Virtualized WAF Transparent Protection Method and System Based on Open vSwitch
The Open vSwitch-based virtualized WAF system addresses integration and scalability issues in cloud environments by providing transparent traffic handling and failover capabilities, ensuring continuous service availability and protection against attacks.
Patent Information
- Application Number
- CN202510607789.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-13
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-05-13
AI Technical Summary
Existing Web Application Firewalls (WAFs) face challenges in virtualized environments, requiring manual configuration changes for each site and lacking seamless integration with cloud services, leading to increased operational complexity and potential service disruptions during node failures.
A virtualized WAF system using Open vSwitch for transparent protection, which includes a host machine with Open vSwitch, a cloud WAF virtual machine for traffic detection and filtering, and a WAF management node for dynamic policy adjustments, enabling seamless integration and failover without manual configuration changes.
Facilitates easy and scalable WAF deployment with transparent traffic handling, ensuring continuous service availability and protection against attacks like DDoS by dynamically adjusting policies and implementing failover mechanisms.
Smart Images

Figure CN120185922B_ABST
Abstract
Description
Technical Field
[0001] One or more embodiments of the present specification relate to the field of network technology, and specifically to a virtualized WAF transparent protection method and system based on OpenVSwitch. Background Art
[0002] Web Application Firewall (waf) is a web security product that implements attack identification, detection, and blocking by loading security modules on the web server, and has good real-time performance. Usually waf is deployed before the user's application server. The requested user traffic first reaches the server where waf is deployed. waf analyzes the requested traffic, intercepts malicious and risky traffic, releases the detected safe traffic, and then forwards it to the back-end server, thereby protecting the application server.
[0003] At present, with the maturity and promotion of cloud-based devices and virtualization technology, more and more services are moved to the cloud or local private virtualization deployment. Compared with traditional hardware WAF devices, which cannot meet the deployment requirements in such scenarios, the reverse proxy mode is generally used when WAF is used to protect web services on the cloud. In the reverse proxy mode, the configuration of the site needs to modify the DNS and the forwarding rules of the WAF itself. The same configuration needs to be done when the configuration is cancelled. When the number of sites is large, it will cause a large workload for the virtual LAN VLAN. In addition, when the software version of WAF is abnormal, it only supports the master-slave switching mechanism to take over the traffic. This method makes the WAF node directly affect the user's access to the normal application server when there are batch problems due to its own program. Therefore, there is an urgent need for a virtualized WAF transparent protection system that can support batch and convenient WAF access and ensure protection capabilities. Summary of the invention
[0004] The embodiment of this specification provides a virtualized WAF transparent protection method and system based on openvswitch, and its technical solution is as follows:
[0005] An embodiment of this specification provides a virtualized WAF transparent protection system based on Open vSwitch, including: a host for running a Web site and deploying an Open vSwitch, and the Open vSwitch performs traffic transparent forwarding through link switching and VLAN isolation; a cloud WAF virtual machine for connecting to a first virtual switch in the Open vSwitch through a virtual network card, receiving user traffic forwarded by the first virtual switch, performing traffic detection and protection on the user traffic, and sending the detected normal user traffic to the Web site through a second virtual switch in the Open vSwitch; a WAF management node for connecting to the cloud WAF virtual machine and the first virtual switch respectively, dynamically adjusting the WAF protection policy, and preventing attack traffic in the user traffic from entering the Open vSwitch through the Open vSwitch flow table rules.
[0006] On the other hand, an embodiment of this specification provides a virtualized WAF transparent protection method based on Open vSwitch, including: setting a host for running a Web site and deploying an Open vSwitch, and the Open vSwitch performs traffic transparent forwarding through link switching and VLAN isolation; setting a cloud WAF virtual machine for connecting to a first virtual switch in the Open vSwitch through a virtual network card, receiving user traffic forwarded by the first virtual switch, performing traffic detection and protection on the user traffic, and sending the detected normal user traffic to the Web site through a second virtual switch in the Open vSwitch; setting a WAF management node for connecting to the cloud WAF virtual machine and the first virtual switch respectively, dynamically adjusting the WAF protection policy, and preventing attack traffic in the user traffic from entering the Open vSwitch through the Open vSwitch flow table rules.
