Network proxy method and system for protected computing environment

By deploying the routing rule scheduling module and multiple routing agents in a large-scale computing environment, dynamically update routing rules to adapt to changes in computing instances, solving the problem of disconnection between routing rules and computing instance status in the prior art, and improving the flexibility and reliability of the system.

CN119996287APending Publication Date: 2025-05-13SHANGHAI SPEEDSTONE INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510329333.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In a large-scale computing environment protected by security, it is difficult for the prior art to dynamically adjust routing rules to adapt to changes in computing instances, resulting in the disconnection of routing rules from the actual computing instance state, affecting the flexibility and reliability of the system.

Method used

Provides a network proxy method and system, by deploying a routing rule scheduling module and multiple routing agents, listens to computing instance change events in real time, updates routing rules dynamically, and automatically expands the number of routing agents during large-scale access to ensure system stability.

Benefits of technology

Dynamic update and maintenance of routing rules is realized, which significantly improves the flexibility and reliability of large-scale computing environments, and avoids routing rules failure problems caused by changes in computing instance state.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996287A_ABST
    Figure CN119996287A_ABST
Patent Text Reader

Abstract

A network proxy method and system for a protected computing environment is disclosed. The method relates to a routing rule scheduling module, a plurality of computing instances and a plurality of routing agents deployed in a protected large-scale computing environment, the plurality of routing agents are channels for externally accessing the plurality of computing instances, and the routing rule scheduling module is capable of sensing life cycle changes of the computing instances and transmitting the life cycle changes of the computing instances to the plurality of routing agents. According to the method and the device, the routing rule is dynamically adjusted according to the change of the computing instance, external security access to the protected computing environment is completed, and the routing rule can be scheduled to other routing agents when each routing agent fails, so that the high availability of the routing agents is realized, and the security access of the external security access to the protected computing environment is realized. And each routing agent has a protocol-level security agent mechanism, and security control of the routing agents can be realized through a three-layer protection strategy of beforehand limitation, in-event interception and after-event auditing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present disclosure relate to the field of computer technology, and more particularly to a network proxy method and system for a protected computing environment. Background Art

[0002] In a large-scale computing environment with security protection, various computing instances (including bare metal servers, containers, virtual machines, and edge devices) generally provide computing services. In order to ensure the security of computing instances and their networks, such environments implement strict network security policies, including multi-level firewall settings and physical network boundary protection measures, which prevent external direct access to computing instances through network requests and only allow direct access from the internal network.

[0003] However, in some cases, it is still necessary to allow external networks to access computing instances (such as SSH), in which case a proxy is required as an intermediary. The proxy is usually deployed on an edge server between the external network and the internal network, responsible for receiving external network requests and forwarding them to the internal target computing instance.

[0004] Given the dynamics and scale of the computing environment, this proxy needs to be able to dynamically adjust routing rules based on changes in computing instances and be able to scale itself during large-scale access to ensure high stability. Summary of the invention

[0005] The purpose of the embodiments of the present disclosure is to provide a network proxy method and system for a protected computing environment to solve the problems in the prior art.

[0006] According to a first aspect of an embodiment of the present disclosure, a network proxy method for a protected computing environment is provided, the network proxy method involving a routing rule scheduling module, a plurality of computing instances, and a plurality of routing agents deployed in the protected large-scale computing environment, the plurality of routing agents being channels for external access to the plurality of computing instances, the routing rule scheduling module performing:

[0007] Monitor computing instance change events;

[0008] When a computing instance change event is monitored, a routing rule change notification carrying a unique identifier of the corresponding computing instance is created;

[0009] sending the routing rule change notification to a corresponding routing agent among the plurality of routing agents; and

[0010] Update the routing information in the metadata that associates the compute instance with the routing agent;

[0011] The routing agent performs:

[0012] The local routing rules are updated according to the routing rule change notification, and the communication connection and request forwarding with the corresponding computing instance are controlled according to the updated routing rules.

