Automatic security service chain system and method for cloud security resource pool

Through the automated security business chain system of the cloud security resource pool, the business chain is sensed and dynamically adjusted in real time, solving the problem of poor scalability of traditional hardware devices in the cloud computing environment, and achieving efficient and flexible security resource management.

CN120342683APending Publication Date: 2025-07-18BEIJING VENUS INFORMATION SECURITY TECH +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510476985.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-16
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

传统硬件安全设备在云计算环境中扩展性差、管理复杂,无法满足动态安全资源调度需求。

Method used

An automated security business chain system using a cloud security resource pool is used to obtain scheduling requests and security domain changes in real time through the perceptron module. The business chain controller dynamically adjusts the business chain composition and configuration, including micro-business chain model, load balancing, main and backup chain switching and priority algorithms.

Benefits of technology

It improves the utilization rate of security resources, meets the diversified business protection needs of cloud tenants, and reduces the complexity and cost of security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342683A_ABST
    Figure CN120342683A_ABST
Patent Text Reader

Abstract

The invention provides an automatic security service chain system and method for a cloud security resource pool. Relates to the technical field of cloud computing. Wherein the sensor module can capture a direct scheduling request and dynamic changes of the security device and the security domain in real time, and the real-time sensing capability ensures that the system can quickly respond to changes of a cloud environment, so that the utilization rate of security resources is effectively improved. More importantly, based on the real-time data of the sensor module, the service chain controller can dynamically adjust the composition and configuration of the service chain. The dynamic adjustment mechanism not only meets diversified service protection requirements of the tenants on the cloud, but also ensures that the services of the tenants always accord with the safety compliance standard. Through the mode, the system realizes efficient and accurate distribution of security resources, and the complexity and cost of security management are effectively reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cloud computing technology, and particularly to an automated security service chain system and method for a cloud security resource pool. Background Art

[0002] With the rapid development of cloud computing technology, cloud service providers need to provide more flexible and efficient security protection measures for cloud tenants. Due to problems such as its fixity, poor scalability, and high management complexity, traditional hardware security devices have been difficult to meet the dynamic requirements for security resources in the cloud environment. Therefore, the concept of a cloud security resource pool emerged. It virtualizes security devices through virtualization technology to achieve centralized management and dynamic scheduling of security resources.

[0003] In a cloud environment, a security resource pool can provide various security services including firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), web application firewalls (WAF), etc. These services can be virtualized into software instances and then dynamically allocated and adjusted according to the needs of tenants. As the complexity of cloud services increases, traditional static security policies can no longer meet the requirements. Therefore, a new security service chain is needed to achieve refined management and flexible scheduling of security resources, which is urgently needed by those skilled in the art. Summary of the Invention

[0004] In view of the above problems, this application provides an automated security service chain system and method for a cloud security resource pool, including the following:

[0005] In a first aspect, this application provides an automated security service chain system for a cloud security resource pool, which includes:

[0006] A sensor module, configured to obtain direct scheduling requests in real time, sense changes in security devices and security domains, and trigger dynamic updates of the service chain;

[0007] A service chain controller, configured to dynamically adjust the composition and configuration of the service chain according to the sensing results of the sensor module to meet the service protection and security compliance requirements of cloud tenants.

[0008] Optionally, the sensor module includes:

[0009] A direct scheduling sensing unit, configured to obtain direct scheduling requests;

[0010] A security domain change sensing unit, configured to monitor the status or configuration changes of the security domain and analyze its impact on the service chain;

[0011] A security device change sensing unit, configured to monitor the life cycle events and operating status changes of security devices and trigger corresponding service chain adjustment operations.

[0012] Optionally, for the direct scheduling request, the service chain controller dynamically adjusts the composition and configuration of the service chain according to the sensing result of the sensor module, including:

[0013] Through the microservice chain mode, it is allowed to set a subset within the security domain for a single network element node;

[0014] Traffic that conforms to the subset will enter the network element, and traffic that does not conform will continue to the next node of the service chain;

[0015] When there is no separate configuration for the network element, the complete security domain will take effect by default.

