[0051] Please see Figure 2 , Figure 2 A schematic block diagram of an SDN firewall application verification system provided in this application, such as Figure 2 The SDN firewall application verification system shown includes: The firewall conversion module 210 , the open flow table conversion module 220 , the dual process verification module 230 and the SDN controller 240 .
[0052] Among them, the dual-process verification module includes a firewall rule verification module and an open flow table execution module.
[0053] The firewall conversion module and the open flow table conversion module are used to convert the firewall rules and the open flow table into the firewall rule verification process and the open flow table execution process respectively.
[0054] The dual-process verification module is used to compare the consistency of the parallel operation states of the firewall rule verification process and the open flow table execution process, and generate a firewall verification result.
[0055] The firewall rule verification module and the open flow table execution module are used for firewall rule verification and open flow table execution respectively.
[0056] The SDN controller includes open flow table rules, firewall rules and multiple SDN devices, which are used to control firewall rules. Based on the deadlock information sent by the firewall verification framework module, it determines whether the open flow table executes the firewall rules normally. It is also responsible for determining the forwarding and packet processing rules, and sending forwarding rules to the SDN switch. It can also control the SDN network according to security, QoS and other rules.
[0057] also, Figure 2The specific method performed by the system module shown can be Figure 1 The method for obtaining the data is described and will not be described in detail here.
[0058] Optionally, for the SDN controller, the present application also provides a schematic diagram including the SDN controller, the firewall verification framework module and its internal components.
[0059] Please see Figure 3 , Figure 3 A schematic diagram of an interactive method for SDN controller and firewall verification provided in this application, such as Figure 3 The interaction methods shown include: The SDN controller controls multiple SDN devices to perform dual-process verification of open flow tables and firewall rules.
[0060] During the verification process, the firewall rules and open flow tables are converted into FW processes and PATH processes respectively through the first conversion module and the second conversion module, and then through FW process processing and PATH process processing, the consistency of the parallel operation status of the firewall rule verification process and the open flow table execution process is compared, and the firewall verification result is generated.
[0061] also, Figure 3 The specific methods and module execution contents can be found in Figure 1 The method shown and Figure 2 The system shown will not be described in detail here.
[0062] In some embodiments of the present application, firewall rules and open flow tables are converted into firewall rule verification processes and open flow table execution processes based on a preset programming language, including: selecting a preset script file and placing it in a preset configuration file; executing the script corresponding to the programming language in the configuration file to obtain the firewall rule verification process and the open flow table execution process.
[0063] In the above process, the present application can set up a script in advance through a programming language to directly obtain the firewall rule verification process and the open flow table execution process to facilitate subsequent verification of the two processes.
[0064] Among them, the preset scripts can be set in advance according to different application scenarios. The scripts in the configuration file can be directly obtained according to the current application scenario.
[0065] Step 130: Compare the consistency of the parallel operation states of the firewall rule verification process and the open flow table execution process, and generate a firewall verification result.
[0066] The firewall verification result includes the firewall rule verification result and the open flow table verification result. The firewall rule verification result includes whether the firewall rule is standard and abnormal information. The open flow table verification result includes whether the open flow table is standard and abnormal information. The parallel operation status includes the execution time and node information of the firewall rule verification process and the open flow table execution process.
[0067] In some embodiments of the present application, the consistency of the parallel operation status of the firewall rule verification process and the open flow table execution process is compared, and a firewall verification result is generated, including: comparing whether the parallel operation status of the firewall rule verification process and the open flow table execution process are consistent; when the parallel operation status of the firewall rule verification process and the open flow table execution process are inconsistent, generating locking information of the firewall rules and the open flow table.
[0068] In the above process, the present application executes the firewall rule verification process based on the firewall rules and the open flow table execution process based on the open flow table in parallel, and compares the states of the two to determine the deadlock situation, thereby accurately verifying the abnormal situation of the firewall.
[0069] The lockout information includes whether the switch is executed correctly and / or the conflict between the new and old rules and / or the dual process execution. When the parallel operation status of the firewall rule verification process and the open flow table execution process are consistent, the firewall rule verification process and the open flow table execution process and the subsequent data flow process of the dual process can be executed. When the parallel operation status of the firewall rule verification process and the open flow table execution process are inconsistent, the corresponding firewall rules can also be deleted.
