A cloud platform protection method, system, device, medium and product
By establishing the association relationship between firewall and network service functions in the cloud platform and dynamically adjusting the firewall and switch configuration, the slow response problem caused by static configuration in north-south traffic protection of cloud platform is solved, and the rapid traffic protection effect is achieved.
Patent Information
- Application Number
- CN202510607373.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-05-12
AI Technical Summary
In the prior art, firewall protection for north-south traffic of cloud platforms requires artificial static configuration, which leads to the inability to respond quickly to network changes, increasing maintenance difficulty.
Establish an association relationship between the firewall and the cloud platform network service functions in advance, including the mapping relationship between firewall filtering rules, switch policy routing and subnet-level firewall, realize dynamic linkage between the firewall and the switch, and automatically adjust the configuration to adapt to traffic changes.
By dynamically adjusting the configuration of the firewall and switches, the rate of response to network changes is improved, the difficulty of maintenance of north-south traffic is reduced, and rapid traffic protection is achieved.
Smart Images

Figure CN120128429B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cloud computing, and in particular to a cloud platform protection method, system, device, medium, and product. Background Art
[0002] With the development of cloud platforms, the larger their computing scale and application scope, the more complex the corresponding networking situation becomes. For the protection of the north-south traffic of conventional cloud platforms, static configuration of firewall devices is manually performed according to the corresponding networking changes by professionals, which requires professional network engineers to operate, making it difficult to quickly respond to frequent networking changes, thus increasing the maintenance difficulty of north-south traffic.
[0003] Therefore, how to quickly respond to networking changes and then reduce the maintenance difficulty of north-south traffic is a technical problem that needs to be urgently solved by those skilled in the art. Summary of the Invention
[0004] The purpose of the present invention is to provide a cloud platform protection method, system, device, medium, and product to solve the problem that the conventional firewall protection uses manual static configuration, resulting in the inability to quickly respond to networking changes and thus increasing the maintenance difficulty of north-south traffic.
[0005] To solve the above technical problem, the present invention provides a cloud platform protection method, including:
[0006] Pre-establish a first association relationship between a firewall and a cloud platform network service function; wherein, the first association relationship includes a first sub-association relationship between a firewall filtering rule and the firewall, a second sub-association relationship between a policy route established by a switch and a subnet-level firewall of the firewall, and a third sub-association relationship between a cloud platform network service function and the network of the switch;
[0007] Obtain the north-south traffic to be processed;
[0008] Perform protection processing on the north-south traffic according to the first association relationship to obtain the protected north-south traffic.
[0009] On the one hand, when the north-south traffic is the outgoing cloud traffic corresponding to the outgoing cloud direction, performing protection processing on the north-south traffic according to the first association relationship to obtain the protected north-south traffic includes:
[0010] Determine the target network interface of the switch according to the third sub-association relationship and the outgoing cloud traffic to transmit to the switch;
[0011] Determine the corresponding target subnet-level firewall according to the second sub-association relationship and the outgoing cloud traffic;
[0012] Process the outbound traffic according to the first sub - association relationship and the target subnet - level firewall to obtain the protected north - south traffic.
[0013] On the other hand, when the north - south traffic is the inbound traffic corresponding to the inbound cloud direction, perform protection processing on the north - south traffic according to the first association relationship to obtain the protected north - south traffic, including:
[0014] Determine the corresponding target subnet - level firewall according to the second sub - association relationship and the inbound traffic;
[0015] Process the inbound traffic according to the first sub - association relationship and the target subnet - level firewall to obtain the protected north - south traffic;
[0016] Determine the target network interface of the switch according to the third sub - association relationship and the protected north - south traffic, so as to transmit from the switch to the storage space of the cloud platform network service function.
[0017] On the other hand, the establishment process of the first sub - association relationship includes:
[0018] Establish each subnet - level firewall within the firewall;
[0019] Establish a first mapping relationship between the firewall filtering rules and each subnet - level firewall; wherein, the firewall filtering rules are the filtering and screening rules for the message fields corresponding to the north - south traffic;
[0020] Establish a second mapping relationship between each subnet - level firewall and the global firewall of the firewall; wherein, the second mapping relationship is established through virtual interfaces;
[0021] Take the first mapping relationship and the second mapping relationship as the first sub - association relationship.
[0022] On the other hand, the establishment process of the second sub - association relationship includes:
[0023] Obtain the target message corresponding to the target north - south traffic;
[0024] Determine the target network interface of the switch corresponding to the subnet address of the target message according to the third sub - association relationship;
[0025] Establish a mapping relationship between the target network interface, the subnet address and the identification information corresponding to the subnet - level firewall, and take it as the second sub - association relationship.
[0026] On the other hand, the establishment process of the third sub - association relationship includes:
[0027] Obtain each first network interface of the functional components of the storage space of the cloud platform network service function;
[0028] Obtain each second network interface of the switch;
[0029] Establish a third mapping relationship between each of the first network interfaces and each of the second network interfaces;
[0030] Use the third mapping relationship as the third sub - association relationship.
[0031] On the other hand, when the cloud platform network service function is a logical router, the process of establishing the third mapping relationship includes:
[0032] Establish each first network interface of the logical router and the first subnet;
[0033] Set corresponding first identification information for the first subnet;
[0034] Establish a first sub - network interface and a second sub - network interface of the gateway; wherein, the first sub - network interface is used to connect to the first network interface; the second sub - network interface is used to connect to the second network interface;
[0035] Establish a first sub - gateway rule and a second sub - gateway rule of the gateway;
[0036] Determine the third mapping relationship between the logical router and the switch according to the first sub - gateway rule, the second sub - gateway rule, the gateway, and the first identification information.
[0037] On the other hand, when the cloud platform network service function is a floating Internet protocol address, the process of establishing the third mapping relationship includes:
[0038] Obtain the first network interface corresponding to the floating Internet protocol address;
[0039] Map the first network interface and the second network interface according to the network interface mapping rule to obtain the third mapping relationship.
[0040] On the other hand, the first association relationship is stored in the database of the cloud platform; the database is used to store firewall information during the cloud platform protection process.
[0041] On the other hand, the configuration process of the firewall information includes:
[0042] Pre - add configuration options in the configuration fields of the network service components of the cloud platform;
[0043] Load the firewall plugin according to the configuration options in the configuration fields;
[0044] Control the firewall plugin to read the first target configuration field in the configuration options to obtain the configuration block corresponding to the firewall information;
[0045] Control the firewall plugin to read the second target configuration field in the configuration options, create a firewall resource pool to store the firewall information;
[0046] Control the firewall plugin to read the third target configuration field in the configuration options, and load the driver corresponding to the firewall driver information to drive the firewall.
[0047] On the other hand, the firewall information at least includes firewall resource pool configuration information, firewall resource pool identification information, firewall driver information, communication address of the firewall interface, version information of the firewall interface, firewall username, firewall password information, communication address of the switch interface, version information of the switch interface, switch interface username, and switch interface password information.
[0048] On the other hand, determining the target network interface of the switch according to the third sub - association relationship and the outbound traffic to be transmitted to the switch includes:
[0049] When the cloud platform network service function is a logical router, perform gateway conversion on the outbound traffic according to the logical router to obtain the first traffic;
[0050] Process the first traffic through the tenant network and the third sub - association relationship to determine the target network interface of the switch to be transmitted to the switch.
