Security product deployment method and device
By creating target instances in the security management platform and updating the logo using the security product adapter, the problem of frequently modifying page code in the existing technology is solved, and no-code updates are achieved, improving flexibility and reducing costs.
Patent Information
- Application Number
- CN202510315616.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-07-18
AI Technical Summary
In the prior art, the update of the logo of the security management platform and security products requires frequent modification of the page code and release of new versions, resulting in poor flexibility and high development and deployment costs.
Obtain the virtual machine information of the target security product through the security management platform, create the target instance, and push the logo to the virtual machine update through the security product adapter to realize the codeless update of the logo.
Logo updates can be achieved without modifying the page code, which improves flexibility and reduces development and deployment costs.
Smart Images

Figure CN120337204A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a method and apparatus for deploying security products. Background Art
[0002] The security management platform supports the management of various security products, and the security management platform and security products are generally sold to customers as a whole. Some customers, such as large customers like operators, have customized requirements for the brand icons of the security management platform and security products. For example, when the security products leave the factory, the logo of the security products is the brand icon of the manufacturer, and the customer requests that the logo displayed when the security products are deployed is the customer's own brand icon. How to efficiently modify the logo of the security management platform and security products according to customer requirements is a key research goal in this field. Summary of the Invention
[0003] To overcome the problems in the related art, this application provides a method and apparatus for deploying security products.
[0004] According to the first aspect of the embodiments of this application, a method for deploying security products is provided. The method is applied to a security management platform, and the method includes:
[0005] Obtain virtual machine information of a target security product, and create a target instance according to the virtual machine information, where the target security product is any security product managed by the security management platform;
[0006] Create a target security service, and associate the target security service with the target instance;
[0007] Obtain a first Logo, and push the first Logo to the virtual machine of the target security product corresponding to the target instance to update the Logo of the target security service.
[0008] According to the second aspect of the embodiments of this application, a device for deploying security products is provided. The device includes:
[0009] An instance module, configured to obtain virtual machine information of a target security product, and create a target instance according to the virtual machine information, where the target security product is any security product managed by the security management platform;
[0010] An association module, configured to create a target security service, and associate the target security service with the target instance;
[0011] A first update module, configured to obtain a first Logo, and push the first Logo to the virtual machine of the target security product corresponding to the target instance to update the Logo of the target security service.
[0012] According to a third aspect of the embodiments of the present application, there is provided an electronic device, including:
[0013] a memory and one or more processors; the memory is coupled to the processors; wherein, computer program code is stored in the memory, the computer program code includes computer instructions, and when the computer instructions are executed by the processors, the electronic device executes the method as described above.
[0014] According to a fourth aspect of the embodiments of the present application, there is provided a computer-readable storage medium, including computer instructions, and when the computer instructions run on an electronic device, the electronic device is caused to execute the method as described above.
[0015] According to a fifth aspect of the embodiments of the present application, there is provided a computer program product, and when the computer program product runs on a computer, the computer is caused to execute the method as described above.
[0016] The technical solutions provided by the embodiments of the present application may include the following beneficial effects:
[0017] For the security product deployment method of the embodiments of the present application, a security management platform is used as the brand data entry point, and brand data is pushed during the security service activation process to complete the update of brand information such as Logos. There is no need to perform coding development for the different brand display requirements of different customers, and the same set of security management platform and security product versions can be used by different customers, greatly increasing the flexibility and saving the development and deployment costs.
[0018] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The drawings here are incorporated into the specification and form a part of the present application, showing the embodiments that conform to the present application and, together with the specification, are used to explain the principles of the present application.
[0020] Figure 1 It is a schematic flowchart of the security product deployment method provided by the embodiments of the present application;
[0021] Figure 2 It is a schematic diagram of the implementation process of the security product deployment method provided by the embodiments of the present application;
[0022] Figure 3 It is a schematic structural diagram of the security product deployment device provided by the embodiments of the present application;
[0023] Figure 4 It is a schematic structural diagram of the electronic device provided by the embodiments of the present application. DETAILED DESCRIPTION
[0024] The following describes the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Among them, in the description of the embodiments of the present application, the terms used in the following embodiments are only for the purpose of describing specific embodiments, and are not intended to limit the present application.
