Automatic flow arrangement method and device, equipment and medium
By decrypting and classifying plaintext data in the orchestration device and using the bypass deployment methods of multiple security equipment for security detection, the problem of excessive load of security equipment when connecting 5G private networks to the office network in the nuclear power field is solved, and efficient utilization of security equipment and stable operation of the network is achieved.
Patent Information
- Application Number
- CN202510447916.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-07-04
AI Technical Summary
In the field of nuclear power, when the 5G private network is connected to the office network, the load and loss of security equipment are too high, resulting in the security and efficiency of data transmission cannot be effectively guaranteed.
By decrypting plain text data in the orchestration device, performing type analysis and classification, security detection is performed using the bypass deployment methods of multiple security devices, only plain text data is sent to the corresponding security device for detection, and encryption is performed after passing the detection.
It reduces the load of safety equipment, improves the utilization rate of safety equipment, reduces unnecessary losses, extends the equipment life, and ensures the safe and stable operation of the network.
Smart Images

Figure CN120263740A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and in particular, to an automated traffic orchestration method, apparatus, device, and medium. Background Art
[0002] In the nuclear power field, the office intranet, as a key information infrastructure, is strictly isolated from the external Internet due to the security requirements of its data. Technical means such as firewalls are required to prevent unauthorized external access and ensure the security of the storage and transmission of data related to nuclear safety.
[0003] With the development of 5G networks, more and more nuclear power plants are starting to build 5G private networks to improve production efficiency in the nuclear power field. Thus, in order to promote the intelligent integration of production and management, support mobile office and digital management, and meet communication requirements in special nuclear power environments, such as anti-interference and radiation resistance, it is extremely necessary to connect the 5G private network and the office intranet. To ensure the security and reliability of data transmission, security devices also need to be set up between the 5G private network and the office intranet to detect the security of data in real time.
[0004] However, at the present stage, due to the large volume of data transmission and the need to perform security detection on all data, the load and loss of security devices are too high, resulting in the inability to effectively guarantee the security and efficiency of data transmission. Summary of the Invention
[0005] Embodiments of the present invention provide an automated traffic orchestration method, apparatus, device, and medium, aiming to solve the problem of too high load and loss of security devices in the prior art methods.
[0006] In a first aspect, embodiments of the present invention provide an automated traffic orchestration method, which is applied to an orchestration device deployed between a first network and a second network. The method includes:
[0007] If access traffic data is received, decrypt the access traffic data to obtain the plaintext data corresponding to the access traffic data;
[0008] Perform type analysis on the plaintext data to confirm the traffic type of the access traffic data, and classify the plaintext data based on the traffic type;
[0009] According to the traffic type of the access traffic data, orchestrate the plaintext data to the corresponding security device for security detection;
[0010] Wherein, multiple security devices are provided, and the physical network elements of the multiple security devices are communicatively connected to the orchestration device in a bypass deployment manner;
[0011] Encrypt the plaintext data that has passed the security check to obtain ciphertext data, and send the ciphertext data to the corresponding client or server.
[0012] In a second aspect, an embodiment of the present invention provides an orchestration device. The method described in the first aspect is applied to the orchestration device. The orchestration device is deployed between a first network and a second network. The orchestration device includes:
[0013] A decryption module, configured to decrypt the access traffic data if the access traffic data is received, and obtain the plaintext data corresponding to the access traffic data;
[0014] A type analysis module, configured to perform type analysis on the plaintext data to confirm the traffic type of the access traffic data, and classify the plaintext data based on the traffic type;
[0015] An orchestration module, configured to orchestrate the plaintext data to corresponding security devices for security detection according to the traffic type of the access traffic data;
[0016] Wherein, multiple security devices are provided, and physical network elements of the multiple security devices are communicatively connected to the orchestration device in a bypass deployment manner;
[0017] An encryption and sending module, configured to encrypt the plaintext data that has passed the security check to obtain ciphertext data, and send the ciphertext data to the corresponding client or server.
[0018] In a third aspect, an embodiment of the present invention provides a computer device. The device includes a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus;
[0019] The memory is used to store a computer program;
[0020] The processor is configured to implement the steps of the method for automated orchestration of traffic described in the first aspect when executing the program stored on the memory.