[0051] On the other hand, determining the target network interface of the switch according to the third sub - association relationship and the outbound traffic to be transmitted to the switch includes:
[0052] When the cloud platform network service function is a floating Internet protocol address, obtain the target packet corresponding to the outbound traffic;
[0053] Determine the cloud host address corresponding to the target packet according to the mapping relationship between the subnet address of the target packet and the floating Internet protocol address;
[0054] Determine the target network interface of the switch according to the cloud host address and the third sub - association relationship to be transmitted to the switch.
[0055] On the other hand, determining the corresponding target subnet - level firewall according to the second sub - association relationship and the outbound traffic includes:
[0056] Obtain the address information of the first traffic;
[0057] Judge whether the address information carries subnet address information;
[0058] If carried, determine the first policy route according to the subnet address information; and determine the corresponding target subnet-level firewall according to the first policy route and the second sub-association relationship.
[0059] If not carried, determine the second policy route; and determine the corresponding target subnet-level firewall according to the second policy route and the second sub-association relationship.
[0060] To solve the above technical problems, the present invention also provides a cloud platform protection method based on outbound traffic, including:
[0061] Obtain the outbound traffic sent from the cloud platform to the virtual switch.
[0062] Send the outbound traffic to the virtual space corresponding to the cloud platform network service function through the virtual switch.
[0063] Perform protection processing on the outbound traffic in the virtual space according to the first association relationship to obtain the protected outbound traffic; wherein, the first association relationship includes the firewall filtering rule and the first sub-association relationship of the firewall, the second sub-association relationship between the policy route established by the switch and the subnet-level firewall of the firewall, and the third sub-association relationship between the cloud platform network service function and the network of the switch.
[0064] Send the protected outbound traffic to the switch to be sent to the Internet.
[0065] To solve the above technical problems, the present invention also provides a cloud platform protection method based on inbound traffic, including:
[0066] Obtain the inbound traffic sent from the Internet to the switch.
[0067] Perform protection processing on the inbound traffic according to the first association relationship to obtain the protected inbound traffic; wherein, the first association relationship includes the firewall filtering rule and the first sub-association relationship of the firewall, the second sub-association relationship between the policy route established by the switch and the subnet-level firewall of the firewall, and the third sub-association relationship between the cloud platform network service function and the network of the switch.
[0068] Send the protected inbound traffic to the switch to be sent to the virtual space corresponding to the cloud platform network service function.
[0069] Forward the protected inbound traffic to the cloud host corresponding to the cloud platform through the virtual switch.
[0070] To solve the above technical problems, the present invention also provides a cloud platform protection system, and the cloud platform protection system includes a cloud platform, a firewall, a switch, and a controller.
[0071] The cloud platform, the firewall, and the switch are all connected to the controller;
[0072] The controller is configured to execute the steps of the above-mentioned cloud platform protection method to complete the protection process of north-south traffic and complete the protection of north-south traffic.
[0073] To solve the above technical problems, the present invention also provides an electronic device, including a memory for storing a computer program;
[0074] A processor for implementing the steps of the cloud platform protection method as described when executing the computer program.
[0075] To solve the above technical problems, the present invention also provides a computer-readable storage medium, on which a computer program is stored, and the computer program, when executed by a processor, implements the steps of the cloud platform protection method as described.
[0076] To solve the above technical problems, the present invention also provides a computer program product, including a computer program / instructions, and the computer program / instructions, when executed by a processor, implement the steps of the cloud platform protection method.
[0077] The beneficial effects of the present invention are as follows: On the one hand, by pre-establishing a first association relationship between the firewall and the cloud platform network service function, the firewall and the cloud platform are linked, and different mapping relationships are established between the configuration information inside the firewall and the configurations of the switch and the cloud platform. At the same time, corresponding sub-association relationships are respectively established for different transmission parts of the corresponding traffic data during the transmission process of outgoing or incoming traffic, that is, the firewall information and network information are converted into the configurations of the firewall and the switch and are respectively sent to the firewall and the switch. The network information links the cloud platform and the firewall. On the other hand, through the linkage process of the above-mentioned first association relationship, based on the first association relationship, the firewall rules and the switch policy routes can be sent to the corresponding firewall and switch respectively to achieve fast configuration synchronization, so as to perform automatic dynamic protection processing in real time based on the network changes of the packet information of the traffic, improve the rate of responding to network changes, and reduce the maintenance difficulty of north-south traffic.
[0078] In addition, the present invention also provides a cloud platform protection method based on outgoing cloud traffic, a cloud platform protection method based on incoming cloud traffic, a cloud platform protection system, an electronic device, a computer-readable storage medium, and a computer program product, which have the beneficial effects of the above-mentioned cloud platform protection method. BRIEF DESCRIPTION OF THE DRAWINGS
[0079] To more clearly illustrate the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0080] Figure 1 Flowchart of a cloud platform protection method provided by an embodiment of the present invention;
[0081] Figure 2 Schematic diagram of a protection mechanism for outgoing cloud traffic provided by an embodiment of the present invention;
[0082] Figure 3 Schematic diagram of a protection mechanism for incoming cloud traffic provided by an embodiment of the present invention;
[0083] Figure 4 Architecture diagram of a cloud platform protection system provided by an embodiment of the present invention;
[0084] Figure 5 Flowchart of a cloud platform protection method based on outgoing cloud traffic provided by an embodiment of the present invention;
[0085] Figure 6 Flowchart of a cloud platform protection method based on incoming cloud traffic provided by an embodiment of the present invention;
[0086] Figure 7 Structure diagram of a cloud platform protection device provided by an embodiment of the present invention;
[0087] Figure 8 Structure diagram of a cloud platform protection device based on outgoing cloud traffic provided by an embodiment of the present invention;
[0088] Figure 9 Structure diagram of a cloud platform protection device based on incoming cloud traffic provided by an embodiment of the present invention;
[0089] Figure 10 Structure diagram of an electronic device provided by an embodiment of the present invention. Detailed implementation manners
[0090] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present invention.
[0091] The core of the present invention is to provide a cloud platform protection method, system, device, medium and product to solve the problem that the conventional firewall protection uses manual static configuration, resulting in the inability to quickly respond to network changes, thus increasing the maintenance difficulty of north-south traffic.
[0092] To enable those skilled in the art to better understand the solution of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0093] In the conventional technology, the north-south traffic of the cloud platform is usually protected by external firewall devices. With the development of cloud computing in recent years, the scale of cloud computing has become larger and larger, the application scope has become wider and wider, and the networking situation of the cloud platform has become more and more complex. The configuration of the firewall device for protecting the north-south traffic of the cloud platform has also become more complex. When the networking situation of the cloud platform changes, the configuration of the corresponding firewall device also needs to be modified. When the networking situation of the cloud platform becomes complex, the difficulty of manually modifying the configuration of the corresponding hardware firewall device also increases, and the response speed becomes relatively slow. The cloud platform protection method provided by the present invention can solve the above technical problems.