[0013] In some embodiments, the computing instance change event is the creation of a computing instance, the routing rule change notification includes a unique identifier of the computing instance and a routing rule for establishing a communication connection with the computing instance, and sending the routing rule change notification to a corresponding routing agent among the multiple routing agents includes:

[0014] filtering out unavailable routing proxies from the plurality of routing proxies; and

[0015] The routing rule change notification is dispatched to the remaining routing agents.

[0016] In some embodiments, the computing instance change event is the destruction of a computing instance, the routing rule change notification includes a unique identifier of the computing instance and a notification of stopping the routing rule of the computing instance, and sending the routing rule change notification to a corresponding routing agent among the multiple routing agents includes:

[0017] Determining a routing agent associated with the computing instance according to the routing information; and

[0018] The routing rule change notification is sent to the associated routing agent.

[0019] In some embodiments, the computing instance change event is a change in the IP address of a computing instance, the routing rule change notification includes a unique identifier of the computing instance, a new IP address, and a new routing rule, and sending the routing rule change notification to a corresponding routing agent among the multiple routing agents includes:

[0020] Determining a routing agent associated with the computing instance according to the routing information; and

[0021] The routing rule change notification is sent to the associated routing agent.

[0022] In some embodiments, the routing rule scheduling module further performs:

[0023] Listen for routing proxy change events;

[0024] When a routing proxy change event is monitored, the routing rules of the routing proxy are dispatched to other routing proxies, and the routing information associating the computing instance with the routing proxy in the metadata is updated.

[0025] In some embodiments, the routing proxy to which the routing rule change notification is to be sent is determined according to a load balancing algorithm.

[0026] In some embodiments, the routing rule change notification currently to be scheduled is scheduled according to asynchronous scheduling logic.

[0027] In some embodiments, the network proxy method further includes: if there is no routing proxy that meets the conditions, waiting until a reasonable routing proxy is matched.

[0028] In some embodiments, each routing agent periodically reports its own status information.

[0029] In some embodiments, each routing agent is also equipped with a security mechanism that deeply analyzes network protocols to implement pre-emptive restriction of protocol functions, interception of high-risk commands during the process, and generation of structured audit logs afterwards.

[0030] According to a second aspect of an embodiment of the present disclosure, a network proxy system for a protected computing environment is provided, comprising:

[0031] Computing instance management system, used to manage computing instances;

[0032] A computing instance monitoring component, used to monitor and obtain computing instance change events in the computing instance management system, and create a routing rule change notification carrying a unique identifier of the corresponding computing instance;

[0033] Multiple routing agents respectively update local routing rules according to the routing rule change notification, and control the communication connection and request forwarding with the corresponding computing instance according to the changed routing rules;

[0034] The routing management component is used to send the routing rule change notification to the corresponding routing agent among the multiple routing agents, and maintain the routing information of the associated computing instance and the routing agent in the metadata.

[0035] In some embodiments, the computing instance change event is the creation of a computing instance, the routing rule change notification includes a unique identifier of the computing instance and a routing rule for establishing a communication connection with the computing instance, and the routing management component includes:

[0036] filtering out unavailable routing proxies from the plurality of routing proxies; and

[0037] The routing rule change notification is dispatched to other routing agents.

[0038] In some embodiments, the computing instance change event is the destruction of a computing instance, the routing rule change notification includes a unique identifier of the computing instance and a notification of stopping the routing rule of the computing instance, and the routing management component includes:

[0039] Determining a routing agent associated with the computing instance according to the routing information; and

[0040] The routing rule change notification is sent to the associated routing agent.

[0041] In some embodiments, the computing instance change event is a change in the IP address of a computing instance, the routing rule change notification includes a unique identifier and a new IP address of the computing instance, and the routing management component includes:

[0042] Determining a routing agent associated with the computing instance according to the routing information; and

[0043] The routing rule change notification is sent to the associated routing agent.

[0044] In some embodiments, the routing management component includes:

[0045] Listen for routing proxy change events;

[0046] When a routing proxy change event is monitored, the routing rules of the routing proxy are dispatched to other routing proxies, and the routing information associating the computing instance with the routing proxy in the metadata is updated.