[0025] It should be noted that "at least one" in the present application means one or more, and "a plurality" means two or more than two. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. The terms "first", "second", "third", etc. (if any) in the description, claims and drawings of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence.
[0026] In the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly, using words such as "exemplary" or "for example" is intended to present relevant concepts in a specific way.
[0027] To ensure that the brand icons of customers are displayed when the security management platform and security products are deployed, the traditional implementation solution is as follows: (1) According to the customer's logo, modify the page code of the security management platform, and the security management platform releases a specified version according to the modified page code; (2) According to the customer's logo, modify the page code of each security product, and the security management platform releases a specified version according to the modified page code.
[0028] The above implementation solution has the following problems: For each customer who requests to modify the logo, the page code needs to be modified once and a new version needs to be released. The flexibility is poor, and the operations of frequently modifying the page code and releasing new versions increase the development and deployment costs.
[0029] To solve the above problems, the present application provides a security product deployment method and device.
[0030] Next, the embodiments of the present application will be described in detail.
[0031] The embodiments of the present application provide a security product deployment method, which is applied to a security management platform, as Figure 1 shown, and the method may include the following steps:
[0032] Step 110: Obtain the virtual machine information of the target security product and create a target instance according to the virtual machine information;
[0033] Step 120: Create a target security service and associate the target security service with the target instance;
[0034] Step 130: Obtain the first Logo and push the first Logo to the virtual machine of the target security product corresponding to the target instance to update the Logo of the target security service.
[0035] The security management platform refers to a platform for uniformly managing various security products. Among them, the target security product is any security product managed by the security management platform, such as a bastion host, a Web Application Firewall (WAF), and endpoint security.
[0036] During the deployment process of the target security product, the virtual machine information of the target security product (such as IP address, management account, management password, etc.) is entered into the security management platform to obtain a target instance. Then, a target security service is created, and the target security service and the target instance are associated according to the virtual machine information. Then, the first Logo is obtained, and the first Logo is pushed to the virtual machine of the target security product corresponding to the target instance to update the Logo of the target security service. In this way, this embodiment can achieve the purpose of modifying the Logo of the security product without modifying the page code and without republishing a new version of the security product.
[0037] As a specific implementation method, the Logo of each security product can be modified through a security product adapter. For example, in this embodiment, the Logo of the target security service can be updated in the following way: Call the brand update interface of the security product adapter to enable the security product adapter to update the Logo of the target security service according to the first Logo. Specifically, the security product adapter pushes the first Logo to the virtual machine by calling the interface of the virtual machine of the target security product, and the virtual machine takes the received first Logo into effect in real time, thereby achieving the update of the Logo of the target security service. Among them, the passing parameters of the brand update interface include the first Logo, as well as the IP address, management account, and management password of the target instance.
[0038] The execution method of the above step 130 can be automatically executed at a preset time node. For example, the first Logo is stored in a specified directory. After the target security service is associated with the target instance, the system automatically reads the first Logo from the specified directory and pushes the first Logo to the virtual machine of the target security product corresponding to the target instance to update the Logo of the target security service.
[0039] The execution manner of step 130 described above can also be to execute after detecting a preset event. For example, when detecting a brand information update request, obtain the first Logo according to the Logo information carried in the brand information update request.
[0040] This embodiment does not limit the execution manner of step 130, and it can be specifically set or adjusted according to actual requirements.
[0041] In addition to being able to modify and update the Logo of the target security product, as a preferred embodiment, this embodiment can also modify and update the Logo of the security management platform itself. Specifically, obtain the second Logo and save it to the target static resource directory, and the browser will automatically load the new image resource and update the page, so as to update the Logo of the security management platform.
[0042] It can be understood that in the scenario of deploying the security management platform and various security products for the same customer, the above first Logo and second Logo can be the same Logo.
