A firewall verification method and device for software-defined networks

By obtaining and converting firewall rules and open flow tables in SDN and comparing their parallel operation status, the complex configuration and deadlock of SDN firewall rules are solved, and the correct execution of firewall rules and network security is achieved.

CN119922015BActive Publication Date: 2025-06-24ZIGUANG HENGYUE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510398580.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-01
Publication Date
2025-06-24
Estimated Expiration
2045-04-01

AI Technical Summary

Technical Problem

The firewall rules in existing software-defined networks (SDNs) are complex in configuration, which can easily cause deadlock problems and affect the normal operation of the network. Inconsistent with the actual execution of the firewall rules and data planes will lead to deadlocks and security vulnerabilities.

Method used

By obtaining the open flow table generated during the data flow process when issuing firewall rules in the software-defined network controller, and converting the firewall rules and open flow tables into firewall rules verification processes and open flow table execution processes based on the preset programming language. Compare the consistency of the parallel operation status of these two processes and generate firewall verification results to judge the deadlock situation.

Benefits of technology

It realizes accurate detection of the execution status of firewall rules in the open flow table, timely discovers rule execution exceptions, ensures the correct execution of SDN firewall rules, and improves network security and consistency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119922015B_ABST
    Figure CN119922015B_ABST
Patent Text Reader

Abstract

This application relates to the field of network security, and specifically provides a firewall verification method and device for software-defined networks. The method includes: when the software-defined network controller issues firewall rules, obtaining the OpenFlow table generated during the data flow process; converting the firewall rules and the OpenFlow table into a firewall rule verification process and an OpenFlow table execution process based on a preset programming language; comparing the consistency of the parallel operation states of the firewall rule verification process and the OpenFlow table execution process, and generating a firewall verification result. Through this method, the effect of accurately verifying abnormal situations of the firewall can be achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security. Specifically, it relates to a firewall verification method and device for software-defined networks. Background Art

[0002] With the development of SDN (Software-Defined Network) technology, network management has become more flexible and efficient. However, the firewall rule configuration in existing SDNs is complex and prone to deadlock problems, affecting the normal operation of the network. Therefore, an effective verification system and method are needed to ensure the correct execution of SDN firewall rules and improve network security and consistency.

[0003] Inconsistencies between firewall rules and actual data plane execution in SDN networks can lead to deadlock and security vulnerability problems, including but not limited to: rules are successfully configured in the controller, but not correctly executed by the switch. Network problems occur due to conflicts between old and new rules during dynamic rule updates.

[0004] Therefore, how to accurately verify abnormal situations of the firewall is a technical problem that needs to be solved. Summary of the Invention

[0005] The purpose of the embodiments of this application is to provide a firewall verification method for software-defined networks, and the technical solutions of the embodiments of this application can achieve the effect of accurately verifying abnormal situations of the firewall.

[0006] In a first aspect, the embodiments of this application provide a firewall verification method for software-defined networks, including: when a software-defined network controller issues firewall rules, obtaining the OpenFlow table generated during the data flow process; converting the firewall rules and the OpenFlow table into a firewall rule verification process and an OpenFlow table execution process based on a preset programming language, where the firewall rule verification process includes a first conversion module for converting the firewall rule verification process and a firewall rule verification process module for executing the firewall rule verification process, and the OpenFlow table execution process includes a second conversion module for converting the OpenFlow table execution process and an OpenFlow table execution process module for executing the OpenFlow table execution process; comparing the consistency of the parallel operation states of the firewall rule verification process and the OpenFlow table execution process, and generating a firewall verification result, where the firewall verification result includes a firewall rule verification result and an OpenFlow table verification result.

[0007] In the above embodiments of the present application, when the software-defined network controller issues firewall rules, by concurrently executing the firewall rule verification process based on the firewall rules and the OpenFlow table execution process based on the OpenFlow table, and comparing the states of the two to determine deadlock situations, the execution status of the firewall rules in the OpenFlow table can be accurately detected, and rule execution anomalies can be discovered in a timely manner. Through this method, the effect of accurately verifying firewall anomalies can be achieved.

[0008] In some embodiments, comparing the consistency of the parallel operation states of the firewall rule verification process and the OpenFlow table execution process, and generating a firewall verification result, includes: comparing whether the parallel operation states of the firewall rule verification process and the OpenFlow table execution process are consistent; when the parallel operation states of the firewall rule verification process and the OpenFlow table execution process are inconsistent, generating deadlock information for the firewall rules and the OpenFlow table.