[0007] The beneficial effects brought by the technical solutions provided by some embodiments of this specification at least include:
[0008] The virtualized WAF transparent protection method and system provided by the embodiments of this specification set up a cloud WAF virtual machine deployment topology and integrated protection solution based on an open virtual switch, as well as a forwarding strategy and process for user traffic, supporting a convenient and seamless WAF access method that requires no additional external configuration and does not cause task interruption, and also supports batch deployment. Moreover, the embodiments of this specification provide a unified traffic interception control mechanism, that is, by setting up cloud WAF virtual machines and WAF management nodes, unified interception and protection can be achieved on the traffic side, and attack traffic in user traffic can be blocked from entering the open virtual switch through open virtual switch flow table rules. The embodiments of this specification can support network traffic layer attacks such as DDOS. In addition, the embodiments of this specification not only have a clear network topology for convenient operation and maintenance management, but also set up a fault tolerance mechanism, that is, the WAF protection strategy can be dynamically adjusted, and the high availability switching of cloud WAF virtual machines in the open virtual switch can be linked to ensure that the system can normally provide services to users and continue to provide protection capabilities. Brief Description of the Drawings
[0009] To more clearly illustrate the technical solutions in the embodiments of this specification, the accompanying drawings required for use in the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of this specification. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0010] Figure 1 It is a schematic structural diagram of the virtualized WAF transparent protection system provided by this specification.
[0011] Figure 2 It is a schematic structural diagram of the cloud WAF virtual machine provided by this specification.
[0012] Figure 3 It is a schematic flowchart of attacking identification and interception for user traffic carrying a policy identification value provided by this specification.
[0013] Figure 4 It is a schematic structural diagram of an electronic device for a host computer provided by this specification. Detailed Embodiments
[0014] Next, the technical solutions in the embodiments of this specification will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this specification.
[0015] In the description, claims, and the above-mentioned drawings of this specification, the terms "first", "second", etc. are used to distinguish different objects, rather than to describe a specific order. In addition, the term "comprising" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally further include steps or units not listed, or may optionally further include other steps or units inherent to these processes, methods, products, or devices.
[0016] Please refer to Figure 1 , Figure 1 FIG. is a schematic structural diagram of a virtualized WAF transparent protection system provided by an embodiment of the present invention. The virtualized WAF transparent protection system 100 may at least include: a host 110, which is used to run a Web site 150 and deploy an open virtual switch. The open virtual switch performs traffic transparent forwarding through link switching and VLAN isolation; the open virtual switch may include a first virtual switch 130 and a second virtual switch 140; a cloud WAF virtual machine 120, which is used to connect to the first virtual switch 130 in the open virtual switch through a virtual network card, receive user traffic forwarded by the first virtual switch 130, perform traffic detection and protection on the user traffic, and send the detected normal user traffic to the Web site 150 through the second virtual switch 140 in the open virtual switch; a WAF management node 160, which is used to connect to the cloud WAF virtual machine 120 and the first virtual switch 130 respectively, dynamically adjust the WAF protection policy, and prevent attack traffic in the user traffic from entering the open virtual switch through the open virtual switch flow table rules.
[0017] In this embodiment, the host 110 is a physical server that can run virtual machines and is responsible for providing computing, storage, and network resources for the virtual machines. The host supports hardware virtualization and can support the coexistence of multiple virtual machines through CPU virtualization (such as Intel VT-x); the host can also perform resource allocation and manage the sharing and isolation of the CPU, memory, and disk by the virtual machines. The user traffic in the embodiments of this specification may be data requested by users, such as task traffic such as HTTP / HTTPS web page access, API calls, and video streams that enter the host through a physical switch.
[0018] In this embodiment, a Web site is an application program that provides web services through the HTTP / HTTPS protocol, including a front end, a back end, and a database. Among them, the front end of the Web site supports HTML, CSS, or JavaScript code and can directly interact with users; the back end of the Web site is used for services that process business logic (such as PHP, Node.js); the database of the Web site is used to store user data (such as MySQL, MongoDB). The Web site 150 in the embodiments of this specification may include several sites, and the several sites may be Web site A, Web site B, Web site C, Web site D, etc. respectively.
[0019] In this embodiment, the cloud WAF virtual machine 120 may include several protection node virtual machines, and the several protection node virtual machines may include protection node virtual machine node1, protection node virtual machine node2, protection node virtual machine node3, etc. The cloud WAF virtual machine 120 runs on the host 110 and runs through the virtualization resources (CPU, memory, virtual network, etc.) provided by the host 110. The cloud WAF virtual machine is a virtual server running the WAF service virtualized by the cloud service provider for protecting the Web site from attacks (such as SQL injection, XSS). The cloud WAF virtual machine 120 can perform attack detection, that is, identify malicious attack traffic based on rules (such as OWASP CRS) or an AI model. OWASP CRS (Core Rule Set) is a general attack detection rule set for Web application firewalls and can protect Web application programs from various attacks.