[0016] Optionally, for the direct scheduling request, the service chain controller is also used to adopt different processing mechanisms for different types of service chains. The adopting different processing mechanisms for different types of service chains includes:

[0017] For the component high-availability service chain, the service chain controller assigns tasks to the components within the load group. When any component within the load group has an exception, the service chain controller skips the faulty component through the single-point bypass mechanism and schedules the tasks to other normal components;

[0018] For the primary / backup service chain, tasks are preferentially scheduled to the primary chain. When a device in the primary chain fails, the tasks are switched to the backup chain;

[0019] For the component load service chain, tasks are assigned to the components within the load group according to the preset load balancing policy; when any component within the load group has an exception, the entire load group is bypassed and the tasks are re-assigned to other normal components.

[0020] Optionally, for the security domain change and the security device change, the service chain controller dynamically adjusts the composition and configuration of the service chain according to the sensing result of the sensor module, including:

[0021] The service chain controller adopts a dynamic scheduling algorithm and dynamically adjusts the allocation and processing order of service requests in the service chain according to the real-time status information during the operation of the service chain, so as to optimize the overall performance and resource utilization rate of the service chain;

[0022] And the service chain controller adopts a priority algorithm to assign different priorities to different services or service requests in the service chain, and preferentially meets the requirements of high-priority services during the resource allocation and service scheduling process.

[0023] Optionally, the sensing security device includes:

[0024] Perceive the lifecycle events of security devices, including the creation, deletion, and migration of the security devices;

[0025] And perceive the startup status and running status of the security devices.

[0026] Optionally, the changes of the security domain include:

[0027] Perceive the status or configuration change situation of the security domain.

[0028] In a second aspect, the present application provides an automated security service chain method for a cloud security resource pool, and the method includes:

[0029] Obtain a direct scheduling request and perceive the changes of security devices and security domains;

[0030] Dynamically adjust the composition and configuration of the service chain according to the direct scheduling request and the perception result.

[0031] Optionally, the obtaining of the direct scheduling request and perceiving the changes of security devices and security domains includes:

[0032] Obtain a direct scheduling request through the direct scheduling perception unit of the sensor;

[0033] The security domain change perception unit monitors the status or configuration change of the security domain and analyzes its impact on the service chain;

[0034] The security device change perception unit monitors the lifecycle events and running status changes of the security devices and triggers corresponding service chain adjustment operations.

[0035] Optionally, for the direct scheduling request, the dynamically adjusting the composition and configuration of the service chain according to the direct scheduling request and the perception result includes:

[0036] Through the micro service chain mode, it is allowed to set subsets within the security domain for individual network element nodes;

[0037] The traffic that conforms to the subset will enter the network element, and the traffic that does not conform will continue to the next node of the service chain;

[0038] When there is no separate configuration for the network element, the complete security domain will take effect by default.

[0039] Optionally, for the direct scheduling request, different processing mechanisms are adopted for different types of service chains, and the adopting different processing mechanisms for different types of service chains includes:

[0040] For the highly available service chain of components, tasks are assigned to the components within the load group. When any component within the load group encounters an exception, the service chain controller uses a single-point bypass mechanism to skip the faulty component and schedule the tasks to other normal components;

[0041] For the primary / backup service chain, tasks are preferentially scheduled to the primary chain. When a device in the primary chain fails, the tasks are switched to the backup chain;

[0042] For the component load service chain, tasks are assigned to the components within the load group according to the preset load balancing policy; when any component within the load group encounters an exception, the entire load group is bypassed and the tasks are re-assigned to other normal components.

[0043] Optionally, for the security domain change and the security device change, the dynamic adjustment of the composition and configuration of the service chain according to the perception result of the sensor module includes:

[0044] The service chain controller adopts a dynamic scheduling algorithm to dynamically adjust the allocation and processing order of service requests in the service chain according to the real-time status information during the operation of the service chain, so as to optimize the overall performance and resource utilization rate of the service chain;

[0045] And the service chain controller adopts a priority algorithm to assign different priorities to different services or service requests in the service chain, and preferentially meets the requirements of high-priority services during the resource allocation and service scheduling process.

[0046] Optionally, the security device perception includes:

[0047] Perceiving the lifecycle events of the security device, including the creation, deletion, and migration of the security device;

[0048] And perceiving the startup status and running status of the security device.

[0049] Optionally, the change of the security domain includes:

[0050] Perceiving the status or configuration change situation of the security domain.

[0051] In a third aspect, the present application provides a device, which includes a memory and a processor. The memory is used to store instructions or codes, and the processor is used to execute the instructions or codes so that the device executes the automated security service chain method of the cloud security resource pool introduced in any implementation manner of the foregoing second aspect.

