Cloud platform protection method, system, device, medium and product
By pre-establishing the association between the firewall and the cloud platform network service functions in the cloud platform, the problem that conventional firewall configurations are difficult to quickly respond to network changes is solved, and efficient protection and maintenance of north-south traffic is achieved.
Patent Information
- Application Number
- CN202510607373.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2045-05-12
AI Technical Summary
Conventional firewall protection adopts artificial static configuration, which makes it impossible to respond quickly to network changes, thereby increasing the difficulty of maintenance of north-south traffic.
By pre-establishing the first correlation between the firewall and the cloud platform network service functions, including firewall filtering rules, sub-affinity relationships and network mapping relationships, the automatic configuration synchronization of the firewall and switches is achieved, and traffic changes are responded in real time.
It realizes rapid response to network changes, reduces the difficulty of maintenance of north-south traffic, and improves the efficiency and flexibility of protection processing.
Smart Images

Figure CN120128429A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cloud computing, and particularly to a cloud platform protection method, system, device, medium and product. Background Art
[0002] With the development of cloud platforms, the larger their computing scale and application scope, the more complex the corresponding networking situation becomes. For the protection of the north-south traffic of conventional cloud platforms, manual static configuration of firewall devices is carried out according to the networking change situation by humans, which requires professional network engineers to operate, making it difficult to quickly respond to frequent networking changes, thus increasing the maintenance difficulty of north-south traffic.
[0003] Therefore, how to quickly respond to networking changes and then reduce the maintenance difficulty of north-south traffic is a technical problem that those skilled in the art urgently need to solve. Summary of the Invention
[0004] The purpose of the present invention is to provide a cloud platform protection method, system, device, medium and product to solve the problem that the conventional firewall protection uses manual static configuration, resulting in the inability to quickly respond to networking changes and thus increasing the maintenance difficulty of north-south traffic.
[0005] To solve the above technical problem, the present invention provides a cloud platform protection method, including: Pre-establish a first association relationship between a firewall and a cloud platform network service function; wherein, the first association relationship includes a first sub-association relationship between a firewall filtering rule and the firewall, a second sub-association relationship between a policy route established by a switch and a subnet-level firewall of the firewall, and a third sub-association relationship between a cloud platform network service function and the network of the switch; Obtain the north-south traffic to be processed; Perform protection processing on the north-south traffic according to the first association relationship to obtain the protected north-south traffic.
[0006] On the one hand, when the north-south traffic is the outgoing cloud traffic corresponding to the outgoing cloud direction, performing protection processing on the north-south traffic according to the first association relationship to obtain the protected north-south traffic includes: Determine the target network interface of the switch according to the third sub-association relationship and the outgoing cloud traffic to transmit to the switch; Determine the corresponding target subnet-level firewall according to the second sub-association relationship and the outgoing cloud traffic; Process the outgoing cloud traffic according to the first sub-association relationship and the target subnet-level firewall to obtain the protected north-south traffic.
[0007] On the other hand, when the north-south traffic is the cloud-inbound traffic corresponding to the cloud-inbound direction, perform protection processing on the north-south traffic according to the first association relationship to obtain the protected north-south traffic, including: Determine the corresponding target subnet-level firewall according to the second sub-association relationship and the cloud-inbound traffic; Process the cloud-inbound traffic according to the first sub-association relationship and the target subnet-level firewall to obtain the protected north-south traffic; Determine the target network interface of the switch according to the third sub-association relationship and the protected north-south traffic, so as to transmit from the switch to the storage space of the cloud platform network service function.
[0008] On the other hand, the establishment process of the first sub-association relationship includes: Establish each subnet-level firewall within the firewall; Establish a first mapping relationship between the firewall filtering rules and each subnet-level firewall; wherein, the firewall filtering rules are the filtering and screening rules for the message fields corresponding to the north-south traffic; Establish a second mapping relationship between each subnet-level firewall and the global firewall of the firewall; wherein, the second mapping relationship is established through virtual interfaces; Take the first mapping relationship and the second mapping relationship as the first sub-association relationship.
[0009] On the other hand, the establishment process of the second sub-association relationship includes: Obtain the target message corresponding to the target north-south traffic; Determine the target network interface of the switch corresponding to the subnet address of the target message according to the third sub-association relationship; Establish a mapping relationship between the target network interface, the subnet address, and the identification information corresponding to the subnet-level firewall, and use it as the second sub-association relationship.
[0010] On the other hand, the establishment process of the third sub-association relationship includes: Obtain each first network interface of the functional components of the storage space of the cloud platform network service function; Obtain each second network interface of the switch; Establish a third mapping relationship between each of the first network interfaces and each of the second network interfaces; Take the third mapping relationship as the third sub-association relationship.
[0011] On the other hand, when the cloud platform network service function is a logical router, the establishment process of the third mapping relationship includes: Establish each first network interface of the logical router and the first subnet; Set corresponding first identification information for the first subnet; Establish a first sub-network interface and a second sub-network interface of the gateway; wherein, the first sub-network interface is used to connect to the first network interface; the second sub-network interface is used to connect to the second network interface; Establish a first sub-gateway rule and a second sub-gateway rule of the gateway; Determine the third mapping relationship between the logical router and the switch according to the first sub-gateway rule, the second sub-gateway rule, the gateway, and the first identification information.
[0012] On the other hand, when the cloud platform network service function is a floating Internet protocol address, the process of establishing the third mapping relationship includes: Obtain the first network interface corresponding to the floating Internet protocol address; Map the first network interface and the second network interface according to the network interface mapping rule to obtain the third mapping relationship.
[0013] On the other hand, the first association relationship is stored in the database of the cloud platform; the database is used to store firewall information during the cloud platform protection process.
[0014] On the other hand, the configuration process of the firewall information includes: Pre-add configuration options in the configuration fields of the network service components of the cloud platform; Load the firewall plugin according to the configuration options in the configuration fields; Control the firewall plugin to read the first target configuration field in the configuration options to obtain the configuration block corresponding to the firewall information; Control the firewall plugin to read the second target configuration field in the configuration options to create a firewall resource pool to store the firewall information; Control the firewall plugin to read the third target configuration field in the configuration options to load the firewall driver information to drive the firewall.
[0015] On the other hand, the firewall information at least includes firewall resource pool configuration information, firewall resource pool identification information, firewall driver information, communication address of the firewall interface, version information of the firewall interface, firewall username, firewall password information, communication address of the switch interface, version information of the switch interface, switch interface username, and switch interface password information.
[0016] On the other hand, determining the target network interface of the switch according to the third sub-association relationship and the outbound traffic to transmit to the switch includes: When the cloud platform network service function is a logical router, perform gateway conversion on the outbound cloud traffic according to the logical router to obtain first traffic; Process the first traffic through the tenant network and the third sub - association relationship to determine the target network interface of the switch for transmission to the switch.