[0094] Figure 1 The flowchart of a cloud platform protection method provided by an embodiment of the present invention is as Figure 1 shown, and the method includes:
[0095] S11: Establish a first association relationship between the firewall and the cloud platform network service function in advance;
[0096] Among them, the first association relationship includes a first sub-association relationship between the firewall filtering rule and the firewall, a second sub-association relationship between the policy routing established by the switch and the subnet-level firewall of the firewall, and a third sub-association relationship between the cloud platform network service function and the network of the switch;
[0097] S12: Obtain the north-south traffic to be processed;
[0098] S13: Perform protection processing on the north-south traffic according to the first association relationship to obtain the protected north-south traffic.
[0099] Specifically, when establishing the first association relationship between the firewall and the cloud platform network service function, in the conventional technical solution, there is a manual static setting for protecting the corresponding traffic data or there is no firewall protection at all. The packet data corresponding to the traffic in the outbound cloud direction is directly sent to the Internet through the switch, or the packet data corresponding to the traffic in the inbound cloud direction is uploaded to the cloud platform through the switch. In this embodiment, whether it is the outbound cloud direction or the inbound cloud direction, the firewall needs to perform protection processing on the packet data.
[0100] The first association relationship established in step S11 corresponds to the entire process of full transmission of north-south traffic from the cloud platform to the Internet. Taking the out-cloud direction as an example, the establishment of the firewall filtering rule and the first sub-association relationship of the firewall is to filter the packet data corresponding to the traffic inside the firewall through the firewall filtering rule to screen out the packet data that can be sent to the Internet. The second sub-association relationship between the policy route established by the switch and the subnet-level firewall of the firewall is a mapping relationship of the path of how the out-cloud direction packet data is transmitted to the subnet-level firewall of the firewall after reaching the switch. The third sub-association relationship between the cloud platform network service function and the network of the switch is a mapping relationship of the out-cloud direction from the network interface of the cloud platform to the switch.
[0101] The cloud platform network service function is a network function component of the cloud platform. It can be a logical router used to implement the routing function between different networks and is implemented through the Linux network namespace (Network Namespace). Each router has its own independent routing table. The main functions of the logical router include: realizing communication between different subnets; providing the Network Address Translation (NAT) function to enable virtual machines to access the external network; providing an isolated network environment for tenants. It can also be a floating Internet Protocol Address (IP) that allows the public IP address to be dynamically assigned to the virtual machines of tenants. Its main functions include: enabling virtual machines to directly access the Internet; allowing the external network to access virtual machine instances; providing the static NAT function to establish a one-to-one mapping between the external network IP address and the IP address of the project where the instance is located. For the two components of the cloud platform network service function, the subsequent association relationship establishment processes are different, and both are protected by the present invention.
[0102] The firewall filtering rule is the screening process of the packet data corresponding to the traffic inside the firewall. It can be a restriction corresponding to the packet fields or other characteristics of the packet, such as the packet address information, etc. It is not limited here and can be set according to the actual situation.
[0103] The policy route of the switch is a mechanism for route selection based on the policies formulated by users. It can determine the forwarding path of the packet according to various attributes of the packet (such as source address, destination address, protocol type, port number, etc.). The policy route in this embodiment is the path of how the packet data is received by the network interface of the switch and then reaches the subnet-level firewall of the firewall from the switch.
[0104] The subnet-level firewall of the firewall configures independent firewall filtering rules for each subnet or specific virtual machine port to achieve more flexible security control.
[0105] Obtain the north-south traffic to be processed. It should be noted that the north-south traffic here is a general term, which can be the packet data in the out-cloud direction or the packet data in the in-cloud direction. No matter what direction the data is, it can be included. However, the execution order of each sub-association relationship within the corresponding association relationship for the two directions is not limited here, and the protection and processing of the packet data can be achieved.
[0106] In some embodiments, when the north-south traffic is the out-cloud traffic corresponding to the out-cloud direction, perform protection processing on the north-south traffic according to the first association relationship to obtain the protected north-south traffic, including:
[0107] Determine the target network interface of the switch according to the third sub-association relationship and the out-cloud traffic, and transmit it to the switch;
[0108] Determine the corresponding target sub-network level firewall according to the second sub-association relationship and the out-cloud traffic;
[0109] Process the out-cloud traffic according to the first sub-association relationship and the target sub-network level firewall to obtain the protected north-south traffic.
[0110] Specifically, considering the out-cloud traffic in the out-cloud direction, its corresponding link is still within the cloud platform. Determine the target network interface of the switch corresponding to the out-cloud traffic through the third sub-association relationship, and at this time, it can be transmitted into the switch. Then, through the second sub-association relationship, the target sub-network level firewall can be determined through the mapping between the policy route and the sub-network level firewall. Then, perform the protection processing by filtering according to the firewall filtering rules of the first sub-association relationship.
[0111] Figure 2 Schematic diagram of a protection mechanism for out-cloud traffic provided by an embodiment of the present invention, as Figure 2 shown, the cloud host sends the packet data corresponding to the out-cloud traffic, which passes through the logical switch of the cloud platform and the components of the cloud platform network service function and is sent to the switch through the third sub-association relationship. The switch forwards it to the target sub-network level firewall through the policy route of the second sub-association relationship. In the target sub-network level firewall, filtering processing is performed according to the first sub-association relationship, and it returns to the public firewall (global firewall) of the firewall, and then returns to the switch and is forwarded to the Internet.
[0112] In this embodiment, the firewall filtering rules under the sub-network level firewall are found through three different sub-association relationships in the transmission path. While improving the mapping accuracy of the packet data through different sub-association relationships, the protection processing is completed to achieve the protection of the out-cloud traffic.
[0113] In other embodiments, when the north-south traffic is the in-cloud traffic corresponding to the in-cloud direction, perform protection processing on the north-south traffic according to the first association relationship to obtain the protected north-south traffic, including:
[0114] Determine the corresponding target subnet-level firewall according to the second sub-association relationship and the cloud-inbound traffic;
[0115] Process the cloud-inbound traffic according to the first sub-association relationship and the target subnet-level firewall to obtain the protected north-south traffic;
[0116] Determine the target network interface of the switch according to the third sub-association relationship and the protected north-south traffic, so as to transmit from the switch to the storage space of the cloud platform network service function.
[0117] Specifically, considering the cloud-inbound traffic in the cloud-inbound direction, its corresponding link is located in the switch. According to the second sub-association relationship, the target subnet-level firewall can be determined through the mapping between the policy route and the subnet-level firewall. The protection process is carried out by filtering according to the firewall filtering rules of the first sub-association relationship, and then the target network interface of the switch corresponding to the cloud-outbound traffic is determined through the third sub-association relationship. At this time, it can be transmitted into the switch for sending to the components of the cloud platform network service function to enter the cloud.
[0118] Figure 3 It is a schematic diagram of a protection mechanism for cloud-inbound traffic provided by an embodiment of the present invention. As Figure 3 shown, the Internet sends the packet data of the cloud-inbound traffic to the switch. The switch routes the packet data through the public firewall of the firewall according to the policy route of the second sub-association relationship, and then to the target subnet-level firewall. The filtering is carried out through the firewall filtering rules of the first sub-association relationship. After returning to the public firewall, it returns to the switch. The switch sends it to the components of the cloud platform network service function according to the third sub-association relationship, reaches the logical switch, and is forwarded to the cloud host.
