Stream visualization display method and device and electronic equipment
By grouping and displaying servers on multi-level canvases, the problem of slow and stuttering page loading caused by the large number of servers is solved, and clear visual display and improved page loading speed are achieved.
Patent Information
- Application Number
- CN202311515750.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-14
- Publication Date
- 2025-05-16
AI Technical Summary
In the case of a large number of servers, it is difficult for the prior art to effectively display the server and access relationship on the canvas, resulting in slow loading and stuttering of pages.
By obtaining the total number of servers in the target network, and limiting the maximum number of servers displayed on each layer of canvas, determining the number of packets and the number of packets, and then grouping and displaying the servers on a multi-level canvas, and visually displaying the server access relationship diagram on each layer of canvas.
By limiting the number of servers that can be displayed on each layer of canvas, the number of access relationships that can be displayed on a single layer of canvas is reduced, allowing users to clearly see the points and lines on the canvas, improving page loading speed and reducing lag problems.
Smart Images

Figure CN120017289A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a flow visualization display method, device and electronic equipment. Background Art
[0002] In the prior art, in order to realize the visualization of server access relationship, the adopted solutions mainly include: obtaining the initial access relationship of the virtual machine based on the tag information of the virtual machine, and then correcting the initial access relationship according to the data flow information, so as to generate the access relationship between the virtual machines.
[0003] However, based on the existing technology, when the number of servers is large, there are also many points (corresponding servers) and lines (corresponding access relationships) on the canvas, and the servers and access relationships on the canvas cannot be clearly seen, and there are problems of slow page loading and freezing. Summary of the invention
[0004] In view of the problems existing in the prior art, the present invention provides a flow visualization display method, device and electronic equipment.
[0005] The present invention provides a flow visualization display method, comprising:
[0006] Get the total number of servers in the target network;
[0007] According to the total number and the maximum number of servers that are limited to be displayed on each layer of the canvas, the number of groups and the number of group levels are determined; the number of groups indicates the number of groups that can be displayed on each layer of the canvas, and the number of group levels indicates the number of group levels corresponding to each group;
[0008] According to the number of groups and the number of group levels, the servers in the target network are displayed on each layer of canvas, and a server access relationship graph is visually displayed on each layer of canvas, wherein the server access relationship graph is generated based on the access relationship between the servers.
[0009] According to a flow visualization display method provided by the present invention, determining the number of groups and the number of grouping levels according to the total number and the maximum number of servers limited to be displayed on each layer of the canvas includes:
[0010] When the total number is greater than the first preset threshold, the number of groups M and the number of group levels N are calculated using formula (1) according to the total number and the maximum number of servers that are limited to be displayed on each layer of the canvas;
[0011] M N R>=W (1);
[0012] Wherein, W represents the total number; R represents the maximum number of servers limited to be displayed on each layer of the canvas; M, N and K are all greater than 1.
[0013] According to a flow visualization display method provided by the present invention, the server in the target network is displayed on each layer of canvas according to the number of groups and the number of group levels, including:
[0014] Determine the number of canvas layers according to the number of grouping levels;
[0015] According to the number of groups, the number of grouping levels and the number of canvas layers, the servers in the target network are grouped in multiple levels to obtain M groups; wherein the M groups are displayed on the same layer of canvas, each group corresponds to N grouping levels, and each grouping level corresponds to one layer of canvas; each grouping level includes multiple servers and M sub-groups; the number of servers included in each grouping level does not exceed the maximum number of servers limited to be displayed on each layer of canvas;
[0016] For a target grouping level corresponding to any group, the server and M sub-grouping levels included in the target grouping level are displayed on a target canvas corresponding to the target grouping level.
[0017] According to a flow visualization display method provided by the present invention, the method further includes:
[0018] For each layer of the canvas, a firewall access control policy is established based on the corresponding server access relationship diagram.
[0019] According to a flow visualization display method provided by the present invention, for each layer of canvas, a firewall access control strategy is established based on a corresponding server access relationship diagram, including:
[0020] Based on the target firewall function, create a global monitoring rule on the firewall rule page, wherein the global monitoring rule is used to monitor whether the access relationship between servers is abnormal or normal;
[0021] Based on the global monitoring rule, the connection lines of the normal access relationship are set to the first format, and the connection lines of the abnormal access relationship are set to the second format; the second format is used to represent the abnormal alarm;
[0022] For each layer of canvas, for each access relationship in the server access relationship diagram, if the access relationship is a normal access relationship, create an allow rule associated with the access relationship on the firewall rule page;
[0023] The global monitoring rule is modified into a global blocking rule, and based on the global blocking rule, the connection lines of the second format that have no access relationship associated with the permission rule are deleted.