[0017] On the other hand, determining the target network interface of the switch according to the third sub - association relationship and the outbound cloud traffic for transmission to the switch includes: When the cloud platform network service function is a floating Internet protocol address, obtain the target packet corresponding to the outbound cloud traffic; Determine the cloud host address corresponding to the target packet according to the mapping relationship between the subnet address of the target packet and the floating Internet protocol address; Determine the target network interface of the switch according to the cloud host address and the third sub - association relationship for transmission to the switch.
[0018] On the other hand, determining the corresponding target subnet - level firewall according to the second sub - association relationship and the outbound cloud traffic includes: Obtain the address information of the first traffic; Judge whether the address information carries subnet address information; If it carries, determine the first policy route according to the subnet address information; and determine the corresponding target subnet - level firewall according to the first policy route and the second sub - association relationship; If it does not carry, determine the second policy route; and determine the corresponding target subnet - level firewall according to the second policy route and the second sub - association relationship.
[0019] To solve the above technical problems, the present invention also provides a cloud platform protection method based on outbound cloud traffic, including: Obtain the outbound cloud traffic sent from the cloud platform to the virtual switch; Send the outbound cloud traffic to the virtual space corresponding to the cloud platform network service function through the virtual switch; Perform protection processing on the outbound cloud traffic in the virtual space according to the first association relationship to obtain the protected outbound cloud traffic; wherein, the first association relationship includes the firewall filtering rule and the first sub - association relationship of the firewall, the second sub - association relationship between the policy route established by the switch and the subnet - level firewall of the firewall, and the third sub - association relationship between the cloud platform network service function and the network of the switch; Send the protected outbound cloud traffic to the switch for sending to the Internet.
[0020] To solve the above technical problems, the present invention also provides a cloud platform protection method based on inbound cloud traffic, including: Obtain the cloud-inbound traffic sent from the Internet to the switch; Perform protection processing on the cloud-inbound traffic according to the first association relationship to obtain the protected cloud-inbound traffic; wherein, the first association relationship includes the firewall filtering rules and the first sub-association relationship of the firewall, the second sub-association relationship between the policy routing established by the switch and the subnet-level firewall of the firewall, and the third sub-association relationship between the cloud platform network service function and the network of the switch; Send the protected cloud-inbound traffic to the switch to be sent to the virtual space corresponding to the cloud platform network service function; Forward the protected cloud-inbound traffic to the cloud host corresponding to the cloud platform through the virtual switch.
[0021] To solve the above technical problems, the present invention also provides a cloud platform protection system, and the cloud platform protection system includes a cloud platform, a firewall, a switch and a controller; The cloud platform, the firewall and the switch are all connected to the controller; The controller is used to execute the steps of the above cloud platform protection method to complete the protection processing of the north-south traffic and complete the protection of the north-south traffic.
[0022] To solve the above technical problems, the present invention also provides an electronic device, including a memory for storing a computer program; A processor for implementing the steps of the cloud platform protection method when executing the computer program.
[0023] To solve the above technical problems, the present invention also provides a computer-readable storage medium, and a computer program is stored on the computer-readable storage medium, and the computer program realizes the steps of the cloud platform protection method when executed by a processor.
[0024] To solve the above technical problems, the present invention also provides a computer program product, including a computer program / instructions, and the computer program / instructions realize the steps of the cloud platform protection method when executed by a processor.
[0025] The beneficial effects of the present invention are as follows. On the one hand, by pre - establishing the first association relationship between the firewall and the network service function of the cloud platform, the firewall and the cloud platform are linked, and different mapping relationships are established between the configuration information inside the firewall and the configuration of the switch and the cloud platform. At the same time, sub - association relationships are respectively established for different transmission parts of the corresponding traffic data during the transmission process of outgoing or incoming traffic, that is, the firewall information and network information are converted into the configurations of the firewall and the switch and respectively sent to the firewall and the switch. The network information links the cloud platform and the firewall. On the other hand, through the linkage process of the above - mentioned first association relationship, based on the first association relationship, the firewall rules and switch policy routes can be sent to the corresponding firewall and switch respectively to achieve fast configuration synchronization, so as to automatically perform dynamic protection processing in real - time based on the networking changes of packet information of traffic, improve the rate of responding to networking changes, and reduce the maintenance difficulty of north - south traffic.
[0026] In addition, the present invention also provides a cloud platform protection method based on outgoing cloud traffic, a cloud platform protection method based on incoming cloud traffic, a cloud platform protection system, an electronic device, a computer - readable storage medium, and a computer program product, which have the beneficial effects of the above - mentioned cloud platform protection method. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] In order to more clearly illustrate the embodiments of the present invention, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0028] Figure 1 It is a flowchart of a cloud platform protection method provided by an embodiment of the present invention; Figure 2 It is a schematic diagram of a protection mechanism for outgoing cloud traffic provided by an embodiment of the present invention; Figure 3 It is a schematic diagram of a protection mechanism for incoming cloud traffic provided by an embodiment of the present invention; Figure 4 It is an architecture diagram of a cloud platform protection system provided by an embodiment of the present invention; Figure 5 It is a flowchart of a cloud platform protection method based on outgoing cloud traffic provided by an embodiment of the present invention; Figure 6 It is a flowchart of a cloud platform protection method based on incoming cloud traffic provided by an embodiment of the present invention; Figure 7 It is a structural diagram of a cloud platform protection device provided by an embodiment of the present invention; Figure 8Structural diagram of a cloud platform protection device provided by an embodiment of the present invention based on egress traffic; Figure 9 Structural diagram of a cloud platform protection device provided by an embodiment of the present invention based on ingress traffic; Figure 10 Structural diagram of an electronic device provided by an embodiment of the present invention. Detailed implementation manners
[0029] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0030] The core of the present invention is to provide a cloud platform protection method, system, device, medium and product to solve the problem that the conventional firewall protection uses manual static configuration, resulting in the inability to quickly respond to network changes, thereby increasing the maintenance difficulty of north-south traffic.
[0031] In order to enable those skilled in the art to better understand the solution of the present invention, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.
[0032] In the conventional technology, the north-south traffic of the cloud platform is usually protected by an external firewall device. With the development of cloud computing in recent years, the scale of cloud computing has become larger and larger, the application range has become wider and wider, and the networking situation of the cloud platform has become more and more complex. The configuration of the firewall device for protecting the north-south traffic of the cloud platform has also become more complex. When the networking situation of the cloud platform changes, the configuration of the corresponding firewall device also needs to be modified. When the networking situation of the cloud platform becomes complex, the difficulty of manually modifying the configuration of the corresponding hardware firewall device also increases, and the response speed becomes relatively slow. The cloud platform protection method provided by the present invention can solve the above technical problems.