[0119] In this embodiment, the firewall filtering rules under the subnet-level firewall are found through three different sub-association relationships in the transmission path. While improving the mapping accuracy of the packet data through different sub-association relationships, the flexibility and diversity of the configuration are also improved according to the transmission path of the cloud-inbound traffic, and the protection process is completed to achieve the protection of the cloud-outbound traffic.
[0120] The beneficial effects of the embodiments of the present invention are as follows. On the one hand, by pre - establishing the first association relationship between the firewall and the network service function of the cloud platform, the firewall and the cloud platform are linked, and different mapping relationships are established between the configuration information inside the firewall and the configurations of the switches with the cloud platform. At the same time, corresponding sub - association relationships are respectively established for different transmission parts of the corresponding incoming or outgoing traffic data during the transmission process, that is, the firewall information and network information are converted into the configurations of the firewall and the switch and respectively sent to the firewall and the switch. The network information links the cloud platform and the firewall. On the other hand, through the linkage process of the above - mentioned first association relationship, based on the first association relationship, the firewall rules and the switch policy routes can be sent to the corresponding firewall and switch respectively, so as to realize rapid configuration synchronization, automatically and dynamically protect against real - time traffic - based packet information network changes, improve the response rate to network changes, and reduce the maintenance difficulty of north - south traffic.
[0121] In some embodiments, the establishment process of the first sub - association relationship includes:
[0122] Establish sub - network - level firewalls within the firewall;
[0123] Establish a first mapping relationship between the firewall filtering rules and each sub - network - level firewall; wherein, the firewall filtering rules are the filtering and screening rules for the message fields corresponding to the north - south traffic;
[0124] Establish a second mapping relationship between each sub - network - level firewall and the global firewall of the firewall; wherein, the second mapping relationship is established through virtual interfaces;
[0125] Take the first mapping relationship and the second mapping relationship as the first sub - association relationship.
[0126] Specifically, as Figure 2 、 3 shown, establish sub - network - level firewalls within the firewall, and establish a first mapping relationship between the firewall filtering rules and each sub - network - level firewall. Here, the first mapping relationship is to add the screening rules for the sub - network address information or field information corresponding to each network change as the firewall filtering rules within each sub - network - level firewall. It should be noted that the firewall filtering rules of this embodiment can be added, deleted, modified, etc. according to real - time network changes. There can be multiple firewall filtering rules in one sub - network - level firewall, and the multiple firewall filtering rules can be stored in the order of time sequence or screened according to the incoming message data for calling, and this is not limited here.
[0127] Establish a second mapping relationship between each sub - network - level firewall and the global firewall of the firewall. Here, the second mapping relationship is a many - to - one mapping, that is, the mapping relationship between multiple sub - network - level firewalls and one global firewall.
[0128] For the establishment of the first sub - association relationship provided in this embodiment, the firewall filtering rules in its firewall resource pool are associated with the firewall, a subnet - level firewall is created on the firewall, a virtual interface pair between the sub - firewall and the public firewall is created, and firewall filtering rules are created in the sub - firewall. To achieve the function of protecting the north - south traffic of the cloud platform.
[0129] In some embodiments, the process of establishing the second sub - association relationship includes:
[0130] Obtain the target packet corresponding to the target north - south traffic;
[0131] Determine the target network interface of the switch corresponding to the subnet address of the target packet according to the third sub - association relationship;
[0132] Establish a mapping relationship among the target network interface, the subnet address, and the identification information corresponding to the subnet - level firewall, and use it as the second sub - association relationship.
[0133] Specifically, to obtain the target packet corresponding to the target north - south traffic, the target network interface corresponding to the subnet address of the target packet can be determined through the network interface of the switch within the third sub - association relationship. In this embodiment, a mapping relationship among the target network interface, the subnet address, and the identification information corresponding to the subnet - level firewall is established to create a policy - based route, that is, the second sub - association relationship.
[0134] For the second sub - association relationship provided in this embodiment, that is, after the target packet is sent to the public firewall of the firewall through the switch direct - connection network according to the policy - based route, the public firewall forwards the target packet to the corresponding sub - firewall for filtering.
[0135] In some embodiments, the process of establishing the third sub - association relationship includes:
[0136] Obtain each first network interface of the functional components of the network service function of the cloud platform;
[0137] Obtain each second network interface of the switch;
[0138] Establish a third mapping relationship between each first network interface and each second network interface;
[0139] Use the third mapping relationship as the third sub - association relationship.
[0140] Specifically, in this embodiment, a third mapping relationship is established between the first network interface corresponding to the cloud platform network service function, which is a functional component, and the second network interface of the switch, so as to serve as a bridge between the cloud platform and the switch. It should be noted that since the cloud platform network service function, which is a functional component, can be a logical router or a floating IP, and the method of establishing the third mapping relationship is different, it is necessary to establish it according to different cloud platform network services.
[0141] In some embodiments, when the cloud platform network service function is a logical router, the process of establishing the third mapping relationship includes:
[0142] Establish each first network interface of the logical router and the first subnet;
[0143] Set the corresponding first identification information for the first subnet;
[0144] Establish the first sub-network interface and the second sub-network interface of the gateway; wherein, the first sub-network interface is used to connect to the first network interface; the second sub-network interface is used to connect to the second network interface;
[0145] Establish the first sub-gateway rule and the second sub-gateway rule of the gateway;
[0146] Determine the third mapping relationship between the logical router and the switch according to the first sub-gateway rule, the second sub-gateway rule, the gateway, and the first identification information.
[0147] Specifically, a logical router is usually used to connect different virtual networks or subnets and provide routing functions. In the open-source cloud computing management platform project OpenStack, a logical router can be managed through the L3 Agent of the Neutron component that provides network services. When a logical router is connected to a Virtual Local Area Network (VLAN) network, the mapping relationship can be established in the following way: Create a VLAN network and a subnet: Create a VLAN network and a subnet through the Neutron Application Programming Interface (API) and specify the VLAN ID; Configure the logical router interface: Connect the interfaces of the logical router to these VLAN networks. Neutron will automatically handle the encapsulation and decapsulation of VLAN tags, that is, establish the first network interface of the logical router and the first subnet, and set the corresponding first identification information for the first subnet.
[0148] The NAT gateway is used to implement address translation between the internal network and the external network. In a cloud platform, the NAT gateway is usually used in conjunction with a logical router. The mapping relationship can be established in the following ways: Configure the external network interface: Configure an external network interface for the NAT gateway, and this interface is connected to a VLAN network. Configure the internal network interface: Configure one or more internal network interfaces for the NAT gateway, and these interfaces are connected to the internal VLAN network. Set NAT rules: Configure source network address translation (SNAT) and destination network address translation (DNAT) rules on the NAT gateway to enable communication between the internal network and the external network, that is, establish the first sub-network interface and the second sub-network interface of the gateway; where the first sub-network interface is used to connect to the first network interface; the second sub-network interface is used to connect to the second network interface; establish the first sub-gateway rule and the second sub-gateway rule of the gateway.
[0149] The VLAN network interface mapping of the switch can be implemented through VLAN mapping technology, that is, determine the third mapping relationship between the logical router and the switch according to the first sub-gateway rule, the second sub-gateway rule, the gateway, and the first identification information.
[0150] The third mapping relationship established between the logical router, the NAT gateway, and the VLAN network interface of the switch provided in this embodiment optimizes network performance, can effectively reduce the size of the broadcast domain, and reduce the impact of broadcast traffic on network performance. The traffic of different departments or services can be isolated in different VLANs to prevent unauthorized access and improve network security.