[0021] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method for automated orchestration of traffic described in the first aspect are implemented.
[0022] An embodiment of the present invention provides a method, apparatus, device, and medium for automatic traffic orchestration. The method is applied to an orchestration device deployed between a first network and a second network. The method includes: if access traffic data is received, decrypt the access traffic data to obtain the plaintext data corresponding to the access traffic data; perform type analysis on the plaintext data to confirm the traffic type of the access traffic data, and classify the plaintext data based on the traffic type; according to the traffic type of the access traffic data, orchestrate the plaintext data to a corresponding security device for security detection; wherein, multiple security devices are provided, and the physical network elements of the multiple security devices are communicatively connected to the orchestration device in a bypass deployment manner; encrypt the plaintext data that passes the security check to obtain ciphertext data, and send the ciphertext data to the corresponding client or server. The present invention can enable different types of traffic to only pass through the security devices that should pass through, which can reduce the load on the security devices, improve the utilization rate of the security devices, and reduce unnecessary losses of other security devices. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0024] Figure 1 It is a flowchart of the method for automatic traffic orchestration provided by the embodiment of the present invention;
[0025] Figure 2 It is a sub-flowchart of the method for automatic traffic orchestration provided by the embodiment of the present invention;
[0026] Figure 3 It is a sub-flowchart of the method for automatic traffic orchestration provided by the embodiment of the present invention;
[0027] Figure 4 It is a sub-flowchart of the method for automatic traffic orchestration provided by the embodiment of the present invention;
[0028] Figure 5 It is a schematic block diagram of the orchestration device provided by the embodiment of the present invention;
[0029] Figure 6 It is a schematic block diagram of the computer device provided by the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0030] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0031] It should be understood that when used in this specification and the appended claims, the terms "comprising" and "including" indicate the presence of the described features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.
[0032] It should also be understood that the terms used in the specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in the specification of the present invention and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" are intended to include the plural forms.
[0033] It should be further understood that the term " / and / " used in the specification of the present invention and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0034] It should also be noted that, unless otherwise clearly defined and limited, terms such as "installation", "connection", "connection", "fixation", "setting", etc. should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or integrated; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements or the interaction relationship between two elements. When an element is referred to as being "on" or "under" another element, the element can be "directly" or "indirectly" located above the other element, or there may also be one or more intermediate elements. The terms "first", "second", "third", etc. are only for the convenience of describing the present technical solution and cannot be understood as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first", "second", "third", etc. can explicitly or implicitly include one or more of such features. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0035] Please refer to Figure 1 , an embodiment of the present invention application provides an automated orchestration method for traffic. The method is applied to an orchestration device, and the orchestration device is deployed between a first network and a second network. The method includes steps S1 to S4.
[0036] S1. If access traffic data is received, decrypt the access traffic data to obtain the plaintext data corresponding to the access traffic data.
[0037] In this embodiment, the first network and the second network are two networks with isolated boundaries. The first network and the second network can specifically be any two combinations of the nuclear power office intranet, the Internet, and the nuclear power 5G private network. To avoid redundant descriptions, in the following embodiments, the nuclear power office intranet is used as the first network and the Internet is used as the second network for illustration. The scenarios of initiating access behaviors from the first network to the second network may include: internal personnel of the nuclear power plant accessing the Internet, accessing cloud services, and proxying the Internet based on office operations. The scenarios of initiating access behaviors from the second network to the first network may include: external personnel accessing the business systems inside the nuclear power enterprise, etc.
[0038] When a user initiates an access behavior through the first network or the second network, since the orchestration device is deployed between the first network and the second network, before the access traffic data enters the target network, it will first pass through the orchestration device. Thus, when the access traffic data flows through the orchestration device, the orchestration device actively traps it and decrypts the access traffic data.