[0033] Figure 1 Flowchart of a cloud platform protection method provided by an embodiment of the present invention, as Figure 1 shown, the method includes: S11: Establish a first association relationship between the firewall and the cloud platform network service function in advance; Among them, the first association relationship includes a first sub-association relationship between the firewall filtering rule and the firewall, a second sub-association relationship between the policy routing established by the switch and the subnet-level firewall of the firewall, and a third sub-association relationship between the cloud platform network service function and the network of the switch; S12: Obtain the north-south traffic to be processed; S13: Perform protection processing on the north-south traffic according to the first association relationship to obtain the protected north-south traffic.
[0034] Specifically, establish the first association relationship between the firewall and the cloud platform network service function. In the conventional technical solution, there is either a manual static setting for protecting the corresponding traffic data or no firewall protection at all. The packet data corresponding to the traffic in the out-cloud direction is directly sent to the Internet through the switch, or the packet data corresponding to the traffic in the in-cloud direction is uploaded to the cloud platform through the switch. In this embodiment, whether it is the out-cloud direction or the in-cloud direction, it is only necessary to perform protection processing on the packet data through the firewall.
[0035] The first association relationship established in step S11 corresponds to the entire transmission process of the north-south traffic from the cloud platform to the Internet. Taking the out-cloud direction as an example, the establishment of the firewall filtering rule and the first sub-association relationship of the firewall is to filter the packet data corresponding to the traffic through the firewall filtering rule inside the firewall to screen out the packet data that can be sent to the Internet. The establishment of the policy route by the switch and the second sub-association relationship between the switch and the subnet-level firewall of the firewall is the mapping relationship of the path for the packet data in the out-cloud direction to be transmitted to the subnet-level firewall of the firewall after reaching the switch. The third sub-association relationship between the cloud platform network service function and the network of the switch is the mapping relationship of the network interface between the cloud platform and the switch in the out-cloud direction.
[0036] The cloud platform network service function is a network function component of the cloud platform. It can be a logical router, which is used to implement the routing function between different networks and is implemented through the Linux Network Namespace. Each router has its own independent routing table. The main functions of the logical router include: realizing communication between different subnets; providing the Network Address Translation (NAT) function to enable virtual machines to access the external network; providing an isolated network environment for tenants. It can also be a floating Internet Protocol Address (IP), which allows the public IP address to be dynamically allocated to the virtual machines of tenants. Its main functions include: enabling virtual machines to directly access the Internet; allowing the external network to access virtual machine instances; providing the static NAT function to establish a one-to-one mapping between the external network IP address and the IP address of the project where the instance is located. Regarding the two components of the cloud platform network service function, the subsequent association relationship establishment processes are different, and both are protected by the present invention.
[0037] The firewall filtering rule is a process of screening the packet data corresponding to the traffic inside the firewall. It can be a restriction on the packet fields or other characteristics of the packet, such as the packet address information, etc. There is no limitation here and it can be set according to the actual situation.
[0038] The policy routing of the switch is a mechanism for routing selection based on the policies formulated by users. It can determine the forwarding path of the packet according to various attributes of the packet (such as source address, destination address, protocol type, port number, etc.). The policy routing of this embodiment is how the packet data received by the network interface of the switch reaches the subnet-level firewall of the firewall along such a path.
[0039] The subnet-level firewall of the firewall configures independent firewall filtering rules for each subnet or specific virtual machine port to achieve more flexible security control.
[0040] Obtain the north-south traffic to be processed. It should be noted that the north-south traffic here is a general term. It can be the packet data in the direction of going out of the cloud or the packet data in the direction of entering the cloud. No matter what direction the data is, it can be included. However, the execution order of the sub-association relationships inside the corresponding association relationships for the two directions is not limited here, and both can achieve the protection and processing of the packet data.
[0041] In some embodiments, when the north-south traffic is the outgoing cloud traffic corresponding to the direction of going out of the cloud, perform protection processing on the north-south traffic according to the first association relationship to obtain the protected north-south traffic, including: Determine the target network interface of the switch according to the third sub-association relationship and the outgoing cloud traffic to transmit to the switch; Determine the corresponding target subnet-level firewall according to the second sub-association relationship and the outgoing cloud traffic; Perform processing on the outgoing cloud traffic according to the first sub-association relationship and the target subnet-level firewall to obtain the protected north-south traffic.
[0042] Specifically, considering the outgoing cloud traffic in the direction of going out of the cloud, the corresponding link is still within the cloud platform. Determine the target network interface of the switch corresponding to the outgoing cloud traffic through the third sub-association relationship, and at this time it can be transmitted into the switch. Then, through the second sub-association relationship, the target subnet-level firewall can be determined through the mapping between the policy routing and the subnet-level firewall. Then, perform the protection processing by filtering according to the firewall filtering rule of the first sub-association relationship.
[0043] Figure 2 It is a schematic diagram of a protection mechanism for outgoing cloud traffic provided by an embodiment of the present invention, as Figure 2As shown in the figure, the cloud host sends the packet data corresponding to the outbound cloud traffic. After passing through the logical switch of the cloud platform and the components of the cloud platform network service function, it is sent to the switch through the third sub - association relationship. The switch forwards it to the target subnet - level firewall through the policy routing of the second sub - association relationship, and performs filtering processing in the target subnet - level firewall according to the first sub - association relationship. Then it returns to the public wall (global firewall) of the firewall, and then returns to the switch and is forwarded to the Internet.
[0044] In this embodiment, three different sub - association relationships under the transmission path are used to find the firewall filtering rules under the subnet - level firewall. While improving the mapping accuracy of the packet data through different sub - association relationships, protection processing is completed to achieve the protection of the outbound cloud traffic.
[0045] In some other embodiments, when the north - south traffic is the inbound cloud traffic corresponding to the inbound cloud direction, protection processing is performed on the north - south traffic according to the first association relationship to obtain the protected north - south traffic, including: Determine the corresponding target subnet - level firewall according to the second sub - association relationship and the inbound cloud traffic; Process the inbound cloud traffic according to the first sub - association relationship and the target subnet - level firewall to obtain the protected north - south traffic; Determine the target network interface of the switch according to the third sub - association relationship and the protected north - south traffic, so as to transmit from the switch to the storage space of the cloud platform network service function.
[0046] Specifically, considering the inbound cloud traffic in the inbound cloud direction, its corresponding link is located in the switch. According to the second sub - association relationship, the target subnet - level firewall can be determined through the mapping between the policy routing and the subnet - level firewall. Protection processing is performed through filtering according to the firewall filtering rules of the first sub - association relationship, and then the target network interface of the switch corresponding to the outbound cloud traffic is determined through the third sub - association relationship. At this time, it can be transmitted into the switch to be sent to the components of the cloud platform network service function for inbound cloud.
[0047] Figure 3 It is a schematic diagram of a protection mechanism for inbound cloud traffic provided by an embodiment of the present invention. As Figure 3 shown, the Internet sends the packet data of the inbound cloud traffic to the switch. The switch passes the packet data through the public wall of the firewall according to the policy routing of the second sub - association relationship, and then to the target subnet - level firewall. Filtering is performed through the firewall filtering rules of the first sub - association relationship. After returning to the public wall, it returns to the switch again. The switch sends it to the components of the cloud platform network service function according to the third sub - association relationship, reaches the logical switch, and is forwarded to the cloud host.
