Security device management and security service arrangement method and system
By building virtual security instances in a virtual network and using two-stage abstract methods to form a virtual resource pool, the problem of too long queueing of security services in the existing technology is solved, and the effect of improving the efficiency of security services is achieved.
Patent Information
- Application Number
- CN202411969188.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-30
AI Technical Summary
In the prior art, the received security services are processed in sequence according to time, resulting in too long queues, which seriously affects the processing efficiency of security services.
By building virtual security instances of underlying devices in a virtual network, using a two-stage abstraction method to abstract the ability of virtual security device instances to provide virtual resources, forming a virtual machine in the virtual resource pool, thereby improving the processing efficiency of the services to be executed.
It effectively reduces the time for queueing during the process of the business to be executed and improves the processing efficiency of security services.
Smart Images

Figure CN120068054A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of software-defined security, and particularly relates to a method and system for security device management and security service orchestration. Background Art
[0002] In the existing network, due to the virtualization of various network facilities and network functions, the service objects of security services are no longer simple devices or entities, but complex virtual objects in the virtual network. Using traditional security protection methods for individual devices or entities will ignore many internal flows. Therefore, on the basis of defining security requirement analysis in the software of border security protection measures, by constructing a software-defined security framework for border security protection measures, an infrastructure is provided for solving security protection in a virtualized environment.
[0003] When constructing a software-defined security framework in the prior art, elastic computing resource virtualization is used in the resource virtualization modeling module; in the resource management module, an open and unified interface is provided for the resource pool constructed by semantic knowledge units for centralized scheduling and management of virtual resources. When virtualizing the entity device resource provisioning capabilities under the software-defined security resource pool component interaction framework, the attributes of different heterogeneous devices need to be considered, and device abstraction and virtualization are realized based on the attributes to facilitate operation and management in the system.
[0004] When using the software-defined security framework constructed by the prior art to process security services, the received security services are processed in sequence according to the reception time, resulting in too long queuing time for processing security services, seriously affecting the processing efficiency of security services. Summary of the Invention
[0005] In order to solve the problem of too long queuing time caused by processing received security services in sequence according to time in the prior art, the present invention proposes a method and system for security device management and security service orchestration. In a security device management method proposed by the present invention, by using the current business scenario and security requirements, the underlying devices accessed are managed and configured, and virtual security instances of the underlying devices accessed are constructed in the virtual network; using a two-stage abstraction method, the ability of the virtual security device instance to provide virtual resources is abstracted to obtain virtual machines in the virtual resource pool; the virtual resource pool is used to shield the differences between different underlying devices, facilitate the management and scheduling efficiency of virtual resources of different underlying devices, and the virtual resources provided by the virtual machines in the virtual resource pool run the to-be-executed services, thereby improving the processing efficiency of the to-be-executed services and reducing the queuing duration during the processing of the to-be-executed services.
[0006] On the one hand, the present invention proposes a security device management method, including:
[0007] According to the accessed service scenarios and security requirements, in a virtual network environment, manage and configure each accessed underlying device to obtain a virtual security device instance corresponding to each underlying device;
[0008] Based on the virtual resource provisioning capabilities of each virtual security device instance, use a first-stage abstraction method to perform digital descriptions respectively, and regard the description results of the virtual resources of each virtual security device as an abstract device model;
[0009] Based on the multiple abstract device models, use a second-stage abstraction method to perform homogeneous merging and aggregation on the virtual resources represented by the multiple abstract device models, and regard each merging and aggregation result as a virtual machine in the virtual resource pool; each virtual machine in the virtual resource pool is used to provide computing resources for multiple to-be-executed services accessed.
[0010] Optionally, the step of using a first-stage abstraction method to perform digital descriptions respectively based on the virtual resource provisioning capabilities of each virtual security device instance and regarding the description results of the virtual resources of each virtual security device as an abstract device model includes:
[0011] Obtain the static attributes and dynamic attributes of each virtual security device instance;
[0012] According to the dynamic attributes of each virtual security device instance, filter each virtual security device instance respectively to obtain multiple virtual security device instances to be processed;
[0013] According to the static attributes of each virtual security device instance to be processed, perform digital description on the virtual resource provisioning capabilities of each virtual security device instance, and regard the description results of the virtual resources of each virtual security device as an abstract device model.
[0014] Optionally, if the management and configuration of each accessed underlying device includes establishing a virtual security device instance, then the step of managing and configuring each accessed underlying device in a virtual network environment according to the accessed service scenarios and security requirements to obtain a virtual security device instance corresponding to each underlying device includes:
[0015] According to the accessed service scenarios and security requirements, in a virtual network environment, obtain the original images and XML files of each accessed underlying device, and generate a mac address corresponding to each underlying device;
[0016] According to each mac address, respectively mount the corresponding data port bridge from their respective original images;
[0017] Based on each mounted data port bridge, modify their respective corresponding XML files, create a virtual security device instance respectively, and store each virtual security device instance in a database.
[0018] Optionally, if the management configuration of each accessed underlying device includes deleting a virtual security device instance, then the step of performing management configuration on each accessed underlying device in the virtual network environment according to the current service scenario and security requirements to obtain a virtual security device instance corresponding to each underlying device includes:
[0019] In the virtual network environment, obtain the MAC address of the virtual security device instance corresponding to each accessed underlying device according to the accessed service scenario and security requirements;
[0020] Determine the XML file of each virtual security device instance according to the MAC address of each virtual security device instance;
[0021] Modify the XML file of each virtual security device instance, delete the virtual bridge and interface mounted on each XML file respectively, and delete the corresponding virtual security device instance.
[0022] Optionally, if the management configuration of each accessed underlying device includes modifying a virtual security device instance, then the step of performing management configuration on each accessed underlying device in the virtual network environment according to the current service scenario and security requirements to obtain a virtual security device instance corresponding to each underlying device includes:
[0023] In the virtual network environment, obtain the MAC address of the virtual security device instance corresponding to each accessed underlying device according to the accessed service scenario and security requirements;
[0024] Modify the XML file of each virtual security device instance according to the MAC address of each virtual security device instance, and determine each modified virtual security device instance;
[0025] Update each virtual security device instance in the database according to each modified virtual security device instance.
[0026] On the other hand, the present invention also provides a security device management system, including:
[0027] A device management unit, configured to perform management configuration on each accessed underlying device in the virtual network environment according to the accessed service scenario and security requirements to obtain a virtual security device instance corresponding to each underlying device;
[0028] A model abstraction unit, configured to perform digital description respectively by using a one-stage abstraction method based on the virtual resource providing capabilities of each virtual security device instance, and use the description result of one kind of virtual resource of each virtual security device as an abstract device model;
[0029] A resource pool construction unit, which is used to perform homogeneous merging and aggregation on the virtual resources represented by multiple abstract device models by using a second-stage abstraction method based on the multiple abstract device models, and use each merging and aggregation result as a virtual machine in the virtual resource pool; each virtual machine in the virtual resource pool is used to provide computing resources for multiple to-be-executed services accessed.
[0030] On the other hand, the present invention also provides a security service orchestration method, including:
[0031] Perform virtualization modeling on the virtual resources of multiple virtual machines in the virtual resource pool to obtain a virtual resource scheduling model, and each virtual machine in the virtual resource pool is obtained according to the security device management method described in the above technical solution;
[0032] Based on multiple to-be-executed services accessed, according to the characteristics of each to-be-executed service, use a preset service sorting method to perform problem modeling to obtain an optimization objective and constraints, and the optimization objective includes the minimum total execution time, minimum total response time, and maximum single resource utilization rate of multiple to-be-executed services;
[0033] Use the service priorities of multiple to-be-executed services accessed as an initial service sorting queue, determine the service sorting criteria of the multiple to-be-executed services, and use a differential evolution algorithm to determine the weight vector of each service sorting criterion;
[0034] Based on the weight vector of each service sorting criterion, use a multi-criteria decision-making algorithm to evaluate the precedence relationship of the multiple to-be-executed services to obtain a final service sorting queue;
[0035] Use the virtual resource scheduling model and the constraints of the optimization objective to solve the optimization objective, and determine a multi-service multi-virtual resource parallel preemptive scheduling method based on priorities;
[0036] According to the multi-service multi-virtual resource parallel preemptive scheduling method based on priorities, schedule the virtual resources of each virtual machine in the virtual resource pool to process the multiple to-be-executed services in the final service sorting queue.
