Method and system for cloud management platform to apply for hillstone safety service

Through the automated configuration and management of the cloud management platform, the cumbersome application and configuration methods of existing cloud security services are solved, efficient and flexible cloud security service management is achieved, and the security and efficiency of the cloud environment are improved.

CN120034349APending Publication Date: 2025-05-23SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411306553.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-09-19
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The existing cloud security service application and configuration methods are cumbersome and lack flexibility, making it difficult to meet the security and efficiency requirements of different users.

Method used

Provides a method and system for applying for Shanshi security services on the cloud management platform. Users log in through the cloud management platform, select the required service type, fill in and submit the security service application form, and the cloud management platform automatically reviews and automatically configures security services based on the predefined security configuration template.

Benefits of technology

It simplifies the application and configuration process of cloud security services, improves security and efficiency, provides the ability to centrally manage and automatically configure, and ensures comprehensive protection of the cloud environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034349A_ABST
    Figure CN120034349A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of cloud computing, in particular to a method and system for applying for a hillstone safety service by a cloud management platform, and the method comprises the following steps: a user logs in the system through the cloud management platform; selecting a required hillstone safety service type in the platform; the user fills in and submits a security service application form, wherein the form contains necessary configuration information; the cloud management platform system automatically checks the user application, and automatically configures a hillstone safety service according to a predefined safety configuration template; the method and the system for applying for the hillstone security service by the cloud management platform have the beneficial effects that the security is improved, the cloud management platform provides integrated security service, and data and applications can be effectively protected from network attacks and unauthorized access. These services include firewall management, intrusion detection, and anti-virus protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cloud computing technology, and specifically to a method and system for a cloud management platform to apply for Shanshi security services. Background Art

[0002] With the rapid development of cloud computing technology, more and more enterprises are migrating their businesses to cloud platforms. However, this migration also brings the complexity of security management. Enterprises have a growing demand for cloud security services. Cloud security services are designed to protect data, applications, and infrastructure in cloud platforms, and achieve this goal through a series of policies, controls, and technologies.

[0003] The existing cloud security service application and configuration methods are usually cumbersome and lack flexibility, making it difficult to meet the security and efficiency requirements of different users. In this context, the cloud management platform, as a tool for unified management of cloud resources, needs to integrate cloud security services to provide comprehensive cloud environment protection, and a simplified and flexible method for applying for cloud security services on the cloud management platform is needed. Summary of the invention

[0004] The purpose of the present invention is to provide a method and system for applying for Shanshi security services on a cloud management platform to solve the problems raised in the above-mentioned background technology.

[0005] To achieve the above object, the present invention provides the following technical solution: a method for a cloud management platform to apply for Hillstone security services, the method comprising the following steps:

[0006] Users log in to the system through the cloud management platform;

[0007] Select the type of Hillstone security service you need on the platform;

[0008] The user fills in and submits the security service application form, which contains the necessary configuration information;

[0009] The cloud management platform system automatically reviews user applications and automatically configures Hillstone security services based on predefined security configuration templates;

[0010] After the system configuration is completed, the user is informed through the notification mechanism that the security service has been successfully started, and all VM virtual machines are ensured to be under the security protection control of Shanshi Cloud.

[0011] Preferably, the following security policy setting principles are also included:

[0012] Adopting the whitelist mode, all access is blocked by default, requiring cloud tenants to explicitly enable corresponding security policies for VMs to access network resources;

[0013] The source / destination IP address settings in the security policy must meet the following requirements: at least one parameter is the IP address of the tenant VM, with a 32-bit mask. It is forbidden to configure the IP segment to IP segment or Any to Any security policy.

[0014] The action parameters of the security policy include "Allow" and "Block", but the default setting is "Block" to ensure security.

[0015] Preferably, the following security policy management mechanism is also included:

[0016] The unique ID of the cloud tenant is automatically filled in the description of the security policy to distinguish and isolate the security policy sets of different tenants;

[0017] When a VM is deleted, a mechanism is automatically triggered to delete or mark the corresponding security policy as invalid, guiding the cloud tenant to perform manual cleanup.

[0018] Preferably, the definition rules of the custom service name are also included:

[0019] The custom service name must contain the unique identifier of the cloud tenant to prevent service configurations between different tenants from interfering with each other.