[0039] Specifically, before "if access traffic data is received, decrypt the access traffic data to obtain the plaintext data corresponding to the access traffic data", the orchestration device can perform handshake negotiation with the client and the server respectively based on the SSL (Secure Sockets Layer) protocol. The SSL protocol is a network security protocol used to establish an encrypted channel between the client and the server, aiming to ensure the confidentiality and integrity of data transmission. For example, when external personnel access the business systems inside the nuclear power plant, the client is deployed in the second network and the server is deployed in the first network. The server can be the server of the business systems inside the nuclear power enterprise. The orchestration device performs SSL handshake negotiation with both ends (the client and the server) by importing the server's certificate and private key, or using the device's temporarily issued certificate and private key, or remotely invoking the HSM (hardware security module) device for asymmetric encryption and decryption operations. It both simulates the server on the client side and the client on the server side, is not restricted by the cipher suite, and can decrypt the traffic of any port according to the configuration. Thus, the process of decrypting the access traffic data actively trapped by the orchestration device is realized, enabling it to obtain the plaintext data corresponding to the access traffic data.
[0040] S2. Analyze the type of the plaintext data to confirm the traffic type of the access traffic data, and classify the plaintext data based on the traffic type.
[0041] In this embodiment, the orchestration device can perform type analysis on the plaintext data to confirm the traffic type of the access traffic data. The orchestration device can confirm the traffic type of the access traffic data by obtaining the source IP, destination IP, accessed domain name, application, etc. of the access traffic data. And the traffic type includes the flow direction type and the protocol type.
[0042] Please refer to Figure 2 , first of all, the type analysis of the plaintext data to confirm the traffic type of the access traffic data and classify the plaintext data based on the traffic type includes sub-steps S21 to S22.
[0043] S21. Perform a first-level analysis on the plaintext data to confirm the flow direction type of the access traffic data corresponding to the plaintext data.
[0044] In this embodiment, the flow direction type includes accessing the second network from the first network or accessing the first network from the second network. The orchestration device can judge the flow direction type of the access traffic data by judging the source IP and destination IP of the plaintext data. Specifically, the first network is the nuclear power office intranet, and the orchestration device can pre-store the common fields of all IP addresses in the first network. After obtaining the plaintext data, it can judge whether the source IP and destination IP of the plaintext data contain the common fields. If the source IP does not contain the common fields while the destination IP contains the common fields, it is confirmed that the flow direction type of the access traffic data corresponding to the plaintext data is accessing the first network from the second network; if the source IP contains the common fields while the destination IP does not contain the common fields, it is confirmed that the flow direction type of the access traffic data corresponding to the plaintext data is accessing the second network from the first network.
[0045] S22. Perform a second-level analysis on the plaintext data to confirm the protocol type adopted by the access traffic data corresponding to the plaintext traffic.
[0046] In this embodiment, after confirming the flow direction type of the access traffic data, it is necessary to further confirm its protocol type. Specifically, the orchestration device can judge the protocol type adopted by the access traffic data by judging the IP header field and the target port of the plaintext data. For example, the IP header field for the TCP protocol is 6, and the IP header field for the UDP protocol is 17; the target port for the plaintext data based on the HTTP protocol is 80, and the target port for the plaintext data based on the HTTPS protocol is 443, etc. In this way, the orchestration device can realize the confirmation and classification of the protocol type of the plaintext data.
[0047] S3. According to the traffic type of the access traffic data, orchestrate the plaintext data to the corresponding security device for security detection.
[0048] Among them, multiple types of security devices are provided, and physical network elements of the multiple types of security devices are communicatively connected to the orchestration device in a bypass deployment manner. The security devices may include FW (Firewall), behavior management devices, IPS (Intrusion Prevention System), WAF (Web Application Firewall), IDS (intrusion detection system), probes, and the like.
[0049] The physical network elements of the security devices are communicatively connected to the orchestration device in a bypass deployment manner, that is, the security devices are not connected in series at the physical connection level. The key point is that since the physical network elements are deployed in a bypass manner, after the orchestration device forwards the plaintext data to a security device for security detection, the plaintext data that passes the detection is not and cannot be directly forwarded to the next security device, but is instead forwarded back to the orchestration device by the security device, and the orchestration device determines whether it is necessary to forward the plaintext data to other security devices for further security detection. Embodiments of the present invention can avoid all traffic data from flowing through all security devices. For example, the WAF is only orchestrated to detect traffic based on the HTTP protocol, while traffic based on the UDP protocol is orchestrated to other security devices for detection without passing through the WAF, so that traffic of different types of business systems only passes through the security devices that should be passed through, which can reduce the load on the security devices, improve the utilization rate of the security devices, reduce unnecessary losses of other security devices, and reduce service latency; and extend the working life of the security devices, ensure the secure transmission of network data, and thus ensure the safe and stable operation of the office intranet. Moreover, the security devices are deployed in the form of physical network element groups, which can effectively achieve load balancing and flexible expansion compared with pure software protection.