[0048] In this embodiment, three different sub - association relationships under the transmission path are used to find the firewall filtering rules under the subnet - level firewall. While improving the mapping accuracy of packet data through different sub - association relationships, the flexibility and diversity of configuration are also improved according to the transmission path of the incoming cloud traffic, and protection processing is completed to achieve the protection of the outgoing cloud traffic.
[0049] The beneficial effects of the embodiments of the present invention are as follows. On the one hand, by pre - establishing the first association relationship between the firewall and the network service function of the cloud platform, the firewall and the cloud platform are linked, and different mapping relationships are established between the configuration information inside the firewall and the configurations of the switches and the cloud platform. At the same time, corresponding sub - association relationships are respectively established for different transmission parts of the corresponding incoming or outgoing traffic data during the transmission process, that is, it is realized that the firewall information and network information are converted into the configurations of the firewall and the switch and respectively sent to the firewall and the switch. The network information links the cloud platform and the firewall. On the other hand, through the linkage process of the above - mentioned first association relationship, based on the first association relationship, the firewall rules and the switch policy routes can be sent to their respective corresponding firewalls and switches to achieve fast configuration synchronization, so as to perform automatic dynamic protection processing in real - time based on the networking changes of the packet information of the traffic, improve the rate of responding to networking changes, and reduce the maintenance difficulty of north - south traffic.
[0050] In some embodiments, the establishment process of the first sub - association relationship includes: Establish each subnet - level firewall inside the firewall; Establish a first mapping relationship between the firewall filtering rules and each subnet - level firewall; among them, the firewall filtering rule is the filtering and screening rule for the packet fields corresponding to the north - south traffic; Establish a second mapping relationship between each subnet - level firewall and the global firewall of the firewall; among them, the second mapping relationship is established through virtual interfaces; Take the first mapping relationship and the second mapping relationship as the first sub - association relationship.
[0051] Specifically, as Figure 2 、 3 shown, establish each subnet - level firewall inside the firewall, and establish a first mapping relationship between the firewall filtering rules and each subnet - level firewall. Here, the first mapping relationship is to add the screening rules for the subnet address information or field information corresponding to each networking change as the firewall filtering rules inside each subnet - level firewall. It should be noted that the firewall filtering rules of this embodiment can be added, deleted, modified, etc. according to the real - time networking changes. There can be multiple firewall filtering rules in one subnet - level firewall, and the multiple firewall filtering rules can be stored in the order of time sequence or screened according to the incoming packet data, and this is not limited here.
[0052] The second mapping relationship is established between each subnet-level firewall and the global firewall of the firewall. Here, the second mapping relationship is a many-to-one mapping, that is, the mapping relationship between multiple subnet-level firewalls and one global firewall.
[0053] The establishment of the first sub-association relationship provided in this embodiment associates the firewall filtering rules of its firewall resource pool with the firewall, creates a subnet-level firewall on the firewall, creates a virtual interface pair between the sub-wall and the public wall, and creates firewall filtering rules in the sub-wall. To achieve the function of protecting the north-south traffic of the cloud platform.
[0054] In some embodiments, the establishment process of the second sub-association relationship includes: Obtain the target packet corresponding to the target north-south traffic; Determine the target network interface of the switch corresponding to the subnet address of the target packet according to the third sub-association relationship; Establish a mapping relationship between the target network interface, the subnet address, and the identification information corresponding to the subnet-level firewall, and use it as the second sub-association relationship.
[0055] Specifically, obtain the target packet corresponding to the target north-south traffic, and the target network interface corresponding to the subnet address of the target packet can be determined through the network interface of the switch within the third sub-association relationship. In this embodiment, a mapping relationship between the target network interface, the subnet address, and the identification information corresponding to the subnet-level firewall is established to create a policy route, that is, the second sub-association relationship.
[0056] The second sub-association relationship provided in this embodiment is that after the target packet is sent to the public wall of the firewall through the switch direct connection network according to the policy route, the public wall forwards the target packet to the corresponding sub-wall for filtering.
[0057] In some embodiments, the establishment process of the third sub-association relationship includes: Obtain each first network interface of the functional components of the cloud platform network service function; Obtain each second network interface of the switch; Establish a third mapping relationship between each first network interface and each second network interface; Use the third mapping relationship as the third sub-association relationship.
[0058] Specifically, in this embodiment, a third mapping relationship is established between the first network interface corresponding to the functional component of the cloud platform network service function and the second network interface of the switch to realize the bridge between the cloud platform and the switch. It should be noted that since the functional component of the cloud platform network service function can be a logical router or a floating IP, the method of establishing the third mapping relationship is different. Therefore, it is necessary to establish it according to different cloud platform network service functions.
[0059] In some embodiments, when the cloud platform network service function is a logical router, the process of establishing the third mapping relationship includes: Establish each first network interface and the first subnet of the logical router; Set corresponding first identification information for the first subnet; Establish the first sub-network interface and the second sub-network interface of the gateway; wherein, the first sub-network interface is used to connect to the first network interface; the second sub-network interface is used to connect to the second network interface; Establish the first sub-gateway rule and the second sub-gateway rule of the gateway; Determine the third mapping relationship between the logical router and the switch according to the first sub-gateway rule, the second sub-gateway rule, the gateway, and the first identification information.
[0060] Specifically, a logical router is typically used to connect different virtual networks or subnets and provide routing functions. In the open-source cloud computing management platform project OpenStack, a logical router can be managed by the L3 Agent of the Neutron component that provides network services. When a logical router is connected to a Virtual Local Area Network (VLAN) network, the mapping relationship can be established in the following way: Create a VLAN network and a subnet: Create a VLAN network and a subnet through the Neutron Application Programming Interface (API) and specify the VLAN ID; Configure the logical router interface: Connect the interfaces of the logical router to these VLAN networks. Neutron will automatically handle the encapsulation and decapsulation of VLAN tags, that is, establish the first network interface and the first subnet of the logical router, and set the corresponding first identification information for the first subnet.
[0061] The NAT gateway is used to implement address translation between the internal network and the external network. In a cloud platform, the NAT gateway is usually used in conjunction with a logical router. The mapping relationship can be established in the following ways: Configure the external network interface: Configure an external network interface for the NAT gateway, and this interface is connected to a VLAN network. Configure the internal network interface: Configure one or more internal network interfaces for the NAT gateway, and these interfaces are connected to the internal VLAN network. Set NAT rules: Configure source network address translation (SNAT) and destination network address translation (DNAT) rules on the NAT gateway to enable communication between the internal network and the external network, that is, establish the first sub-network interface and the second sub-network interface of the gateway; where the first sub-network interface is used to connect to the first network interface; the second sub-network interface is used to connect to the second network interface; establish the first sub-gateway rule and the second sub-gateway rule of the gateway.