[0009] In the above embodiments of the present application, by concurrently executing the firewall rule verification process based on the firewall rules and the OpenFlow table execution process based on the OpenFlow table, and comparing the states of the two to determine deadlock situations, firewall anomalies have been accurately verified.

[0010] In some embodiments, after comparing the consistency of the parallel operation states of the firewall rule verification process and the OpenFlow table execution process, and generating a firewall verification result, it further includes: generating a log and issuing an alarm according to the deadlock information, where the log includes error rules and node information of the firewall rule verification process and the OpenFlow table.

[0011] In the above embodiments of the present application, when there are firewall anomalies, an alarm can be issued in a timely manner to discover and solve firewall anomaly problems.

[0012] In some embodiments, when the software-defined network controller issues firewall rules, obtaining the OpenFlow table generated during the data flow process, includes: when the software-defined network controller controls multiple nodes to transmit data, obtaining the firewall rules issued by the controller and the OpenFlow table generated during the data transmission process, where the application scenarios where the software-defined network controller controls multiple nodes to transmit data include: the enterprise internal network firewall protecting enterprise data and resources scenarios, the data center network traffic transmission protecting network isolation and security policies between different users, verifying whether the firewall set by each user is correctly executed during cloud computing, and verifying firewall rules in the software-defined network during telecommunication network communication data transmission.

[0013] In the above embodiments of the present application, there can be multiple scenarios for the firewall verification of the present application, and accurate verification of firewall rules and anomalies can be achieved through the dual-process verification method of the present application in different scenarios.

[0014] In some embodiments, converting firewall rules and OpenFlow tables into a firewall rule verification process and an OpenFlow table execution process based on a preset programming language includes: selecting a preset script file and placing it in a preset configuration file; executing the script corresponding to the programming language in the configuration file to obtain the firewall rule verification process and the OpenFlow table execution process.

[0015] In the above embodiments of the present application, a script can be set in advance through a programming language to directly obtain the firewall rule verification process and the OpenFlow table execution process, so as to facilitate the subsequent verification of the two processes.

[0016] In a second aspect, an embodiment of the present application provides a firewall verification device for a software-defined network, including:

[0017] An acquisition module, configured to acquire an OpenFlow table generated during the data flow when the software-defined network controller issues firewall rules;

[0018] A conversion module, configured to convert firewall rules and an OpenFlow table into a firewall rule verification process and an OpenFlow table execution process based on a preset programming language, where the firewall rule verification process includes a first conversion module for converting the firewall rule verification process and a firewall rule verification process module for executing the firewall rule verification process, and the OpenFlow table execution process includes a second conversion module for converting the OpenFlow table execution process and an OpenFlow table execution process module for executing the OpenFlow table execution process;

[0019] A verification module, configured to compare the consistency of the parallel operation states of the firewall rule verification process and the OpenFlow table execution process and generate a firewall verification result, where the firewall verification result includes a firewall rule verification result and an OpenFlow table verification result.

[0020] Optionally, the verification module is specifically configured to:

[0021] Compare whether the parallel operation states of the firewall rule verification process and the OpenFlow table execution process are consistent;

[0022] When the parallel operation states of the firewall rule verification process and the OpenFlow table execution process are inconsistent, generate lock-up information for the firewall rules and the OpenFlow table.

[0023] Optionally, the device further includes:

[0024] An alarm module, configured to generate a log and give an alarm according to the lock-up information after the verification module compares the consistency of the parallel operation states of the firewall rule verification process and the OpenFlow table execution process and generates a firewall verification result, where the log includes error rules and node information of the firewall rule verification process and the OpenFlow table.

[0025] Optionally, the obtaining module is specifically configured to:

[0026] When the software-defined network controller controls multiple nodes to transmit data, obtain the firewall rules issued by the controller and the OpenFlow tables generated during the data transmission process. The application scenarios where the software-defined network controller controls multiple nodes to transmit data include: enterprise internal network firewall protecting enterprise data and resources, data center network traffic transmission protecting network isolation and security policies between different users, verifying whether the firewall set by each user is correctly executed during cloud computing, and verifying the firewall rules in the software-defined network during telecommunication network communication data transmission.