[0020] In this embodiment, the cloud WAF virtual machine 120 can also perform traffic filtering, that is, intercept attack requests and allow normal user traffic to pass through. When the cloud WAF virtual machine 120 is detected by the WAF management node to be in an abnormal state, the WAF management node can dynamically switch the link through the API of the Open vSwitch to switch to a normal cloud WAF virtual machine.
[0021] In this embodiment, the Open vSwitch (OVS) is an open-source virtual switch that can run in a virtualization environment (such as KVM, Docker, etc.), can efficiently forward user traffic between virtual machines, containers, and physical network cards, and supports centralized management of Software-Defined Networking (SDN).
[0022] In some embodiments, the host 110 is connected to a physical switch located outside the host 110 through a host network card. The physical switch is used to send user traffic to the first virtual switch 130 through the host 110 network card. The first virtual switch 130 is used to receive the user traffic sent by the physical switch and select a corresponding port to forward the user traffic to the cloud WAF virtual machine according to the MAC address and port mapping relationship table. The second virtual switch is used to isolate multiple Web site port pairs through VLANs and receive the normal user traffic sent by the cloud WAF virtual machine. The normal user traffic is forwarded to the target Web site based on the Web site port pair.
[0023] In this embodiment, the user traffic enters the first virtual switch 130 of the host through the physical switch connected to the host network card. The first virtual switch 130 dynamically records and updates the association relationship between the MAC address of the device and the corresponding port by automatically detecting the user traffic, and then selects a corresponding port to enter the cloud WAF virtual machine according to the learned MAC address and port mapping relationship table. The MAC address in the embodiments of this specification may be the MAC address of a user device (such as a user PC, mobile phone, etc.) outside the host, and the port may be the interface in the first virtual switch 130 that forwards the user traffic to the cloud WAF virtual machine.
[0024] The first virtual switch 130 in the embodiments of this specification can construct a MAC address and port mapping relationship table through self-learning. The specific process may be: when the user traffic enters the first virtual switch 130 of the host through the physical switch connected to the host network card, the first virtual switch 130 records the mapping relationship between the MAC address of the user device and the port of the first virtual switch 130; if the target MAC is unknown, the first virtual switch 130 broadcasts the data packet corresponding to the user traffic to all ports; after receiving the broadcast packet, the cloud WAF virtual machine returns a response through the virtual network card in the cloud WAF virtual machine (i.e., the cloud WAF virtual network card). At this time, the first virtual switch 130 can learn the relationship between the MAC address of the user device and the port corresponding to the cloud WAF virtual network card, and the port corresponding to the cloud WAF virtual network card corresponds one-to-one with the port of the first virtual switch 130. Therefore, the association relationship between the MAC address of the user device and the port of the first virtual switch 130 can be determined.
[0025] In this embodiment, the port corresponding to the cloud WAF virtual network card corresponds one-to-one with the port of the first virtual switch 130. For example Figure 1As shown in the figure, the first port a0 of the first virtual switch 130 corresponds to the first ingress network card enp1s0 in the protection node virtual machine node1, the second port a1 of the first virtual switch 130 corresponds to the second ingress network card enp2s0 in the protection node virtual machine node1, the third port a2 of the first virtual switch 130 corresponds to the third ingress network card enp3s0 in the protection node virtual machine node2, and the fourth port a3 of the first virtual switch 130 corresponds to the fourth ingress network card enp4s0 in the protection node virtual machine node3.
[0026] In this embodiment, the second virtual switch 140 can isolate multiple Web site port pairs through a Virtual Local Area Network (VLAN) and receive normal user traffic sent by the cloud waf virtual machine; forward the normal user traffic to the target Web site based on the Web site port pairs. As Figure 1 shown in the figure, the second virtual switch 140 can include a first Web site port pair, a second Web site port pair, a third Web site port pair, and a fourth Web site port pair. The first Web site port pair is located in the virtual local area network VLAN, the second Web site port pair is located in the virtual local area network VLAN101, the third Web site port pair is located in the virtual local area network VLAN102, and the fourth Web site port pair is located in VLAN103. The first Web site port pair can include a first access port b0 and a first egress port b1; the second Web site port pair can include a second access port b2 and a second egress port b3, the third Web site port pair can include a third access port b4 and a third egress port b5, and the fourth Web site port pair can include a fourth access port b6 and a fourth egress port b7.