[0062] The VLAN network interface mapping of the switch can be achieved through VLAN mapping technology, that is, determine the third mapping relationship between the logical router and the switch according to the first sub-gateway rule, the second sub-gateway rule, the gateway, and the first identification information.
[0063] The third mapping relationship established among the logical router, NAT gateway, and VLAN network interface of the switch provided in this embodiment optimizes network performance, can effectively reduce the size of the broadcast domain, and reduce the impact of broadcast traffic on network performance. The traffic of different departments or services can be isolated in different VLANs to prevent unauthorized access and improve network security.
[0064] In some other embodiments, when the cloud platform network service function is a floating Internet protocol address, the process of establishing the third mapping relationship includes: Obtain the first network interface corresponding to the floating Internet protocol address; Map the first network interface and the second network interface according to the network interface mapping rule to obtain the third mapping relationship.
[0065] Specifically, floating IP is usually used to map the private IP address of a virtual machine to a public IP address so that the virtual machine can access the external network or be accessed by the external network. When configuring VLAN mapping on the VLAN network interface of the switch, the VLAN where the virtual machine is located can be mapped to the VLAN of the external network, thereby realizing the function of floating IP.
[0066] Create a second network interface on the switch, add the second network interface to the corresponding VLAN, and configure the second network interface of the switch to the corresponding type to allow traffic of a specific VLAN to pass through. Map the first network interface and the second network interface according to the network interface mapping rule to implement VLAN mapping configuration.
[0067] The VLAN mapping technology provided by this embodiment can map the VLAN where the floating IP is located to the VLAN network interface of the switch, so as to realize the communication between the virtual machine and the external network, realize flexible traffic scheduling, enhance network security, and hide the internal network structure.
[0068] In some embodiments, the first association relationship is stored in the database of the cloud platform; the database is used to store firewall information during the cloud platform protection process.
[0069] Figure 4 For the architecture diagram of a cloud platform protection system provided by an embodiment of the present invention, as Figure 4 shown, the first association relationship of this embodiment is stored in the database of the cloud platform, and this database is used to store firewall information corresponding to all involved firewalls.
[0070] In some embodiments, the firewall information at least includes firewall resource pool configuration information, firewall resource pool identification information, firewall driver information, communication address of the firewall interface, version information of the firewall interface, firewall username, firewall password information, communication address of the switch interface, version information of the switch interface, switch interface username, and switch interface password information.
[0071] The setting of each firewall information provided by this embodiment enhances the flexibility and diversity of the firewall linkage mechanism, so as to facilitate real-time configuration information.
[0072] In some embodiments, the configuration process of the firewall information includes: Add configuration options to the configuration fields of the network service components of the cloud platform in advance; Load the firewall plugin according to the configuration options in the configuration fields; Control the firewall plugin to read the first target configuration field in the configuration options to obtain the configuration block corresponding to the firewall information; Control the firewall plugin to read the second target configuration field in the configuration options to create a firewall resource pool to store the firewall information; Control the firewall plugin to read the third target configuration field in the configuration options to load the driver corresponding to the firewall driver information.
[0073] Specifically, taking the cloud platform OpenStack as an example, configuration options "edge-firewall" and are added to the existing configuration field "service_plugins" of the network service component (Neutron), indicating that the hardware firewall plugin needs to be loaded when Neutron starts. At the same time, a new configuration block is added, which is used to store firewall information.
[0074] When Neutron starts, according to the value of "edge-firewall" in the "service_plugins" configuration field, the hardware firewall plugin is loaded. The hardware firewall plugin will read the "edge_firewall_sections" configuration field (the first target configuration field) to obtain the hardware firewall resource pool configuration block. The hardware firewall plugin uses the hardware firewall resource pool configuration block as the firewall resource pool name and the "pool_id" field (the second target configuration field) as the firewall resource pool ID to create a firewall resource pool object and store it in the database. The hardware firewall plugin loads the hardware firewall driver according to the "device_driver" configuration field (the third target configuration field) and initializes the hardware firewall driver with the configuration in the hardware firewall resource pool configuration block.
[0075] Among them, the firewall information is embodied in the form of each field: "edge_firewall_sections": A list of hardware firewall resource pool configuration blocks; "pool_id": The ID of the hardware firewall resource pool, in the format of uuid; "device_driver": The driver of the hardware firewall resource pool, which is a component used to send configurations to the firewall devices and switch devices in the hardware firewall resource pool and read the working status of the firewall devices and switch devices in the hardware firewall resource pool; "firewall_api_url": The Uniform Resource Locator (URL) of the firewall device API; "firewall_api_version": The version number of the firewall device API; "firewall_username": The username of the firewall device; "firewall_password": The password of the firewall device; "switch_api_url": The URL of the switch device API; "switch_api_version": The version number of the switch device API; "switch_username": The username of the switch device; switch_password: The password of the switch device.
[0076] The present embodiment provides for pre-configuring each configuration information to facilitate subsequent linkage with the firewall, improving the configuration ability and efficiency.
[0077] In some embodiments, determining the target network interface of the switch according to the third sub-association relationship and the outbound traffic for transmission to the switch includes: When the network service function of the cloud platform is a logical router, performing gateway conversion on the outbound traffic by the logical router to obtain a first traffic; Processing the first traffic through the tenant network and the third sub-association relationship to determine the target network interface of the switch for transmission to the switch.
[0078] Specifically, in this embodiment, taking the logical router as an example, the transmission path corresponding to its third sub-association relationship is that the logical router performs gateway conversion on the outbound traffic to obtain a first traffic, and it processes the first traffic through the tenant network and the third sub-association relationship. Here, the processing is mainly to determine the target network interface of the next transmission switch according to the corresponding mapping relationship for transmission to the switch.
[0079] The present embodiment provides the transmission path corresponding to the logical router and the switch, realizing refined network management and improving the transmission rate.
[0080] In other embodiments, determining the target network interface of the switch according to the third sub-association relationship and the outbound traffic for transmission to the switch includes: When the network service function of the cloud platform is a floating Internet protocol address, obtaining the target packet corresponding to the outbound traffic; Determining the cloud host address corresponding to the target packet according to the mapping relationship between the subnet address of the target packet and the floating Internet protocol address; Determining the target network interface of the switch according to the cloud host address and the third sub-association relationship for transmission to the switch.
[0081] Specifically, mainly based on the mapping relationship between the subnet address of the target packet and the floating IP address, the corresponding cloud host address can be determined. According to the subnet address and interface mapping of the cloud host address and the third sub-association relationship, the target network interface of the switch can be determined for transmission to the switch.
[0082] The present embodiment provides the transmission path corresponding to the floating IP and the switch, realizing the diversity and flexibility of network transmission and improving the transmission rate.