[0070] In some embodiments of the present application, after comparing the consistency of the parallel operation states of the firewall rule verification process and the open flow table execution process and generating the firewall verification result, Figure 1 The method shown also includes: generating a log and issuing an alarm according to the locking information, wherein the log includes the firewall rule verification process and the error rules and node information of the open flow table.
[0071] In the above process, the present application can timely alarm when there is an abnormality in the firewall, discover and solve the abnormal problem of the firewall.
[0072] The error rules include abnormal information and time of the firewall rules, and the node information includes the location and time of the node.
[0073] In the above Figure 1In the process shown, the present application obtains the open flow table generated in the data flow process when the software-defined network controller issues the firewall rules; based on the preset programming language, the firewall rules and the open flow table are converted into a firewall rule verification process and an open flow table execution process, wherein the firewall rule verification process includes a first conversion module for converting the firewall rule verification process and a firewall rule verification process module for executing the firewall rule verification process, and the open flow table execution process includes a second conversion module for converting the open flow table execution process and an open flow table execution process module for executing the open flow table execution process; compare the consistency of the parallel operation state of the firewall rule verification process and the open flow table execution process, and generate a firewall verification result, wherein the firewall verification result includes the firewall rule verification result and the open flow table verification result. When the software-defined network controller issues the firewall rules, by executing the firewall rule verification process based on the firewall rules and the open flow table execution process based on the open flow table in parallel, and comparing the states of the two to determine the deadlock situation, the execution state of the firewall rules in the open flow table can be accurately detected, and the rule execution anomalies can be discovered in time. This method can achieve the effect of accurately verifying the abnormal situation of the firewall.
[0074] Previous article Figure 1 The firewall verification method for software-defined networks is described below. Figure 4-Figure 5 Describe the firewall verification device for software defined networks.
[0075] Please refer to Figure 4 , is a schematic block diagram of a software-defined network firewall verification device 400 provided in an embodiment of the present application. The verification device 400 may be a module, program segment or code on an electronic device. The verification device 400 is similar to the above Figure 1 The method embodiment corresponds to and can be executed Figure 1 The various steps involved in the method embodiment and the specific functions of the verification device 400 can be found in the description below. To avoid repetition, the detailed description is appropriately omitted here.
[0076] Optionally, the verification device 400 includes: The acquisition module 410 is used to acquire the open flow table generated in the data flow process when the software defined network controller issues the firewall rules; A conversion module 420, configured to convert the firewall rules and the open flow table into a firewall rule verification process and an open flow table execution process based on a preset programming language, wherein the firewall rule verification process includes a first conversion module for converting the firewall rule verification process and a firewall rule verification process module for executing the firewall rule verification process, and the open flow table execution process includes a second conversion module for converting the open flow table execution process and an open flow table execution process module for executing the open flow table execution process; The verification module 430 is used to compare the consistency of the parallel operation states of the firewall rule verification process and the open flow table execution process, and generate a firewall verification result, wherein the firewall verification result includes a firewall rule verification result and an open flow table verification result.
[0077] Optionally, the verification module is specifically used to: Compare whether the parallel operation states of the firewall rule verification process and the open flow table execution process are consistent; when the parallel operation states of the firewall rule verification process and the open flow table execution process are inconsistent, generate locking information of the firewall rule and the open flow table.
[0078] Optionally, the device further comprises: The alarm module is used to generate a log and issue an alarm according to the lock information after the verification module compares the consistency of the parallel operation status of the firewall rule verification process and the open flow table execution process and generates a firewall verification result, wherein the log includes the error rules and node information of the firewall rule verification process and the open flow table.
[0079] Optionally, the acquisition module is specifically used to: When a software-defined network controller controls multiple nodes to transmit data, the firewall rules issued by the controller and the open flow table generated during the data transmission process are obtained. The application scenarios of the software-defined network controller controlling multiple nodes to transmit data include: enterprise internal network firewall protection of enterprise data and resource scenarios, data center network traffic transmission protection of network isolation and security policies between different users, verification of whether the firewall set by each user is correctly executed during cloud computing, and verification of firewall rules in the software-defined network during telecommunications network communication data transmission.