[0052] Fourthly, the present application provides a computer-readable storage medium, in which code is stored. When the code runs, the device running the code implements the automated security service chain method of the cloud security resource pool introduced in any implementation manner of the foregoing second aspect.

[0053] The present application provides an automated security service chain system for a cloud security resource pool. The system includes a sensor module, which is used to obtain direct scheduling requests in real time, sense changes in security devices and security domains, and trigger dynamic updates of the service chain, and a service chain controller, which is used to dynamically adjust the composition and configuration of the service chain according to the sensing results of the sensor module to meet the service protection and security compliance requirements of cloud tenants. Among them, the sensor module can capture direct scheduling requests and dynamic changes in security devices and security domains in real time. This real-time sensing ability ensures that the system can quickly respond to changes in the cloud environment, thereby effectively improving the utilization rate of security resources. More importantly, based on the real-time data of the sensor module, the service chain controller can dynamically adjust the composition and configuration of the service chain. This dynamic adjustment mechanism not only meets the diverse service protection needs of cloud tenants, but also ensures that tenant services always comply with security compliance standards. In this way, the system realizes the efficient and precise allocation of security resources, effectively reducing the complexity and cost of security management.

[0054] In summary, through refined management and flexible scheduling mechanisms, the present system significantly improves the operation efficiency of the cloud security resource pool, providing more reliable and efficient security services for cloud tenants. Description of the Drawings

[0055] To more clearly illustrate the technical solutions in the embodiments or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0056] Figure 1 It is a schematic structural diagram of an automated security service chain system for a cloud security resource pool provided by an embodiment of the present application;

[0057] Figure 2 It is a schematic configuration diagram under a micro-service chain mode provided by an embodiment of the present application;

[0058] Figure 3 It is a schematic micro-service chain configuration diagram provided by an embodiment of the present application;

[0059] Figure 4 It is a schematic service chain structure diagram provided by an embodiment of the present application;

[0060] Figure 5 Another schematic diagram of the service chain structure provided by the embodiment of the present application;

[0061] Figure 6 Another schematic diagram of the service chain structure in the embodiment of the present application;

[0062] Figure 7 A schematic flowchart of service chain control provided by the embodiment of the present application;

[0063] Figure 8 A schematic flowchart of perceiving changes in security devices provided by the embodiment of the present application;

[0064] Figure 9 A flowchart of an automated security service chain method for a cloud security resource pool provided by the embodiment of the present application. Detailed implementation manners

[0065] In order to make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0066] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions.

[0067] Figure 1 A schematic diagram of the structure of an automated security service chain system for a cloud security resource pool provided by the embodiment of the present application. As shown in Figure 1 The automated security service chain system 100 for a cloud security resource pool provided by the embodiment of the present application may include:

[0068] A sensor module 110, configured to obtain direct scheduling requests in real time, perceive changes in security devices and security domains, and trigger dynamic updates of the service chain.

[0069] A sensor is a component or technology for real-time monitoring, data collection, and environmental perception. It provides support for the management and decision-making of the cloud security resource pool by collecting and analyzing various information in the cloud environment. In the cloud security resource pool, the sensor is mainly responsible for the following functions:

[0070] Data collection: The sensor can collect various data in the cloud environment in real time, including network traffic, server status, user behavior, configuration information, etc.

[0071] Environmental monitoring: The sensor can monitor the running status of the cloud resource pool, including the usage of hardware resources, the running status of software systems, and security-related metrics (such as intrusion detection, abnormal traffic, etc.).

[0072] Event detection: The sensor can identify potential security events or abnormal behaviors and generate alarms or notifications in a timely manner.

[0073] Information feedback: The sensor feeds back the collected data and analysis results to the cloud security management system, providing a basis for the dynamic management of the resource pool and the adjustment of security policies.

[0074] In this application, the sensor module is used to obtain direct scheduling requests in real time, sense changes in security devices and security domains, and trigger dynamic updates of the service chain. Direct scheduling means that when a direct call request is received, the sensor first performs relevant verification operations, including permission verification, parameter checking, etc., to ensure the legality and effectiveness of the call. After passing the verification, the sensor will directly schedule the service chain capabilities and execute the corresponding business processes. For the control of security domain changes, the sensor continuously monitors the changes in the security domain. Once it detects changes in the status or configuration of the security domain, it will automatically analyze the impact of these changes on the service chain and modify the configuration or execution process of the service chain accordingly to ensure the security and effectiveness of the service chain. The sensing of security device changes includes the change management of the security device life cycle and the status change management of the security device.