[0047] In some embodiments, asynchronous scheduling logic is used to schedule the routing rule change notification currently to be scheduled.

[0048] In some embodiments, the computing instance monitoring component is formed as a plug-in to the computing instance management system.

[0049] The disclosed embodiment proposes a dynamic routing rule maintenance mechanism, which can perceive the life cycle changes of computing instances in the computing instance management system in real time (such as creation, destruction, IP change, etc.), and automatically update routing rules according to these changes. The difference between it and the prior art is that the network layer agent and application layer agent of the prior art usually need to manually configure static routing rules, and cannot actively perceive the changes of computing instances, resulting in the routing rules being out of touch with the actual computing instance status, while the present embodiment realizes the dynamic update and maintenance of routing rules. Moreover, the dynamic routing maintenance mechanism of the disclosed embodiment can significantly improve the flexibility and reliability of large-scale computing environments, and avoid the problem of routing rule failure caused by changes in computing instance status.

[0050] The dynamic routing maintenance mechanism of the disclosed embodiment can be formed as a portable lightweight plug-in for integration into a computing instance management system. The plug-in can monitor the life cycle events of the computing instance and dynamically generate routing rule change notifications. The difference from the prior art is that the proxy solution in the prior art is usually independent of the computing instance management system and lacks dynamic integration capabilities. The disclosed embodiment achieves seamless integration with the computing instance management system through a lightweight plug-in, which significantly improves the flexibility and scalability of the system. Moreover, the lightweight expansion mechanism of the disclosed embodiment can significantly improve the integration capabilities and dynamic management capabilities of large-scale computing environments. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] The above and other objects, features and advantages of the embodiments of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:

[0052] Figure 1 is a schematic diagram of a network structure used in an embodiment of the present disclosure;

[0053] Figure 2 is a flow chart of a routing rule scheduling process of a routing rule scheduling module provided in an embodiment of the present disclosure;

[0054] Figure 3 is a swim lane diagram provided by an embodiment of the present disclosure;

[0055] Figure 4 It is a swim lane diagram provided by another embodiment of the present disclosure. DETAILED DESCRIPTION

[0056] The embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. In each of the accompanying drawings, the same elements are represented by similar reference numerals. For the sake of clarity, the various parts in the accompanying drawings are not drawn to scale. In addition, some well-known parts may not be shown.

[0057] The following describes the embodiments of the present disclosure based on the embodiments, but the embodiments of the present disclosure are not limited to these embodiments. In the detailed description of the embodiments of the present disclosure below, some specific details are described in detail. For those skilled in the art, the embodiments of the present disclosure can be fully understood without the description of these details. In order to avoid confusing the essence of the embodiments of the present disclosure, well-known methods, processes, processes, components and circuits are not described in detail.

[0058] Unless the context clearly requires otherwise, the words "include", "comprising", and the like throughout the specification and claims should be interpreted as inclusive rather than exclusive or exhaustive; that is, as "including but not limited to". In the description of the embodiments of the present disclosure, it should be understood that the terms "first", "second", etc. are used for descriptive purposes only and are not to be understood as indicating or implying relative importance. In addition, in the description of the embodiments of the present disclosure, unless otherwise specified, "plurality" means two or more.

[0059] Terms used in this article:

[0060] Calculation Example

[0061] In a variety of technical environments such as cloud computing and network services, computing instances are a widely used concept, referring to any virtual or physical computing resource unit that can provide computing services to meet user computing needs. Common forms: Linux bare metal, containers, virtual machines, edge devices, etc. Computing instances are dynamic and have a flexible life cycle. Usually, their life cycle ends after a specific computing task is completed.

[0062] ●Network layer proxy

[0063] The network layer proxy is a proxy mechanism based on the network layer (also known as the 4-layer proxy), which is mainly used to forward data packets at the network layer. It usually makes routing decisions based on network layer information such as port numbers. In the network layer proxy, the proxy server forwards the user's request to the target computing instance according to the preset port mapping rules.