[0151] In some other embodiments, when the cloud platform network service function is a floating Internet protocol address, the process of establishing the third mapping relationship includes:
[0152] Obtain the first network interface corresponding to the floating Internet protocol address;
[0153] Map the first network interface and the second network interface according to the network interface mapping rule to obtain the third mapping relationship.
[0154] Specifically, floating IP is usually used to map the private IP address of a virtual machine to a public IP address so that the virtual machine can access the external network or be accessed by the external network. When configuring VLAN mapping on the VLAN network interface of the switch, the VLAN where the virtual machine is located can be mapped to the VLAN of the external network, thereby realizing the function of floating IP.
[0155] Create a second network interface on the switch, add the second network interface to the corresponding VLAN, and configure the second network interface of the switch to the corresponding type to allow traffic of a specific VLAN to pass through. Map the first network interface and the second network interface according to the network interface mapping rule to implement VLAN mapping configuration.
[0156] The VLAN mapping technology provided in this embodiment can map the VLAN where the floating IP is located to the VLAN network interface of the switch, so as to realize the communication between the virtual machine and the external network, realize flexible traffic scheduling, enhance network security, and hide the internal network structure.
[0157] In some embodiments, the first association relationship is stored in the database of the cloud platform; the database is used to store firewall information during the cloud platform protection process.
[0158] Figure 4 For the architecture diagram of a cloud platform protection system provided by an embodiment of the present invention, as Figure 4 shown, the first association relationship in this embodiment is stored in the database of the cloud platform, and this database is used to store firewall information corresponding to all involved firewalls.
[0159] In some embodiments, the firewall information at least includes firewall resource pool configuration information, firewall resource pool identification information, firewall driver information, communication address of the firewall interface, version information of the firewall interface, firewall username, firewall password information, communication address of the switch interface, version information of the switch interface, switch interface username, and switch interface password information.
[0160] The setting of each firewall information provided in this embodiment enhances the flexibility and diversity of the firewall linkage mechanism for facilitating real-time configuration information.
[0161] In some embodiments, the configuration process of the firewall information includes:
[0162] Pre-add configuration options in the configuration fields of the network service component of the cloud platform;
[0163] Load the firewall plugin according to the configuration options in the configuration fields;
[0164] Control the firewall plugin to read the first target configuration field in the configuration options to obtain the configuration block corresponding to the firewall information;
[0165] Control the firewall plugin to read the second target configuration field in the configuration options to create a firewall resource pool to store the firewall information;
[0166] Control the firewall plugin to read the third target configuration field in the configuration options to load the driver corresponding to the firewall driver information.
[0167] Specifically, taking the cloud platform OpenStack as an example, configuration options edge-firewall and are added to the existing configuration field service_plugins of the network service component (Neutron), indicating that the hardware firewall plugin needs to be loaded when Neutron starts. At the same time, a new configuration block is added, which is used to store firewall information.
[0168] When Neutron starts, according to the edge-firewall value in the service_plugins configuration field, the hardware firewall plugin is loaded. The hardware firewall plugin will read the edge_firewall_sections configuration field (the first target configuration field) to obtain the hardware firewall resource pool configuration block. The hardware firewall plugin uses the hardware firewall resource pool configuration block as the firewall resource pool name and the pool_id field (the second target configuration field) as the firewall resource pool ID to create a firewall resource pool object and store it in the database. The hardware firewall plugin loads the hardware firewall driver according to the device_driver configuration field (the third target configuration field) and initializes the hardware firewall driver with the configuration in the hardware firewall resource pool configuration block.
[0169] Among them, the firewall information is reflected in the form of each field:
[0170] edge_firewall_sections: A list of hardware firewall resource pool configuration blocks;
[0171] pool_id: The ID of the hardware firewall resource pool, in the format of uuid;
[0172] device_driver: The driver of the hardware firewall resource pool, which is used to send configurations to the firewall devices and switch devices in the hardware firewall resource pool and read the working status of the firewall devices and switch devices in the hardware firewall resource pool;
[0173] firewall_api_url: The Uniform Resource Locator (URL) of the firewall device API;
[0174] firewall_api_version: The version number of the firewall device API;
[0175] firewall_username: The username of the firewall device;
[0176] firewall_password: The password of the firewall device;
[0177] switch_api_url: The URL of the switch device API;
[0178] switch_api_version: The version number of the switch device API;
[0179] switch_username: The username of the switch device;
[0180] switch_password: The password of the switch device.
[0181] This embodiment provides for pre - configuring each configuration information to facilitate subsequent linkage with the firewall, improving the configuration ability and efficiency.
[0182] In some embodiments, determining the target network interface of the switch according to the third sub - association relationship and the outbound traffic for transmission to the switch includes:
[0183] When the network service function of the cloud platform is a logical router, performing gateway conversion on the outbound traffic by the logical router to obtain the first traffic;
[0184] Processing the first traffic through the tenant network and the third sub - association relationship to determine the target network interface of the switch for transmission to the switch.
[0185] Specifically, in this embodiment, taking the logical router as an example, the transmission path corresponding to its third sub - association relationship is that the logical router performs gateway conversion on the outbound traffic to obtain the first traffic, and it processes the first traffic through the tenant network and the third sub - association relationship. Here, the processing is mainly to determine the target network interface of the next - transmitted switch according to the corresponding mapping relationship for transmission to the switch.
[0186] This embodiment provides the transmission path corresponding to the logical router and the switch, realizing refined network management and improving the transmission rate.
[0187] In other embodiments, determining the target network interface of the switch according to the third sub - association relationship and the outbound traffic for transmission to the switch includes:
[0188] When the network service function of the cloud platform is a floating Internet protocol address, obtaining the target packet corresponding to the outbound traffic;
[0189] Determining the cloud host address corresponding to the target packet according to the mapping relationship between the subnet address of the target packet and the floating Internet protocol address;
[0190] Determining the target network interface of the switch according to the cloud host address and the third sub - association relationship for transmission to the switch.
[0191] Specifically, based on the mapping relationship between the subnet address and the floating IP address of the target packet, the corresponding cloud host address can be determined. According to the cloud host address and the subnet address and interface mapping of the third sub-association relationship, the target network interface of the switch can be determined for transmission to the switch.
[0192] The transmission path corresponding to the floating IP and the switch provided in this embodiment realizes the diversity and flexibility of network transmission and improves the transmission rate.
[0193] In some embodiments, determining the corresponding target subnet-level firewall according to the second sub-association relationship and the outbound traffic includes:
[0194] Obtain the address information of the first traffic;
[0195] Determine whether the address information carries subnet address information;
[0196] If it carries, determine the first policy route according to the subnet address information; and determine the corresponding target subnet-level firewall according to the first policy route and the second sub-association relationship;
[0197] If it does not carry, determine the second policy route; and determine the corresponding target subnet-level firewall according to the second policy route and the second sub-association relationship.
[0198] Considering that the address information of the packet data of the outbound traffic may carry sub-website information or not carry sub-website information, so here it is discussed in different cases. In the case of carrying, determine the first policy route according to the subnet address information to determine the corresponding target subnet-level firewall according to the first policy route and the second sub-association relationship; if not, directly determine the second policy route and determine the corresponding target subnet-level firewall according to the second policy route and the second sub-association relationship.