[0027] It should be noted that Figure 1 the structural schematic diagram of the virtualized waf transparent protection system 100 shown in the figure is only an example. The virtualized waf transparent protection system and scenarios described in the embodiments of the present invention are for more clearly illustrating the technical solutions of the embodiments of the present invention, and do not constitute a limitation to the technical solutions provided by the embodiments of the present invention. Those of ordinary skill in the art can know that with the evolution of the virtualized waf transparent protection system and the emergence of new scenarios, the technical solutions provided by the embodiments of the present invention are also applicable to similar technical problems.
[0028] Please refer to Figure 2 , Figure 2 which is the structural schematic diagram of the cloud waf virtual machine provided by the embodiments of the present invention. As Figure 2As shown in the figure, the cloud WAF virtual machine 120 includes a network card pairing module 200, a traffic receiving module 210, a traffic identification module 220, and a detection module 230. Among them, the network card pairing module 200 is used for network card pairing. Each pair of network cards includes an ingress network card and an egress network card. The ingress network card and the egress network card are connected through a bridge, and the egress network card forwards user traffic to the second virtual switch; the traffic receiving module 210 is used to determine the port through which a virtual switch forwards user traffic, and select the ingress network card corresponding to the port to receive user traffic; the traffic identification module 220 is used to generate a policy identification value based on the MAC address and port information, write the policy identification value into the metadata field of the data stream corresponding to the user traffic, and obtain the user traffic carrying the policy identification value; the detection module 230 is used to forward the user traffic carrying the policy identification value to the local virtual network card. The local virtual network card is the virtual network interface of the host 110, and the virtual network interface is connected to the listening ports of the HTTP proxy service and the security detection engine in the user space. The HTTP proxy service and the security detection engine perform attack identification and interception on the user traffic carrying the policy identification value.
[0029] As Figure 1 shown, the protection node virtual machine node1 may include a link link0 and a link link1, the protection node virtual machine node2 may include a link link2, and the protection node virtual machine node3 may include a link link3. In the protection node virtual machine node1, the link link0 may include a first ingress network card enp1s0 and a first egress network card enp1s1, and the first ingress network card enp1s0 and the first egress network card enp1s1 are connected through a first bridge br1; the link link1 may include a second ingress network card enp2s0 and a second egress network card enp2s1, and the second ingress network card enp2s0 and the second egress network card enp2s1 are connected through a second bridge br2. In the protection node virtual machine node2, the link link2 may include a third ingress network card enp3s0 and a third egress network card enp3s1, and the third ingress network card enp3s0 and the third egress network card enp3s1 are connected through a third bridge br3. In the protection node virtual machine node3, the link link3 may include a fourth ingress network card enp4s0 and a fourth egress network card enp4s1, and the fourth ingress network card enp4s0 and the fourth egress network card enp4s1 are connected through a fourth bridge br4.
[0030] Please refer to Figure 3 , Figure 3 which is a schematic flowchart of attack identification and interception of user traffic carrying a policy identification value provided by an embodiment of the present invention. As Figure 3 shown, the HTTP proxy service and the security detection engine perform attack identification and interception on the user traffic carrying the policy identification value, including:
[0031] 300. The HTTP proxy service receives user traffic carrying a policy identification value, parses the application layer protocol, and determines the corresponding security detection rule library according to the policy identification value.
[0032] 310. The security detection engine performs multi-level detection on the user traffic carrying the policy identification value based on the security detection rule library, and identifies and intercepts attacks on the user traffic carrying the policy identification value according to the detection results.
[0033] In this embodiment, the security detection rule library can be a predefined or dynamically generated set of rules for identifying malicious patterns in network traffic, user behavior, or system logs. When the user traffic (such as HTTP requests, DNS queries, API calls) matches the attack pattern in the rule library, the system will trigger an alarm or blocking operation to achieve security protection.
[0034] In this embodiment, the HTTP proxy service is an intermediate service between the client (such as a browser) and the host, responsible for forwarding HTTP / HTTPS requests and responses. The host can send the user traffic carrying the policy identification value to the HTTP proxy service. After receiving the user traffic carrying the policy identification value, the HTTP proxy service parses the application layer protocol based on the user traffic and determines the corresponding security detection rule library according to the policy identification value. The embodiments of this specification achieve dynamic policy binding through the policy identification value, that is, different user traffic can apply different security rules.