[0064] ●Application layer proxy

[0065] The application layer proxy is a proxy mechanism based on the application layer (also known as the 7-layer proxy), which is mainly used to forward data packets at the application layer. It can understand and process specific application layer protocols (such as SSH, VNC) and perform in-depth analysis and processing on the data. The present invention belongs to a type of application layer proxy.

[0066] ●Proxy Node

[0067] A proxy node is a node used to host proxy services. It is a server or device located at the boundary between the external network and the internal network, responsible for receiving user network requests and forwarding them to the target computing instance in the internal network.

[0068] SSH protocol

[0069] Secure Shell (SSH) is an encrypted network transmission protocol used to provide a secure transmission environment for network services in an insecure network. Users initiate requests through SSH clients to establish a secure connection with computing instances and implement remote operations (such as executing commands and transferring files).

[0070] The various embodiments of the present disclosure are further described in detail below in conjunction with the drawings and examples. Figure 1 It is a schematic diagram of the network structure applied in the embodiment of the present disclosure.

[0071] refer to Figure 1 The internal network 101 provides a protected large-scale computing environment, such as a private network within an enterprise or organization, including terminal devices (such as desktops, laptops) and servers. The servers are used to provide various services and software and hardware resources. Users of terminal devices can access the servers to obtain services and software and hardware resources. The external network 103 is an extension of the internal network. It can be the internal network of a partner, supplier or customer. Network devices 102 such as firewalls, routers, switches, etc. are arranged between the internal network 101 and the external network 103. On the one hand, these devices establish a communication connection between the internal network 101 and the external network 103 to realize the data flow between the internal network 101 and the external network 103. On the other hand, they provide secure access and security protection strategies to realize network security protection and secure access.

[0072] According to the background technology, computing instances are deployed on servers in the internal network 101, and the network device 102 prevents the external network 103 from directly accessing the computing instances through network requests, and only allows direct access between internal computing instances through network requests. However, in some cases, it is still necessary to allow external networks to access internal computing instances.

[0073] In order to meet this demand and adapt to the real-time changes of computing instances in the internal network 101, the embodiment of the present disclosure provides an edge server deployed in the internal network 101 or one or more routing agents deployed in the network device 102, and can automatically expand the number of routing agents during large-scale access to ensure the stability of the system. Each routing agent maintains routing rules with one or more computing instances in the internal network 101, and when receiving an external network request, forwards the external network request to the target computing instance according to the routing rules. At the same time, the embodiment of the present disclosure also provides a routing rule scheduling module presented in the form of a computer program. The routing rule scheduling module is deployed on a server in the internal network 101, and is used to perceive the life cycle changes of each computing instance in the internal network 101 (such as creation, destruction, IP change, etc.), and update the routing specification changes corresponding to these changes to the corresponding routing agent. In this way, the routing rule scheduling module and the routing agent collaborate to complete the external security access of the internal network 101, and have the ability to dynamically adjust the routing rules according to the changes of the computing instance. In addition, as a channel for external access to the internal network 101, the routing agent can also be equipped with a security mechanism that deeply analyzes network protocols, implements a three-layer protection strategy of restricting protocol functions in advance, intercepting high-risk commands during the process, and generating structured audit logs afterwards, so as to comprehensively ensure the security of the computing environment.

[0074] Figure 2 It is a flowchart of the routing rule scheduling process of the routing rule scheduling module provided in the embodiment of the present disclosure, including the following steps.

[0075] In step S201, computing instance change events are continuously monitored.

[0076] In step S202, a computing instance change event is monitored, and if yes, step S203 is executed.

[0077] In step S203, a routing rule change notification carrying a unique identifier of a corresponding computing instance is created.

[0078] In step S204, the created routing rule change notification is provided to corresponding routing agents of the plurality of routing agents so that they can perform routing rule management.

[0079] In step S205, routing information associating the computing instance with the routing agent in the metadata is updated.