[0043] In addition to the Logo, this embodiment also supports flexible updating of other page elements of the target security product, such as page icons and background images. Specifically, obtain the first page icon and / or the first background image, and push the first page icon and / or the first background image to the virtual machine of the target security product corresponding to the target instance to update the page icon and / or background image of the target security service.
[0044] Correspondingly, this embodiment also supports flexible updating of other page elements of the security management platform, such as page icons and background images. Specifically, obtain the second page icon and / or the second background image and save it to the target static resource directory to update the page icon and / or background image of the security management platform.
[0045] Next, take an actual application as an example to describe the security product deployment method of this application in detail. As Figure 2 shown, in this embodiment, the security management platform internally has a Logo management module, a service management module, and an instance management module; the security products include a bastion host and a WAF; the service management module can modify any security product through a security product adapter.
[0046] Based on Figure 2 the system architecture, the deployment process of the security product is as follows:
[0047] (1) Upload the brand data of the target customer, such as Logo, page icons, background images, etc., to the Logo management module of the security management platform;
[0048] (2) The security management platform saves the received brand data in the static resource directory of the security management platform front end, and the browser automatically refreshes and loads the new brand data;
[0049] (3) Enter the IP address, management account, and management password of the security product bastion host into the instance management module of the security management platform and name it instance 1;
[0050] (4) Create a bastion host service from the service management module and name it service 1;
[0051] (5) The service management module queries the instance management module and finds that instance 1 is available, and associates instance 1 with service 1;
[0052] (6) The service management module obtains brand data from the logo management module;
[0053] (7) The service management module calls the brand update interface of the security product adapter and passes the IP address, management account, management password, logo image, page icon, and background image of parameter instance 1;
[0054] (8) The security product adapter uses the IP address of instance 1 to assemble the URL for obtaining the token, named URL1, and uses URL1 and the parameters management account and management password to assemble the first HTTP request to obtain the token;
[0055] (9) The security product adapter uses the IP address of Instance 1 to assemble the URL for setting the brand information, named URL2, and uses URL2 and parameters such as the logo image, page icon, and background image to assemble the second HTTP request. At the same time, the token is placed in the request header of the second HTTP request to initiate the HTTP request;
[0056] (10) The bastion host virtual machine corresponding to instance 1 receives the brand data and takes effect in real time. The user can load the new logo image the next time he opens the security service.
[0057] It can be seen from the above technical solutions that the security product deployment method of this application uses the security management platform as the brand data entry, each security product receives brand data, pushes brand data during the security service activation process, and completes the update of brand information such as Logo. There is no need to develop coding for different brand display requirements of different customers. Different customers can use the same set of security management platform and security product versions, which greatly increases flexibility.
[0058] Based on the same inventive concept, the present application also provides a security product deployment device, the structural diagram of which is shown in FIG. Figure 3 As shown, specifically including:
[0059] An instance module 310 is used to obtain virtual machine information of a target security product and create a target instance according to the virtual machine information, where the target security product is any security product managed by the security management platform;
[0060] An association module 320 is used to create a target security service and associate the target security service with the target instance;
[0061] A first update module 330 is used to obtain a first Logo and push the first Logo to the virtual machine of the target security product corresponding to the target instance to update the Logo of the target security service.
[0062] As a specific implementation manner, the device further includes:
[0063] A second update module is used to obtain a second Logo and save it to a target static resource directory to update the Logo of the security management platform.
[0064] As a specific implementation manner, the device further includes:
[0065] A page element update module is used to obtain a first page icon and / or a first background image and push the first page icon and / or the first background image to the virtual machine of the target security product corresponding to the target instance to update the page icon and / or the background image of the target security service.
[0066] As a specific implementation manner, the first update module 330 updates the Logo of the target security service in the following specific way:
[0067] Call the brand update interface of the security product adapter to enable the security product adapter to update the Logo of the target security service according to the first Logo, where the transmission parameters of the brand update interface include the first Logo, and also include the IP address, management account, and management password of the target instance.
[0068] As a specific implementation manner, the first update module 330 obtains the first Logo in the following specific way:
[0069] When receiving a brand information update request, obtain the first Logo according to the Logo information carried in the brand information update request.