[0020] Preferably, the settings of IPS and AV functions are also included:

[0021] The operation actions of IPS and AV functions include "alarm" and "block", and the default setting is "alarm";

[0022] The cloud platform does not provide detailed IPS and AV function configuration operations, but only executes according to predefined default templates. It also designs a mechanism to regularly check and proofread configuration information to ensure the consistency of configuration information between the cloud platform and Shanshi Cloud products.

[0023] A cloud management platform applies for a Hillstone security service system, the system comprising:

[0024] User interface module, used for user login and submission of security service applications;

[0025] Audit module, automatically audits security service applications submitted by users;

[0026] The configuration module automatically configures the Hillstone security service for approved applications based on predefined configuration templates, ensuring that all VMs are protected and controlled by Hillstone Cloud.

[0027] Monitoring module, real-time monitoring of the operating status of Hillstone security services;

[0028] Notification module, which sends service startup notifications and any abnormal alerts to users;

[0029] The system adopts a whitelist mode when implementing security policies. All access is blocked by default. Access to network resources is allowed only after the cloud tenant has enabled the corresponding security policy for its VM, and the cloud tenant cannot perform deprotection operations.

[0030] Preferably, the security policy configuration requirements include:

[0031] At least one of the source / destination IP addresses is the tenant's VM IP address, with a 32-bit mask.

[0032] It is forbidden to configure the security policy from IP segment to IP segment;

[0033] It is forbidden to configure the Any to Any security policy.

[0034] The action parameters of the security policy include "allow" and "block". The default setting is "block", but in view of the principle error, it should be clearly set to "allow" in actual implementation and must be explicitly specified by the tenant;

[0035] The unique ID of the cloud tenant is automatically filled in the description information of the security policy to isolate the security policy sets of different tenants.

[0036] Preferably, a linkage mechanism between security policies and VM lifecycle management is also included. When a VM is deleted, the system automatically deletes or marks the corresponding security policy as invalid, and guides the cloud tenant to perform manual cleanup.

[0037] Preferably, the custom service name definition format is also automatically filled with the unique identifier of the cloud tenant to prevent the custom service configurations between different cloud tenants from interfering with each other.

[0038] Preferably, it also includes: settings of IPS and AV functions, whose operation actions include "alarm" and "blocking", the default setting is "alarm", and currently no detailed configuration operation of the function is provided to the cloud tenant, and only the preset default template function is executed;

[0039] The regular inspection and proofreading function is used to verify the configuration information in the cloud platform and Shanshi Cloud products to ensure the consistency and security of the system.

[0040] Compared with the prior art, the present invention has the following beneficial effects:

[0041] The method and system for applying for Hillstone security services on a cloud management platform proposed in the present invention improve security. The cloud management platform provides integrated security services that can effectively protect data and applications from network attacks and unauthorized access. These services include firewall management, intrusion detection, and anti-virus protection.

[0042] Simplified management: Through the cloud management platform, enterprises can centrally manage security policies and configurations, reducing the complexity of multi-platform management and the risks of manual operations, and ensuring consistency across all environments.

[0043] Cost savings: Cloud management platforms usually adopt an on-demand billing model. Enterprises can apply for and pay for security services based on actual needs, avoiding the high upfront investment and maintenance costs of traditional security infrastructure.

[0044] Enhanced compliance: Many industries have strict data protection and privacy regulations. The security services provided by the cloud management platform can help enterprises meet these regulatory requirements, ensure compliance and simplify the reporting process through automated tools and audit functions.

[0045] Real-time monitoring and response: The cloud management platform provides real-time security monitoring and rapid response capabilities, which can promptly detect and respond to security threats and reduce potential losses and risks.

[0046] Automation and intelligence: With the help of artificial intelligence and machine learning, the security services of the cloud management platform can automatically identify abnormal behaviors and potential threats, provide intelligent security protection measures, and improve the overall security protection level.