[0024] According to a flow visualization display method provided by the present invention, the method further includes:
[0025] For any server in the target network, the permission rules associated with all server access relationships of the server are combined into a control policy, and the control policy is applied to the server.
[0026] According to a flow visualization display method provided by the present invention, the target firewall function is different from the firewall function provided by the server operating system.
[0027] The present invention also provides a flow visualization display device, comprising:
[0028] An acquisition module, used to obtain the total number of servers in the target network;
[0029] A determination module, used to determine the number of groups and the number of group levels according to the total number and the maximum number of servers that are limited to be displayed on each layer of the canvas; the number of groups indicates the number of groups that can be displayed on each layer of the canvas, and the number of group levels indicates the number of group levels corresponding to each group;
[0030] A display module is used to display the servers in the target network on each layer of canvas according to the number of groups and the number of group levels, and to visually display the server access relationship diagram on each layer of canvas, wherein the server access relationship diagram is generated based on the access relationship between the servers.
[0031] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, any of the above-mentioned flow visualization display methods is implemented.
[0032] The present invention also provides a non-transitory computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the flow visualization display method described in any one of the above is implemented.
[0033] The present invention also provides a computer program product, including a computer program, wherein when the computer program is executed by a processor, the computer program implements any of the above-mentioned flow visualization display methods.
[0034] The flow visualization display method, device and electronic device provided by the present invention determine the number of groups and the number of grouping levels according to the total number and the maximum number of servers limited to be displayed on each layer of canvas, and then perform multi-level grouping and display of servers in the target network on each layer of canvas according to the number of groups and the number of grouping levels, and visualize and display the server access relationship diagram on each layer of canvas. Since the number of servers that can be displayed on each layer of canvas is limited, the number of access relationships that can be displayed on a single layer of canvas is limited, so that the user can clearly see the points and lines on the canvas, which can improve the page loading speed and reduce the jamming problem. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0036] Figure 1 It is a flow chart of the flow visualization display method provided by the present invention;
[0037] Figure 2 It is a structural schematic diagram of the flow visualization display device provided by the present invention;
[0038] Figure 3 It is a schematic diagram of the physical structure of the electronic device provided by the present invention. DETAILED DESCRIPTION
[0039] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0040] Combine the following Figure 1-Figure 3 The flow visualization display method, device and electronic device of the present invention are described.
[0041] Figure 1 is a flow chart of the flow visualization display method provided by the present invention, such as Figure 1 As shown, the method includes steps 101 to 103, wherein:
[0042] Step 101: Obtain the total number of servers in the target network.
[0043] It should be noted that the flow visualization method provided by the present invention can be applicable to flow visualization scenarios. The execution subject of the method can be a flow visualization display device, such as an electronic device, a server, or a control module in the device for executing the flow visualization method provided by the present invention. The target network is, for example, a virtual network of a cloud platform.
[0044] Step 102: Determine the number of groups and the number of group levels according to the total number and the maximum number of servers that can be displayed on each layer of the canvas; the number of groups indicates the number of groups that can be displayed on each layer of the canvas, and the number of group levels indicates the number of group levels corresponding to each group.
[0045] Optionally, when the total number is greater than a first preset threshold, the number of groups and the number of grouping levels are determined according to the total number and a maximum number of servers limited to be displayed on each layer of the canvas (eg, a second preset threshold).
[0046] Optionally, the first preset threshold and the second preset threshold may be determined in advance by the user based on experience or demand. The second preset threshold is 256, for example.
[0047] Optionally, a specific implementation of step 102 may include, for example: when the total number is greater than a first preset threshold, according to the total number and the maximum number of servers limited to be displayed on each layer of the canvas (i.e., the second preset threshold), using formula (1) and formula (2) to calculate the number of groups M, the number of group levels N, and the number of canvas layers K;
[0048] M N R>=W (1);
[0049] K = N + 1 (2);
[0050] Wherein, W represents the total number; R represents the maximum number of servers that can be displayed on each layer of the canvas; M, N and K are all greater than 1. R is 256, for example.