[0037] Optionally, the step of using a multi-criteria decision-making algorithm to evaluate the precedence relationship of the multiple to-be-executed services based on the weight vector of each service sorting criterion to obtain a final service sorting queue includes:
[0038] Based on the weight vector of each service sorting criterion, use a multi-criteria decision-making algorithm to evaluate the precedence relationship of the multiple to-be-executed services to obtain an evaluation result;
[0039] According to the evaluation results, perform descending distillation and ascending distillation on the multiple to-be-executed services to obtain a descending sorting sequence and an ascending sorting sequence;
[0040] Combine the descending sorting sequence and the ascending sorting sequence to generate a complete global priority sorting of the multiple to-be-executed services, determine the final priorities of the multiple to-be-executed services, and obtain the final service sorting queue of the multiple to-be-executed services.
[0041] Optionally, based on the weight vector of each service sorting criterion, use a multi-criterion decision-making algorithm to evaluate the precedence relationship of the multiple to-be-executed services, and the obtained evaluation results include:
[0042] Based on the weight vector of each service sorting criterion, obtain the partial coordination index, global coordination index, and partial incoordination index of the multiple to-be-executed services for each service sorting criterion;
[0043] According to the partial coordination index, global coordination index, and partial incoordination index of each service sorting criterion, generate a credibility matrix of the multiple to-be-executed services corresponding to the service sorting criterion;
[0044] Integrate the credibility matrices of the multiple to-be-executed services for each service sorting criterion, evaluate the precedence relationship of the multiple to-be-executed services, and obtain the evaluation results.
[0045] Optionally, use the virtual resource scheduling model and the constraints of the optimization objective to solve the optimization objective, and determine a parallel preemptive scheduling method for multiple services and multiple virtual resources based on priorities, including:
[0046] Use the virtual resource scheduling model and the constraints of the optimization objective to determine the total execution time, total response time, and single resource utilization rate of the multiple to-be-executed services;
[0047] According to the total execution time, total response time, and single resource utilization rate of the multiple to-be-executed services, solve the optimization objective, and use the result as a parallel preemptive scheduling method for multiple services and multiple virtual resources based on priorities.
[0048] Optionally, the total execution time, total response time, and single resource utilization rate of the multiple to-be-executed services respectively satisfy the following expressions:
[0049]
[0050] RT i =FT i -AT i ,
[0051]
[0052] FT i = max{FT ij} j∈[M] ,
[0053] WT ij = BT ij - AT i ,
[0054]
[0055] C ij = WT ij + ET ij ,
[0056] In the formula, represents the virtual resource VS in the virtual resource scheduling model j the total execution time for running the to-be-executed service; j represents the j-th virtual resource in the virtual resource scheduling model, j ∈ (1, 2,..., M); RT i represents the total response time of the to-be-executed service T i ; i represents the i-th to-be-executed service accessed, i ∈ (1, 2,..., N); M represents the total number of virtual resources in the virtual resource scheduling model; FT ij represents the end time of the to-be-executed service T i ; FT i represents the end time of the last to-be-executed service; BT ij represents the start execution time of the to-be-executed service T i ; AT i represents the access time of the to-be-executed service T i ; RU j represents the utilization rate of the virtual resource VS j ; WT ij represents the waiting time of the to-be-executed service T i on the virtual resource VS j ; ET ij represents the execution time of the to-be-executed service T i on the virtual resource VS j ; L i represents the number of virtual resources j required by the to-be-executed service T i ; speed represents the number of virtual resources that the virtual resource VS j can provide per second; C ij represents the total time of the to-be-executed service T i on the virtual resource VS j .
[0057] On the other hand, the present invention also discloses a security service orchestration system, including:
[0058] A virtual resource modeling module, which is used to perform virtualization modeling on the virtual resources of each virtual machine in the virtual resource pool to obtain a virtual resource scheduling model, and each virtual machine in the virtual resource pool is obtained according to the security device management method described in the above technical solution;
[0059] An optimization objective construction module, which is used to perform problem modeling based on multiple to-be-executed services to be accessed, according to the characteristics of each to-be-executed service, and adopt a preset service sorting method to obtain an optimization objective and constraints, where the optimization objective includes minimizing the total execution time, minimizing the total response time, and maximizing the single resource utilization rate of multiple to-be-executed services;
[0060] A weight vector determination module, which is used to use the service priorities of multiple to-be-executed services to be accessed as an initial service sorting queue, determine the service sorting criteria of the multiple to-be-executed services, and use the differential evolution algorithm to determine the weight vector of each service sorting criterion;
[0061] A service sorting module, which is used to evaluate the precedence relationship of the multiple to-be-executed services based on the weight vector of each service sorting criterion by using a multi-criteria decision-making algorithm to obtain a final service sorting queue;
[0062] A resource scheduling module, which is used to solve the optimization objective by using the virtual resource scheduling model and the constraints of the optimization objective, and determine a multi-service multi-virtual resource parallel preemptive scheduling method based on priorities;
[0063] A service processing module, which is used to schedule the virtual resources of each virtual machine in the virtual resource pool according to the multi-service multi-virtual resource parallel preemptive scheduling method based on priorities, and perform service processing on the multiple to-be-executed services in the final service sorting queue.
[0064] On the other hand, the present invention further provides an electronic device, including: at least one processor and a memory; the memory and the processor are connected through a bus;
[0065] The memory is used to store one or more programs;
[0066] When the one or more programs are executed by the at least one processor, the security device management method described in the above technical solution or the security service orchestration method described in the above technical solution is implemented.
[0067] On the other hand, the present invention further provides a readable storage medium, on which an execution program is stored, and when the execution program is executed, the security device management method described in the above technical solution or the security service orchestration method described in the above technical solution is implemented.
[0068] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0069] In a security device management method provided by the present invention, by utilizing the current business scenario and security requirements, the underlying devices accessing are managed and configured, and virtual security instances of the underlying devices accessing are constructed in a virtual network; by using a two-stage abstraction method, the ability of the virtual security device instance to provide virtual resources is abstracted to obtain virtual machines in a virtual resource pool; the virtual resource pool is used to shield the differences between different underlying devices, facilitate the management and scheduling efficiency of virtual resources of different underlying devices, and the virtual resources provided by the virtual machines in the virtual resource pool are used to run the to-be-executed services, thereby improving the processing efficiency of the to-be-executed services and reducing the queuing duration during the processing of the to-be-executed services.
[0070] The present invention also provides a security service orchestration method, in which a differential evolution algorithm is used to evaluate the sequence of the to-be-executed services accessing, and the to-be-executed services are re-sorted according to the evaluation results, ensuring the objectivity of sorting the to-be-executed services. Then, a multi-service multi-virtual resource parallel preemptive scheduling method is used to process the sorted to-be-executed services, avoiding the situation that a single service monopolizes a certain virtual resource for a long time, realizing flexible scheduling of the virtual resources required for running the to-be-executed services, and improving the processing efficiency of using virtual resources for the to-be-executed services. BRIEF DESCRIPTION OF THE DRAWINGS
[0071] Figure 1 It is a flowchart of a security device management method of the present invention;
[0072] Figure 2 It is a flowchart of managing and configuring each underlying device accessing in a security device management method of the present invention;
[0073] Figure 3 It is a flowchart of adopting a first-stage abstraction method and a second-stage abstraction method in a security device management method of the present invention;
[0074] Figure 4 It is a flowchart of a security device management system of the present invention;
[0075] Figure 5 It is a flowchart of a security service orchestration method of the present invention;
[0076] Figure 6 It is a schematic diagram of a preset architecture of a security service orchestration method of the present invention;
[0077] Figure 7 It is a bar chart after sorting the to-be-executed services in a security service orchestration method of the present invention;
[0078] Figure 8 Schematic diagram of a security service orchestration system according to the present invention;
[0079] Figure 9 Schematic diagram of an electronic device according to the present invention. Detailed implementation manners
[0080] Embodiment 1:
[0081] As Figure 1 shown, the present invention provides a security device management method, including:
[0082] S101, according to the accessed service scenarios and security requirements, in a virtual network environment, manage and configure each accessed underlying device to obtain a virtual security device instance corresponding to each underlying device;
[0083] S102, based on the virtual resource providing capabilities of each virtual security device instance, adopt a first-stage abstraction method to perform digital descriptions respectively, and use the description results of the virtual resources of each virtual security device as an abstract device model;
[0084] S103, based on the multiple abstract device models, adopt a second-stage abstraction method to perform homogeneous merging and aggregation on the virtual resources represented by the multiple abstract device models, and use each merging and aggregation result as a virtual machine in the virtual resource pool; each virtual machine in the virtual resource pool is used to provide computing resources for multiple to-be-executed services accessed.