[0199] This embodiment considers that the policy routes corresponding to the address information of the packet data may carry sub-website information or not carry sub-website information, and it is discussed in different cases, improving the flexibility and diversity of the target subnet-level firewall.
[0200] Furthermore, the present invention also provides a cloud platform protection method based on outbound traffic, Figure 5 which is a flowchart of a cloud platform protection method provided by an embodiment of the present invention, as Figure 5 shown, and includes:
[0201] S21: Obtain the outbound traffic sent from the cloud platform to the virtual switch;
[0202] S22: Send the outbound traffic to the virtual space corresponding to the cloud platform network service function through the virtual switch;
[0203] S23: Perform protection processing on the outbound traffic of the virtual space according to the first association relationship to obtain the protected outbound traffic;
[0204] Among them, the first association relationship includes the firewall filtering rules and the first sub - association relationship of the firewall, the second sub - association relationship between the policy routing established by the switch and the subnet - level firewall of the firewall, and the third sub - association relationship between the cloud platform network service function and the network of the switch;
[0205] S24: Send the protected outbound traffic to the switch for sending to the Internet.
[0206] As Figure 2 shown, the cloud host sends a message. The logical switch forwards the message from the Generic Network Virtualization Encapsulation (Geneve) interface, reaches the logical router through the tunnel network. The logical router performs SNAT conversion on the message, then through the tenant network, sends it to the switch device. The switch device forwards the message to the public wall of the firewall device through the direct - connected network according to the policy routing. The public wall of the firewall device forwards the message to the corresponding sub - wall through the virtual interface pair. After packet filtering in the sub - wall, it returns to the public wall, then returns to the switch device, and finally forwards it to the Internet.
[0207] For the introduction of a cloud platform protection method based on outbound traffic provided by the present invention, please refer to the above - mentioned method embodiments. The present invention will not be elaborated here, and it has the same beneficial effects as the above - mentioned cloud platform protection method.
[0208] Furthermore, the present invention also provides a cloud platform protection method based on inbound traffic. Figure 6 As the flowchart of a cloud platform protection method based on inbound traffic provided by an embodiment of the present invention, as Figure 6 shown, it includes:
[0209] S31: Obtain the inbound traffic sent from the Internet to the switch;
[0210] S32: Perform protection processing on the inbound traffic according to the first association relationship to obtain the protected inbound traffic;
[0211] Among them, the first association relationship includes the firewall filtering rules and the first sub - association relationship of the firewall, the second sub - association relationship between the policy routing established by the switch and the subnet - level firewall of the firewall, and the third sub - association relationship between the cloud platform network service function and the network of the switch;
[0212] S33: Send the protected inbound traffic to the switch for sending to the virtual space corresponding to the cloud platform network service function;
[0213] S34: Forward the protected traffic to the corresponding cloud host in the cloud platform through the virtual switch.
[0214] As Figure 3 shown, the Internet sends a message to the switch device. The switch device forwards the message to the firewall device's public wall through the direct network according to the logical route. The firewall device's public wall forwards the message to the corresponding sub-wall. After the message is packet-filtered in the sub-wall and returns to the public wall, it then returns to the switch device. The switch device sends the message from the corresponding VLAN interface, reaches the logical router through the tenant network. The logical router performs DNAT conversion on the message. The message is sent out from the Geneve interface, reaches the logical switch through the tunnel network, and finally is forwarded to the cloud host.
[0215] For the introduction of a cloud platform protection method provided by the present invention, please refer to the above method embodiments. The present invention will not be elaborated here again, and it has the same beneficial effects as the above cloud platform protection method.
[0216] Furthermore, the present invention also provides a cloud platform protection system. The cloud platform protection system includes a cloud platform, a firewall, a switch, and a controller;
[0217] The cloud platform, the firewall, and the switch are all connected to the controller;
[0218] The controller is used to execute the steps of the above cloud platform protection method to complete the protection process of north-south traffic and complete the protection of north-south traffic.
[0219] It should be noted that the controller in this embodiment is a device additional to the above-mentioned cloud platform, firewall, and switch. This device can also be set within the cloud platform, and no limitation is made here.
[0220] For the introduction of a cloud platform protection system provided by the present invention, please refer to the above method embodiments. The present invention will not be elaborated here again, and it has the same beneficial effects as the above cloud platform protection method.
[0221] The above has described in detail each embodiment corresponding to the cloud platform protection method. On this basis, the present invention also discloses a cloud platform protection device corresponding to the above method, Figure 7 which is the structural diagram of a cloud platform protection device provided by an embodiment of the present invention. As Figure 7 shown, the cloud platform protection device includes:
[0222] A establishing module 11, which is used to pre-establish a first association relationship between the firewall and the network service function of the cloud platform;
[0223] Among them, the first association relationship includes the firewall filtering rules and the first sub-association relationship of the firewall, the second sub-association relationship between the policy routing established by the switch and the subnet-level firewall of the firewall, and the third sub-association relationship between the cloud platform network service function and the network of the switch;
[0224] The first acquisition module 12 is used to acquire the north-south traffic to be processed;
[0225] The first protection module 13 is used to perform protection processing on the north-south traffic according to the first association relationship to obtain the protected north-south traffic.
[0226] Since the embodiments of the device part correspond to the above embodiments, the embodiments of the device part are described with reference to the embodiments of the above method part and will not be elaborated here.
[0227] For the introduction of a cloud platform protection device provided by the present invention, please refer to the above method embodiments. The present invention will not be elaborated here, and it has the same beneficial effects as the above cloud platform protection method.
[0228] The above has described in detail each embodiment corresponding to the cloud platform protection method based on the outbound traffic. On this basis, the present invention also discloses a cloud platform protection device based on the outbound traffic corresponding to the above method. Figure 8 The structural diagram of a cloud platform protection device based on the outbound traffic provided by the embodiment of the present invention. As Figure 8 shown, the cloud platform protection device based on the outbound traffic includes:
[0229] The second acquisition module 14 is used to acquire the outbound traffic sent by the cloud platform to the virtual switch;
[0230] The first sending module 15 is used to send the outbound traffic to the virtual space corresponding to the cloud platform network service function through the virtual switch;
[0231] The second protection module 16 is used to perform protection processing on the outbound traffic in the virtual space according to the first association relationship to obtain the protected outbound traffic; among them, the first association relationship includes the firewall filtering rules and the first sub-association relationship of the firewall, the second sub-association relationship between the policy routing established by the switch and the subnet-level firewall of the firewall, and the third sub-association relationship between the cloud platform network service function and the network of the switch;
[0232] The second sending module 17 is used to send the protected outbound traffic to the switch for sending to the Internet.
[0233] For the introduction of a cloud platform protection device based on the outbound traffic provided by the present invention, please refer to the above method embodiments. The present invention will not be elaborated here, and it has the same beneficial effects as the above cloud platform protection method.