[0027] Optionally, the conversion module is specifically configured to:

[0028] Select a preset script file and place it in a preset configuration file;

[0029] Execute the script corresponding to the programming language in the configuration file to obtain the firewall rule verification process and the OpenFlow table execution process.

[0030] In a third aspect, an embodiment of the present application provides an electronic device, including a processor and a memory. The memory stores computer-readable instructions. When the computer-readable instructions are executed by the processor, the steps in the method provided in the first aspect above are run.

[0031] In a fourth aspect, an embodiment of the present application provides a readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in the method provided in the first aspect above are run.

[0032] Other features and advantages of the present application will be described in the subsequent specification, and part of them will become obvious from the specification, or can be understood by implementing the embodiments of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required to be used in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0034] Figure 1 It is a flowchart of a firewall verification method for a software-defined network provided by an embodiment of the present application;

[0035] Figure 2 It is a schematic block diagram of an SDN firewall application verification system provided by an embodiment of the present application;

[0036] Figure 3 Schematic diagram of an interaction method for SDN controller and firewall verification provided by an embodiment of the present application;

[0037] Figure 4 Schematic block diagram of a firewall verification device for a software-defined network provided by an embodiment of the present application;

[0038] Figure 5 Structural schematic diagram of a firewall verification device for a software-defined network provided by an embodiment of the present application. Detailed implementation manners

[0039] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Usually, the components of the embodiments of the present application described and shown in the accompanying drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application claimed, but only represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.

[0040] It should be noted that: similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, the terms "first", "second", etc. are only used for distinguishing descriptions, and cannot be understood as indicating or implying relative importance.

[0041] First, some terms involved in the embodiments of the present application will be described to facilitate the understanding of those skilled in the art.

[0042] Firewall Policy: Specifies the allowable or prohibited conditions for network access, such as determining the processing method (allow passing or discarding) of data packets according to the source IP, destination IP, etc.

[0043] Open Flow Table: A rule table used by switches in the SDN network to forward data packets, which is issued by the SDN controller and determines the flow direction of data packets in the network.

[0044] Process: In this patent, it refers to the FW process (the first process) based on the firewall policy and the PATH process (the second process) based on the open flow table, which are used to process data packets and judge the rule execution situation.

[0045] Synchronization: A coordination mechanism between the FW process and the PATH process to ensure consistency when processing data packets. For example, synchronization is achieved through the event input signal (event in signal).

[0046] Software Defined Network (SDN) is a new type of network innovation architecture proposed by the Clean-Slate research group at Stanford University in the United States. It is a way to implement network virtualization. Its core technology, OpenFlow, separates the control plane and data plane of network devices, thereby achieving flexible control of network traffic, making the network more intelligent, and providing a good platform for the innovation of core networks and applications.

[0047] ‌ACL rules are the specific rules in an Access Control List (ACL) used to control network traffic and access permissions. ACL rules consist of a series of conditional statements, which can include the source address, destination address, port number, etc. of the packet. By configuring these rules, filtering and control of network traffic can be achieved to ensure that only packets meeting specific conditions can pass.

[0048] ‌The FW process usually refers to the Firewall process.‌ In the field of network security, FW is the abbreviation of Firewall, representing the firewall. A firewall is a security system used to protect a computer or network device from unauthorized access or attacks. It monitors and controls network traffic, prevents malware, viruses, or hacker attacks, and helps administrators implement access control policies and regulate network behavior.‌

[0049] ‌The PATH process is an environment variable in the operating system, mainly used to specify the path for the operating system to search for executable files when executing commands. When a user enters a command in the terminal, the system will search for the executable file of the command in PATH and then perform the corresponding operation.

[0050] ‌QoS rules (Quality of Service Rule) refer to the rules formulated to ensure the quality of data transmission in a communication network.

[0051] This application is applied to the scenario of firewall verification. The specific scenario is to convert firewall rules and OpenFlow tables through a preset programming language, compare the obtained FW process and PATH process in a parallel operation state, generate information on whether a deadlock occurs between the two, and thus implement the firewall verification process.