[0085] To solve the problem of virtual device management in the software-defined environment in the prior art, the present invention realizes the elastic deployment and efficient management of security devices through the decoupling of the data plane and the control plane, and by adopting a distributed resource management framework and virtualization technology. For the security devices at the bottom layer of the software-defined security framework, the present invention provides a security device management method. By first managing virtual security devices in a virtual environment, including starting, modifying, deleting, etc. of the devices, and being able to automatically complete device configuration and network configuration to adapt to different service scenarios and security requirements. Then, using a two-stage virtual security device abstraction method, first abstract the virtual security devices into abstract device models that can provide resources externally, facilitating the centralized management and unified regulation of the resources that the underlying security devices can provide by the system; then abstract the resource-providing capabilities of the abstract device models into virtual machines in the virtual resource pool to provide the resources required by the centralized management layer services.
[0086] Referring to Figure 2 , optionally, S101 includes:
[0087] Obtain the static attributes and dynamic attributes of each virtual security device instance;
[0088] Filter each virtual security device instance respectively according to its dynamic attributes, and obtain multiple virtual security device instances to be processed;
[0089] Digitally describe the virtual resource provisioning capabilities of each virtual security device instance according to the static attributes of each virtual security device instance to be processed, and use the description results of the virtual resources of each virtual security device as an abstract device model.
[0090] Exemplarily, the static attributes represent the basic device attributes such as the resource types, quantities, speeds, loads, etc. that the underlying security device can provide, and these attributes will not change due to system changes; while the dynamic attributes represent the operating states of the corresponding underlying devices, including shutdown, running, failure, etc. The dynamic attributes determine the feasibility of device abstraction, the necessity of device abstraction determined by device lifespan, etc., which are attributes that change with system operation; by using the static attributes of the underlying security device to determine the type of the abstract model after abstraction, and the respective dynamic attributes of each underlying security device determine the participating devices before abstraction, which facilitates the subsequent combination of the static and dynamic attributes of the underlying physical devices to achieve device abstraction.
[0091] Refer to Figure 3 , optionally, if the management configuration of each underlying device to be accessed includes creating a virtual security device instance, then the management configuration of each underlying device to be accessed in the virtual network environment according to the accessed service scenario and security requirements to obtain the virtual security device instance corresponding to each underlying device includes:
[0092] In the virtual network environment, obtain the original image and XML (Extensible Markup Language) file of each underlying device to be accessed according to the accessed service scenario and security requirements, and generate the mac address (Media Access Control Address) corresponding to each underlying device;
[0093] Mount the corresponding data port bridge from the respective original images according to each mac address;
[0094] Based on each mounted data port bridge, modify the respective corresponding XML files, create a virtual security device instance respectively, and store each virtual security device instance in the database.
[0095] Exemplarily, when establishing a virtual security device instance, first use the security control layer to receive the control instructions for service transformation to find the original image location and XML file location of the underlying device, and generate a MAC address, where the XML file represents the file used to configure and manage the virtual security device, and the MAC address represents the unique identifier of the virtual security device; then modify the instance XML file according to the configuration of each underlying security device, and create it from the original image. At the same time, mount network interfaces and set the management port network for the virtual security device instance to enable the virtual security device instance to be connected to the network; finally, write the detailed information of the virtual security device instance into the database, and send the successful establishment information to the virtualization module for resource virtualization processing.
[0096] Optionally, if the management configuration of each accessed underlying device includes deleting the virtual security device instance, then according to the current service scenario and security requirements, in the virtual network environment, perform management configuration on each accessed underlying device to obtain the virtual security device instance corresponding to each underlying device, including:
[0097] According to the accessed service scenario and security requirements, in the virtual network environment, obtain the MAC address of the virtual security device instance corresponding to each accessed underlying device;
[0098] According to the MAC address of each virtual security device instance, determine the XML file of each virtual security device instance;
[0099] Modify the XML file of each virtual security device instance, delete the virtual bridge and interface mounted on each XML file respectively, and delete the corresponding virtual security device instance.
[0100] Exemplarily, when deleting the virtual security device instance, the accessed service scenario and security requirements include deletion request data. According to the received deletion request data, query the corresponding location in the database to obtain the MAC address of the corresponding virtual security device instance and delete it; then modify the XML file according to the MAC address of the virtual security device instance, and delete the virtual bridge and the mounted network interface associated with the virtual security device instance. After that, delete the virtual security device instance; finally, send the information of the deleted virtual security device instance to the virtualization module, and the virtualization module performs release processing on the virtual resources provided by the deleted virtual security device instance.
[0101] Optionally, if the management configuration of each accessed underlying device includes modifying the virtual security device instance, then according to the current service scenario and security requirements, in the virtual network environment, perform management configuration on each accessed underlying device to obtain the virtual security device instance corresponding to each underlying device, including:
[0102] According to the accessed service scenarios and security requirements, in a virtual network environment, obtain the MAC address of the virtual security device instance corresponding to each underlying device accessed;
[0103] According to the MAC address of each virtual security device instance, modify the XML file of each virtual security device instance to determine each modified virtual security device instance;
[0104] According to each modified virtual security device instance, update each virtual security device instance in the database.
[0105] Exemplarily, when modifying a virtual security device instance, the accessed service scenarios and security requirements include operations such as starting, restarting, shutting down, and suspending for an already established virtual security device instance. Query the database at the corresponding location according to the accessed request data to obtain the MAC address of the corresponding virtual security device instance; then modify the status of the corresponding virtual security device instance (such as starting, restarting, shutting down, or suspending) according to the MAC address of the virtual security device instance and update the status in the database to the current status; finally, send the information of the modified virtual security device instance to the virtualization module, and the virtualization module modifies the virtual resources provided by the modified virtual security device instance.
[0106] In some embodiments, S102 can be implemented as: using a "one-to-many" method to digitally describe the virtual resource provisioning capabilities of each underlying device, and converting each virtual resource description result provided into an abstract device.
[0107] The present invention first uses a "one-to-many" abstraction method to convert the underlying security device from a physical entity into an abstract digital model. The converted abstract digital model facilitates subsequent unified operation and management of the current virtual resources.
[0108] In some embodiments, S103 can be implemented as: using a "many-to-one" method to merge and aggregate the multiple virtual resource provisioning capabilities of each abstract digital model to realize the construction of a virtual resource pool.
[0109] In the present invention, in the stage from the abstract device model to virtual resources, using a "many-to-one" abstraction method, by merging and aggregating the same type of static attribute device models abstracted from different devices, extracting the production capabilities of the abstract device entities, and merging and accessing them into the resource pool as the resource pool for providing virtual resources externally, it can shield the differences between different devices, and at the same time, device management and scheduling are more centralized; the resource pool provides an overall productivity resource of different types that can be arbitrarily divided, which can effectively reduce the coupling between devices and resources and improve the management efficiency of the resource pool.
[0110] The present invention utilizes a two-stage abstraction method to extract the ability of underlying security entity devices to provide virtual resources, and merges the extracted virtual resources of the same type and accesses them into a resource pool, thereby constructing a resource pool of one-to-many abstract device models of physical devices and many-to-one virtual resources of abstract device models, which facilitates the system to subsequently access and schedule virtual resources according to business needs and improves the response speed of virtual resources.
[0111] The present invention provides a security device management method that improves the configuration, scheduling and management efficiency of security devices, ensuring that reliable security services can be provided in complex virtualized environments. Through the present invention, security devices can be abstracted into underlying virtualized hardware resource pools, providing flexible security service deployment and management, achieving efficient task scheduling, and providing a solid infrastructure for security protection in virtualized environments.
[0112] In a security device management method provided by the present invention, the accessed underlying device is managed and configured by utilizing the current business scenario and security requirements, and a virtual security instance of the accessed underlying device is constructed in a virtual network; the ability of the virtual security device instance to provide virtual resources is abstracted by utilizing a two-stage abstraction method to obtain a virtual machine in a virtual resource pool; the virtual resource pool is used to shield the differences between different underlying devices, and to facilitate the efficiency of managing and scheduling virtual resources of different underlying devices; the virtual resources provided by the virtual machines in the virtual resource pool run the services to be executed, thereby improving the processing efficiency of the services to be executed and reducing the queuing time during the processing of the services to be executed.