[0035] In this embodiment, the security detection engine can perform multi-level detection on the user traffic carrying the policy identification value based on the security detection rule library, including a rule matching stage, a behavior analysis stage, and context correlation. In the rule matching stage, the traffic characteristics are pattern-matched with the regular expressions in the security detection rule library; in the behavior analysis stage, the request frequency of the traffic with the same policy identification value is counted, triggering the CC attack defense under the sliding window algorithm; in the context correlation, stateful tracking is performed on cross-message sessions with the same identification value (such as Cookie: JSESSIONID=ABC).
[0036] In some embodiments, multi-level detection is performed on the user traffic carrying the policy identification value based on the security detection rule library, and attacks on the user traffic carrying the policy identification value are identified and intercepted according to the detection results, including: when it is detected that the user traffic carrying the policy identification value matches the attack pattern in the security detection rule library, the user traffic is blocked or redirected.
[0037] In this embodiment, when attack features are detected, the system generates actions such as request blocking and traffic redirection; Request blocking: The HTTP proxy returns a 403 Forbidden response and records it in the audit log (including the policy identification value); Traffic redirection: When the policy identification value is a high risk (such as 0xFF00), the traffic is forced to be forwarded to the honeypot system.
[0038] In some embodiments, multi-level detection is performed on user traffic carrying a policy identification value based on a security detection rule library, and attack identification and interception are performed on user traffic carrying a policy identification value according to the detection results. It further includes: When it is not detected that the user traffic carrying a policy identification value matches the attack pattern in the security detection rule library, the user traffic carrying a policy identification value is determined as normal user traffic, and the normal user traffic is forwarded to the corresponding egress network card through a bridge.
[0039] In some embodiments, the WAF management node dynamically adjusts the WAF protection policy, including: When an abnormality of the cloud WAF virtual machine is detected, an open virtual switching flow table update is triggered, and the link is switched to connect to the Web site.
[0040] In this embodiment, in a normal protection scenario, external user traffic can enter the host and enter the corresponding Web site (such as Web site A) through a link. When an abnormality occurs in a protection node virtual machine in the cloud WAF virtual machine, the WAF management node triggers an open virtual switching flow table update, and the WAF management node can control the cloud WAF virtual machine to perform high-availability virtual machine switching by switching the link to ensure that the Web site can provide services normally.
[0041] The open virtual switching flow table in the embodiments of this specification is a set of rules for controlling network traffic or resource access permissions, and can determine the forwarding path of data packets (such as discarding, forwarding to a specific port or virtual machine). For example, the rules in the open virtual switching flow table can include forwarding traffic with a destination IP of 10.0.0.1 to the protection node virtual machine node1. When the protection node virtual machine node1 in the embodiments of this specification is abnormal, the WAF management node can update the open virtual switching flow table so that traffic with a destination IP of 10.0.0.1 is forwarded to the protection node virtual machine node2.
[0042] In some embodiments, when an abnormality of the cloud WAF virtual machine is detected, an open virtual switching flow table update is triggered, and the link is switched to connect to the Web site, including: The cloud WAF virtual machine performs real-time self-check and reports its running status to the WAF management node; When the WAF management node detects that the running status does not conform to the preset status, it determines that the cloud WAF virtual machine reporting the running status is in an abnormal state, and dynamically switches the link through the API of the open virtual switch to switch to a normal cloud WAF virtual machine.
[0043] For example, external user traffic can enter the host and enter Website A through link link0. When the protection node virtual machine node1 in the cloud WAF virtual machine has an abnormality, the WAF management node can control the cloud WAF virtual machine to perform high-availability virtual machine switching, switch to link link3, and user traffic can enter Website A through link link3, ensuring that Website A can provide services normally.
[0044] In some embodiments, the WAF management node prevents attack traffic in user traffic from reaching the open virtual switch through open virtual switch flow table rules, including: the WAF management node establishes a benchmark model for HTTP / S requests through machine learning or statistical analysis, and when it detects through the benchmark model that the user traffic exceeds the benchmark threshold in the benchmark model, it determines that the user traffic is attack traffic sent by an attacker, and globally intercepts the attack traffic through the open virtual switch flow table rules.