[0052] With the development of Software-Defined Network (SDN) technology, network management has become more flexible and efficient. However, the firewall rule configuration in existing SDNs is complex and prone to deadlock problems, affecting the normal operation of the network. Therefore, an effective verification system and method are needed to ensure the correct execution of SDN firewall rules and improve network security and consistency. The inconsistency between firewall rules and the actual execution in the data plane in the SDN network can lead to deadlock and security vulnerability problems, including but not limited to: the rules are successfully configured in the controller, but not correctly executed by the switch. When dynamically updating rules, conflicts between new and old rules cause problems in the network.

[0053] To this end, in this application, when the software-defined network controller issues firewall rules, the open flow table generated during the data flow process is obtained; based on a preset programming language, the firewall rules and the open flow table are converted into a firewall rule verification process and an open flow table execution process. Among them, the firewall rule verification process includes a first conversion module for converting the firewall rule verification process and a firewall rule verification process module for executing the firewall rule verification process, and the open flow table execution process includes a second conversion module for converting the open flow table execution process and an open flow table execution process module for executing the open flow table execution process; the consistency of the parallel operation states of the firewall rule verification process and the open flow table execution process is compared, and a firewall verification result is generated. Among them, the firewall verification result includes a firewall rule verification result and an open flow table verification result. When the software-defined network controller issues firewall rules, by parallelly executing the firewall rule verification process based on the firewall rules and the open flow table execution process based on the open flow table, and comparing the states of the two to judge the deadlock situation, the execution state of the firewall rules in the open flow table can be accurately detected, and abnormal rule execution can be discovered in time. Through this method, the effect of accurately verifying abnormal situations of the firewall can be achieved.

[0054] In the embodiments of this application, the execution subject may be a firewall verification device of the software-defined network in the software-defined network firewall verification system. In actual applications, the firewall verification device of the software-defined network may be electronic devices such as terminal devices and servers, which are not limited here.

[0055] The following combines Figure 1 to describe in detail the software-defined network firewall verification method of the embodiments of this application.

[0056] Please refer to Figure 1 , Figure 1 which is a flowchart of a software-defined network firewall verification method provided by the embodiments of this application. As Figure 1 shown, the software-defined network firewall verification method includes:

[0057] Step 110: When the software-defined network controller issues firewall rules, obtain the OpenFlow table generated during the data flow process.

[0058] Among them, the firewall rules can be obtained from the historically stored firewall rules or manually uploaded after being compiled by the user. The data can be the enterprise internal network firewall protecting enterprise data and resources, the data center network traffic transmission protecting network isolation and security policies between different users, verifying the firewall data set by each user during cloud computing, and telecommunications network communication data, etc. This application is not limited thereto. The OpenFlow table includes the nodes through which the data flows, the type of data, the specific content of the data, and whether the data flows normally when passing through each node. At the same time, the software-defined network controller can also be responsible for determining the forwarding and packet processing rules, issuing the packet processing rules to the SDN switch, and controlling the SDN network according to rules such as security and QoS.

[0059] In some embodiments of this application, when the software-defined network controller issues firewall rules, obtaining the OpenFlow table generated during the data flow process includes: when the software-defined network controller controls multiple nodes to transmit data, obtaining the firewall rules issued by the controller and the OpenFlow table generated during the data transmission process. Among them, the application scenarios where the software-defined network controller controls multiple nodes to transmit data include: the enterprise internal network firewall protecting enterprise data and resources scenario, the data center network traffic transmission protecting network isolation and security policies between different users, verifying whether the firewall set by each user is correctly executed during cloud computing, and verifying the firewall rules in the software-defined network during telecommunications network communication data transmission.

[0060] In the above process of this application, there can be multiple scenarios for the firewall verification of this application, and the accurate verification of firewall rules and exceptions can be achieved through the dual-process verification method of this application in different scenarios.

[0061] Among them, the multiple nodes can be the nodes that the data needs to pass through in any application scenario during the data flow.

[0062] Step 120: Based on a preset programming language, convert the firewall rules and the OpenFlow table into a firewall rule verification process and an OpenFlow table execution process.

[0063] Among them, the firewall rule verification process includes a first conversion module for converting the firewall rule verification process (FW process) and a firewall rule verification process module for executing the firewall rule verification process. The open flow table execution process includes a second conversion module for converting the open flow table execution process (PATH process) and an open flow table execution process module for executing the open flow table execution process. The FW process module can also receive firewall-related signals. For example, it can receive synchronization signals of data information, firewall rule signals, signals indicating whether the firewall is abnormal, etc. The PATH process module can also send firewall-related information and transmit data packets. For example, it can send synchronization signals of data information, firewall rule signals, signals indicating whether the firewall is abnormal, etc. The programming language can be obtained by relevant personnel writing according to the programming language required by this application.