[0080] The computing instance change events in this embodiment include, but are not limited to: the creation and destruction of computing instances, the unique identification of computing instances or the change of IP addresses. When a computing instance is monitored to be created, a routing rule change notification is created, which may include the unique identification of the created computing instance in the internal network 101. The notification may also include the routing rules for establishing a communication connection with the created computing instance, including the connection type (e.g., long connection, short connection), verification information (e.g., username and password for password connection), etc. Then, according to the internal scheduling logic (e.g., load balancing), the notification is sent to the target routing agent among the multiple routing agents, and the routing information associated with the target routing agent and the created computing instance is added to the metadata. The target routing agent adds a new routing rule locally based on the received notification, and uses the routing rule in subsequent operations to establish a communication connection with the created computing instance, and forwards external network requests through the connection. If the target routing agent maintains multiple routing rules, the associated data of the computing instance and the routing rule is also maintained locally.

[0081] When a computing instance is detected to be unavailable (destroyed), the routing rule change notification may include the unique identifier of the corresponding computing instance and a notification to stop the routing rule of the computing instance. Then, the target routing agent associated with the target routing rule is obtained by querying the routing information between the routing agent and the computing instance, and the routing rule change notification is sent to the target routing agent. After receiving the notification, the target routing agent determines the target routing rule based on the associated data between the computing instance and the routing rule, and stops using the target routing rule.

[0082] When a change in the IP address of a computing instance is detected, the routing rule change notification may include the unique identifier of the computing instance, the new IP address, and the new routing rule (if any). Then, the target routing proxy associated with the target routing rule is obtained by querying the routing information between the routing proxy and the computing instance, and the routing rule change notification is sent to the target routing proxy. After receiving the notification, the target routing proxy updates the associated data between the computing instance and the routing rule. If in this example, the identifier of the computing instance in the routing rule change notification changes, the routing rule change notification contains the unique identifier of the computing instance before and after the change.

[0083] The above-mentioned routing rule scheduling process also includes: monitoring the routing agent change events of each routing agent. When a routing agent change event with an abnormal routing agent status is monitored, the routing rules of the corresponding routing agent are scheduled to other routing agents, and the routing information of the associated computing instance and routing agent in the metadata is updated, or the scheduling of the routing agent is suspended for the current period of time.

[0084] The embodiment of the present disclosure also provides a network proxy system, which further decomposes the above routing rule scheduling module and organizes it into the following Figure 3 The functional modules shown are:

[0085] The computing instance management system 302 is used to manage computing instances. This system can be built based on the large-scale computing instance (virtual machines, containers, etc.) hosting and full life cycle management functions provided by platforms such as kubernetes and fastone-compute-platform.

[0086] The computing instance monitoring component 301 can be implemented as a portable lightweight plug-in of the computing instance management system, and its function is to monitor the life cycle events (creation, destruction, IP change, etc.) of the computing instance on the computing instance management system, and submit a routing rule change notification to the routing management component, which carries the unique identifier of the computing instance. In some embodiments, the computing instance monitoring component writes back information such as the computing instance, routing rules, and routing agents as metadata in the computing instance management system, so that users on the computing instance management system can view details such as the address and port of the routing agent.

[0087] The routing management component 303 is responsible for processing routing rule change notifications. When a routing rule change notification arrives, the routing rule change notification is dispatched to the routing agent on the corresponding agent node through the internal scheduling logic. If the notification is to create a routing rule, the scheduling process ensures that a reasonable routing agent can be found by filtering out unavailable routing agents and high-load routing agents. If the notification is to modify or delete the routing rule, the target routing agent is determined based on the routing information of the associated computing instance and the routing agent, and the notification is sent accordingly.

[0088] Routing agent 304, each routing agent is usually an instance deployed on the proxy node, and each routing agent is responsible for proxying the routing rules dispatched to the instance. This service is responsible for processing the forwarding of external network requests to internal computing instance requests. The multi-instance nature of the routing agent is to ensure the high reliability of the routing agent. When a specific routing agent is unavailable, the routing management will dispatch the routing rules to the available routing agent.

[0089] Figure 3 The interaction relationship of the above modules is also given, as follows.