[0113] The virtual security device management method provided by the present invention can also improve efficiency and simplify unified processes. By utilizing device virtualization, external expansion and deployment can be performed faster and workload can be reduced. The modeling of virtual security device resources can also be used to unify the interfaces of the capabilities provided by the underlying security devices, simplify subsequent operations, and hide internal details.
[0114] Embodiment 2:
[0115] Reference Figure 4 The present invention based on the same inventive concept also provides a security device management system, including:
[0116] The device management unit is used to manage and configure each underlying device in the virtual network environment according to the access business scenario and security requirements, and obtain the virtual security device instance corresponding to each underlying device;
[0117] A model abstraction unit is used to digitally describe the virtual resource provision capability of each virtual security device instance using a one-stage abstraction method, and the description result of a virtual resource of each virtual security device is used as an abstract device model;
[0118] A resource pool construction unit, which is used to perform homogeneous merging and aggregation on the virtual resources represented by multiple abstract device models by using a second-stage abstraction method based on the multiple abstract device models, and use each merging and aggregation result as a virtual machine in the virtual resource pool; each virtual machine in the virtual resource pool is used to provide computing resources for multiple to-be-executed services that are accessed.
[0119] Optionally, the model abstraction unit is specifically used for:
[0120] Obtain the static attributes and dynamic attributes of each virtual security device instance;
[0121] Filter each virtual security device instance respectively according to the dynamic attributes of each virtual security device instance to obtain multiple virtual security device instances to be processed;
[0122] Digitally describe the virtual resource providing capabilities of each virtual security device instance according to the static attributes of each virtual security device instance to be processed, and use the description result of one kind of virtual resource of each virtual security device as an abstract device model.
[0123] Optionally, if the management and configuration of each underlying device to be accessed includes establishing a virtual security device instance, the device management unit is specifically used for:
[0124] In a virtual network environment, obtain the original image and XML file of each underlying device to be accessed according to the accessed service scenario and security requirements, and generate a mac address corresponding to each underlying device;
[0125] Mount the corresponding data port bridge from the respective original images according to each mac address;
[0126] Based on each mounted data port bridge, modify the respective corresponding XML file, create a virtual security device instance respectively, and store each virtual security device instance in the database.
[0127] Optionally, if the management and configuration of each underlying device to be accessed includes deleting a virtual security device instance, the device management unit is specifically used for:
[0128] In a virtual network environment, obtain the mac address of the virtual security device instance corresponding to each underlying device to be accessed according to the accessed service scenario and security requirements;
[0129] Determine the XML file of each virtual security device instance according to the mac address of each virtual security device instance;
[0130] Modify the XML file of each virtual security device instance, delete the virtual bridge and interface mounted on each XML file respectively, and delete the corresponding virtual security device instance.
[0131] Optionally, if the management configuration of each underlying device to be connected includes modifying the virtual security device instance, the device management unit is specifically used for:
[0132] In the virtual network environment, obtain the mac address of the virtual security device instance corresponding to each underlying device to be connected according to the access service scenario and security requirements;
[0133] Modify the XML file of each virtual security device instance according to the mac address of each virtual security device instance, and determine each modified virtual security device instance;
[0134] Update each virtual security device instance in the database according to each modified virtual security device instance.
[0135] Embodiment 3:
[0136] Refer to Figure 5 , based on a security device management method provided in the above embodiment, the present invention also proposes a security service orchestration method, including:
[0137] S201, perform virtualization modeling on the virtual resources of multiple virtual machines in the virtual resource pool to obtain a virtual resource scheduling model, and each virtual machine in the virtual resource pool is obtained according to the security device management method described in the above technical solution;
[0138] S202, based on multiple services to be executed to be connected, according to the characteristics of each service to be executed, use a preset service sorting method to perform problem modeling to obtain an optimization objective and constraints, and the optimization objective includes the minimum total execution time, the minimum total response time, and the maximum single resource utilization rate of multiple services to be executed;
[0139] S203, use the service priorities of multiple services to be executed to be connected as the initial service sorting queue, determine the service sorting criteria of the multiple services to be executed, and use the differential evolution algorithm to determine the weight vector of each service sorting criterion;
[0140] S204, based on the weight vector of each service sorting criterion, use a multi-criteria decision-making algorithm to evaluate the priority relationship of the multiple services to be executed to obtain a final service sorting queue;
[0141] S205, use the virtual resource scheduling model and the constraints of the optimization objective to solve the optimization objective, and determine a multi-service multi-virtual resource parallel preemptive scheduling method based on priorities;
[0142] S206. According to the priority-based multi-service multi-virtual resource parallel preemptive scheduling method, schedule the virtual resources of each virtual machine in the virtual resource pool, and process the multiple services to be executed in the final service sorting queue.
[0143] Refer to Figure 6 , in order to improve the efficiency of processing services, the present invention first designs a virtualization management method for the security devices at the bottom layer of the software-defined security framework. First, manage the virtual security devices, including creating, modifying, and deleting, and automatically completing device configuration and network configuration. Then, design a two-stage abstraction method to abstract the virtual security devices into a virtual resource pool to provide services externally;
[0144] Then, for the security control layer of the software-defined security framework, the present invention first performs virtualization modeling on the resources of the virtual security devices, and then uses a priority-based multi-service multi-virtual resource parallel preemptive scheduling method to achieve the purpose of high resource scheduling efficiency of the virtual security devices;
[0145] At the same time, for the centralized management layer of the software-defined security framework, the present invention uses a multi-criteria decision-making method based on the differential evolution algorithm to arrange the priorities of component services, ensuring the objectivity of service sorting. By closely linking the priority of service sorting with the evaluation results of multi-criteria decision-making, and as the system runs, the service queue can be dynamically adjusted without affecting the previously executed services. Furthermore, it is possible to process the services to be processed in the adjusted service queue using virtual resources, improving the processing efficiency of the services to be processed, and being able to fully consider various attributes of component tasks to achieve efficient orchestration of the services to be executed.
[0146] S201 can be implemented as follows: Based on the security devices at the bottom layer of the software-defined security framework, manage the virtual security devices, including creating, modifying, and deleting, and automatically completing device configuration and network configuration. Then, design a two-stage abstraction method to gather the same static attribute device models abstracted from different devices together as a resource pool for providing virtual resources externally, which can shield the differences between different devices and, at the same time, make device management and scheduling more centralized; The resource pool provides an overall productivity resource of different types that can be arbitrarily divided, which can effectively reduce the coupling between devices and resources and improve the management efficiency of the resource pool.
[0147] By mathematically modeling the virtual security devices and the abstract resources in the virtual resource pool, the reasonable scheduling and optimal utilization of resources are achieved; a perfect virtual resource scheduling model is established to realize the dynamic allocation and scheduling of virtual resources to meet different service requirements and performance indicators; using the mathematical model of virtual resources and combining with the upper-layer service instructions, a priority-based multi-service and multi-virtual resource parallel preemptive scheduling method is designed for components, their service priorities, and virtual resources in the resource pool.
[0148] Referring to Figure 7 , in some embodiments, S202 can be implemented as: performing virtualization modeling on the component services received by the virtual security resources, including problem modeling and optimization objectives. For the convenience of explaining the problem modeling, for the N pending services (T 1 , T 2 ,..., T N ) to be executed by the access security component, all satisfy the following conditions:
[0149] 1) There are different characteristics between services, that is, the service length (the amount of resources L i ), the arrival time of service T i at the service list AT i , the start execution time BT ij , the deadline FT ij , etc., which represent the start execution and deadline of component service T i on the virtual resource VS j ;
[0150] 2) The service will not interrupt itself during execution, but it is preemptible, and the low-priority service is preempted by the high-priority service;
[0151] 3) According to different sorting criteria, the priorities between services will also be different;
[0152] 4) According to the same sorting criteria, the obtained service priorities should be the same.
[0153] At the same time, for the M virtual resources in the virtual resource pool: VS 1 , VS 2 ,..., VS M , each virtual resource is equivalent to a virtual machine and can continuously provide virtual resources; when a service comes, it is equivalent to the service running on the pipeline of this virtual machine, and the number of virtual resources that can be provided per second is represented by speed;
[0154] At the same time, among the K entities in the physical resources corresponding to each virtual resource: PS 1 , PS 2 ,..., PS K .