[0064] Specifically, Figure 1 the method shown can be executed by Figure 1 the system shown.

[0065] Please refer to Figure 2 , Figure 2 which is a schematic block diagram of an SDN firewall application verification system provided by this application. As Figure 2 shown, the SDN firewall application verification system includes:

[0066] A firewall conversion module 210, an open flow table conversion module 220, a dual-process verification module 230, and an SDN controller 240.

[0067] Among them, the dual-process verification module includes a firewall rule verification module and an open flow table execution module.

[0068] The firewall conversion module and the open flow table conversion module are respectively used to convert firewall rules and open flow tables into a firewall rule verification process and an open flow table execution process.

[0069] The dual-process verification module is used to compare the consistency of the parallel operation states of the firewall rule verification process and the open flow table execution process, and generate a firewall verification result.

[0070] The firewall rule verification module and the open flow table execution module are respectively used for firewall rule verification and open flow table execution.

[0071] The SDN controller includes open flow table rules, firewall rules, and multiple SDN devices, and is used to control firewall rules. According to the deadlock information sent by the firewall verification framework module, it determines whether the open flow table normally executes firewall rules. At the same time, it is responsible for determining forwarding and data packet processing rules, and sending forwarding rules to the SDN switch. It can also control the SDN network according to rules such as security and QoS.

[0072] In addition, Figure 2The specific methods executed by the system modules shown can be obtained through Figure 1 the methods described above, and will not be elaborated here.

[0073] Optionally, for the SDN controller, the present application also provides a schematic diagram including the SDN controller, the firewall verification framework module, and its internal components.

[0074] Please refer to Figure 3 , Figure 3 which is a schematic diagram of an interaction method between an SDN controller and firewall verification provided by the present application. As Figure 3 shown, the interaction method includes:

[0075] The SDN controller controls multiple SND devices to perform dual-process verification of the open flow table and the firewall rules.

[0076] During the verification process, the firewall rules and the open flow table are respectively converted into the FW process and the PATH process through the first conversion module and the second conversion module, and then processed through the FW process and the PATH process. The consistency of the parallel operation status of the firewall rule verification process and the open flow table execution process is compared, and a firewall verification result is generated.

[0077] In addition, Figure 3 the specific methods described above and the content executed by the modules can be referred to Figure 1 the methods shown in Figure 2 the system shown, and will not be elaborated here.

[0078] In some embodiments of the present application, converting the firewall rules and the open flow table into a firewall rule verification process and an open flow table execution process based on a preset programming language includes: selecting a preset script file and placing it in a preset configuration file; executing the script corresponding to the programming language in the configuration file to obtain the firewall rule verification process and the open flow table execution process.

[0079] In the above process of the present application, scripts can be set in advance through the programming language to directly obtain the firewall rule verification process and the open flow table execution process, so as to facilitate the subsequent dual-process verification.

[0080] Among them, the preset scripts can be set in advance according to different application scenarios. The scripts in the configuration file can be directly obtained according to the current application scenario.

[0081] Step 130: Compare the consistency of the parallel operation status of the firewall rule verification process and the open flow table execution process, and generate a firewall verification result.

[0082] Among them, the firewall verification result includes the firewall rule verification result and the open flow table verification result. The firewall rule verification result includes whether the firewall rule is standard and the exception information. The open flow table verification result includes whether the open flow table is standard and the exception information. The parallel operation status includes the time and node information of the execution processes of the firewall rule verification process and the open flow table execution process.

[0083] In some embodiments of the present application, comparing the consistency of the parallel operation status of the firewall rule verification process and the open flow table execution process, and generating a firewall verification result, includes: comparing whether the parallel operation status of the firewall rule verification process and the open flow table execution process is consistent; when the parallel operation status of the firewall rule verification process and the open flow table execution process is inconsistent, generating deadlock information for the firewall rule and the open flow table.

[0084] In the above process of the present application, by parallelly executing the firewall rule verification process based on the firewall rule and the open flow table execution process based on the open flow table, and comparing the statuses of the two to judge the deadlock situation, the abnormal situation of the firewall has been accurately verified.