[0050] Please refer to Figure 3 , further, the orchestrating the plaintext data to a corresponding security device for security detection according to the traffic type of the access traffic data includes sub-steps S31 to S33.
[0051] S31. Generate a security device type directory according to the traffic type of the access traffic data;
[0052] In this embodiment, after confirming the traffic type of the access traffic data, a security device type directory is generated, where the traffic type includes a flow direction type and a protocol type. The directory entries of the security device type directory are the names of the security devices that need to perform security detection on the plaintext data.
[0053] Specifically, a correspondence tree between traffic types and security devices is pre-stored in the orchestration device. In the first correspondence tree among them, the outermost node is the "flow direction type", and at least two child nodes are connected thereafter to respectively represent different traffic flow directions. For example, the first flow direction is accessing the first network from the second network, and the second flow direction is accessing the second network from the first network. After each child node representing a flow direction, multiple child nodes representing security device names are connected. In the second correspondence tree among them, the outermost node is the "protocol type", and multiple child nodes are connected thereafter to respectively represent different protocol types. After each child node representing a protocol type, multiple child nodes representing security device names are connected. Among them, at least one name of a security device dedicated to detecting the traffic corresponding to the protocol type is included in the child nodes after each child node representing a protocol type.
[0054] After the orchestration device confirms the flow direction type and the protocol type, first, multiple security device names are pre-selected as the first sub-directory according to the path of the first correspondence tree, and then multiple security device names are selected as the second sub-directory according to the path of the second correspondence tree. The first sub-directory is compared with the second sub-directory, and the same items in the first sub-directory and the second sub-directory are retained as the security device type directory. That is, the security devices corresponding to the directory entries in the security device type directory are the security devices that need to perform security detection on the plaintext data.
[0055] Please refer to Figure 4 , further, in the automated traffic orchestration method, the first network is an office intranet; generating a security device type directory according to the traffic type of the access traffic data includes sub-steps S311. If the flow direction type of the access traffic data is accessing the second network from the first network, at least include the behavior management device in the security device type directory; S312. If the flow direction type of the access traffic data is accessing the first network from the second network, do not include the behavior management device in the security device type directory.
[0056] In this embodiment, the second network is the Internet. The behavior management device is dedicated to controlling the Internet access behaviors of users on the office intranet to employees on the office intranet, and can audit and check traffic such as web, mail, FTP / HTTP, P2P, chat software, and video traffic in the Internet access behaviors of employees. When pre-storing the correspondence tree between traffic types and security devices, the child node representing the behavior management device can be set in the child nodes connected after the second flow direction, and the child node representing the behavior management device is not set in the child nodes connected after the first flow direction.
[0057] S32. Orchestrate the logical link chain of security devices according to the security device type directory.
[0058] Among them, the protection accuracy of the security device located at the rear node of the logical circuit chain is higher than that of the security device located at the front node of the logical circuit chain. In this embodiment, after generating the catalog of security device types, the logical circuit chain of security devices is arranged according to the names of security devices recorded in the catalog of security device types. And the security devices with higher protection accuracy are arranged at the rear end of the logical circuit chain according to the devices. This embodiment considers that during security protection, the protection accuracies of different security devices are different. For example, although the FW can filter attacks at the network layer at the network layer, it lacks the ability to deeply analyze the application layer and cannot identify attacks specific to Web applications, while the WAF focuses on the application layer, can deeply analyze HTTP / HTTPS traffic, and can identify and defend against attacks specific to Web applications. Then, if the catalog of security device types includes FW and WAF, the WAF is arranged at the rear end of the FW. And the logical circuit chain can include at least two security devices. On the one hand, it is to reduce the load pressure of a single security device. On the other hand, it is to cooperate in protection to improve the overall protection ability.