[0090] Steps S1 to S5 provide a routing creation process, including: the computing instance monitoring component 301 monitors the creation of the computing instance from the computing instance management system 302, then notifies the routing management component 303, the routing management component 303 creates routing rules, and associates the routing rules with the unique identifier of the computing instance, thereby completing the binding of the routing rules and the computing instance; then the routing management component 303 schedules the routing rules to a suitable routing agent 304 according to the load balancing algorithm, and binds the unique identifier of the routing agent 304 to the computing instance; then, the computing instance monitoring component 301 monitors the successful scheduling of the routing rules from the routing management component 303, and notifies the computing instance management system 302 or the corresponding computing instance therein to update the routing information, and the routing information may include one or more of the following items: the unique identifier of the computing instance and the routing agent, the server IP address where the computing instance is located, and the server IP address where the routing agent is located.

[0091] Steps S6 to S10 provide a process for triggering route rescheduling when the state of a computing instance changes, including: the computing instance monitoring component 301 monitors the state change of the computing instance from the computing instance management system 302 (for example, IP address change, change from normal operation to suspension), and then notifies the routing management component 303 to adjust the state of the routing rules; then, the routing management component 303 notifies the corresponding routing agent 304 to adjust the state of the routing rules, and can reschedule the routing rules according to the load balancing algorithm. The computing instance monitoring component 301 monitors the successful scheduling of the routing rules from the computing instance management system 302, and notifies the computing instance management system 302 or the corresponding computing instance therein to update the routing information.

[0092] In steps S11 to S13, a routing change triggers the updating of routing information, including: when the routing management component 303 finds that a routing agent 304 is unavailable, the routing rules are rescheduled according to the load balancing algorithm to schedule the routing rules of the routing agent 304 to other routing agents 304, and then a routing agent change notification is sent to the computing instance monitoring component 301, and the computing instance monitoring component 301 notifies the computing instance management system 302 or the related computing instances to update the routing information.

[0093] Steps S14 to S16 provide a process for route deletion, including: when the computing instance monitoring component 301 detects that a computing instance is unavailable (the computing instance has been destroyed), the routing management component 303 is notified to delete the routing rules and disconnect the associated proxy connection. The routing management component 303 is disconnected from the associated routing proxy 304 accordingly.

[0094] Figure 4 The workflow of routing agent using SSH protocol is given.

[0095] In steps S01 to S08, the routing agent 304 receives the SSH connection from the client 306 and waits for it to send an authentication request. When the authentication request initiated by the client 306 arrives, the routing agent 304 extracts the user name from the request, searches the routing rule according to the user name in the request, extracts the configured target address from it, and establishes an SSH connection from the routing agent 304 to the computing instance 305. The routing agent 304 obtains the authentication method from the authentication request of the client 306, and adopts the following different authentication strategies according to different authentication methods: publickey authentication or password authentication. Publickey authentication is that the routing agent 304 initiates a publickey authentication process to the computing instance 305 according to the privatekey configured in the routing rule and the user name of the corresponding target computing instance 305 configured in the routing rule. Password authentication is that the routing agent 304 extracts the user name of the target computing instance 305 configured in the routing rule and the decrypted password of the client 306, and uses them as parameters of the password authentication request to initiate password authentication to the SSH connection of the computing instance 305. In addition, the routing agent 304 also notifies the routing management component 303 to record the port information of the client 306 and the computing instance 305 .

[0096] Steps S09 to S14 are the processing flow of the client 306 actively initiating a request, including: the client 306 initiates a request, the routing agent 304 performs security control and sends an event to the routing management component 303 so that the routing management component 303 records relevant information, the routing agent 304 forwards the request to the computing instance 305, the computing instance 305 provides a response result, and the routing agent 304 sends the response result to the client 306.

[0097] Steps S15 to S20 are the processing flow of the computing instance 305 actively initiating a request, including: the computing instance 305 initiates a request, the routing agent 304 performs security control and sends an event to the routing management component 303 so that the routing management component 303 records relevant information, the routing agent 304 forwards the request to the client 306, the client 306 responds to the result, and the routing agent 304 sends the response result to the computing instance 305.

[0098] Steps S21 to S22 are the routing proxy 304 closing the connection with the computing instance 305 and the client 306 respectively. The routing proxy 304 can synchronously wait for the connection closing signal from either the client 306 or the computing instance 305, close the connection of the other party and end the routing forwarding behavior.