[0047] Elasticity and scalability: The security services provided by the cloud management platform are highly elastic and scalable, and can dynamically adjust security resources according to business needs to ensure that security measures can keep pace when the business grows. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1 This is a system architecture diagram of the present invention;

[0049] Figure 2 The figure is a flow chart of the method of the present invention. DETAILED DESCRIPTION

[0050] In order to make the purpose and technical solution of the present invention clearly and completely described, and the advantages more clearly understood, the embodiments of the present invention are further described in detail with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are part of the embodiments of the present invention, not all of them, and are only used to explain the embodiments of the present invention, and are not used to limit the embodiments of the present invention. All other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0051] For example, see Figure 2 The present invention provides a technical solution: a method for a cloud management platform to apply for Hillstone security services, the method comprising the following steps:

[0052] Users log in to the system through the cloud management platform;

[0053] Select the type of Hillstone security service you need on the platform;

[0054] The user fills in and submits the security service application form, which contains the necessary configuration information;

[0055] The cloud management platform system automatically reviews user applications and automatically configures Hillstone security services based on predefined security configuration templates;

[0056] After the system configuration is completed, the user is informed through the notification mechanism that the security service has been successfully started, and all VM virtual machines are ensured to be under the security protection control of Shanshi Cloud.

[0057] The following design scheme takes Shanshi Yunge's security service as an example, design principles and requirements:

[0058] 1. All VMs must be subject to the protection control of Cloud Grid, that is, all VMs must be protected by Cloud Grid;

[0059] 2. The security policy adopts the whitelist mode, that is, the default control is to block all. Cloud tenants must enable the corresponding security policy for their VMs before they can access network resources;

[0060] 3. Due to the constraints of "Principle a", cloud tenants cannot perform the "deprotection" operation;

[0061] 4. Requirements for setting source / destination IP addresses in security policies:

[0062] a. In the source / destination IP, at least one parameter is the tenant's VM IP address (32-bit mask)

[0063] b. Security policy configuration from IP segment to IP segment is not allowed;

[0064] c. Security policy configuration from Any (any address) to Any is not allowed;

[0065] 5. The action parameters of the security policy include "allow" and "block", and the default setting is "allow";

[0066] 6. In the description of the security policy, the cloud platform needs to fill in the unique identifier of the cloud tenant during design to facilitate search and proofreading, and to isolate the security policy sets that can be seen by different tenants;

[0067] 7. Security policies must be managed with the lifecycle of VMs. When a VM is deleted, the corresponding security policies can be automatically deleted, or a prompt indicating that the policy is invalid can be given to guide cloud tenants to manually delete the security policies.

[0068] 8. The name definition format of the custom service. The cloud platform must also be able to fill in the unique identifier of the cloud tenant during design to avoid mutual interference between custom service configurations of different cloud tenants.

[0069] 9. Regarding the settings of IPS and AV functions, there are two operation actions: "alarm" and "block", and the default value is set to "alarm". Note: Currently, detailed configuration operations of the functions are not provided to cloud tenants, and can only be executed according to the default template functions.

[0070] 10. Since there are some configuration information in the cloud platform and Shanshi Cloud products, the cloud platform needs to consider the function design of regular inspection and proofreading.

[0071] Application scenario: Regarding security policy management, the page design presented to cloud tenants involves the following 9 main operation options:

[0072]

[0073] The above options are mainly used for:

[0074] (1) Add policies for tenants who add new VMs

[0075] If each tenant adds a new business virtual machine, it is necessary to add security policies and add protection

[0076] (2) Tenants add or modify existing security policies

[0077] Tenants can add or edit existing policies for each tenant.

[0078] (3) Tenants can perform operations that bypass the cloud firewall

[0079] When debugging a service failure, the cloud firewall performs bypass and unbypass operations.

[0080] Cloud management platform page design:

[0081] 1) Page 1

[0082] ① Home page: Create a new VM for the tenant and compile a security policy (supports creating multiple policies)

[0083] Options involved: Options 1-7 in Table 1

[0084] ②Sub-page: presents a list of security policies, allowing tenants to edit, delete, and shift security policies, including creating custom service operations.

[0085] Options involved: Options 1-7 in Table 1

[0086] 2) Page 2

[0087] ③ Home page: presents a list of all security policies of the tenant, and the functional operations include: add, delete, modify, check, and move. Among them, the "add" and "modify" operations require jumping to page 3 and page 4, and other operations can be completed directly on the home page.

[0088] 3) Page 3

[0089] ① Home page: Add a new security policy, which is one of the sub-pages of page 2 and contains the operation of creating a custom service.

[0090] Options involved: Options 1-8 in Table 1

[0091] 4) Page 4

[0092] ① Home page: Modify security policy, which is also one of the subpages of page 2, and contains the operation of creating a custom service.