[0045] In this embodiment, the WAF management node can perform traffic control and interception. The WAF management node can establish a benchmark model for HTTP / S requests (such as request frequency, URL distribution, session duration) through machine learning or statistical analysis. For example, the number of times a normal user accesses the / login page per second ≤ 50 times. Real-time deviation warning: When the user traffic exceeds the baseline threshold (such as a sudden increase of 10 times), an alarm is triggered, which may be an HTTP Flood attack, and the attack traffic can be globally intercepted through the open virtual switch flow table rules.
[0046] The WAF management node in the embodiment of this specification can globally intercept attack traffic through open virtual switch flow table rules, that is, the WAF management node can centrally define traffic matching and interception rules in a virtualized or cloud environment, thereby preventing malicious traffic (such as DDoS, scanning, intrusion attempts, etc.) from reaching the target website.
[0047] In some embodiments, the WAF management node intercepts attack traffic through open virtual switch flow table rules, including: the WAF management node extracts attack features based on the attack traffic, and then intercepts the attack traffic through the open virtual switch flow table rules based on the attack features.
[0048] In this embodiment, the WAF management node can extract attack features (such as abnormal SYN rate) based on the attack traffic, then obtain the interception rules corresponding to the attack features in the open virtual switch flow table, and intercept the attack traffic through the interception rules. The abnormal SYN rate in the embodiment of this specification can be that in network communication, the sending rate of SYN packets is abnormally higher than the normal level. The SYN packet is the first packet in the TCP connection establishment process and is used to request the establishment of a connection.
[0049] For example, when malicious attacks or crawlers occur, the WAF management node can intercept all traffic destined for the virtual machines of all protection nodes through the open virtual switching flow table rules, achieving efficient and unified interception. The traffic attacks of network layer DDOS can also be intercepted through the open virtual switching flow table rules, improving the protection ability of the virtual machines of the protection nodes against traffic-side attacks.
[0050] This specification provides a virtualized WAF transparent protection method based on Open vSwitch, including: setting a host computer, which is used to run a Web site and deploy an open virtual switch, and the open virtual switch performs transparent traffic forwarding through link switching and VLAN isolation; setting a cloud WAF virtual machine, which is used to connect to a first virtual switch in the open virtual switch through a virtual network card, receive user traffic forwarded by the first virtual switch, perform traffic detection and protection on the user traffic, and send the detected normal user traffic to the Web site through a second virtual switch in the open virtual switch; setting a WAF management node, which is used to connect to the cloud WAF virtual machine and the first virtual switch respectively, dynamically adjust the WAF protection policy, and prevent attack traffic in the user traffic from entering the open virtual switch through the open virtual switching flow table rules.
[0051] The virtualized WAF transparent protection method and system provided by the embodiments of this specification set up a cloud WAF virtual machine deployment topology and integrated protection scheme based on open virtual switching, as well as a forwarding strategy and process for user traffic, support a convenient and seamless WAF access method, do not require additional external configuration and will not cause task interruption, and support batch deployment. Moreover, the embodiments of this specification provide a unified traffic interception control mechanism, that is, by setting up a cloud WAF virtual machine and a WAF management node, unified interception and protection can be achieved on the traffic side, and attack traffic in the user traffic can be prevented from entering the open virtual switch through the open virtual switching flow table rules. The embodiments of this specification can support network traffic layer attacks such as DDOS. In addition, the embodiments of this specification not only have a clear network topology, which is convenient for operation and maintenance management; but also set up a fault tolerance mechanism, that is, the WAF protection policy can be dynamically adjusted, and the high-availability switching of the cloud WAF virtual machine integrated with the open virtual switch can be linked to ensure that the system can normally provide services to users and can continue to provide protection capabilities.
[0052] The above description is of specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired results. Additionally, the processes depicted in the drawings do not necessarily require the particular order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0053] Please refer to Figure 4 FIG. is a schematic structural diagram of an electronic device regarding the host computer 110 in the virtualized waf transparent protection system provided by the embodiments of this specification shown.
[0054] As Figure 4 shown, the electronic device 400 may include: at least one processor 410, at least one network interface 440, a user interface 430, a memory 450, and at least one communication bus 420.
[0055] Among them, the communication bus 420 can be used to realize the connection and communication of the above-mentioned various components.
[0056] Among them, the user interface 430 may include buttons, and the optional user interface may further include a standard wired interface and a wireless interface.