[0059] For example, when the arrangement device confirms that the flow type of the access traffic data is the first flow, that is, accessing the first network from the second network, and the protocol type is the protocol type based on HTTP / HTTPS, the catalog items of the generated catalog of security device types include FW, WAF, and IPS, and the arranged logical circuit chain is "FW→IPS→WAF"; when the arrangement device confirms that the flow type of the access traffic data is the second flow, that is, accessing the second network from the first network, and the protocol type is the protocol type based on HTTP / HTTPS, the catalog items of the generated catalog of security device types include FW, WAF, IPS, and the behavior management device, and the arranged logical circuit chain is "FW→behavior management device→IPS→WAF".
[0060] It should be noted that the logical circuit chain of security devices only means that the data is in series in terms of transmission logic, that is, it only represents the order of plaintext data passing through security devices, and does not mean that the plaintext data is directly sent from the first security device of the logical circuit chain to the second security device. For example: after the arrangement device sends the plaintext data to the physical network element of the FW for security detection, the FW then sends the plaintext data that passes the detection to the arrangement device, and the arrangement device then sends the plaintext data to the physical network element of the next security device on the logical circuit chain, and so on. The reason is that the physical network elements of multiple security devices are connected to the arrangement device in a bypass deployment form. And the physical network elements of multiple security devices cannot be connected in a series deployment form, because the series deployment of physical network elements will cause the plaintext data to be forced to pass through all physical network elements, even if some of the physical network elements cannot provide targeted protection for this type of traffic, which will lead to an increase in the load of the security device, that is, it cannot solve the problem to be solved by implementing the present invention.
[0061] S33. According to the order of the logical link chain, sequentially send the plaintext data to the physical network elements of the security devices deployed in each bypass.
[0062] Sequentially send the plaintext data to the physical network elements of the security devices deployed in each bypass. Specifically, if the logical link chain sequentially includes a first security device, a second security device, and a third security device, the transmission order of the plaintext data is as follows: The orchestration device sends the plaintext data to the physical network element of the first security device for security detection. Then, the second security device sends the plaintext data that has passed the detection to the orchestration device. The orchestration device then sends the plaintext data to the physical network element of the third security device, and the third security device then sends the detected plaintext data to the orchestration device.
[0063] S4. Encrypt the plaintext data that has passed the security check to obtain ciphertext data, and send the ciphertext data to the corresponding client or server.
[0064] In this embodiment, after the plaintext data passes the checks of all the security devices on the logical link chain, the orchestration device encrypts the plaintext data to obtain ciphertext data, and sends it to the corresponding client or server according to the destination IP and target port. Among them, when the client is deployed in the first network, the server is deployed in the second network; when the server is deployed in the first network, the client is deployed in the second network.
[0065] In some embodiments, for the correct and effective execution of subsequent steps, before the method decrypts the access traffic data and obtains the plaintext data corresponding to the access traffic data if it receives the access traffic data, it further includes: Real-time monitoring of the physical interface status of the security device, and health detection of the network link layer where the security device is located; Regularly detecting the forwarding ability of the security device by means of loopback detection. Among them, the health detection of the network link layer where the security device is located can be implemented based on various detection methods such as TCP, HTTP, DNS, and ICMP protocols.
[0066] In a further embodiment, the regularly detecting the forwarding ability of the security device by means of loopback detection includes:
[0067] Regularly send probe messages to each security device in the security device chain;
[0068] Judge whether a response message sent from the security device is received within a predetermined time to obtain a first judgment result;
[0069] Among them, the response message is generated based on the probe message, and it can be the same as or different from the probe message, as long as the orchestration device can identify it;
[0070] If the first judgment result is negative, that is, it is determined that the forwarding ability of the security device is abnormal, then the corresponding security device is removed.
[0071] Please refer to Figure 5 , an embodiment of the present invention further provides an orchestration device. The automated orchestration method of the traffic is applied to the orchestration device. The orchestration device is deployed between a first network and a second network. The orchestration device includes:
[0072] A decryption module 110, configured to decrypt the access traffic data if the access traffic data is received, and obtain the plaintext data corresponding to the access traffic data.