[0155] Therefore, based on the business T to be executed i on the virtual resource VS j for all the time C ij , including the waiting time WT ij (the response time on VS j ) and the execution time ET ij , we can obtain:
[0156]
[0157] RT i = FT i - AT i ,
[0158]
[0159] FT i = max{FT ij}} j∈[M] ,
[0160] WT ij = BT ij - AT i ,
[0161]
[0162] C ij = WT ij + ET ij ,
[0163] In the formula, represents the total execution time of the business T to be executed on the virtual resource VS j ; j represents the j-th virtual resource in the virtual resource scheduling model, j ∈ (1, 2,..., M); RT i represents the total response time of the business T to be executed i ; i represents the i-th business to be executed accessed, i ∈ (1, 2,..., N); M represents the total number of virtual resources in the virtual resource scheduling model; FT ij represents the end time of the business T to be executed i ; FT i represents the end time of the last business to be executed; BT ij represents the start execution time of the business T to be executed i ; AT i represents the access time of the business T to be executed i ; RU j represents the utilization rate of the virtual resource VS j ; WT ij represents the waiting time of the business T to be executedi The waiting time on the virtual resource VS j ; ET ij represents the business T to be executed i The execution time on the virtual resource VS j ; L i represents the business T to be executed i The number of virtual resources j required; speed represents the number of virtual resources that the virtual resource VS j can provide per second; C ij represents the business T to be executed i The total time on the virtual resource VS j .
[0164] In summary, the constructed optimization objectives include:
[0165] Objective 1: Minimize the total execution time to improve the system operation efficiency, that is, minimize the total time completed by the entire business system
[0166] Objective 2: Minimize the total response time of the business system, that is, minimize
[0167] Objective 3: Maximize the utilization rate of a single resource, that is, maximize the resource utilization rate of the entire system, which is to maximize
[0168] In some embodiments, S203 is specifically implemented as:
[0169] For the centralized management layer of the software-defined security framework, the multi-criteria decision-making method based on the differential evolution algorithm provided by the present invention includes:
[0170] (1) Initialization stage: Determine the component business waiting queue, which must be sorted and stored in the global queue once a business is received from the component; Determine the criterion g j for component business sorting, where j ∈ n indicates that this multi-criteria decision-making process includes n criteria, and the criteria include component priority, business length (the number of resources L i ) required for a certain resource, business T i Arrival time of the business list AT i Start execution time BT ij Deadline FT ij etc.;
[0171] (2) Differential evolution to determine criterion weights stage: Use the differential evolution algorithm to determine the weights of the criteria determined in the initialization stage. The differential evolution algorithm is used as a generator of optimal weights, which can well meet the constraints imposed by the multi-criteria decision-making problem, and then generate different weight vectors, and each vector is a set related to the criterion gj associated non - negative weight w j , where n is the number of criteria, and the weights of each criterion satisfy the following conditions:
[0172]
[0173] Optionally, S204 includes:
[0174] S2041, based on the weight vectors of each service sorting criterion, using a multi - criterion decision - making algorithm, evaluate the precedence relationship of the multiple services to be executed, and obtain an evaluation result;
[0175] S2042, according to the evaluation result, perform descending distillation and ascending distillation on the multiple services to be executed, and obtain a descending sorting sequence and an ascending sorting sequence;
[0176] S2043, combine the descending sorting sequence and the ascending sorting sequence, generate a complete global priority sorting of the multiple services to be executed, determine the final priority of the multiple services to be executed, and obtain the final service sorting queue of the multiple services to be executed.
[0177] Exemplarily, the specific implementation of S2041 is:
[0178] Based on the weight vectors of each service sorting criterion, obtain the partial coordination index, global coordination index, and partial incoordination index of the multiple services to be executed for each service sorting criterion;
[0179] According to the partial coordination index, global coordination index, and partial incoordination index of each service sorting criterion, generate a credibility matrix of the multiple services to be executed corresponding to the service sorting criterion;
[0180] Integrate the credibility matrices of the multiple services to be executed for each service sorting criterion, evaluate the precedence relationship of the multiple services to be executed, and obtain an evaluation result.
[0181] Exemplarily, evaluating the component services and determining the final component service priority includes two sub - parts:
[0182] The first part: First, the construction of the precedence relationship. The solution of the criterion weight vector is used as the input of multi - criterion decision - making. Secondly, in the step of constructing the precedence relationship, calculate the coordination index (partial coordination index and global coordination index), partial incoordination index, and credibility matrix, and use the coordination index, partial incoordination index, and credibility matrix to compare multiple alternative priority schemes.
[0183] The partial coordination index satisfies the following expression:
[0184]
[0185] In the formula, C j (x, y) represents the measure that service x is higher than service y under criterion g j ; g j (x) represents the evaluation value of service x under criterion g j ; g j (y) represents the evaluation value of service y under criterion g j ; q j represents the indifference threshold; p j represents the preference threshold.
[0186] The global coordination index satisfies the following expression:
[0187]
[0188] In the formula, C(x, y) represents the sum of the measures under any criterion that all services conform to service x being higher than service y; w j is the non - negative weight of criterion g j .
[0189] The partial incoordination index satisfies the following expression:
[0190]
[0191] In the formula, D j (x, y) represents the measure of disagreement that service x is higher than service y under criterion g j ; v j represents the veto threshold; p j represents the tolerance limit that the resource scheduling module is willing to accept any compensation;
[0192] The credibility matrix satisfies the following expression:
[0193]
[0194] In the formula, σ(x, y) represents the credibility index that service x is higher than service y under any criterion.
[0195] Second, the utilization of the priority relationship, in which descending and ascending distillations are respectively performed, fully considering the influence of multi - criterion decision weights, to form a complete ranking and generate the final priority ranking.
[0196] First, generate the ranking of alternative solutions from the credibility matrix, and construct two sequences Z 1 and Z 2 using the descending and ascending distillation processes. The first sequence (descending distillation) first selects the component service with the best ranking and then ends with the component service with the worst ranking. The second sequence (ascending distillation) first selects the component service with the worst ranking and then ends with the component service with the best ranking.
[0197] Therefore, the results of the two distillation sortings are combined to form a complete sorting, and a priority sorting Z = Z 1 ∩Z 2 is obtained, which is the global priority sorting of the component services, realizing the orchestration of the component services.
[0198] The flowchart for orchestrating component services by the multi-criteria decision-making method based on the differential evolution algorithm provided by the present invention specifically includes:
[0199] 1. Determining the waiting queue of component services. Once a service is received from a component, it must be sorted and stored in the global queue;
[0200] 2. Determining the sorting criteria for component services: including component priority, service length (the amount of a certain resource required), service arrival time at the service list, start execution time, deadline, etc.;
[0201] 3. Using the sorting criteria of component services as the input of the differential evolution algorithm to obtain multiple groups of optimal weight vectors;
[0202] 4. Determining the thresholds in the multi-criteria decision-making process according to the weight vectors, including the indifference threshold, preference threshold, and veto threshold;
[0203] 5. Calculating the partial coordination index, global coordination index, and partial incoordination index between component services respectively;
[0204] 6. Generating a credibility matrix between component services under different criteria through the coordination index and incoordination index between services, and further generating multiple alternative priority schemes;
[0205] 7. Constructing two sequences using the descending and ascending distillation processes:
[0206] Sequence 1: First select the component service with the best ranking, and then end with the component service with the worst ranking;
[0207] Sequence 2: First select the component service with the worst ranking, and then end with the component service with the best ranking;
[0208] 8. Combining the results of the two distillation sortings to form a complete sorting to generate a priority sorting, which is the priority orchestration sequence of component services.
[0209] Optionally, S205 includes:
[0210] Using the virtual resource scheduling model and the constraints of the optimization objective to determine the total execution time, total response time, and single resource utilization rate of the multiple services to be executed;
[0211] Solve the optimization objective according to the total execution time, total response time, and single resource utilization rate of the multiple to-be-executed services, and use the result as a parallel preemptive scheduling method for multiple services and multiple virtual resources based on priorities.