[0099] exist Figure 4In the embodiment shown, both the client and the computing instance can initiate requests. The routing proxy adds security control to the request during the forwarding process, specifically supporting the three-layer security protection strategy, which is mainly as follows:

[0100] 1) Prior restrictions: Perform prior restrictions at the application layer level based on the support functions configured in the routing rules, such as command execution, X11 forwarding, SFTP file operations, forward tunnel, reverse tunnel function restrictions, etc.

[0101] 2) Interception during the process: Intercept dangerous operations during the request process, including: matching high-risk commands (such as sudo rm -rf / ) according to the regular expression configured in the routing rules and intercepting them during the execution of the command; and limiting whether the client can transfer data to the outside of the computing instance according to the SFTP data download switch configured in the routing rules.

[0102] 3) Post-audit: The routing management component 303 records events in the SSH protocol, so that post-audit can be performed, for example, command execution records, SFTP file operation records.

[0103] In summary, the network proxy method and system provided by the embodiment of the present disclosure can meet the needs of proxying network services for computing instances with short life cycles and large numbers in large-scale computing environments, introduce a dynamic routing maintenance mechanism, perceive the creation, destruction, IP change and other state changes of computing instances in real time, and automatically update routing rules. At the same time, in order to meet the reliability of the proxy function, a highly reliable proxy mechanism is introduced: based on multiple routing agents to achieve high availability, each routing agent is responsible for proxying the routing rules dispatched to it, and dynamically allocates the routing rules to the loaded routing agent through a load balancing method (CPU / memory / connection number multi-dimensional weight evaluation). In addition, a state fuse mechanism of the routing agent is introduced, and the routing rules are dispatched to other routing agents when a specific routing agent fails. In addition, in order to meet the security of the routing proxy function, the routing agent introduces a protocol-level security proxy mechanism, including: based on deep parsing of the network protocol, extracting the user identifier from the request and obtaining the target instance configured in the corresponding routing rule, and implementing a three-layer protection strategy to ensure the security of the protocol level.

[0104] In addition, the embodiments of the present disclosure also provide a computer device, including a memory, a processor, and computer instructions stored in the memory and executable by the processor. When the processor executes the computer instructions, it can implement the functions of each module in the network proxy method of the above embodiment and the routing rule scheduling system in the above embodiment.

[0105] The disclosed embodiments also provide a computer-readable storage medium on which computer instructions are stored. When the computer instructions are executed by the above-mentioned computer device, the functions of each module in the network proxy method of the above-mentioned embodiment and the routing rule scheduling system of the above-mentioned embodiment can be realized.

[0106] The embodiments according to the embodiments of the present disclosure are described above, and these embodiments do not describe all the details in detail, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and changes can be made based on the above description. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the embodiments of the present disclosure, so that those skilled in the art can make good use of the embodiments of the present disclosure and the modified use based on the embodiments of the present disclosure. The embodiments of the present disclosure are limited only by the claims and their full scope and equivalents.

Claims

1. A network proxy method for a protected computing environment, comprising: a routing rule scheduling module, a plurality of computing instances, and a plurality of routing agents deployed in the protected computing environment, wherein the plurality of routing agents are channels for external access to the plurality of computing instances, and the routing rule scheduling module executes: Monitor computing instance change events; When a computing instance change event is monitored, a routing rule change notification carrying a unique identifier of the corresponding computing instance is created; sending the routing rule change notification to a corresponding routing agent among the plurality of routing agents; and Update the routing information in the metadata that associates the compute instance with the routing agent; The routing agent performs: The local routing rules are updated according to the routing rule change notification, and the communication connection and request forwarding with the corresponding computing instance are controlled according to the updated routing rules.

2. The network proxy method according to claim 1, wherein: The computing instance change event is the creation of a computing instance, the routing rule change notification includes a unique identifier of the computing instance and a routing rule for establishing a communication connection with the computing instance, and sending the routing rule change notification to a corresponding routing agent among the multiple routing agents includes: filtering out unavailable routing proxies from the plurality of routing proxies; and The routing rule change notification is dispatched to the remaining routing agents.