[0083] In some embodiments, determining the corresponding target subnet-level firewall according to the second sub-association relationship and the outbound traffic includes: Obtain the address information of the first traffic; Determine whether the address information carries subnet address information; If it carries, determine the first policy route according to the subnet address information; and determine the corresponding target subnet-level firewall according to the first policy route and the second sub-association relationship; If it does not carry, determine the second policy route; and determine the corresponding target subnet-level firewall according to the second policy route and the second sub-association relationship.
[0084] Considering that the address information of the packet data of the traffic out of the cloud may carry sub-website information or not carry sub-website information, so, here it is discussed in different cases. In the case of carrying, determine the first policy route according to the subnet address information, so as to determine the corresponding target subnet-level firewall according to the first policy route and the second sub-association relationship; if not, directly determine the second policy route, and determine the corresponding target subnet-level firewall according to the second policy route and the second sub-association relationship.
[0085] This embodiment considers that the policy routes corresponding to the address information of the packet data may carry sub-website information or not carry sub-website information, and it is discussed in different cases, improving the flexibility and diversity of the target subnet-level firewall.
[0086] Furthermore, the present invention also provides a cloud platform protection method based on the traffic out of the cloud, Figure 5 which is a flowchart of a cloud platform protection method provided by an embodiment of the present invention, as Figure 5 shown, including: S21: Obtain the traffic out of the cloud sent by the cloud platform to the virtual switch; S22: Send the traffic out of the cloud through the virtual switch to the virtual space corresponding to the cloud platform network service function; S23: Perform protection processing on the traffic out of the cloud in the virtual space according to the first association relationship to obtain the protected traffic out of the cloud; wherein, the first association relationship includes a firewall filtering rule and a first sub-association relationship of the firewall, a second sub-association relationship between the policy route established by the switch and the subnet-level firewall of the firewall, and a third sub-association relationship between the cloud platform network service function and the network of the switch; S24: Send the protected traffic out of the cloud to the switch to be sent to the Internet.
[0087] As Figure 2As shown in the figure, the cloud host sends a message. The logical switch forwards the message from the Generic Network Virtualization Encapsulation (Geneve) interface, reaches the logical router through the tunnel network. The logical router performs SNAT conversion on the message, and then sends it through the tenant network to the switch device. The switch device forwards the message to the public wall of the firewall device according to the policy routing through the direct connection network. The public wall of the firewall device forwards the message to the corresponding sub-wall. After the message is packet-filtered in the sub-wall, it returns to the public wall, then returns to the switch device, and finally is forwarded to the Internet.
[0088] For the introduction of a cloud platform protection method based on outbound cloud traffic provided by the present invention, please refer to the above method embodiments. The present invention will not be elaborated herein, and it has the same beneficial effects as the above cloud platform protection method.
[0089] Furthermore, the present invention also provides a cloud platform protection method based on inbound cloud traffic. Figure 6 It is a flowchart of a cloud platform protection method based on inbound cloud traffic provided by an embodiment of the present invention. As Figure 6 shown, it includes: S31: Obtain the inbound cloud traffic sent from the Internet to the switch; S32: Perform protection processing on the inbound cloud traffic according to the first association relationship to obtain the protected inbound cloud traffic; Among them, the first association relationship includes the firewall filtering rule and the first sub-association relationship of the firewall, the second sub-association relationship between the policy routing established by the switch and the subnet-level firewall of the firewall, and the third sub-association relationship between the cloud platform network service function and the network of the switch; S33: Send the protected inbound cloud traffic to the switch to be sent to the virtual space corresponding to the cloud platform network service function; S34: Forward the protected inbound cloud traffic to the cloud host corresponding to the cloud platform through the virtual switch.
[0090] As Figure 3 shown, the Internet sends a message to the switch device. The switch device forwards the message to the public wall of the firewall device according to the logical routing through the direct connection network. The public wall of the firewall device forwards the message to the corresponding sub-wall. After the message is packet-filtered in the sub-wall, it returns to the public wall, then returns to the switch device. The switch device sends the message from the corresponding VLAN interface, reaches the logical router through the tenant network. The logical router performs DNAT conversion on the message. The message is sent out from the Geneve interface, reaches the logical switch through the tunnel network, and finally is forwarded to the cloud host.
[0091] For the introduction of a cloud platform protection method based on incoming cloud traffic provided by the present invention, please refer to the above method embodiments. The present invention will not repeat them here, and it has the same beneficial effects as the above cloud platform protection method.
[0092] Further, the present invention also provides a cloud platform protection system. The cloud platform protection system includes a cloud platform, a firewall, a switch, and a controller. The cloud platform, the firewall, and the switch are all connected to the controller. The controller is used to execute the steps of the above cloud platform protection method to complete the protection processing of north-south traffic and complete the protection of north-south traffic.
[0093] It should be noted that the controller in this embodiment is a device additional to the above-mentioned cloud platform, firewall, and switch. This device can also be set within the cloud platform, and no limitation is made here.
[0094] For the introduction of a cloud platform protection system provided by the present invention, please refer to the above method embodiments. The present invention will not repeat them here, and it has the same beneficial effects as the above cloud platform protection method.
[0095] The above has described in detail each embodiment corresponding to the cloud platform protection method. On this basis, the present invention also discloses a cloud platform protection device corresponding to the above method. Figure 7 It is a structural diagram of a cloud platform protection device provided by an embodiment of the present invention. As Figure 7 shown, the cloud platform protection device includes: A establishment module 11, which is used to pre-establish a first association relationship between the firewall and the cloud platform network service function. Among them, the first association relationship includes a first sub-association relationship between the firewall filtering rule and the firewall, a second sub-association relationship between the policy route established by the switch and the subnet-level firewall of the firewall, and a third sub-association relationship between the cloud platform network service function and the network of the switch. A first acquisition module 12, which is used to acquire the north-south traffic to be processed. A first protection module 13, which is used to perform protection processing on the north-south traffic according to the first association relationship to obtain the protected north-south traffic.
[0096] Since the embodiments of the device part correspond to the above embodiments, the embodiments of the device part please refer to the embodiments of the above method part for description, and will not be repeated here.
[0097] For the introduction of a cloud platform protection device provided by the present invention, please refer to the above method embodiments. The present invention will not repeat them here, and it has the same beneficial effects as the above cloud platform protection method.
[0098] The above has described in detail each embodiment corresponding to the cloud platform protection method based on egress traffic. On this basis, the present invention also discloses a cloud platform protection device based on egress traffic corresponding to the above method. Figure 8 It is a structural diagram of a cloud platform protection device based on egress traffic provided by an embodiment of the present invention. As Figure 8 shown, the cloud platform protection device based on egress traffic includes: A second acquisition module 14, configured to acquire egress traffic sent from the cloud platform to the virtual switch; A first sending module 15, configured to send the egress traffic to the virtual space corresponding to the cloud platform network service function via the virtual switch; A second protection module 16, configured to perform protection processing on the egress traffic in the virtual space according to the first association relationship to obtain the protected egress traffic; wherein, the first association relationship includes a firewall filtering rule and a first sub-association relationship of the firewall, a second sub-association relationship between the policy route established by the switch and the subnet-level firewall of the firewall, and a third sub-association relationship between the cloud platform network service function and the network of the switch; A second sending module 17, configured to send the protected egress traffic to the switch for sending to the Internet.