[0212] Optionally, the total execution time, total response time, and single resource utilization rate of the multiple to-be-executed services respectively satisfy the following expressions:
[0213]
[0214]
[0215] FT i = max{FT ij} j∈[M] ,
[0216] WT ij = BT ij - AT i ,
[0217]
[0218] C ij = WT ij + ET ij ,
[0219] In the formula, represents the total execution time of the virtual resource VS j in the virtual resource scheduling model for running the to-be-executed service; j represents the jth virtual resource in the virtual resource scheduling model, j ∈ (1, 2,..., M); RT i represents the total response time of the to-be-executed service T i ; i represents the ith to-be-executed service accessed, i ∈ (1, 2,..., N); M represents the total number of virtual resources in the virtual resource scheduling model; FT ij represents the end time of the to-be-executed service T i ; FT i represents the end time of the last to-be-executed service; BT ij represents the start execution time of the to-be-executed service T i ; AT i represents the access time of the to-be-executed service T i ; RU j represents the utilization rate of the virtual resource VS j ; WT ij represents the waiting time of the to-be-executed service T i on the virtual resource VS j ; ET ij represents the execution time of the to-be-executed service T i on the virtual resource VSj Execution time on; L i Indicates the business T to be executed i The quantity of virtual resource j required; speed represents virtual resource VS j The quantity of virtual resources that can be provided per second; C ij Indicates the business T to be executed i On virtual resource VS j Total time.
[0220] The present invention proposes a priority-based multi-service and multi-virtual resource parallel preemptive scheduling method, which will not result in a situation where a service monopolizes a certain resource, and the scheduling is more flexible, and subjective preemption can be achieved by modifying the priority. The following conditions are met:
[0221] (1) The initial scheduling sequence between component services satisfies the global priority sorting;
[0222] (2) Component services will not interrupt themselves when using virtual resources;
[0223] (3) As much as possible, ensure that multiple component services and multiple virtual resources execute in parallel at the same time;
[0224] (4) Low-priority component services will be interrupted by high-priority component services that require the same virtual resources;
[0225] (5) The priority of the service component subjectively modified is higher than the global priority generated by the multi-criteria decision-making algorithm.
[0226] In the security service orchestration method provided by the present invention, the differential evolution algorithm is used to evaluate the sequence of the incoming services to be executed, and the services to be executed are re-sorted according to the evaluation results, ensuring the objectivity of sorting the services to be executed. Then, the multi-service and multi-virtual resource parallel preemptive scheduling method is used to process the sorted services to be executed, avoiding the situation where a single service monopolizes a certain virtual resource for a long time, realizing flexible scheduling of the virtual resources required for running the services to be executed, and improving the processing efficiency of using virtual resources for the services to be executed.
[0227] An embodiment of the present invention provides a virtual security device management method based on differential evolution multi-task scheduling and parallel preemptive resource scheduling. First, for the centralized management layer of the software-defined security framework, a multi-criteria decision-making method based on the differential evolution algorithm is designed to schedule component services, realizing efficient service processing before virtual security device resource invocation. Then, for the security control layer, a parallel preemptive scheduling method for multiple services and multiple virtual resources based on priority is designed to improve the resource scheduling efficiency of virtual security devices. Finally, for the underlying software-defined security devices, a two-stage virtual security device abstraction method is designed, including virtualized device management and virtual resource management, to achieve the secure and efficient management of virtual security devices under software-defined security for perimeter security protection measures.
[0228] Embodiment 4:
[0229] Referring to Figure 8 , the present invention based on the same inventive concept also provides a security service scheduling system, including:
[0230] A virtual resource modeling module, configured to perform virtualization modeling on the virtual resources of each virtual machine in the virtual resource pool to obtain a virtual resource scheduling model, where each virtual machine in the virtual resource pool is obtained according to the security device management method described in the above technical solution;
[0231] An optimization objective construction module, configured to perform problem modeling based on multiple incoming services to be executed, according to the characteristics of each service to be executed, using a preset service sorting method, to obtain an optimization objective and constraints, where the optimization objective includes minimizing the total execution time of multiple services to be executed, minimizing the total response time, and maximizing the utilization rate of a single resource;
[0232] A weight vector determination module, configured to use the service priorities of multiple incoming services to be executed as an initial service sorting queue, determine the service sorting criteria for the multiple services to be executed, and use the differential evolution algorithm to determine the weight vector of each service sorting criterion;
[0233] A service sorting module, configured to evaluate the priority relationship of the multiple services to be executed using a multi-criteria decision-making algorithm based on the weight vector of each service sorting criterion to obtain a final service sorting queue;
[0234] A resource scheduling module, configured to solve the optimization objective using the virtual resource scheduling model and the constraints of the optimization objective to determine a parallel preemptive scheduling method for multiple services and multiple virtual resources based on priority;
[0235] A service processing module, configured to schedule the virtual resources of each virtual machine in the virtual resource pool according to the priority-based multi-service and multi-virtual resource parallel preemptive scheduling method, and process the multiple services to be executed in the final service sorting queue.
[0236] Optionally, the service sorting module includes:
[0237] A priority relationship evaluation unit, configured to evaluate the priority relationship of the multiple services to be executed based on the weight vector of each service sorting criterion by using a multi-criterion decision-making algorithm, and obtain an evaluation result;
[0238] A distillation sorting unit, configured to perform descending distillation and ascending distillation on the multiple services to be executed according to the evaluation result, and obtain a descending sorting sequence and an ascending sorting sequence;
[0239] A service final sorting unit, configured to combine the descending sorting sequence and the ascending sorting sequence, generate a global priority complete sorting of the multiple services to be executed, determine the final priority of the multiple services to be executed, and obtain the final service sorting queue of the multiple services to be executed.
[0240] Optionally, the priority relationship evaluation unit is specifically configured to:
[0241] Based on the weight vector of each service sorting criterion, obtain the partial coordination index, global coordination index, and partial incoordination index of the multiple services to be executed for each service sorting criterion;
[0242] Generate a credibility matrix of the multiple services to be executed for the corresponding service sorting criterion according to the partial coordination index, global coordination index, and partial incoordination index of each service sorting criterion;
[0243] Comprehensively evaluate the priority relationship of the multiple services to be executed based on the credibility matrix of the multiple services to be executed for each service sorting criterion, and obtain an evaluation result.
[0244] Optionally, the resource scheduling module includes:
[0245] A problem modeling unit, configured to determine the total execution time, total response time, and single resource utilization rate for running the multiple services to be executed by using a virtual resource scheduling model and the constraints of the optimization objective;
[0246] An optimization objective unit, configured to solve the optimization objective according to the total execution time, total response time, and single resource utilization rate of the multiple services to be executed, and use the result as the priority-based multi-service and multi-virtual resource parallel preemptive scheduling method.
[0247] Optionally, the total execution time, total response time, and single resource utilization rate of the multiple to-be-executed services respectively satisfy the following expressions:
[0248]
[0249] RT i =FT i -AT i ,
[0250]
[0251] FT i =max{FT ij} j∈[M] ,
[0252] WT ij =BT ij -AT i ,
[0253]
[0254] C ij =WT ij +ET ij ,
[0255] In the formula, represents the virtual resource VS in the virtual resource scheduling model j The total execution time of running the to-be-executed service; j represents the jth virtual resource in the virtual resource scheduling model, j ∈ (1, 2,..., M); RT i represents the total response time of the to-be-executed service T i ; i represents the ith to-be-executed service accessed, i ∈ (1, 2,..., N); M represents the total number of virtual resources in the virtual resource scheduling model; FT ij represents the end time of the to-be-executed service T i ; FT i represents the end time of the last to-be-executed service; BT ij represents the start execution time of the to-be-executed service T i ; AT i represents the access time of the to-be-executed service T i ; RU j represents the utilization rate of the virtual resource VS j ; WT ij represents the waiting time of the to-be-executed service T i on the virtual resource VS j ; ET ij represents the execution time of the to-be-executed service T i on the virtual resource VS j ; Li Indicates the business T to be executed i The quantity of virtual resource j required; speed represents the virtual resource VS j The quantity of virtual resources that can be provided per second; C ij Indicates the business T to be executed i On the virtual resource VS j All the time.
[0256] Embodiment 5:
[0257] As Figure 9 As shown, the present invention further provides an electronic device, which may be a computer device, a single-chip microcomputer device, a smart mobile device, etc. The electronic device in this embodiment may include a processor, a memory, a transceiver component, etc. The memory, the processor, and the transceiver component are connected by a bus; the memory can be used to store an execution program, and the exemplary execution program may include instructions; the processor is used to execute the instructions stored in the memory. The memory can also be used to store data, and the data can be called and / or modified when the instructions are executed.