[0051] Optionally, the number of canvas layers is determined according to the number of grouping levels. For example, based on formula (2), it can be known that K=N+1.
[0052] For example, if the total number of servers in the target network is 80,000, then it can be calculated that the number of groups M is 7, the number of group levels N is 3, and the number of canvas layers K is 4.
[0053] Step 103: Display the servers in the target network on each layer of canvas according to the number of groups and the number of group levels, and visualize the server access relationship graph on each layer of canvas, wherein the server access relationship graph is generated based on the access relationship between the servers.
[0054] Optionally, based on the number of groups, the number of grouping levels and the number of canvas layers, the servers in the target network are grouped and displayed in multiple levels; wherein the number of servers displayed on each layer of the canvas does not exceed the second preset threshold.
[0055] Optionally, the specific implementation method of displaying the servers in the target network on each layer of the canvas according to the number of groups and the number of group levels may include steps ac:
[0056] Step a, determining the number of canvas layers according to the number of grouping levels;
[0057] Step b: performing multi-level grouping of the servers in the target network according to the number of groups, the number of group levels and the number of canvas layers to obtain M groups; wherein the M groups are displayed on the same layer of canvas, each group corresponds to N group levels, and each group level corresponds to one layer of canvas; each group level includes multiple servers and M sub-groups; the number of servers included in each group level does not exceed the maximum number of servers limited to be displayed on each layer of canvas.
[0058] Optionally, M groups are displayed on the first layer of the canvas, and multiple servers are displayed on the last layer of the canvas.
[0059] For example, take the number of groups as M, the number of group levels as N, and the number of canvas layers as K=4. Display the M groups on the first canvas layer 1;
[0060] When any group (eg group 1) on the first layer canvas 1 is selected, another layer canvas 2 is displayed, on which the group level corresponding to group 1 is displayed, and the group level includes at least one server and M sub-groups.
[0061] When any one of the M subgroups (eg, subgroup 11) is selected, another layer of canvas 3 is displayed, on which the grouping level corresponding to subgroup 11 is displayed, and the grouping level includes at least one server and M sub-subgroups.
[0062] When any one of the M sub-sub-groups (eg, sub-sub-group 111) is selected, another layer of canvas 4 is displayed, on which the grouping level corresponding to sub-sub-group 111 is displayed, and the grouping level includes at least one server.
[0063] By limiting the upper limit of the number of servers at each grouping level, the number of servers that can be displayed on the canvas is limited, making it easier for users to see the points and lines on the canvas clearly.
[0064] Step c: for a target grouping level corresponding to any group, display the server and M sub-grouping levels included in the target grouping level on a target canvas corresponding to the target grouping level.
[0065] Optionally, the target grouping level refers to any grouping level.
[0066] Optionally, a server access relationship diagram is generated on each layer of the canvas according to the traffic data in the target network and the servers displayed on each layer of the canvas.
[0067] Optionally, after turning on the function switch, the server in the target network reports the traffic data. After obtaining the traffic data in the target network, a server access relationship diagram is generated on each layer of the canvas according to the traffic data in the target network and the servers displayed on each layer of the canvas, and each layer of the canvas corresponds to a different server access relationship diagram. Optionally, the server access relationship diagram is also a flow visualization diagram. For example, in the server access relationship diagram displayed on the L-th layer canvas, the access relationship between each server on the L-th layer canvas is displayed.
[0068] Optionally, for each layer of canvas, a firewall access control policy is established based on the corresponding server access relationship diagram.
[0069] Based on the firewall access control strategy adopted by the present invention, through fine-grained access control and isolation strategies, the workloads in the network (such as servers, virtual machines, etc.) are logically isolated to ensure that each network segment has only one computing resource, and the traffic needs to pass through the access control device to achieve micro-isolation requirements.
[0070] Optionally, for each layer of canvas, based on the corresponding server access relationship diagram, a specific implementation method of establishing a firewall access control policy includes, for example, steps (1)-(4):
[0071] Step (1), based on the target firewall function, create a global monitoring rule on the firewall rule page, wherein the global monitoring rule is used to monitor whether the access relationship between servers is an abnormal relationship or a normal relationship;
[0072] Step (2): based on the global monitoring rule, the connection lines of the normal access relationship are set to the first format, and the connection lines of the abnormal access relationship are set to the second format; the second format is used to represent the abnormal alarm.