[0093] Options involved: Options 1-8 in Table 1

[0094] 5) Page 5

[0095] ① Home page: tenant bypass / unbypass cloud firewall control operations. This operation only provides customers with a debugging operation to bypass cloud firewall control when business abnormalities occur.

[0096] Options involved: 9 options in Table 1

[0097] When an abnormal access occurs to a business VM, the tenant can perform a Bypass operation on each of their own business VMs to temporarily bypass the security control of the cloud firewall. After the problem is resolved, the tenant can perform an UnBypass operation to bring the VM back under the control of the cloud firewall.

[0098] Entrance design

[0099] 1) When tenants create tenant networks and VMs

[0100] Principle: Only create policies at the vm_IP level. When the vm is recycled by the cloud management platform, the cloud management platform automatically deletes the policy of the vm.

[0101] ①After the tenant creation (network, vm) is completed,

[0102] ② Enter the security configuration and create multiple security policies for the VM

[0103] ③ Add protection (hide this operation from tenants). After the policy is created, add protection for the newly added VM

[0104] ④Complete (Submit)

[0105] 2) Tenant security policy table

[0106] Displays all security policies of the tenant and supports the following actions:

[0107] ① Deletion, query, and movement of security policies

[0108] ②Add new security policies

[0109] ③Modify security policy

[0110] 3) Tenant VM Bypass

[0111] ①Tenants select VMs that need to be Bypassed / UnBypassed in a list format.

[0112] ② The tenant’s VM protection status is recorded by the cloud platform or queried through the YunGe product and then presented to the tenant.

[0113] ③Tenants need to be prompted that this operation is used for problem debugging, with the purpose of bypassing the control of the cloud firewall for the traffic of the corresponding VM virtual machine.

[0114] 4) Cloud firewall abnormality

[0115] When a YunGe product fails, the situational awareness system can obtain this status and message.

[0116] The cloud management platform can work with the situational awareness system to present this status to cloud tenants and inform them that the affected VMs have lost cloud firewall protection, thereby proactively contacting administrators for processing.

[0117] Embodiment 2, based on Embodiment 1, proposes a system for applying for Shanshi security service via a cloud management platform according to the method for applying for Shanshi security service via a cloud management platform according to any one of claims 1 to 5, the system comprising:

[0118] User interface module, used for user login and submission of security service applications;

[0119] Audit module, automatically audits security service applications submitted by users;

[0120] The configuration module automatically configures the Hillstone security service for approved applications based on predefined configuration templates, ensuring that all VMs are protected and controlled by Hillstone Cloud.

[0121] Monitoring module, real-time monitoring of the operating status of Hillstone security services;

[0122] Notification module, which sends service startup notifications and any abnormal alerts to users;

[0123] The system adopts a whitelist mode when implementing security policies. All access is blocked by default. Access to network resources is allowed only after the cloud tenant has enabled the corresponding security policy for its VM. The cloud tenant cannot perform deprotection operations.

[0124] Security policy configuration requirements include:

[0125] At least one of the source / destination IP addresses is the tenant's VM IP address, with a 32-bit mask.

[0126] It is forbidden to configure the security policy from IP segment to IP segment;

[0127] It is forbidden to configure the Any to Any security policy.

[0128] The action parameters of the security policy include "allow" and "block". The default setting is "block", but in view of the principle error, it should be clearly set to "allow" in actual implementation and must be explicitly specified by the tenant;

[0129] The unique ID of the cloud tenant is automatically filled in the description of the security policy to isolate the security policy sets of different tenants.

[0130] It also includes a linkage mechanism between security policies and VM lifecycle management. When a VM is deleted, the system automatically deletes or marks the corresponding security policy as invalid, and guides cloud tenants to perform manual cleanup.

[0131] It also includes automatically filling in the unique ID of the cloud tenant in the custom service name definition format to prevent custom service configurations between different cloud tenants from interfering with each other.

[0132] It also includes: IPS and AV function settings, whose operation actions include "alarm" and "blocking", and the default setting is "alarm". Currently, detailed configuration operations of the functions are not provided to cloud tenants, and only the preset default template functions are executed;

[0133] The regular inspection and proofreading function is used to verify the configuration information in the cloud platform and Shanshi Cloud products to ensure the consistency and security of the system.