[0075] The service chain controller 120 is used to dynamically adjust the composition and configuration of the service chain according to the sensing results of the sensor module to meet the business protection and security compliance requirements of cloud tenants.

[0076] The service chain controller is a tool or device for managing and configuring the service chain. The service chain is a directed processing path composed of multiple service functions (Service Functions, SFs) implemented through the service function chaining (SFC) technology. Packets pass through these functions or services in this order in the network to meet specific business requirements. In this application, the service chain controller is used to dynamically configure and manage the service chain according to business requirements and security policies.

[0077] The above briefly introduced the structure of the automated security service chain system of the cloud security resource pool in this application. Next, the automated security service chain system of the cloud security resource pool in this application will be introduced in more detail in combination with specific embodiments.

[0078] In an implementation manner of the embodiment of the present application, the sensor module includes:

[0079] A direct scheduling sensing unit, configured to obtain a direct scheduling request.

[0080] Although there are multiple security devices in a serial service chain, some security devices only protect some specific traffic, such as web traffic. Based on this scenario, the present application provides a micro service chain for customers to configure, and a subset within the security domain can be set for a single network element node. Specifically, for the direct scheduling request, the service chain controller dynamically adjusts the composition and configuration of the service chain according to the sensing result of the sensor module, including: in the micro service chain mode, allowing a subset within the security domain to be set for a single network element node; traffic that conforms to the subset will enter the network element, and traffic that does not conform will continue to the next node of the service chain; when there is no separate configuration for the network element, the entire security domain will take effect by default. As Figure 2 shown, Figure 2 FIG. is a configuration schematic diagram of a micro service chain mode provided by an embodiment of the present application. This figure shows a traffic decision-making process based on an IP address range, where traffic is directed to different security devices (firewall or WAF) according to whether it conforms to a specific subset (10.0.0.1 / 24). This mechanism allows network administrators to set security policies for specific network elements or load groups, thereby improving the security and flexibility of the network. When creating a micro service chain, the security domain or security device can be edited to set its port or a specific security domain subset. When the service chain is updated, the update button in the service chain list can be clicked to set the security domain or security device, and then submitted to update the service chain. When automatically joining the service chain, the port or a specific security domain subset can be optionally filled in to adapt to the micro service chain. As Figure 3 shown, Figure 3 FIG. is a configuration schematic diagram of a micro service chain provided by an embodiment of the present application, which includes the setting of ports or specific security domain subsets. After the setting is completed, security domains A, B, and C are obtained, so that when automatically joining the service chain, traffic can flow into the corresponding security domain according to the filled port or specific security domain subset.

[0081] In an implementation manner of the embodiment of the present application, for the direct scheduling request, the service chain controller is further configured to adopt different processing mechanisms for different types of service chains. The adopting different processing mechanisms for different types of service chains includes:

[0082] For the component highly available service chain, the service chain controller assigns tasks to the components within the load group. When any component within the load group fails, the service chain controller uses the single-point bypass mechanism to skip the faulty component and schedules the tasks to other normal components. As Figure 4 shown, Figure 4 This is a schematic diagram of a service chain provided by an embodiment of the present application. Here, vrouter is the abbreviation of virtual router, which is usually used in a virtual network environment to implement the routing function of the virtual network. Load group A is a load balancing group that distributes traffic to different components to improve the availability and performance of the system. The figure shows that load group A receives traffic from vrouter and distributes it to component A1 and component A2. Component A1 and component A2 are two components located after load group A and are responsible for processing specific business logics or tasks. Component B is another independent component that is parallel to load group A and does not directly participate in the traffic processing of load group A. The security domain is used to isolate and manage traffic with different security levels in the network. The security domain in the figure is located on the far right, indicating that this is a set of IP addresses dynamically protected by the service function chain. When a load group is cascaded in the service chain, the component high availability (HA) is different from component load. Among the security components within the load group, they are in a highly available relationship. When some security components within the group fail, the load group nodes still work normally, and the service chain has partial single-point bypass. When there is no load group, such as when there is no Figure 4 component in the dashed box in the figure, the service chain in the figure represents a conventional single service chain.