[0085] Among them, the deadlock information includes whether the switch is correctly executed and / or the conflict situation between the new and old rules and / or the execution situation of the dual processes. When the parallel operation status of the firewall rule verification process and the open flow table execution process is consistent, the firewall rule verification process, the open flow table execution process, and the subsequent data flow process of the dual processes can be executed. When the parallel operation status of the firewall rule verification process and the open flow table execution process is inconsistent, the corresponding firewall rule can also be deleted.

[0086] In some embodiments of the present application, after comparing the consistency of the parallel operation status of the firewall rule verification process and the open flow table execution process, and generating a firewall verification result, Figure 1 the method shown further includes: generating a log and giving an alarm according to the deadlock information, where the log includes the error rules and node information of the firewall rule verification process and the open flow table.

[0087] In the above process of the present application, when there is an abnormality in the firewall, an alarm can be given in a timely manner to discover and solve the firewall abnormality problem.

[0088] Among them, the error rules include the exception information and time of the firewall rule, and the node information includes the location and time of the node, etc.

[0089] In the above Figure 1In the process shown, when the software-defined network controller issues a firewall rule, this application obtains the OpenFlow table generated during the data flow; based on a preset programming language, the firewall rule and the OpenFlow table are converted into a firewall rule verification process and an OpenFlow table execution process. Among them, the firewall rule verification process includes a first conversion module for converting the firewall rule verification process and a firewall rule verification process module for executing the firewall rule verification process. The OpenFlow table execution process includes a second conversion module for converting the OpenFlow table execution process and an OpenFlow table execution process module for executing the OpenFlow table execution process; compare the consistency of the parallel operation status of the firewall rule verification process and the OpenFlow table execution process, and generate a firewall verification result. Among them, the firewall verification result includes a firewall rule verification result and an OpenFlow table verification result. When the software-defined network controller issues a firewall rule, by concurrently executing the firewall rule verification process based on the firewall rule and the OpenFlow table execution process based on the OpenFlow table, and comparing the states of the two to judge the deadlock situation, the execution status of the firewall rule in the OpenFlow table can be accurately detected, and rule execution anomalies can be discovered in a timely manner. Through this method, the abnormal situation of the firewall can be accurately verified.

[0090] The foregoing has Figure 1 described the firewall verification method of the software-defined network. Next, in combination with Figures 4 - 5 describe the firewall verification device of the software-defined network.

[0091] Please refer to Figure 4 , which is a schematic block diagram of a firewall verification device 400 for a software-defined network provided in an embodiment of this application. This verification device 400 can be a module, program segment, or code on an electronic device. This verification device 400 corresponds to the above Figure 1 method embodiment and can execute Figure 1 each step involved in the method embodiment. The specific functions of this verification device 400 can be seen in the following description. To avoid repetition, the detailed description is appropriately omitted here.

[0092] Optionally, the verification device 400 includes:

[0093] An acquisition module 410, configured to obtain the OpenFlow table generated during the data flow when the software-defined network controller issues a firewall rule;

[0094] A conversion module 420 is configured to convert firewall rules and OpenFlow tables into a firewall rule verification process and an OpenFlow table execution process based on a preset programming language. The firewall rule verification process includes a first conversion module for converting the firewall rule verification process and a firewall rule verification process module for executing the firewall rule verification process. The OpenFlow table execution process includes a second conversion module for converting the OpenFlow table execution process and an OpenFlow table execution process module for executing the OpenFlow table execution process.

[0095] A verification module 430 is configured to compare the consistency of the parallel operation states of the firewall rule verification process and the OpenFlow table execution process and generate a firewall verification result. The firewall verification result includes a firewall rule verification result and an OpenFlow table verification result.

[0096] Optionally, the verification module is specifically configured to:

[0097] Compare whether the parallel operation states of the firewall rule verification process and the OpenFlow table execution process are consistent; when the parallel operation states of the firewall rule verification process and the OpenFlow table execution process are inconsistent, generate lock-up information for the firewall rules and the OpenFlow tables.

[0098] Optionally, the apparatus further includes:

[0099] An alarm module is configured to generate a log and give an alarm according to the lock-up information after the verification module compares the consistency of the parallel operation states of the firewall rule verification process and the OpenFlow table execution process and generates a firewall verification result. The log includes error rules and node information of the firewall rule verification process and the OpenFlow tables.