[0258] The processor may be a central processing unit (Central Processing Unit, CPU), or may also be other general-purpose processors, digital signal processors (Digital Signal Processor, DSP), application specific integrated circuits (Application Specific Integrated Circuit, ASIC), off-the-shelf programmable gate arrays (Field-Programmable Gate Array, FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, and is suitable for implementing one or more instructions. Specifically, it is suitable for loading and executing one or more instructions in the storage medium to implement the corresponding method flow or corresponding function, so as to implement the steps of a security device management method or a security service orchestration method in the above embodiments.
[0259] Embodiment 6:
[0260] Based on the same inventive concept, the present invention also provides a readable storage medium, specifically an electronic device-readable storage medium (Memory). The electronic device-readable storage medium is a memory device in the electronic device and is used to store programs and data. It can be understood that the storage medium here can include both the built-in storage medium in the electronic device and, of course, the extended storage medium supported by the electronic device. The storage medium provides a storage space, and this storage space stores the operating system of the terminal. Moreover, one or more instructions suitable for being loaded and executed by the processor are stored in this storage space, and these instructions can be one or more execution programs (including program codes). It should be noted that the storage medium here can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. By the processor loading and executing one or more instructions stored in the storage medium, the steps of a security device management method or a security service orchestration method in the above embodiments can be implemented.
[0261] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.
[0262] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0263] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0264] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable apparatus to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one process or a plurality of processes and / or blocks Figure 1 one process or a plurality of processes and / or blocks Figure 1 in one block or a plurality of blocks.
[0265] The above are only embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention are included within the scope of the claims of the present invention pending approval.
Claims
1. A security device management method, characterized in that: include: According to the access business scenarios and security requirements, manage and configure each underlying device in the virtual network environment to obtain the virtual security device instance corresponding to each underlying device; Based on the virtual resource provision capability of each virtual security device instance, the first-stage abstract method is adopted to digitally describe each instance, and the description result of the virtual resources of each virtual security device is used as an abstract device model; Based on the multiple abstract device models, the second-stage abstract method is adopted to merge and aggregate the virtual resources represented by the multiple abstract device models, and each merged and aggregated result is used as a virtual machine in a virtual resource pool; each virtual machine in the virtual resource pool is used to provide computing resources for multiple connected services to be executed.
2. The method according to claim 1, characterized in that The virtual resource provision capability based on each virtual security device instance is described digitally using the first-stage abstract method, and the description result of the virtual resources of each virtual security device is used as an abstract device model, including: Obtain static and dynamic properties of each virtual security device instance; According to the dynamic attribute of each virtual security device instance, each virtual security device instance is screened respectively to obtain a plurality of virtual security device instances to be processed; According to the static attributes of each virtual security device instance to be processed, the virtual resource provision capability of each virtual security device instance is digitally described, and the description result of the virtual resources of each virtual security device is used as an abstract device model.
3. The method according to claim 1, characterized in that If the management and configuration of each underlying device connected includes establishing a virtual security device instance, then according to the business scenario and security requirements of the access, in the virtual network environment, each underlying device connected is managed and configured to obtain a virtual security device instance corresponding to each underlying device, including: According to the access business scenarios and security requirements, in the virtual network environment, obtain the original image and XML file of each underlying device accessed, and generate the MAC address corresponding to each underlying device; According to each MAC address, the corresponding data port bridge is mounted by the respective original image; Based on each mounted data port bridge, the corresponding XML file is modified, and a virtual security device instance is created respectively, and each virtual security device instance is stored in the database.
4. The method according to claim 1, characterized in that If the management configuration of each underlying device connected includes deleting the virtual security device instance, then according to the current business scenario and security requirements, in the virtual network environment, each underlying device connected is managed and configured to obtain the virtual security device instance corresponding to each underlying device, including: According to the access business scenario and security requirements, in the virtual network environment, obtain the MAC address of the virtual security device instance corresponding to each underlying device accessed; Determine the XML file of each virtual security device instance according to the MAC address of each virtual security device instance; Modify the XML file of each virtual security device instance, delete the virtual bridge and interface mounted by each XML file, and delete the corresponding virtual security device instance.
5. The method according to claim 1, characterized in that If the management configuration of each underlying device connected includes modifying the virtual security device instance, then according to the current business scenario and security requirements, in the virtual network environment, each underlying device connected is managed and configured to obtain the virtual security device instance corresponding to each underlying device, including: According to the access business scenario and security requirements, in the virtual network environment, obtain the MAC address of the virtual security device instance corresponding to each underlying device accessed; According to the MAC address of each virtual security device instance, modify the XML file of each virtual security device instance to determine each virtual security device instance after modification; According to each modified virtual security device instance, each virtual security device instance in the database is updated.
6. A safety equipment management system, characterized in that: include: The device management unit is used to manage and configure each underlying device in the virtual network environment according to the access business scenario and security requirements, and obtain the virtual security device instance corresponding to each underlying device; A model abstraction unit is used to digitally describe the virtual resource provision capability of each virtual security device instance using a one-stage abstraction method, and the description result of a virtual resource of each virtual security device is used as an abstract device model; The resource pool construction unit is used to merge and aggregate the virtual resources represented by the multiple abstract device models based on the multiple abstract device models by adopting the second stage abstract method, and use each merged and aggregated result as a virtual machine in the virtual resource pool; each virtual machine in the virtual resource pool is used to provide computing resources for the multiple connected services to be executed.
7. The system according to claim 6, characterized in that The model abstraction unit is specifically used for: Obtain static and dynamic properties of each virtual security device instance; According to the dynamic attribute of each virtual security device instance, each virtual security device instance is screened respectively to obtain a plurality of virtual security device instances to be processed; According to the static attributes of each virtual security device instance to be processed, the virtual resource provision capability of each virtual security device instance is digitally described, and the description result of a virtual resource of each virtual security device is used as an abstract device model.
8. The system according to claim 6, characterized in that If the management configuration of each underlying device connected includes establishing a virtual security device instance, the device management unit is specifically used to: According to the access business scenarios and security requirements, in the virtual network environment, obtain the original image and XML file of each underlying device accessed, and generate the MAC address corresponding to each underlying device; According to each MAC address, the corresponding data port bridge is mounted by the respective original image; Based on each mounted data port bridge, the corresponding XML file is modified, and a virtual security device instance is created respectively, and each virtual security device instance is stored in the database.
9. The system according to claim 6, characterized in that If the management configuration of each underlying device connected includes deleting the virtual security device instance, the device management unit is specifically used to: According to the access business scenario and security requirements, in the virtual network environment, obtain the MAC address of the virtual security device instance corresponding to each underlying device accessed; Determine the XML file of each virtual security device instance according to the MAC address of each virtual security device instance; Modify the XML file of each virtual security device instance, delete the virtual bridge and interface mounted by each XML file, and delete the corresponding virtual security device instance.
10. The system according to claim 6, characterized in that If the management and configuration of each underlying device connected includes modifying the virtual security device instance, the device management unit is specifically used to: According to the access business scenario and security requirements, in the virtual network environment, obtain the MAC address of the virtual security device instance corresponding to each underlying device accessed; According to the MAC address of each virtual security device instance, modify the XML file of each virtual security device instance to determine each virtual security device instance after modification; According to each modified virtual security device instance, each virtual security device instance in the database is updated.
11. A security service arrangement method, characterized in that: include: Virtual resources of multiple virtual machines in a virtual resource pool are virtualized and modeled to obtain a virtual resource scheduling model, wherein each virtual machine in the virtual resource pool is obtained according to the security device management method described in any one of claims 1 to 5; Based on the multiple services to be executed that are accessed, according to the characteristics of each service to be executed, a preset service ranking method is used to perform problem modeling to obtain optimization objectives and constraints, wherein the optimization objectives include minimizing the total execution time of the multiple services to be executed, minimizing the total response time, and maximizing the utilization rate of a single resource; Using the service priorities of the multiple services to be executed as the initial service sorting queue, determining the service sorting criteria of the multiple services to be executed, and using the differential evolution algorithm to determine the weight vector of each service sorting criteria; Based on the weight vector of each service sorting criterion, a multi-criteria decision algorithm is used to evaluate the priority relationship of the multiple services to be executed to obtain a final service sorting queue; The optimization target is solved by using the virtual resource scheduling model and the constraints of the optimization target, and a priority-based multi-service multi-virtual resource parallel preemptive scheduling method is determined; According to the priority-based multi-service multi-virtual resource parallel preemptive scheduling method, the virtual resources of each virtual machine in the virtual resource pool are scheduled, and the multiple to-be-executed services in the final service sorting queue are processed.