[0234] The above has described in detail each embodiment corresponding to the cloud platform protection method based on incoming cloud traffic. On this basis, the present invention also discloses a cloud platform protection device based on incoming cloud traffic corresponding to the above method. Figure 9 It is a structural diagram of a cloud platform protection device based on incoming cloud traffic provided by an embodiment of the present invention. As Figure 9 shown, the cloud platform protection device based on incoming cloud traffic includes:
[0235] A third acquisition module 18, configured to acquire incoming cloud traffic sent from the Internet to the switch;
[0236] A third protection module 19, configured to perform protection processing on the incoming cloud traffic according to the first association relationship to obtain the protected incoming cloud traffic; wherein, the first association relationship includes a firewall filtering rule and a first sub-association relationship of the firewall, a second sub-association relationship between the policy routing established by the switch and the subnet-level firewall of the firewall, and a third sub-association relationship between the cloud platform network service function and the network of the switch;
[0237] A third sending module 20, configured to send the protected incoming cloud traffic to the switch to be sent to the virtual space corresponding to the cloud platform network service function;
[0238] A forwarding module 21, configured to forward the protected incoming cloud traffic to the cloud host corresponding to the cloud platform through the virtual switch.
[0239] For the introduction of a cloud platform protection device based on incoming cloud traffic provided by the present invention, please refer to the above method embodiments. The present invention will not elaborate here, and it has the same beneficial effects as the above cloud platform protection method.
[0240] Figure 10 It is a structural diagram of an electronic device provided by an embodiment of the present invention. As Figure 10 shown, the device includes:
[0241] A memory 22, configured to store a computer program;
[0242] A processor 23, configured to implement the steps of the cloud platform protection method when executing the computer program.
[0243] Among them, the processor 23 may include one or more processing cores, such as a quad-core processor, an octa-core processor, etc. The processor 23 may be implemented in at least one hardware form of a digital signal processor (DSP), a field-programmable gate array (FPGA), and a programmable logic array. The processor 23 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the wake state, also known as a central processing unit (CPU); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 23 may be integrated with a graphics processing unit (GPU), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 23 may further include an artificial intelligence (AI) processor, and the AI processor is used to process computational operations related to machine learning.
[0244] The memory 22 may include one or more computer-readable storage media, and the computer-readable storage media may be non-transitory. The memory 22 may further include high-speed random access memory and non-volatile memory, such as one or more disk storage devices and flash storage devices. In this embodiment, the memory 22 is at least used to store the following computer program 211. After the computer program is loaded and executed by the processor 23, it can implement the relevant steps of the cloud platform protection method disclosed in any of the foregoing embodiments. In addition, the resources stored in the memory 22 may further include an operating system 212 and data 213, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system 212 may include Windows, Unix, Linux, etc. The data 213 may include, but is not limited to, the data involved in the cloud platform protection method, and so on.
[0245] In some embodiments, the electronic device may further include a display screen 24, an input / output interface 25, a communication interface 26, a power supply 27, and a communication bus 28.
[0246] Those skilled in the art can understand that Figure 10 the structure shown in
[0247] does not constitute a limitation on the electronic device, and may include more or fewer components than shown in the figure.
[0248] For the introduction of an electronic device provided by the present invention, please refer to the above method embodiments, which will not be elaborated herein again. It has the same beneficial effects as the above cloud platform protection method.
[0249] Furthermore, the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor 23, the steps of the above cloud platform protection method are implemented.
[0250] It can be understood that if the method in the above embodiments is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and executes all or part of the steps of the methods in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0251] For the introduction of a computer-readable storage medium provided by the present invention, please refer to the above method embodiments, which will not be elaborated herein again. It has the same beneficial effects as the above cloud platform protection method.
[0252] Further, the present invention also provides a computer program product, including a computer program / instructions. When the computer program / instructions are executed by a processor, the steps of the above cloud platform protection method are implemented.
[0253] For the introduction of a computer program product provided by the present invention, please refer to the above method embodiments, which will not be elaborated herein again. It has the same beneficial effects as the above cloud platform protection method.
[0254] The above has provided a detailed introduction to a cloud platform protection method, system, device, medium, and product provided by the present invention. The various embodiments in the specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other. For the device disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple. For the relevant parts, please refer to the description in the method part. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements and modifications can still be made to the present invention, and these improvements and modifications also fall within the protection scope of the present invention.
[0255] It should also be noted that in this specification, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent in such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.
Claims
1. A cloud platform protection method, characterized in that, Including: Pre - establish a first association relationship between a firewall and cloud platform network service functions; wherein, the first association relationship includes a first sub - association relationship between firewall filtering rules and the firewall, a second sub - association relationship between the policy routing established by a switch and the subnet - level firewall of the firewall, and a third sub - association relationship between cloud platform network service functions and the network of the switch; Obtain north - south traffic to be processed; Perform protection processing on the north - south traffic according to the first association relationship to obtain protected north - south traffic; Among them, the establishment process of the first sub - association relationship includes: establish each subnet - level firewall within the firewall; establish a first mapping relationship between the firewall filtering rules and each subnet - level firewall; establish a second mapping relationship between each subnet - level firewall and the global firewall of the firewall; use the first mapping relationship and the second mapping relationship as the first sub - association relationship; Correspondingly, the establishment process of the second sub - association relationship includes: obtain the target packet corresponding to the target north - south traffic; determine the target network interface of the switch corresponding to the subnet address of the target packet according to the third sub - association relationship; establish a mapping relationship between the target network interface, the subnet address, and the identification information corresponding to the subnet - level firewall, and use it as the second sub - association relationship; Correspondingly, the establishment process of the third sub - association relationship includes: obtain each first network interface of the functional components in the storage space of the cloud platform network service function; obtain each second network interface of the switch; establish a third mapping relationship between each first network interface and each second network interface; use the third mapping relationship as the third sub - association relationship.
2. The cloud platform protection method according to claim 1, wherein When the north - south traffic is the outgoing cloud traffic corresponding to the outgoing cloud direction, performing protection processing on the north - south traffic according to the first association relationship to obtain protected north - south traffic includes: Determine the target network interface of the switch according to the third sub - association relationship and the outgoing cloud traffic for transmission to the switch; Determine the corresponding target subnet - level firewall according to the second sub - association relationship and the outgoing cloud traffic; Process the outgoing cloud traffic according to the first sub - association relationship and the target subnet - level firewall to obtain protected north - south traffic.
3. The cloud platform protection method according to claim 1, characterized in that When the north - south traffic is the incoming cloud traffic corresponding to the incoming cloud direction, performing protection processing on the north - south traffic according to the first association relationship to obtain protected north - south traffic includes: Determine the corresponding target subnet - level firewall according to the second sub - association relationship and the incoming cloud traffic; Process the incoming cloud traffic according to the first sub - association relationship and the target subnet - level firewall to obtain protected north - south traffic; Determine the target network interface of the switch according to the third sub - association relationship and the protected north - south traffic for transmission from the switch to the storage space of the cloud platform network service function.
4. The cloud platform protection method according to claim 2 or 3, characterized in that, The firewall filtering rule is the filtering and screening rule for the packet fields corresponding to the north - south traffic; Correspondingly, the second mapping relationship is established through virtual interfaces.
5. The cloud platform protection method according to claim 1, characterized in that When the network service function of the cloud platform is a logical router, the process of establishing the third mapping relationship includes: Establish each first network interface and the first subnet of the logical router; Set corresponding first identification information for the first subnet; Establish a first sub-network interface and a second sub-network interface of the gateway; wherein, the first sub-network interface is used to connect to the first network interface; the second sub-network interface is used to connect to the second network interface; Establish a first sub-gateway rule and a second sub-gateway rule of the gateway; Determine the third mapping relationship between the logical router and the switch according to the first sub-gateway rule, the second sub-gateway rule, the gateway, and the first identification information.