[0134] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A method for applying for Hillstone security services on a cloud management platform, characterized by: The method comprises the following steps: Users log in to the system through the cloud management platform; Select the type of Hillstone security service you need on the platform; The user fills in and submits the security service application form, which contains the necessary configuration information; The cloud management platform system automatically reviews user applications and automatically configures Hillstone security services based on predefined security configuration templates; After the system configuration is completed, the user is informed through the notification mechanism that the security service has been successfully started, and all VM virtual machines are ensured to be under the security protection control of Shanshi Cloud.

2. The method for applying for Hillstone security service on a cloud management platform according to claim 1, characterized in that: The following security policy setting principles are also included: Adopting the whitelist mode, all access is blocked by default, requiring cloud tenants to explicitly enable corresponding security policies for VMs to access network resources; The source / destination IP address settings in the security policy must meet the following requirements: at least one parameter is the IP address of the tenant VM, with a 32-bit mask. It is forbidden to configure the IP segment to IP segment or Any to Any security policy. The action parameters of the security policy include "allow" and "block", but the default setting is "block" to ensure security.

3. The method for applying for Hillstone security service on a cloud management platform according to claim 1, characterized in that: It also includes the following security policy management mechanisms: The unique ID of the cloud tenant is automatically filled in the description of the security policy to distinguish and isolate the security policy sets of different tenants; When a VM is deleted, a mechanism is automatically triggered to delete or mark the corresponding security policy as invalid, guiding the cloud tenant to perform manual cleanup.

4. The method for applying for Hillstone security service on a cloud management platform according to claim 1, characterized in that: It also includes rules for defining custom service names: The custom service name must contain the unique identifier of the cloud tenant to prevent service configurations between different tenants from interfering with each other.

5. The method for applying for Hillstone security service on a cloud management platform according to claim 1, characterized in that: Also includes settings for IPS and AV functions: The operation actions of IPS and AV functions include "alarm" and "block", and the default setting is "alarm"; The cloud platform does not provide detailed IPS and AV function configuration operations, but only executes according to predefined default templates. It also designs a mechanism to regularly check and proofread configuration information to ensure the consistency of configuration information between the cloud platform and Shanshi Cloud products.

6. A system for applying for Shanshi security service via a cloud management platform according to the method for applying for Shanshi security service via a cloud management platform according to any one of claims 1 to 5, characterized in that: The system comprises: User interface module, used for user login and submission of security service applications; Audit module, automatically audits security service applications submitted by users; The configuration module automatically configures the Hillstone security service for approved applications based on predefined configuration templates, ensuring that all VMs are protected and controlled by Hillstone Cloud. Monitoring module, real-time monitoring of the operating status of Hillstone security services; Notification module, which sends service startup notifications and any abnormal alerts to users; The system adopts a whitelist mode when implementing security policies. All access is blocked by default. Access to network resources is allowed only after the cloud tenant has enabled the corresponding security policy for its VM, and the cloud tenant cannot perform deprotection operations.

7. The cloud management platform application for Shanshi security service system according to claim 6, characterized in that: Security policy configuration requirements include: At least one of the source / destination IP addresses is the tenant's VM IP address, with a 32-bit mask. It is forbidden to configure the security policy from IP segment to IP segment; It is forbidden to configure the Any to Any security policy. The action parameters of the security policy include "allow" and "block". The default setting is "block", but in view of the principle error, it should be clearly set to "allow" in actual implementation and must be explicitly specified by the tenant; The unique ID of the cloud tenant is automatically filled in the description information of the security policy to isolate the security policy sets of different tenants.

8. The cloud management platform application for Shanshi security service system according to claim 6, characterized in that: It also includes a linkage mechanism between security policies and VM lifecycle management. When a VM is deleted, the system automatically deletes or marks the corresponding security policy as invalid, and guides cloud tenants to perform manual cleanup.

9. The cloud management platform application for Shanshi security service system according to claim 6, characterized in that: It also includes automatically filling in the unique ID of the cloud tenant in the custom service name definition format to prevent custom service configurations between different cloud tenants from interfering with each other.

10. The cloud management platform application for Shanshi security service system according to claim 6, characterized in that: Also includes: The settings of IPS and AV functions include "alarm" and "blocking". The default setting is "alarm". Currently, detailed configuration operations of the functions are not provided to cloud tenants. They are only executed according to the preset default template functions. The regular inspection and proofreading function is used to verify the configuration information in the cloud platform and Shanshi Cloud products to ensure the consistency and security of the system.