[0070] An embodiment of the present application provides an electronic device, which may include: a memory and one or more processors. The memory is used to store computer program code, and the computer program code includes computer instructions. When the processor executes the computer instructions, the electronic device can execute each function or step of the above method embodiment.
[0071] The structure of the electronic device can be referred to Figure 4 the structure of the electronic device 100 shown in the figure.
[0072] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0073] This application embodiment also provides a computer-readable storage medium, which includes computer instructions. When the computer instructions run on the electronic device, the electronic device is enabled to execute each function or step of the above method embodiment.
[0074] The above-mentioned computer-readable storage medium includes, but is not limited to, any of the following: USB flash drive, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disc, etc., various media that can store program codes.
[0075] This application embodiment also provides a computer program product. When the computer program product runs on a computer, the computer is enabled to execute each function or step of the above method embodiment.
[0076] Among them, the electronic device, computer-readable storage medium, and computer program product provided by this application embodiment are all used to execute the corresponding method provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method provided above, and will not be elaborated here.
[0077] Through the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and simplicity of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.
[0078] In several embodiments provided in the present application, it should be understood that the disclosed method can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division, and there may be other division methods in actual implementation; for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the modules or units can be in electrical, mechanical or other forms.
[0079] In addition, each functional unit in various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0080] As described above, only the specific implementation manners of the present application are provided, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method for deploying a security product, characterized in that, The method is applied to a security management platform, and the method includes: Obtain the virtual machine information of a target security product, and create a target instance according to the virtual machine information, where the target security product is any security product managed by the security management platform; Create a target security service, and associate the target security service with the target instance; Obtain a first Logo, and push the first Logo to the virtual machine of the target security product corresponding to the target instance to update the Logo of the target security service.
2. The method according to claim 1, wherein The method further includes: Obtain a second Logo and save it to the target static resource directory to update the Logo of the security management platform.
3. The method according to claim 1, characterized in that, The method further includes: Obtain a first page icon and / or a first background image, and push the first page icon and / or the first background image to the virtual machine of the target security product corresponding to the target instance to update the page icon and / or the background image of the target security service.
4. The method according to claim 1, characterized in that, The method specifically updates the Logo of the target security service in the following manner: Call the brand update interface of the security product adapter, so that the security product adapter updates the Logo of the target security service according to the first Logo, where the transfer parameters of the brand update interface include the first Logo, and also include the IP address, management account, and management password of the target instance.
5. The method according to claim 1, wherein The method specifically obtains the first Logo in the following manner: When receiving a brand information update request, obtain the first Logo according to the Logo information carried in the brand information update request.
6. A security product deployment device, characterized in that, The device includes: An instance module, configured to obtain the virtual machine information of a target security product, and create a target instance according to the virtual machine information, where the target security product is any security product managed by the security management platform; An association module, configured to create a target security service, and associate the target security service with the target instance; A first update module, configured to obtain a first Logo, and push the first Logo to the virtual machine of the target security product corresponding to the target instance to update the Logo of the target security service.
7. The device according to claim 6, characterized in that, The device further includes: A second update module, configured to obtain a second Logo and save it to the target static resource directory to update the Logo of the security management platform.
8. The device according to claim 6, wherein, The device further includes: A page element update module, configured to obtain a first page icon and / or a first background image, and push the first page icon and / or the first background image to the virtual machine of the target security product corresponding to the target instance to update the page icon and / or the background image of the target security service.
9. An electronic device, characterized in that, Includes: A memory, one or more processors; the memory is coupled to the processor; wherein, computer program code is stored in the memory, and the computer program code includes computer instructions, and when the computer instructions are executed by the processor, the electronic device executes the method according to any one of claims 1-5.
10. A computer-readable storage medium, comprising computer instructions, characterized in that, When the computer instructions run on an electronic device, the electronic device is caused to execute the method according to any one of claims 1-5.
11. A computer program product, characterized in that, When the computer program product runs on a computer, the computer is caused to execute the method according to any one of claims 1-5.