[0100] Optionally, the acquisition module is specifically configured to:

[0101] When a software-defined network controller controls multiple nodes to transmit data, acquire the firewall rules issued by the controller and the OpenFlow tables generated during the data transmission process. The application scenarios where the software-defined network controller controls multiple nodes to transmit data include: the enterprise internal network firewall protecting enterprise data and resources scenario, the data center network traffic transmission protecting network isolation and security policies between different users, verifying whether the firewall set by each user is correctly executed during cloud computing, and verifying the firewall rules in the software-defined network during telecommunication network communication data transmission.

[0102] Optionally, the conversion module is specifically configured to:

[0103] Select a preset script file and place it in a preset configuration file; execute the script corresponding to the programming language in the configuration file to obtain the firewall rule verification process and the OpenFlow table execution process.

[0104] Please refer to Figure 5The following is a schematic block diagram of a firewall verification device for a software-defined network provided in an embodiment of the present application. The device may include a memory 510 and a processor 520. Optionally, the device may further include: a communication interface 530 and a communication bus 540. The device corresponds to the above Figure 1 method embodiment and is capable of executing Figure 1 each step involved in the method embodiment. For the specific functions of the device, reference may be made to the descriptions below.

[0105] Specifically, the memory 510 is used to store computer-readable instructions.

[0106] The processor 520 is used to process the readable instructions stored in the memory and is capable of executing Figure 1 each step in the method.

[0107] The communication interface 530 is used to communicate signaling or data with other node devices. For example: for communicating with a server or a terminal, or for communicating with other device nodes. The embodiments of the present application are not limited thereto.

[0108] The communication bus 540 is used to realize the direct connection and communication between the above components.

[0109] Among them, the communication interface 530 of the device in the embodiment of the present application is used to communicate signaling or data with other node devices. The memory 510 may be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. Optionally, the memory 510 may further be at least one storage device located far from the aforementioned processor. The memory 510 stores computer-readable instructions. When the computer-readable instructions are executed by the processor 520, the electronic device executes the above Figure 1 shown method process. The processor 520 may be used on the verification device 400 and is used to execute the functions in the present application. Exemplarily, the above processor 520 may be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. The embodiments of the present application are not limited thereto.

[0110] The embodiment of the present application further provides a readable storage medium. When the computer program is executed by a processor, it executes the method process executed by the electronic device in the Figure 1 shown method embodiment.

[0111] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working process of the above-described device can refer to the corresponding process in the foregoing method, and will not be elaborated herein.

[0112] In summary, the embodiments of the present application provide a firewall verification method and device for a software-defined network. The method includes: when the software-defined network controller issues a firewall rule, obtaining an OpenFlow table generated during the data flow process; converting the firewall rule and the OpenFlow table into a firewall rule verification process and an OpenFlow table execution process based on a preset programming language, where the firewall rule verification process includes a first conversion module for converting the firewall rule verification process and a firewall rule verification process module for executing the firewall rule verification process, and the OpenFlow table execution process includes a second conversion module for converting the OpenFlow table execution process and an OpenFlow table execution process module for executing the OpenFlow table execution process; comparing the consistency of the parallel operation states of the firewall rule verification process and the OpenFlow table execution process, and generating a firewall verification result, where the firewall verification result includes a firewall rule verification result and an OpenFlow table verification result. By this method, the effect of accurately verifying abnormal situations of the firewall can be achieved.

[0113] In several embodiments provided by the present application, it should be understood that the disclosed device and method can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code includes one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0114] In addition, each functional module in various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.

[0115] When the above-mentioned functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.

[0116] The above are only the embodiments of this application and are not used to limit the protection scope of this application. For those skilled in the art, this application can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of this application shall be included in the protection scope of this application. It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0117] As mentioned above, this is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in this application, and all of them should be covered by the protection scope of this application.

[0118] It should be noted that in this text, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising a..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.

Claims

1. A method for verifying a firewall in a software-defined network, characterized in that: include: When the software-defined network controller issues firewall rules, the open flow table generated during the data flow is obtained; Converting the firewall rule and the open flow table into a firewall rule verification process and an open flow table execution process based on a preset programming language, wherein the firewall rule verification process includes a first conversion module for converting the firewall rule verification process and a firewall rule verification process module for executing the firewall rule verification process, and the open flow table execution process includes a second conversion module for converting the open flow table execution process and an open flow table execution process module for executing the open flow table execution process; The consistency of the parallel operation states of the firewall rule verification process and the open flow table execution process is compared, and a firewall verification result is generated, wherein the firewall verification result includes a firewall rule verification result and an open flow table verification result.