[0057] Among them, the network interface 440 may but is not limited to include a Bluetooth module, an NFC module, a ZigBee module, and a UWB module, etc.
[0058] Among them, the processor 410 may include one or more processing cores. The processor 410 connects various parts within the entire electronic device 400 through various interfaces and lines, and by running or executing instructions, programs, code sets, or instruction sets stored in the memory 450, and by calling data stored in the memory 450, it executes various functions of the electronic device 400 and processes data. Optionally, the processor 410 may be implemented in at least one hardware form of a DSP, an FPGA, or a PLA. The processor 410 may integrate one or a combination of several of a CPU and a GPU, etc. Among them, the CPU mainly processes the operating system, the user interface, and application programs, etc.; the GPU is responsible for the rendering and drawing of the content to be displayed on the display screen.
[0059] Among them, the memory 450 may include RAM or ROM. Optionally, the memory 450 includes a non-transitory computer-readable medium. The memory 450 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 450 may include a program storage area and a data storage area. Among them, the program storage area can store instructions for implementing the operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-mentioned method embodiments, etc.; the data storage area can store data involved in the above-mentioned method embodiments. Optionally, the memory 450 may also be at least one storage device located far from the aforementioned processor 410. The memory 450, as a computer storage medium, may include an operating system, a communication module, a user interface module, and a virtualized waf transparent protection application program. The processor 410 can be used to call the virtualized waf transparent protection application program stored in the memory 450 and execute the steps in the virtualized waf transparent protection method based on openvswitch mentioned in the foregoing embodiments.
[0060] The embodiments of this specification also provide a computer-readable storage medium. Instructions are stored in the computer-readable storage medium. When they run on a computer or a processor, the computer or the processor is enabled to execute one or more steps in the above-mentioned embodiments. If the various component modules of the above-mentioned electronic device are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium.
[0061] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of this specification are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted through a computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (for example, floppy disk, hard disk, magnetic tape), an optical medium (for example, Digital Versatile Disc (DVD)), or a semiconductor medium (for example, Solid State Disk (SSD)), etc.
[0062] Those of ordinary skill in the art can understand that all or part of the processes in the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the above embodiments. The foregoing storage media include: various media such as ROM, RAM, magnetic disk, or optical disc that can store program codes. Without conflict, the technical features in this embodiment and the implementation solutions can be combined arbitrarily.
[0063] The above embodiments are only described in the preferred implementation manners of this specification and do not limit the scope of this specification. Without departing from the design spirit of this specification, various deformations and improvements made by those of ordinary skill in the art to the technical solutions of this specification shall fall within the protection scope determined by the claims of this specification.
Claims
1. A virtualized WAF transparent protection system based on Open vSwitch, characterized in that, Including: A host computer, which is used to run a Web site and deploy an open virtual switch. The open virtual switch performs transparent traffic forwarding through link switching and VLAN isolation; A cloud WAF virtual machine, which is used to connect to a first virtual switch in the open virtual switch through a virtual network card, receive user traffic forwarded by the first virtual switch, perform traffic detection and protection on the user traffic, and send the detected normal user traffic to the Web site through a second virtual switch in the open virtual switch; A WAF management node, which is used to connect to the cloud WAF virtual machine and the first virtual switch respectively, dynamically adjust the WAF protection policy, and prevent attack traffic in the user traffic from entering the open virtual switch through the open virtual switch flow table rule; 2. The virtualized WAF transparent protection system based on openvswitch according to claim 1, characterized in that, The host computer is connected to a physical switch located outside the host computer through a host network card, and the physical switch is used to send the user traffic to the first virtual switch through the host network card; The first virtual switch is used to receive the user traffic sent by the physical switch and select a corresponding port to forward the user traffic to the cloud WAF virtual machine according to the MAC address and port mapping relationship table; The second virtual switch is used to isolate multiple Web site port pairs through VLAN and receive the normal user traffic sent by the cloud WAF virtual machine; Forward the normal user traffic to the target Web site based on the Web site port pair; 3. The virtualized WAF transparent protection system based on openvswitch according to claim 1, characterized in that, The cloud WAF virtual machine includes: A network card pairing module, which is used to perform network card pairing. Each pair of network cards includes an entrance network card and an exit network card. The entrance network card and the exit network card are connected through a bridge, and the exit network card forwards the user traffic to the second virtual switch; A traffic receiving module, which is used to determine the port through which the first virtual switch forwards the user traffic, and select the entrance network card corresponding to the port to receive the user traffic; A traffic identification module, which is used to generate a policy identification value based on the MAC address and port information, write the policy identification value into the metadata field of the data stream corresponding to the user traffic, and obtain the user traffic carrying the policy identification value; A detection module, which is used to forward the user traffic carrying the policy identification value to a local virtual network card. The local virtual network card is a virtual network interface of the host computer, and the virtual network interface is connected to the listening ports of the HTTP proxy service and the security detection engine in the user space. The HTTP proxy service and the security detection engine perform attack identification and interception on the user traffic carrying the policy identification value; 4. The virtualized WAF transparent protection system based on openvswitch according to claim 3, characterized in that, The HTTP proxy service and the security detection engine perform attack identification and interception on the user traffic carrying the policy identification value, including: The HTTP proxy service receives the user traffic carrying the policy identification value, parses the application layer protocol, and determines a corresponding security detection rule library according to the policy identification value; The security detection engine performs multi-level detection on the user traffic carrying the policy identification value based on the security detection rule library, and identifies and intercepts attacks on the user traffic carrying the policy identification value according to the detection results.