[0073] A type analysis module 120, configured to perform type analysis on the plaintext data to confirm the traffic type of the access traffic data, and classify the plaintext data based on the traffic type.
[0074] An orchestration module 130, configured to orchestrate the plaintext data to a corresponding security device for security detection according to the traffic type of the access traffic data.
[0075] Wherein, a plurality of security devices are provided, and the physical network elements of the plurality of security devices are communicatively connected to the orchestration device in a bypass deployment manner.
[0076] An encryption and sending module 140, configured to encrypt the plaintext data that passes the security check to obtain ciphertext data, and send the ciphertext data to a corresponding client or server.
[0077] In a further embodiment, the orchestration device further includes:
[0078] A physical interface detection module 150, configured to monitor the physical interface status of the security device in real time.
[0079] A network link layer detection module 160, configured to perform a health check on the network link layer where the security device is located.
[0080] A loopback detection module 170, configured to periodically detect the forwarding ability of the security device by means of loopback detection.
[0081] The above-mentioned orchestration device can be implemented in the form of a computer program, and the computer program can run on a computer device as shown in Figure 6 shown.
[0082] An embodiment of the present invention further provides a security system, including an orchestration device and a plurality of security devices. The physical network elements of the plurality of security devices are communicatively connected to the orchestration device in a bypass deployment manner. The automated orchestration method of the traffic described in the above embodiment is applied to the orchestration device.
[0083] Please refer to Figure 6 , Figure 6 which is a schematic block diagram of a computer device provided by an embodiment of the present invention.
[0084] Refer to Figure 6 , the computer device 500 includes a processor 502, a memory, and a network interface 505 connected through a communication bus 501. Among them, the memory may include a storage medium 503 and an internal memory 504.
[0085] The storage medium 503 can store an operating system 5031 and a computer program 5032. When the computer program 5032 is executed, it can cause the processor 502 to execute an automated traffic orchestration method. Among them, the storage medium 503 can be a volatile storage medium or a non-volatile storage medium.
[0086] The processor 502 is used to provide computing and control capabilities to support the operation of the entire computer device 500.
[0087] The internal memory 504 provides an environment for the operation of the computer program 5032 in the storage medium 503. When the computer program 5032 is executed by the processor 502, it can cause the processor 502 to execute an automated traffic orchestration method.
[0088] The network interface 505 is used for network communication, such as providing the transmission of data information, etc. Those skilled in the art can understand that Figure 6 the structure shown in
[0089] is only a block diagram of a part of the structure related to the solution of the present invention, and does not constitute a limitation on the computer device 500 to which the solution of the present invention is applied. The specific computer device 500 may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0090] Those skilled in the art can understand that Figure 6 the embodiment of the computer device shown in Figure 6 does not constitute a limitation on the specific composition of the computer device. In other embodiments, the computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements. For example, in some embodiments, the computer device may only include a memory and a processor. In such an embodiment, the structure and function of the memory and the processor are the same as those in
[0091] It should be understood that in the embodiments of the present invention, the processor 502 may be a central processing unit (CPU), and the processor 502 may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0092] In another embodiment of the present invention, a computer-readable storage medium is provided. The computer-readable storage medium may be a volatile or non-volatile computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps included in the above-mentioned automated traffic orchestration method are implemented.
[0093] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described devices, apparatuses, and units can refer to the corresponding processes in the foregoing method embodiments, and will not be described herein again. Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0094] In several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. Units with the same function may also be integrated into a single unit. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. In addition, the displayed or discussed couplings, direct couplings, or communication connections to each other may be indirect couplings or communication connections through some interfaces, devices, or units, and may also be electrical, mechanical, or other forms of connection.
[0095] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or may be distributed over multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of the embodiment of the present invention.
[0096] In addition, each functional unit in various embodiments of the present invention may be integrated in a processing unit, may exist separately as individual physical units, or two or more units may be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0097] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a computer-readable storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned computer-readable storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), magnetic disks, or optical discs that can store program codes.