[0080] Optionally, the conversion module is specifically used for: Select a preset script file and place it in a preset configuration file; execute the script corresponding to the programming language in the configuration file to obtain the firewall rule verification process and the open flow table execution process.
[0081] Please refer to Figure 5 The structure schematic block diagram of a software defined network firewall verification device provided in an embodiment of the present application, the device may include a memory 510 and a processor 520. Optionally, the device may also include: a communication interface 530 and a communication bus 540. The device is similar to the above Figure 1 The method embodiment corresponds to and can be executed Figure 1 The various steps involved in the method embodiment and the specific functions of the device can be found in the description below.
[0082] Specifically, the memory 510 is used to store computer-readable instructions.
[0083] Processor 520, configured to process readable instructions stored in the memory, capable of executing Figure 1 The steps in the method.
[0084] The communication interface 530 is used for signaling or data communication with other node devices, for example, for communication with a server or a terminal, or for communication with other device nodes, but the embodiments of the present application are not limited thereto.
[0085] The communication bus 540 is used to realize direct connection and communication among the above components.
[0086] The communication interface 530 of the device in the embodiment of the present application is used to communicate with other node devices for signaling or data. The memory 510 can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. The memory 510 can also be at least one storage device located away from the aforementioned processor. The memory 510 stores computer-readable instructions. When the computer-readable instructions are executed by the processor 520, the electronic device executes the aforementioned Figure 1 The method process shown. The processor 520 can be used on the verification device 400 and used to perform the functions in the present application. Exemplarily, the above-mentioned processor 520 can be a general-purpose processor, a digital signal processor (Digital Signal Processor, DSP), an application-specific integrated circuit (Application Specific Integrated Circuit, ASIC), a field programmable gate array (Field Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, and the embodiments of the present application are not limited to this.
[0087] The embodiment of the present application also provides a readable storage medium, when the computer program is executed by a processor, Figure 1 The method process in the method embodiment shown is executed by the electronic device.
[0088] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the device described above can refer to the corresponding process in the aforementioned method, and will not be described in detail here.
[0089] In summary, the embodiment of the present application provides a method and device for verifying a firewall of a software-defined network, the method comprising: when a software-defined network controller issues firewall rules, obtaining an open flow table generated during data flow; based on a preset programming language, converting the firewall rules and the open flow table into a firewall rule verification process and an open flow table execution process, wherein the firewall rule verification process comprises a first conversion module for converting the firewall rule verification process and a firewall rule verification process module for executing the firewall rule verification process, and the open flow table execution process comprises a second conversion module for converting the open flow table execution process and an open flow table execution process module for executing the open flow table execution process; comparing the consistency of the parallel operation states of the firewall rule verification process and the open flow table execution process, and generating a firewall verification result, wherein the firewall verification result comprises a firewall rule verification result and an open flow table verification result. Through this method, the effect of accurately verifying abnormal conditions of the firewall can be achieved.
[0090] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of a code, and the module, a program segment or a part of a code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.
[0091] In addition, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.
[0092] If the function is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, and other media that can store program codes.
[0093] The above description is only an embodiment of the present application and is not intended to limit the scope of protection of the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings.
[0094] The above description is only a specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application.
[0095] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.
Claims
1. A method for verifying a firewall in a software-defined network, characterized in that: include: When the software-defined network controller issues firewall rules, the open flow table generated during the data flow is obtained; Converting the firewall rule and the open flow table into a firewall rule verification process and an open flow table execution process based on a preset programming language, wherein the firewall rule verification process includes a first conversion module for converting the firewall rule verification process and a firewall rule verification process module for executing the firewall rule verification process, and the open flow table execution process includes a second conversion module for converting the open flow table execution process and an open flow table execution process module for executing the open flow table execution process; The consistency of the parallel operation states of the firewall rule verification process and the open flow table execution process is compared, and a firewall verification result is generated, wherein the firewall verification result includes a firewall rule verification result and an open flow table verification result.