[0073] Optionally, the global monitoring rule has the highest priority. The first format is green, for example, and the second format is red, bold or flashing. It should be noted that the target firewall function is different from the firewall function of the server operating system.
[0074] In the existing technology, micro-isolation solutions are implemented based on the firewall function of the server operating system. As the network topology continues to change, the firewall rules need to be constantly adjusted to adapt to the new network structure. If the firewall that comes with the operating system is used, it may be difficult to maintain and manage the firewall rules due to the lack of centralized management and monitoring tools.
[0075] The target firewall function provided in the present invention is not a firewall function provided by the operating system, which can avoid the problem of difficult management of firewall rules and limited security in the prior art.
[0076] Step (3): for each layer of the canvas, for each access relationship in the server access relationship diagram, if the access relationship is a normal access relationship, create an allow rule associated with the access relationship on the firewall rule page.
[0077] Optionally, determine whether the server access relationship is a normal access relationship; if it is determined that the server access relationship is a normal access relationship, create an allow rule associated with the server access relationship on the firewall rule page.
[0078] Optionally, for any server in the target network, the permission rules associated with all server access relationships of the server are combined into a control policy, and the control policy is applied to the server.
[0079] Generate monitoring alarms for server access relationships that have no associated permission rules.
[0080] Optionally, for a server access relationship without an associated allow rule, on a server access relationship diagram corresponding to the server access relationship, the connection line of the server access relationship is modified to a second format. For example, for a server access relationship without an associated allow rule, on a server access relationship diagram corresponding to the server access relationship, the connection line of the server access relationship is modified to red.
[0081] Step (4), modifying the global monitoring rule into a global blocking rule, and deleting the connection lines of the second format that have no access relationship associated with the permission rule based on the global blocking rule.
[0082] Optionally, the global blocking rule is used to delete the connection line of the server access relationship that has no associated permission rule.
[0083] The flow visualization display method provided by the present invention determines the number of groups and the number of grouping levels according to the total number and the maximum number of servers that are limited to be displayed on each layer of canvas, and then performs multi-level grouping and display of the servers in the target network on each layer of canvas according to the number of groups and the number of grouping levels, and visualizes the server access relationship diagram on each layer of canvas. Since the number of servers that can be displayed on each layer of canvas is limited, the number of access relationships that can be displayed on a single layer of canvas is limited, so that the user can clearly see the points and lines on the canvas, which can improve the page loading speed and reduce the jamming problem.
[0084] The flow visualization display device provided by the present invention is described below. The flow visualization display device described below and the flow visualization display method described above can be referred to each other.
[0085] Figure 2 Schematic diagram of the structure of the flow visualization display device provided by the present invention; Figure 2 As shown, the flow visualization display device 200 includes: an acquisition module 201, a determination module 202 and a display module 203; wherein,
[0086] An acquisition module 201 is used to acquire the total number of servers in the target network;
[0087] The determination module 202 is used to determine the number of groups and the number of group levels according to the total number and the maximum number of servers that are limited to be displayed on each layer of the canvas; the number of groups indicates the number of groups that can be displayed on each layer of the canvas, and the number of group levels indicates the number of group levels corresponding to each group;
[0088] The display module 203 is used to display the servers in the target network on each layer of canvas according to the number of groups and the number of group levels, and to visually display the server access relationship diagram on each layer of canvas, wherein the server access relationship diagram is generated based on the access relationship between the servers.
[0089] The flow visualization display device provided by the present invention determines the number of groups and the number of grouping levels according to the total number and the maximum number of servers that are limited to be displayed on each layer of canvas, and then performs multi-level grouping and display of the servers in the target network on each layer of canvas according to the number of groups and the number of grouping levels, and visualizes the server access relationship diagram on each layer of canvas. Since the number of servers that can be displayed on each layer of canvas is limited, the number of access relationships that can be displayed on a single layer of canvas is limited, so that the user can clearly see the points and lines on the canvas, which can improve the page loading speed and reduce the jamming problem.
[0090] Optionally, the determining module 202 is specifically configured to:
[0091] When the total number is greater than the first preset threshold, the number of groups M and the number of group levels N are calculated using formula (1) according to the total number and the maximum number of servers that are limited to be displayed on each layer of the canvas;
[0092] M N R>=W (1);
[0093] Wherein, W represents the total number; R represents the maximum number of servers limited to be displayed on each layer of the canvas; M, N and K are all greater than 1.