[0099] For the introduction of a cloud platform protection device based on egress traffic provided by the present invention, please refer to the above method embodiment, and the present invention will not elaborate herein. It has the same beneficial effects as the above cloud platform protection method.
[0100] The above has described in detail each embodiment corresponding to the cloud platform protection method based on ingress traffic. On this basis, the present invention also discloses a cloud platform protection device based on ingress traffic corresponding to the above method. Figure 9 It is a structural diagram of a cloud platform protection device based on ingress traffic provided by an embodiment of the present invention. As Figure 9 shown, the cloud platform protection device based on ingress traffic includes: A third acquisition module 18, configured to acquire ingress traffic sent from the Internet to the switch; A third protection module 19, configured to perform protection processing on the ingress traffic according to the first association relationship to obtain the protected ingress traffic; wherein, the first association relationship includes a firewall filtering rule and a first sub-association relationship of the firewall, a second sub-association relationship between the policy route established by the switch and the subnet-level firewall of the firewall, and a third sub-association relationship between the cloud platform network service function and the network of the switch; A third sending module 20, configured to send the protected ingress traffic to the switch for sending to the virtual space corresponding to the cloud platform network service function; A forwarding module 21, configured to forward the protected traffic into the cloud to the corresponding cloud host of the cloud platform through a virtual switch.
[0101] For the introduction of a cloud platform protection device based on traffic into the cloud provided by the present invention, please refer to the above method embodiments. The present invention will not be elaborated herein, and it has the same beneficial effects as the above cloud platform protection method.
[0102] Figure 10 The following is a structural diagram of an electronic device provided by an embodiment of the present invention. As Figure 10 shown, the device includes: A memory 22, configured to store a computer program; A processor 23, configured to implement the steps of the cloud platform protection method when executing the computer program.
[0103] Among them, the processor 23 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 23 may be implemented in at least one hardware form of a digital signal processor (DSP), a field-programmable gate array (FPGA), and a programmable logic array. The processor 23 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the wake state, also known as a central processing unit (CPU); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 23 may be integrated with a graphics processing unit (GPU), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 23 may further include an artificial intelligence (AI) processor, and the AI processor is used to process computational operations related to machine learning.
[0104] The memory 22 may include one or more computer-readable storage media, which may be non-transitory. The memory 22 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices and flash storage devices. In this embodiment, the memory 22 is at least used to store the following computer program 211. After the computer program is loaded and executed by the processor 23, it can implement the relevant steps of the cloud platform protection method disclosed in any of the foregoing embodiments. In addition, the resources stored in the memory 22 may also include an operating system 212 and data 213, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system 212 may include Windows, Unix, Linux, etc. The data 213 may include, but is not limited to, the data involved in the cloud platform protection method, etc.
[0105] In some embodiments, the electronic device may further include a display screen 24, an input / output interface 25, a communication interface 26, a power supply 27, and a communication bus 28.
[0106] Those skilled in the art can understand that Figure 10 the structure shown in does not constitute a limitation on the electronic device, and it may include more or fewer components than those shown in the figure.
[0107] The processor 23 realizes the cloud platform protection method provided in any of the above embodiments by calling the instructions stored in the memory 22.
[0108] For the introduction of an electronic device provided by the present invention, please refer to the above method embodiments. The present invention will not be elaborated herein again, and it has the same beneficial effects as the above cloud platform protection method.
[0109] Furthermore, the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by the processor 23, it realizes the steps of the cloud platform protection method as described above.
[0110] It can be understood that if the method in the above embodiments is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and executes all or part of the steps of the methods of the various embodiments of the present invention. And the foregoing storage media include: USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs, etc., which can store program codes.
[0111] For the introduction of a computer-readable storage medium provided by the present invention, please refer to the above method embodiments. The present invention will not be elaborated herein, and it has the same beneficial effects as the above cloud platform protection method.
[0112] Furthermore, the present invention also provides a computer program product, including computer programs / instructions, which implement the steps of the above cloud platform protection method when executed by a processor.
[0113] For the introduction of a computer program product provided by the present invention, please refer to the above method embodiments. The present invention will not be elaborated herein, and it has the same beneficial effects as the above cloud platform protection method.
[0114] The above has provided a detailed introduction to a cloud platform protection method, system, device, medium, and product provided by the present invention. The embodiments in the specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method part. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the protection scope of the present invention.
[0115] It should also be noted that in this specification, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including an..." does not exclude the existence of additional identical elements in the process, method, article or device including the element.
Claims
1. A cloud platform protection method, characterized in that: include: Pre-establish a first association relationship between the firewall and the cloud platform network service function; wherein the first association relationship includes a first sub-association relationship between the firewall filtering rule and the firewall, a second sub-association relationship between the policy routing established by the switch and the subnet-level firewall of the firewall, and a third sub-association relationship between the cloud platform network service function and the network of the switch; Get the north-south traffic to be processed; The north-south traffic is protected according to the first association relationship to obtain protected north-south traffic.
2. The cloud platform protection method according to claim 1, characterized in that: When the north-south traffic is the outbound traffic corresponding to the outbound direction, protection processing is performed on the north-south traffic according to the first association relationship to obtain protected north-south traffic, including: Determine a target network interface of a switch according to the third sub-association relationship and the outbound cloud traffic, so as to transmit the traffic to the switch; Determine a corresponding target subnet-level firewall according to the second sub-association relationship and the outbound cloud traffic; The outbound cloud traffic is processed according to the first sub-association relationship and the target subnet-level firewall to obtain protected north-south traffic.
3. The cloud platform protection method according to claim 1, characterized in that: When the north-south traffic is cloud inbound traffic corresponding to a cloud inbound direction, protection processing is performed on the north-south traffic according to the first association relationship to obtain protected north-south traffic, including: Determine a corresponding target subnet-level firewall according to the second sub-association relationship and the inbound cloud traffic; Processing the inbound cloud traffic according to the first sub-association relationship and the target subnet-level firewall to obtain protected north-south traffic; The target network interface of the switch is determined according to the third sub-association relationship and the protected north-south traffic, so as to transmit the traffic from the switch to the storage space of the network service function of the storage cloud platform.
4. The cloud platform protection method according to claim 2 or 3, characterized in that: The process of establishing the first sub-association relationship includes: Establish subnet-level firewalls within the firewall; Establishing a first mapping relationship between the firewall filtering rule and each subnet-level firewall; wherein the firewall filtering rule is a filtering and screening rule for the message field corresponding to the north-south traffic; Establish a second mapping relationship between each subnet-level firewall and the global firewall of the firewall; wherein the second mapping relationship is established through a virtual interface; The first mapping relationship and the second mapping relationship are used as the first sub-association relationship.