2. The method according to claim 1, characterized in that The comparing the consistency of the parallel operation states of the firewall rule verification process and the open flow table execution process and generating a firewall verification result includes: Comparing whether the parallel operation states of the firewall rule verification process and the open flow table execution process are consistent; When the parallel operation states of the firewall rule verification process and the open flow table execution process are inconsistent, locking information of the firewall rule and the open flow table is generated.
3. The method according to claim 2, characterized in that After comparing the consistency of the parallel operation states of the firewall rule verification process and the open flow table execution process and generating a firewall verification result, the method further includes: A log is generated according to the deadlock information and an alarm is issued, wherein the log includes the firewall rule verification process and the error rules and node information of the open flow table.
4. The method according to any one of claims 1 to 3, characterized in that: When the software-defined network controller issues firewall rules, obtaining the open flow table generated during the data flow process includes: When a software-defined network controller controls multiple nodes to transmit data, the firewall rules issued by the controller and the open flow table generated during the data transmission process are obtained, wherein the application scenarios of the software-defined network controller controlling multiple nodes to transmit data include: enterprise internal network firewall protection of enterprise data and resource scenarios, data center network traffic transmission protection of network isolation and security policies between different users, verification of whether the firewall set by each user is correctly executed during cloud computing, and verification of firewall rules in the software-defined network during telecommunications network communication data transmission.
5. The method according to any one of claims 1 to 3, characterized in that: The converting the firewall rules and the open flow table into a firewall rule verification process and an open flow table execution process based on a preset programming language includes: Select the preset script file and place it in the preset configuration file; Execute the script corresponding to the programming language in the configuration file to obtain the firewall rule verification process and the open flow table execution process.
6. A software defined network firewall verification device, characterized in that: include: An acquisition module, used to acquire the open flow table generated during the data flow process when the software-defined network controller issues firewall rules; a conversion module, configured to convert the firewall rule and the open flow table into a firewall rule verification process and an open flow table execution process based on a preset programming language, wherein the firewall rule verification process comprises a first conversion module for converting the firewall rule verification process and a firewall rule verification process module for executing the firewall rule verification process, and the open flow table execution process comprises a second conversion module for converting the open flow table execution process and an open flow table execution process module for executing the open flow table execution process; The verification module is used to compare the consistency of the parallel operation states of the firewall rule verification process and the open flow table execution process, and generate a firewall verification result, wherein the firewall verification result includes a firewall rule verification result and an open flow table verification result.
7. The device according to claim 6, characterized in that The verification module is specifically used for: Comparing whether the parallel operation states of the firewall rule verification process and the open flow table execution process are consistent; When the parallel operation states of the firewall rule verification process and the open flow table execution process are inconsistent, locking information of the firewall rule and the open flow table is generated.
8. The device according to claim 7, characterized in that The device also includes: An alarm module is used for the verification module to generate a log and issue an alarm according to the lock information after comparing the consistency of the parallel operation status of the firewall rule verification process and the open flow table execution process and generating a firewall verification result, wherein the log includes error rules and node information of the firewall rule verification process and the open flow table.
9. The device according to any one of claims 6 to 8, characterized in that: The acquisition module is specifically used for: When a software-defined network controller controls multiple nodes to transmit data, the firewall rules issued by the controller and the open flow table generated during the data transmission process are obtained, wherein the application scenarios of the software-defined network controller controlling multiple nodes to transmit data include: enterprise internal network firewall protection of enterprise data and resource scenarios, data center network traffic transmission protection of network isolation and security policies between different users, verification of whether the firewall set by each user is correctly executed during cloud computing, and verification of firewall rules in the software-defined network during telecommunications network communication data transmission.
10. The device according to any one of claims 6 to 8, characterized in that: The conversion module is specifically used for: Select the preset script file and place it in the preset configuration file; Execute the script corresponding to the programming language in the configuration file to obtain the firewall rule verification process and the open flow table execution process.
Citation Information
Patent Citations
Firewall implementation method applied to software defined networking
CN105338003A
Implementation method of software-defined firewall system
CN110381025A
Firewall rule synchronization method and device, electronic equipment and storage medium
CN113765885A
Network-wide verification of invariants
US20140369209A1
Management of the application of a policy in an SDN environment of a communications network
US20210168071A1