2. The method according to claim 1, characterized in that: The comparing the consistency of the parallel operation states of the firewall rule verification process and the open flow table execution process and generating a firewall verification result includes: Comparing whether the parallel operation states of the firewall rule verification process and the open flow table execution process are consistent; When the parallel operation states of the firewall rule verification process and the open flow table execution process are inconsistent, locking information of the firewall rule and the open flow table is generated.

3. The method according to claim 2, characterized in that After comparing the consistency of the parallel operation states of the firewall rule verification process and the open flow table execution process and generating a firewall verification result, the method further includes: A log is generated according to the deadlock information and an alarm is issued, wherein the log includes the firewall rule verification process and the error rules and node information of the open flow table.

4. The method according to any one of claims 1 to 3, characterized in that: When the software-defined network controller issues firewall rules, obtaining the open flow table generated during the data flow process includes: When a software-defined network controller controls multiple nodes to transmit data, the firewall rules issued by the controller and the open flow table generated during the data transmission process are obtained, wherein the application scenarios of the software-defined network controller controlling multiple nodes to transmit data include: enterprise internal network firewall protection of enterprise data and resource scenarios, data center network traffic transmission protection of network isolation and security policies between different users, verification of whether the firewall set by each user is correctly executed during cloud computing, and verification of firewall rules in the software-defined network during telecommunications network communication data transmission.

5. The method according to any one of claims 1 to 3, characterized in that: The converting the firewall rules and the open flow table into a firewall rule verification process and an open flow table execution process based on a preset programming language includes: Select the preset script file and place it in the preset configuration file; Execute the script corresponding to the programming language in the configuration file to obtain the firewall rule verification process and the open flow table execution process.

6. A software defined network firewall verification device, characterized in that: include: An acquisition module, used to acquire the open flow table generated during the data flow process when the software-defined network controller issues firewall rules; a conversion module, configured to convert the firewall rule and the open flow table into a firewall rule verification process and an open flow table execution process based on a preset programming language, wherein the firewall rule verification process comprises a first conversion module for converting the firewall rule verification process and a firewall rule verification process module for executing the firewall rule verification process, and the open flow table execution process comprises a second conversion module for converting the open flow table execution process and an open flow table execution process module for executing the open flow table execution process; The verification module is used to compare the consistency of the parallel operation states of the firewall rule verification process and the open flow table execution process, and generate a firewall verification result, wherein the firewall verification result includes a firewall rule verification result and an open flow table verification result.

7. The device according to claim 6, characterized in that The verification module is specifically used for: Comparing whether the parallel operation states of the firewall rule verification process and the open flow table execution process are consistent; When the parallel operation states of the firewall rule verification process and the open flow table execution process are inconsistent, locking information of the firewall rule and the open flow table is generated.

8. The device according to claim 7, characterized in that The device also includes: An alarm module is used for the verification module to generate a log and issue an alarm according to the lock information after comparing the consistency of the parallel operation status of the firewall rule verification process and the open flow table execution process and generating a firewall verification result, wherein the log includes error rules and node information of the firewall rule verification process and the open flow table.

9. The device according to any one of claims 6 to 8, characterized in that: The acquisition module is specifically used for: When a software-defined network controller controls multiple nodes to transmit data, the firewall rules issued by the controller and the open flow table generated during the data transmission process are obtained, wherein the application scenarios of the software-defined network controller controlling multiple nodes to transmit data include: enterprise internal network firewall protection of enterprise data and resource scenarios, data center network traffic transmission protection of network isolation and security policies between different users, verification of whether the firewall set by each user is correctly executed during cloud computing, and verification of firewall rules in the software-defined network during telecommunications network communication data transmission.

10. The device according to any one of claims 6 to 8, characterized in that: The conversion module is specifically used for: Select the preset script file and place it in the preset configuration file; Execute the script corresponding to the programming language in the configuration file to obtain the firewall rule verification process and the open flow table execution process.

Citation Information

Patent Citations

  • Firewall implementation method applied to software defined networking

    CN105338003A

  • Implementation method of software-defined firewall system

    CN110381025A