[0094] Optionally, the display module 203 is specifically used to:
[0095] Determine the number of canvas layers according to the number of grouping levels;
[0096] According to the number of groups, the number of grouping levels and the number of canvas layers, the servers in the target network are grouped in multiple levels to obtain M groups; wherein the M groups are displayed on the same layer of canvas, each group corresponds to N grouping levels, and each grouping level corresponds to one layer of canvas; each grouping level includes multiple servers and M sub-groups; the number of servers included in each grouping level does not exceed the maximum number of servers limited to be displayed on each layer of canvas;
[0097] For a target grouping level corresponding to any group, the server and M sub-grouping levels included in the target grouping level are displayed on a target canvas corresponding to the target grouping level.
[0098] Optionally, the flow visualization display device 200 further includes:
[0099] A module is established to establish a firewall access control policy for each layer of canvas based on the corresponding server access relationship diagram.
[0100] Optionally, the establishing module is specifically used to:
[0101] Based on the target firewall function, create a global monitoring rule on the firewall rule page, wherein the global monitoring rule is used to monitor whether the access relationship between servers is abnormal or normal;
[0102] Based on the global monitoring rule, the connection lines of the normal access relationship are set to the first format, and the connection lines of the abnormal access relationship are set to the second format; the second format is used to represent the abnormal alarm;
[0103] For each layer of canvas, for each access relationship in the server access relationship diagram, if the access relationship is a normal access relationship, create an allow rule associated with the access relationship on the firewall rule page;
[0104] The global monitoring rule is modified into a global blocking rule, and based on the global blocking rule, the connection lines of the second format that have no access relationship associated with the permission rule are deleted.
[0105] Optionally, the flow visualization display device 200 further includes:
[0106] The policy generation module is used to form a control policy for any server in the target network by combining the permission rules associated with all server access relationships of the server and applying the control policy to the server.
[0107] Optionally, the target firewall function is different from a firewall function provided by the server operating system.
[0108] Figure 3 is a schematic diagram of the physical structure of the electronic device provided by the present invention, such as Figure 3 As shown, the electronic device may include: a processor 310, a communication interface 320, a memory 330 and a communication bus 340, wherein the processor 310, the communication interface 320 and the memory 330 communicate with each other through the communication bus 340. The processor 310 may call the logic instructions in the memory 330 to execute the flow visualization display method, which includes:
[0109] Get the total number of servers in the target network;
[0110] According to the total number and the maximum number of servers that are limited to be displayed on each layer of the canvas, the number of groups and the number of group levels are determined; the number of groups indicates the number of groups that can be displayed on each layer of the canvas, and the number of group levels indicates the number of group levels corresponding to each group;
[0111] According to the number of groups and the number of group levels, the servers in the target network are displayed on each layer of canvas, and a server access relationship graph is visually displayed on each layer of canvas, wherein the server access relationship graph is generated based on the access relationship between the servers.
[0112] In addition, the logic instructions in the above-mentioned memory 330 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when it is sold or used as an independent product. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.
[0113] On the other hand, the present invention further provides a computer program product, the computer program product includes a computer program, the computer program can be stored in a non-transitory computer-readable storage medium, when the computer program is executed by a processor, the computer can execute the flow visualization display method provided by the above methods, the method includes:
[0114] Get the total number of servers in the target network;
[0115] According to the total number and the maximum number of servers that are limited to be displayed on each layer of the canvas, the number of groups and the number of group levels are determined; the number of groups indicates the number of groups that can be displayed on each layer of the canvas, and the number of group levels indicates the number of group levels corresponding to each group;
[0116] According to the number of groups and the number of group levels, the servers in the target network are displayed on each layer of canvas, and a server access relationship graph is visually displayed on each layer of canvas, wherein the server access relationship graph is generated based on the access relationship between the servers.
[0117] In another aspect, the present invention further provides a non-transitory computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the flow visualization display method provided by the above methods is implemented, and the method includes:
[0118] Get the total number of servers in the target network;
[0119] According to the total number and the maximum number of servers that are limited to be displayed on each layer of the canvas, the number of groups and the number of group levels are determined; the number of groups indicates the number of groups that can be displayed on each layer of the canvas, and the number of group levels indicates the number of group levels corresponding to each group;
[0120] According to the number of groups and the number of group levels, the servers in the target network are displayed on each layer of canvas, and a server access relationship graph is visually displayed on each layer of canvas, wherein the server access relationship graph is generated based on the access relationship between the servers.