12. The method according to claim 11, characterized in that The weight vector based on each service sorting criterion adopts a multi-criteria decision algorithm to evaluate the priority relationship of the multiple services to be executed to obtain a final service sorting queue, including: Based on the weight vector of each business ranking criterion, a multi-criteria decision-making algorithm is used to evaluate the priority relationship of the multiple businesses to be executed to obtain an evaluation result; According to the evaluation result, performing descending distillation and ascending distillation on the multiple pending services to obtain a descending sorting sequence and an ascending sorting sequence; The descending sorting sequence and the ascending sorting sequence are combined to generate a global priority complete sorting of the multiple services to be executed, determine the final priorities of the multiple services to be executed, and obtain a final service sorting queue of the multiple services to be executed.
13. The method according to claim 11, characterized in that The weight vector based on each service ranking criterion adopts a multi-criteria decision-making algorithm to evaluate the priority relationship of the multiple services to be executed, and obtains an evaluation result, including: Based on the weight vector of each service sorting criterion, obtaining partial coordination indexes, global coordination indexes and partial incoordination indexes of the multiple services to be executed of each service sorting criterion; Generate a credibility matrix of the plurality of to-be-executed services corresponding to the service sorting criteria according to the partial coordination index, the global coordination index and the partial incoordination index of each service sorting criteria; The credibility matrix of the multiple services to be executed of each service sorting criterion is integrated to evaluate the priority relationship of the multiple services to be executed to obtain an evaluation result.
14. The method according to claim 11, characterized in that The virtual resource scheduling model and the constraints of the optimization target are used to solve the optimization target and determine a priority-based multi-service multi-virtual resource parallel preemptive scheduling method, including: Determine the total execution time, total response time and single resource utilization of the plurality of services to be executed by using the virtual resource scheduling model and the constraints of the optimization target; The optimization target is solved according to the total execution time, total response time and single resource utilization of the multiple services to be executed, and the result is used as a priority-based multi-service multi-virtual resource parallel preemptive scheduling method.
15. The method according to claim 14, characterized in that The total execution time, total response time and single resource utilization of the multiple pending services respectively satisfy the following expressions: RT i =FT i -AT i , FT i =max{FT ij } j∈[M] , WT ij =BT ij -AT i , C ij =WT ij +AND ij , In the formula, Represents the virtual resource VS in the virtual resource scheduling model j The total execution time of the business to be executed; j represents the jth virtual resource in the virtual resource scheduling model, j∈(1,2,…,M); RT i Indicates pending business T i The total response time of ; i represents the i-th service to be executed, i∈(1,2,…,N); M represents the total number of virtual resources in the virtual resource scheduling model; FT ij Indicates pending business T i End time of FT i Indicates the end time of the last pending business; BT ij Indicates pending business T i The start execution time of AT i Indicates pending business T i Access time; RU j Indicates virtual resources VS j Utilization rate of WT ij Indicates pending business T i In virtual resources VS j Waiting time on ET ij Indicates pending business T i In virtual resources VS j Execution time on L i Indicates pending business Y i The number of virtual resources j required; speed represents the virtual resources VS j The number of virtual resources that can be provided per second; C ij Indicates pending business T i In virtual resources VS j All the time on.
16. A security service orchestration system, characterized in that: include: A virtual resource modeling module, used to perform virtualization modeling on the virtual resources of each virtual machine in the virtual resource pool to obtain a virtual resource scheduling model, wherein each virtual machine in the virtual resource pool is obtained according to the security device management method according to any one of claims 1 to 5; An optimization target building module is used to perform problem modeling based on the characteristics of multiple pending services to be executed and to obtain optimization targets and constraints by using a preset service ranking method. The optimization targets include minimizing the total execution time of multiple pending services, minimizing the total response time, and maximizing the utilization rate of a single resource. A weight vector determination module, used to use the service priorities of the multiple services to be executed as the initial service sorting queue, determine the service sorting criteria of the multiple services to be executed, and use the differential evolution algorithm to determine the weight vector of each service sorting criterion; A service sorting module, for evaluating the priority relationship of the plurality of services to be executed based on the weight vector of each service sorting criterion and adopting a multi-criteria decision algorithm to obtain a final service sorting queue; A resource scheduling module, used to solve the optimization target by using the virtual resource scheduling model and the constraints of the optimization target, and determine a priority-based multi-service multi-virtual resource parallel preemptive scheduling method; The service processing module is used to schedule the virtual resources of each virtual machine in the virtual resource pool according to the priority-based multi-service multi-virtual resource parallel preemptive scheduling method, and perform service processing on multiple to-be-executed services in the final service sorting queue.
17. The system of claim 16, wherein: The business sorting module includes: A priority relationship evaluation unit, used to evaluate the priority relationship of the plurality of to-be-executed services by adopting a multi-criteria decision algorithm based on a weight vector of each service sorting criterion, and obtain an evaluation result; A distillation sorting unit, configured to perform descending distillation and ascending distillation on the plurality of pending services according to the evaluation result, to obtain a descending sorting sequence and an ascending sorting sequence; The service final sorting unit is used to combine the descending sorting sequence and the ascending sorting sequence to generate a global priority complete sorting of the multiple services to be executed, determine the final priorities of the multiple services to be executed, and obtain a final service sorting queue of the multiple services to be executed.
18. The system of claim 17, wherein: The priority relationship evaluation unit is specifically used for: Based on the weight vector of each service sorting criterion, obtaining partial coordination indexes, global coordination indexes and partial incoordination indexes of the multiple services to be executed of each service sorting criterion; Generate a credibility matrix of the plurality of to-be-executed services corresponding to the service sorting criteria according to the partial coordination index, the global coordination index and the partial incoordination index of each service sorting criteria; The credibility matrix of the multiple services to be executed of each service sorting criterion is integrated to evaluate the priority relationship of the multiple services to be executed to obtain an evaluation result.
19. The system of claim 16, wherein: The resource scheduling module includes: A problem modeling unit, used to determine the total execution time, total response time and single resource utilization rate of running the multiple services to be executed by using the virtual resource scheduling model and the constraints of the optimization target; The optimization target unit is used to solve the optimization target according to the total execution time, total response time and single resource utilization of the multiple services to be executed, and use the result as a priority-based multi-service multi-virtual resource parallel preemptive scheduling method.
20. The system of claim 19, wherein: The total execution time, total response time and single resource utilization of the multiple pending services respectively satisfy the following expressions: RT i =FT i -AT i , FT i =max{FT ij } j∈[M] , WT ij =BT ij -AT i , C ij =WT ij +AND ij , In the formula, Represents the virtual resource VS in the virtual resource scheduling model j The total execution time of the business to be executed; j represents the jth virtual resource in the virtual resource scheduling model, j∈(1,2,…,M); RT i Indicates pending business T i The total response time of ; i represents the i-th service to be executed, i∈(1,2,…,N); M represents the total number of virtual resources in the virtual resource scheduling model; FT ij Indicates pending business T i End time of FT i Indicates the end time of the last pending business; BT ij Indicates pending business T i The start execution time of AT i Indicates pending business T i Access time; RU j Indicates virtual resources VS j Utilization rate of WT ij Indicates pending business T i In virtual resources VS j Waiting time on ET ij Indicates pending business T i In virtual resources VS j Execution time on L i Indicates pending business T i The number of virtual resources j required; speed represents the virtual resources VS j The number of virtual resources that can be provided per second; C ij Indicates pending business T i In virtual resources VS j All the time on.
21. An electronic device, characterized in that: include: at least one processor and memory; The memory and the processor are connected via a bus; The memory is used to store one or more programs; When the one or more programs are executed by the at least one processor, the security device management method according to any one of claims 1 to 5 or the security service orchestration method according to any one of claims 11 to 15 is implemented.
22. A readable storage medium, characterized in that: An execution program is stored thereon, and when the execution program is executed, the security device management method according to any one of claims 1 to 5 or the security service orchestration method according to any one of claims 11 to 15 is implemented.
Citation Information
Cited By
Internet of Things equipment collaborative management system based on intelligent edge
CN120567947A