5. The virtualized WAF transparent protection system based on openvswitch according to claim 4, wherein, The performing multi-level detection on the user traffic carrying the policy identification value based on the security detection rule library, and identifying and intercepting attacks on the user traffic carrying the policy identification value according to the detection results includes: When it is detected that the user traffic carrying the policy identification value matches the attack pattern in the security detection rule library, block or redirect the user traffic.
6. The virtualized WAF transparent protection system based on openvswitch according to claim 5, characterized in that The performing multi-level detection on the user traffic carrying the policy identification value based on the security detection rule library, and identifying and intercepting attacks on the user traffic carrying the policy identification value according to the detection results further includes: When it is not detected that the user traffic carrying the policy identification value matches the attack pattern in the security detection rule library, determine the user traffic carrying the policy identification value as normal user traffic, and forward the normal user traffic to the corresponding egress network card through the bridge.
7. The virtualized WAF transparent protection system based on openvswitch according to claim 1, characterized in that The waf management node dynamically adjusts the waf protection policy, including: When it is detected that the cloud waf virtual machine is abnormal, trigger the update of the open virtual switch flow table, and connect to the Web site by switching the link.
8. The virtualized WAF transparent protection system based on openvswitch according to claim 7, characterized in that, The when it is detected that the cloud waf virtual machine is abnormal, trigger the update of the open virtual switch flow table, and connect to the Web site by switching the link includes: The cloud waf virtual machine performs real-time self-check and reports the running status to the waf management node; When the waf management node detects that the running status does not conform to the preset status, determine that the cloud waf virtual machine reporting the running status is in an abnormal state, and dynamically switch the link through the API of the open virtual switch to switch to a normal cloud waf virtual machine.
9. The virtualized WAF transparent protection system based on openvswitch according to claim 7, wherein, The waf management node prevents the attack traffic in the user traffic from reaching the open virtual switch through the open virtual switch flow table rule, including: The waf management node establishes a benchmark model for HTTP / S requests through machine learning or statistical analysis, and when it is detected through the benchmark model that the user traffic exceeds the benchmark threshold in the benchmark model, determine that the user traffic is attack traffic sent by an attacker, and globally intercept the attack traffic through the open virtual switch flow table rule; The waf management node extracts attack features based on the attack traffic, and intercepts the attack traffic through the open virtual switch flow table rule based on the attack features.
10. A virtualized WAF transparent protection method based on Open vSwitch, characterized in that Includes: Set up a host, where the host is used to run the Web site and deploy an open virtual switch, and the open virtual switch performs transparent traffic forwarding through link switching and VLAN isolation; Set up a cloud WAF virtual machine, which is used to connect to the first virtual switch in the open virtual switch through a virtual network card, receive the user traffic forwarded by the first virtual switch, perform traffic detection and protection on the user traffic, and send the detected normal user traffic to the Web site through the second virtual switch in the open virtual switch; Set up a WAF management node, which is used to connect to the cloud WAF virtual machine and the first virtual switch respectively, dynamically adjust the WAF protection policy, and prevent the attack traffic in the user traffic from entering the open virtual switch through the open virtual switch flow table rules.
Citation Information
Patent Citations
Message processing method and system and storage medium
CN109525582A
East-west traffic safety protection method and system based on SDN
CN111953661A