3. The network proxy method according to claim 1, wherein: The computing instance change event is the destruction of a computing instance, the routing rule change notification includes a unique identifier of the computing instance and a notification of stopping the routing rule of the computing instance, and sending the routing rule change notification to a corresponding routing agent among the multiple routing agents includes: Determining a routing agent associated with the computing instance according to the routing information; and The routing rule change notification is sent to the associated routing agent.

4. The network proxy method according to claim 1, wherein: The computing instance change event is a change in the IP address of a computing instance, the routing rule change notification includes a unique identifier of the computing instance, a new IP address, and a new routing rule, and sending the routing rule change notification to a corresponding routing agent among the multiple routing agents includes: Determining a routing agent associated with the computing instance according to the routing information; and The routing rule change notification is sent to the associated routing agent.

5. The network proxy method according to claim 1, wherein the routing rule scheduling module further executes: Listen for routing proxy change events; When a routing proxy change event is monitored, the routing rules of the routing proxy are dispatched to other routing proxies, and the routing information associating the computing instance with the routing proxy in the metadata is updated.

6. The network proxy method according to claim 2, wherein: The routing proxy to which the routing rule change notification is to be sent is determined according to a load balancing algorithm.

7. The network proxy method according to claim 2, wherein: Schedule the routing rule change notification currently to be scheduled according to the asynchronous scheduling logic.

8. The network proxy method according to claim 2, further comprising: If there is no routing proxy that meets the conditions, wait until a reasonable routing proxy is matched.

9. The network proxy method according to claim 1, wherein: Each routing agent reports its own status information regularly.

10. The network proxy method according to claim 1, wherein: Each routing agent is also equipped with a security mechanism that deeply analyzes network protocols to implement pre-emptive restrictions on protocol functions, intercept high-risk commands during the process, and generate structured audit logs afterwards.

11. A network proxy system for use in a protected computing environment, comprising: Computing instance management system, used to manage computing instances; A computing instance monitoring component, used to monitor and obtain computing instance change events in the computing instance management system, and create a routing rule change notification carrying a unique identifier of the corresponding computing instance; Multiple routing agents, respectively updating local routing rules according to the routing rule change notification, and controlling communication connections and request forwarding with corresponding computing instances according to the updated routing rules; The routing management component is used to send the routing rule change notification to the corresponding routing agent among the multiple routing agents, and maintain the routing information of the associated computing instance and the routing agent in the metadata.

12. The network proxy system according to claim 11, wherein: The computing instance change event is the creation of a computing instance, the routing rule change notification includes the unique identifier of the computing instance and the routing rule for establishing a communication connection with the computing instance, and the routing management component includes: filtering out unavailable routing proxies from the plurality of routing proxies; and The routing rule change notification is dispatched to the remaining routing agents.

13. The network proxy system according to claim 11, wherein: The computing instance change event is the destruction of a computing instance, the routing rule change notification includes a unique identifier of the computing instance and a notification of stopping the routing rule of the computing instance, and the routing management component includes: Determining a routing agent associated with the computing instance according to the routing information; and The routing rule change notification is sent to the associated routing agent.

14. The network proxy system according to claim 11, wherein: The computing instance change event is a change in the IP address of a computing instance. The routing rule change notification includes a unique identifier of the computing instance and a new IP address. The routing management component includes: Determining a routing agent associated with the computing instance according to the routing information; and The routing rule change notification is sent to the associated routing agent.

15. The network proxy system according to claim 11, wherein: The routing management component includes: Listen for routing proxy change events; When a routing proxy change event is monitored, the routing rules of the routing proxy are dispatched to other routing proxies, and the routing information associating the computing instance with the routing proxy in the metadata is updated.

16. The network proxy system according to claim 12, wherein: The routing management component includes: Asynchronous scheduling logic is used to schedule the routing rule change notifications currently to be scheduled.

17. The network proxy system according to claim 11, wherein: The computing instance monitoring component is formed as a plug-in of the computing instance management system.