[0121] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.
[0122] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0123] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A flow visualization display method, characterized in that: include: Get the total number of servers in the target network; According to the total number and the maximum number of servers that are limited to be displayed on each layer of the canvas, the number of groups and the number of group levels are determined; the number of groups indicates the number of groups that can be displayed on each layer of the canvas, and the number of group levels indicates the number of group levels corresponding to each group; According to the number of groups and the number of group levels, the servers in the target network are displayed on each layer of canvas, and a server access relationship graph is visually displayed on each layer of canvas, wherein the server access relationship graph is generated based on the access relationship between the servers.
2. The flow visualization display method according to claim 1, characterized in that: Determining the number of groups and the number of grouping levels according to the total number and the maximum number of servers limited to be displayed on each layer of the canvas includes: When the total number is greater than the first preset threshold, the number of groups M and the number of group levels N are calculated using formula (1) according to the total number and the maximum number of servers that are limited to be displayed on each layer of the canvas; M N R>=W (1); Wherein, W represents the total number; R represents the maximum number of servers limited to be displayed on each layer of the canvas; M, N and K are all greater than 1.
3. The flow visualization display method according to claim 1, characterized in that: The displaying of the servers in the target network on each layer of canvas according to the number of groups and the number of group levels includes: Determine the number of canvas layers according to the number of grouping levels; According to the number of groups, the number of grouping levels and the number of canvas layers, the servers in the target network are grouped in multiple levels to obtain M groups; wherein the M groups are displayed on the same layer of canvas, each group corresponds to N grouping levels, and each grouping level corresponds to one layer of canvas; each grouping level includes multiple servers and M sub-groups; the number of servers included in each grouping level does not exceed the maximum number of servers limited to be displayed on each layer of canvas; For a target grouping level corresponding to any group, the server and M sub-grouping levels included in the target grouping level are displayed on a target canvas corresponding to the target grouping level.
4. The flow visualization display method according to claim 1, characterized in that: The method further comprises: For each layer of the canvas, a firewall access control policy is established based on the corresponding server access relationship diagram.
5. The flow visualization display method according to claim 4, characterized in that: For each layer of the canvas, a firewall access control strategy is established based on the corresponding server access relationship diagram, including: Based on the target firewall function, create a global monitoring rule on the firewall rule page, wherein the global monitoring rule is used to monitor whether the access relationship between servers is abnormal or normal; Based on the global monitoring rule, the connection lines of the normal access relationship are set to the first format, and the connection lines of the abnormal access relationship are set to the second format; the second format is used to represent the abnormal alarm; For each layer of canvas, for each access relationship in the server access relationship diagram, if the access relationship is a normal access relationship, create an allow rule associated with the access relationship on the firewall rule page; The global monitoring rule is modified into a global blocking rule, and based on the global blocking rule, the connection lines of the second format that have no access relationship associated with the permission rule are deleted.
6. The flow visualization display method according to claim 5, characterized in that: The method further comprises: For any server in the target network, the permission rules associated with all server access relationships of the server are combined into a control policy, and the control policy is applied to the server.
7. The flow visualization display method according to claim 5 or 6, characterized in that: The target firewall function is different from the firewall function that comes with the server operating system.
8. A flow visualization display device, characterized in that: include: An acquisition module, used to obtain the total number of servers in the target network; A determination module, used to determine the number of groups and the number of group levels according to the total number and the maximum number of servers that are limited to be displayed on each layer of the canvas; the number of groups indicates the number of groups that can be displayed on each layer of the canvas, and the number of group levels indicates the number of group levels corresponding to each group; A display module is used to display the servers in the target network on each layer of canvas according to the number of groups and the number of group levels, and to visually display the server access relationship diagram on each layer of canvas, wherein the server access relationship diagram is generated based on the access relationship between the servers.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the flow visualization display method as described in any one of claims 1 to 7 is implemented.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the flow visualization display method according to any one of claims 1 to 7 is implemented.
11. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the flow visualization display method according to any one of claims 1 to 7 is implemented.