6. The cloud platform protection method according to claim 1, wherein When the network service function of the cloud platform is a floating Internet protocol address, the process of establishing the third mapping relationship includes: Obtain the first network interface corresponding to the floating Internet protocol address; Map the first network interface and the second network interface according to the network interface mapping rule to obtain the third mapping relationship.
7. The cloud platform protection method according to claim 1, characterized in that, The first association relationship is stored in the database of the cloud platform; the database is used to store firewall information during the cloud platform protection process.
8. The cloud platform protection method according to claim 7, wherein, The configuration process of the firewall information includes: Pre-add configuration options in the configuration fields of the network service components of the cloud platform; Load the firewall plugin according to the configuration options in the configuration fields; Control the firewall plugin to read the first target configuration field in the configuration options to obtain the configuration block corresponding to the firewall information; Control the firewall plugin to read the second target configuration field in the configuration options to create a firewall resource pool to store the firewall information; Control the firewall plugin to read the third target configuration field in the configuration options to load the firewall driver information to drive the firewall.
9. The cloud platform protection method according to claim 8, wherein The firewall information at least includes firewall resource pool configuration information, firewall resource pool identification information, firewall driver information, communication address of the firewall interface, version information of the firewall interface, firewall username, firewall password information, communication address of the switch interface, version information of the switch interface, switch interface username, and switch interface password information.
10. The cloud platform protection method according to claim 5, wherein, Determine the target network interface of the switch according to the third sub-association relationship and the outbound traffic to transmit to the switch, including: When the network service function of the cloud platform is a logical router, perform gateway conversion on the outbound traffic according to the logical router to obtain the first traffic; Process the first traffic through the tenant network and the third sub-association relationship to determine the target network interface of the switch to transmit to the switch.
11. The cloud platform protection method according to claim 5, wherein Determine the target network interface of the switch according to the third sub-association relationship and the outbound traffic to transmit to the switch, including: When the network service function of the cloud platform is a floating Internet protocol address, obtain the target packet corresponding to the outbound traffic; Determine the cloud host address corresponding to the target packet according to the mapping relationship between the subnet address of the target packet and the floating Internet protocol address; Determine the target network interface of the switch according to the cloud host address and the third sub - association relationship, and transmit it to the switch.
12. The cloud platform protection method according to claim 10, wherein Determine the corresponding target subnet - level firewall according to the second sub - association relationship and the outbound cloud traffic, including: Obtain the address information of the first traffic; Judge whether the address information carries subnet address information; If it carries, determine the first policy route according to the subnet address information; and determine the corresponding target subnet - level firewall according to the first policy route and the second sub - association relationship; If it does not carry, determine the second policy route; and determine the corresponding target subnet - level firewall according to the second policy route and the second sub - association relationship.
13. A cloud platform protection method based on Izumo traffic, characterized in that, Including: Obtain the outbound cloud traffic sent from the cloud platform to the virtual switch; Send the outbound cloud traffic to the virtual space corresponding to the cloud platform network service function through the virtual switch; Perform protection processing on the outbound cloud traffic in the virtual space according to the first association relationship to obtain the protected outbound cloud traffic; wherein, the first association relationship includes the firewall filtering rule and the first sub - association relationship of the firewall, the second sub - association relationship between the policy route established by the switch and the subnet - level firewall of the firewall, and the third sub - association relationship between the cloud platform network service function and the network of the switch; Send the protected outbound cloud traffic to the switch for sending to the Internet; Among them, the establishment process of the first sub - association relationship includes: establishing each subnet - level firewall in the firewall; establishing a first mapping relationship between the firewall filtering rule and each subnet - level firewall; establishing a second mapping relationship between each subnet - level firewall and the global firewall of the firewall; taking the first mapping relationship and the second mapping relationship as the first sub - association relationship; Correspondingly, the establishment process of the second sub - association relationship includes: obtaining the target packet corresponding to the target north - south traffic; determining the target network interface of the switch corresponding to the subnet address of the target packet according to the third sub - association relationship; establishing a mapping relationship between the target network interface, the subnet address and the identification information corresponding to the subnet - level firewall, and taking it as the second sub - association relationship; Correspondingly, the establishment process of the third sub - association relationship includes: obtaining each first network interface of the functional components in the storage space of the cloud platform network service function; obtaining each second network interface of the switch; establishing a third mapping relationship between each first network interface and each second network interface; taking the third mapping relationship as the third sub - association relationship.
14. A cloud platform protection method based on incoming cloud traffic, characterized in that, Including: Obtain the inbound cloud traffic sent from the Internet to the switch; Perform protection processing on the inbound cloud traffic according to the first association relationship to obtain the protected inbound cloud traffic; wherein, the first association relationship includes the firewall filtering rule and the first sub - association relationship of the firewall, the second sub - association relationship between the policy route established by the switch and the subnet - level firewall of the firewall, and the third sub - association relationship between the cloud platform network service function and the network of the switch; Send the protected inbound cloud traffic to the switch for sending to the virtual space corresponding to the cloud platform network service function; Forward the protected inbound cloud traffic to the cloud host corresponding to the cloud platform through the virtual switch; Among them, the process of establishing the first sub - association relationship includes: establishing each sub - network - level firewall within the firewall; establishing a first mapping relationship between the firewall filtering rules and each sub - network - level firewall; establishing a second mapping relationship between each sub - network - level firewall and the global firewall of the firewall; taking the first mapping relationship and the second mapping relationship as the first sub - association relationship; Correspondingly, the process of establishing the second sub - association relationship includes: obtaining the target packet corresponding to the target north - south traffic; determining the target network interface of the switch corresponding to the subnet address of the target packet according to the third sub - association relationship; establishing a mapping relationship between the target network interface, the subnet address, and the identification information corresponding to the sub - network - level firewall, and taking it as the second sub - association relationship; Correspondingly, the process of establishing the third sub - association relationship includes: obtaining each first network interface of the functional components in the storage space of the cloud platform network service function; obtaining each second network interface of the switch; establishing a third mapping relationship between each first network interface and each second network interface; taking the third mapping relationship as the third sub - association relationship.
15. A cloud platform protection system, characterized in that, The cloud platform protection system includes a cloud platform, a firewall, a switch, and a controller; The cloud platform, the firewall, and the switch are all connected to the controller; The controller is used to execute the steps of the cloud platform protection method described in any one of claims 1 to 14 above to complete the protection process of north - south traffic and complete the protection of north - south traffic.
16. An electronic device, characterized in that, It includes a memory for storing a computer program; A processor, when executing the computer program, realizes the steps of the cloud platform protection method described in any one of claims 1 to 14.
17. A computer-readable storage medium, characterized in that, A computer program is stored on the computer - readable storage medium, and when the computer program is executed by the processor, it realizes the steps of the cloud platform protection method described in any one of claims 1 to 14.
18. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, it realizes the steps of the cloud platform protection method described in any one of claims 1 to 14.
Citation Information
Patent Citations
Security service deployment system, method and device
CN111224821A
Cloud host-oriented full-flow network access protection method and device
CN114374526A