5. The cloud platform protection method according to claim 2 or 3, characterized in that: The process of establishing the second sub-association relationship includes: Get the target message corresponding to the target north-south traffic; Determine, according to the third sub-association relationship, a target network interface of a switch corresponding to the subnet address of the target message; A mapping relationship between the target network interface, the subnet address and the identification information corresponding to the subnet-level firewall is established and used as the second sub-association relationship.
6. The cloud platform protection method according to claim 2 or 3, characterized in that: The process of establishing the third sub-association relationship includes: Acquire each first network interface of the functional component of the storage space of the cloud platform network service function; Obtain each second network interface of the switch; Establishing a third mapping relationship between each of the first network interfaces and each of the second network interfaces; The third mapping relationship is used as the third sub-association relationship.
7. The cloud platform protection method according to claim 6, characterized in that: When the cloud platform network service function is a logical router, the process of establishing the third mapping relationship includes: Establishing each first network interface and first subnet of the logical router; Setting the first subnet to the corresponding first identification information; Establishing a first sub-network interface and a second sub-network interface of a gateway; wherein the first sub-network interface is used to connect to the first network interface; and the second sub-network interface is used to connect to the second network interface; Establishing a first sub-gateway rule and a second sub-gateway rule of the gateway; The third mapping relationship between the logical router and the switch is determined according to the first sub-gateway rule, the second sub-gateway rule, the gateway, and the first identification information.
8. The cloud platform protection method according to claim 6, characterized in that: When the cloud platform network service function is a floating Internet Protocol address, the process of establishing the third mapping relationship includes: Acquire a first network interface corresponding to the floating Internet Protocol address; The first network interface and the second network interface are mapped according to a network interface mapping rule to obtain the third mapping relationship.
9. The cloud platform protection method according to claim 1, characterized in that: The first association relationship is stored in a database of the cloud platform; the database is used to store firewall information during the cloud platform protection process.
10. The cloud platform protection method according to claim 9, characterized in that: The configuration process of the firewall information includes: Pre-add configuration options to the configuration fields of the network service components of the cloud platform; Load the firewall plug-in according to the configuration options in the configuration field; Control the firewall plug-in to read the first target configuration field in the configuration option to obtain a configuration block corresponding to the firewall information; Controlling the firewall plug-in to read the second target configuration field in the configuration option and create a firewall resource pool to store the firewall information; The firewall plug-in is controlled to read the third target configuration field in the configuration option, and load the firewall driver information to drive the firewall accordingly.
11. The cloud platform protection method according to claim 10, characterized in that: The firewall information includes at least firewall resource pool configuration information, firewall resource pool identification information, firewall driver information, firewall interface communication address, firewall interface version information, firewall user name, firewall password information, switch interface communication address, switch interface version information, switch interface user name and switch interface password information.
12. The cloud platform protection method according to claim 7, characterized in that: Determining a target network interface of a switch according to the third sub-association relationship and the outbound cloud traffic to transmit the traffic to the switch includes: When the cloud platform network service function is a logical router, performing gateway conversion on the outbound cloud traffic according to the logical router to obtain the first traffic; The first traffic is processed through the tenant network and the third sub-association relationship to determine a target network interface of the switch for transmission to the switch.
13. The cloud platform protection method according to claim 7, characterized in that: Determining a target network interface of a switch according to the third sub-association relationship and the outbound cloud traffic to transmit the traffic to the switch includes: When the cloud platform network service function is a floating Internet Protocol address, obtaining a target message corresponding to the outbound cloud traffic; Determine the cloud host address corresponding to the target message based on the mapping relationship between the subnet address of the target message and the floating Internet Protocol address; The target network interface of the switch is determined according to the cloud host address and the third sub-association relationship for transmission to the switch.
14. The cloud platform protection method according to claim 12, characterized in that: Determining a corresponding target subnet-level firewall according to the second sub-association relationship and the outbound cloud traffic includes: Obtaining address information of the first traffic; Determining whether the address information carries subnet address information; If it is carried, a first policy route is determined according to the subnet address information; and a corresponding target subnet-level firewall is determined according to the first policy route and the second sub-association relationship; If not, determine the second policy route; and determine the corresponding target subnet-level firewall according to the second policy route and the second sub-association relationship.
15. A cloud platform protection method based on outbound cloud traffic, characterized in that: include: Obtain outbound cloud traffic sent by the cloud platform to the virtual switch; Sending the outbound cloud traffic to the virtual space corresponding to the cloud platform network service function via the virtual switch; Performing protection processing on the outbound cloud traffic of the virtual space according to the first association relationship to obtain the protected outbound cloud traffic; wherein the first association relationship includes a first sub-association relationship between the firewall filtering rule and the firewall, a second sub-association relationship between the policy routing established by the switch and the subnet-level firewall of the firewall, and a third sub-association relationship between the cloud platform network service function and the network of the switch; The protected outbound cloud traffic is sent to the switch for transmission to the Internet.
16. A cloud platform protection method based on cloud inbound traffic, characterized in that: include: Obtain the cloud-inbound traffic sent from the Internet to the switch; Performing protection processing on the cloud-entry traffic according to the first association relationship to obtain protected cloud-entry traffic; wherein the first association relationship includes a first sub-association relationship between a firewall filtering rule and a firewall, a second sub-association relationship between a policy routing established by a switch and a subnet-level firewall of the firewall, and a third sub-association relationship between a cloud platform network service function and a network of the switch; Send the protected inbound cloud traffic to the switch to be sent to the virtual space corresponding to the cloud platform network service function; The protected inbound traffic is forwarded to the cloud host corresponding to the cloud platform through the virtual switch.
17. A cloud platform protection system, characterized in that: The cloud platform protection system includes a cloud platform, a firewall, a switch and a controller; The cloud platform, the firewall and the switch are all connected to the controller; The controller is used to execute the steps of the cloud platform protection method described in any one of claims 1 to 16 to complete the protection processing of north-south traffic and complete the protection of north-south traffic.
18. An electronic device, characterized in that: comprising a memory for storing a computer program; A processor, used to implement the steps of the cloud platform protection method as described in any one of claims 1 to 16 when executing the computer program.
19. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, the steps of the cloud platform protection method according to any one of claims 1 to 16 are implemented.
20. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instruction is executed by a processor, the steps of the cloud platform protection method described in any one of claims 1 to 16 are implemented.
Citation Information
Patent Citations
Security service deployment system, method and device
CN111224821A
Cloud host-oriented full-flow network access protection method and device
CN114374526A
Cloud resource management method and device, electronic equipment and storage medium
CN117997754A
Method for transmitting data traffic in cloud platform through virtual firewall and cloud platform
CN119728175A
Method and device for cloud host total traffic network access protection
WO2023050070A1