[0098] As described above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. An automated orchestration method for traffic, characterized in that The method is applied to an orchestration device, which is deployed between a first network and a second network. The method includes: If access traffic data is received, decrypt the access traffic data to obtain the plaintext data corresponding to the access traffic data; Perform type analysis on the plaintext data to confirm the traffic type of the access traffic data, and classify the plaintext data based on the traffic type; According to the traffic type of the access traffic data, orchestrate the plaintext data to a corresponding security device for security detection; Among them, multiple security devices are set, and the physical network elements of the multiple security devices are communicatively connected to the orchestration device in a bypass deployment manner; Encrypt the plaintext data that passes the security check to obtain ciphertext data, and send the ciphertext data to the corresponding client or server.
2. The automated orchestration method for traffic according to claim 1, wherein The step of orchestrating the plaintext data to a corresponding security device for security detection according to the traffic type of the access traffic data includes: Generate a security device type directory according to the traffic type of the access traffic data; Among them, the directory entries of the security device type directory are the names of the security devices that need to perform security detection on the plaintext data; Orchestrate a security device logical link chain according to the security device type directory; Among them, the protection accuracy of the security device located at the rear node of the logical link chain is higher than that of the security device located at the front node of the logical link chain; According to the order of the logical link chain, sequentially send the plaintext data to the physical network elements of each bypass-deployed security device.
3. The automated orchestration method of the flow according to claim 2, characterized in that, The step of performing type analysis on the plaintext data to confirm the traffic type of the access traffic data and classifying the plaintext data based on the traffic type includes: Perform a first-level analysis on the plaintext data to confirm the flow type of the access traffic data corresponding to the plaintext data; Among them, the flow type includes accessing the second network from the first network or accessing the first network from the second network; Perform a second-level analysis on the plaintext data to confirm the protocol type of the access traffic data corresponding to the plaintext traffic.
4. The automated orchestration method of traffic according to claim 3, characterized in that The first network is an office intranet; the step of generating a security device type directory according to the traffic type of the access traffic data includes: If the flow type of the access traffic data is accessing the second network from the first network, at least include a behavior management device in the security device type directory; If the flow type of the access traffic data is accessing the first network from the second network, do not include a behavior management device in the security device type directory.
5. The automated orchestration method of traffic according to claim 1, characterized in that, Before decrypting the access traffic data to obtain the plaintext data corresponding to the access traffic data if access traffic data is received, it further includes: Real-time monitor the physical interface status of the security device; Perform a health check on the network link layer where the security device is located; Regularly detect the forwarding ability of the security device by means of loopback detection.
6. The automated orchestration method of traffic according to claim 5, characterized in that The step of regularly detecting the forwarding ability of the security device by means of loopback detection includes: Periodically send detection messages to each security device in the security device chain; Determine whether a response message sent from a security device is received within a predetermined time to obtain a first determination result; wherein, the response message is generated based on the detection message; If the first determination result is negative, remove the corresponding security device.
7. The automated orchestration method of traffic according to claim 1, characterized in that Before decrypting the access traffic data to obtain the plaintext data corresponding to the access traffic data if the access traffic data is received, it further includes: Perform handshake negotiation with the client and the server respectively based on the SSL protocol.
8. An arrangement device, characterized in that, The method according to any one of claims 1 to 7 is applied to the orchestration device, the orchestration device is deployed between a first network and a second network, and the orchestration device includes: A decryption module, configured to decrypt the access traffic data to obtain the plaintext data corresponding to the access traffic data if the access traffic data is received; A type analysis module, configured to perform type analysis on the plaintext data to confirm the traffic type of the access traffic data, and classify the plaintext data based on the traffic type; An orchestration module, configured to orchestrate the plaintext data to a corresponding security device for security detection according to the traffic type of the access traffic data; Wherein, multiple types of security devices are provided, and the physical network elements of the multiple security devices are communicatively connected to the orchestration device in a bypass deployment manner; An encryption and sending module, configured to encrypt the plaintext data that passes the security check to obtain ciphertext data, and send the ciphertext data to the corresponding client or server.
9. A computer device, characterized in that, The device includes a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus; The memory is used to store a computer program; The processor, when executing the program stored on the memory, implements the steps of the method for automatically orchestrating traffic according to any one of claims 1-7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, The computer program, when executed by the processor, implements the steps of the method for automatically orchestrating traffic according to any one of claims 1-7.