[0083] For the primary and standby service chain, tasks are preferentially scheduled to the primary chain. When a device in the primary chain fails, the tasks are switched to the standby chain. As Figure 5 shown, Figure 5 This is another schematic diagram of a service chain provided by an embodiment of the present application. This service chain has two chains, namely the primary service chain and the standby service chain. The security devices in the primary service chain and the standby service chain are of the same type of security devices. The primary component is connected to the primary service chain, and the standby component is connected to the standby service chain. When the primary component is normal, the traffic passes through the primary service chain; when any component in the primary service chain is abnormal, the traffic is switched to the standby service chain.

[0084] For the component load service chain, tasks are assigned to the components within the load group according to the preset load balancing strategy; when any component within the load group fails, the entire load group is bypassed, and the tasks are re-assigned to other normal components. As Figure 6 shown, Figure 6This is another schematic diagram of the service chain structure in the embodiments of the present application. When a load group is connected in series in the service chain, different from component HA, in the load group, there are security components with a load sharing relationship. When any security component in the group fails, the load group node bypasses, and the service chain part bypasses. It focuses on the load balancing function, that is, the components in the load group can share traffic. When an abnormal component appears in the load group, the entire load group is bypassed. This service chain is suitable for scenarios where multiple components are required to share the load.

[0085] A security domain change perception unit, which is used to monitor the status or configuration changes of the security domain and analyze its impact on the service chain.

[0086] Among them, the changes in the security domain include the status or configuration change situations of the security domain. By continuously monitoring the changes in the security domain through the sensor, once it detects that the status or configuration of the security domain has changed, it will automatically analyze the impact of these changes on the service chain, and correspondingly modify the configuration or execution process of the service chain through the service chain controller to ensure the security and effectiveness of the service chain. The following combines Figure 7 to introduce the specific operation process after perceiving the changes in the security domain. Figure 7 This is a schematic diagram of the process of service chain control provided by the embodiments of the present application.

[0087] S701. Create or update a security domain.

[0088] S702. Determine whether there is a service chain.

[0089] For creating or updating a security domain, first, it is necessary to determine whether there is a service chain in this security domain. If so, execute step S703; if not, execute step S711.

[0090] S703. Determine whether the security domain exists in the service chain.

[0091] If so, execute step S704; if not, execute step S705.

[0092] S704. Update the service chain.

[0093] S705. Determine whether there is a traffic-based security device that has not been added to the service chain.

[0094] If so, execute step S706.

[0095] S706. Determine whether there is a single traffic-based security device.

[0096] If so, execute step S707; if not, execute step S708.

[0097] S707. Automatically create a service chain.

[0098] S708. Determine whether there are multiple flow-based security devices and if there are no duplicates.

[0099] If so, execute step S709; if not, execute step S710.

[0100] S709. Automatically create a service chain.

[0101] S710. Select an existing service chain and update it into the service chain.

[0102] S711. Determine whether there is a flow-based security device.

[0103] If so, execute step S712; if not, execute step S717.

[0104] S712. Determine whether there is a single flow-based security device.

[0105] If so, execute step S713; if not, execute step S714.

[0106] S713. Automatically create a service chain.

[0107] S714. Determine whether there are multiple flow-based security devices and if there are no duplicates.

[0108] If so, execute step S715; if not, execute step S716.

[0109] S715. Automatically create a service chain.

[0110] S716. Do nothing.

[0111] S717. Non-serial security devices are not added to the service chain.

[0112] The security device change perception unit is used to monitor the life cycle events and operating state changes of security devices and trigger corresponding service chain adjustment operations.

[0113] In one implementation manner of the embodiment of the present application, the perceived security device includes: perceiving the life cycle events of the security device, including the creation, deletion, and migration of the security device; and perceiving the startup state and operating state of the security device.

[0114] Lifecycle events for perception security devices include identifying lifecycle events such as the creation, deletion, and migration of security devices, and automatically adjusting the composition and structure of the business chain according to these events. For example, when a certain security device is deleted or migrated, the system may automatically search for and replace a new security device or bypass it to maintain the integrity and functionality of the business chain; when a certain security device is created, the system will automatically find a suitable business chain for the security device to join or create a new business chain, optimize the operation and maintenance operations, and maintain the efficient utilization of security device resources. The specific process is as Figure 8 shown Figure 8 is a schematic flow diagram of perceiving changes in security devices provided by an embodiment of the present application.

[0115] S801. Create a security device.

[0116] S802. Determine whether there is a business chain.

[0117] If yes, execute step S804; if not, execute step S803.

[0118] S803. Apply for a single security device, create a new business chain, and protect all security domains.

[0119] S804. Determine whether all security domains are protected.

[0120] If yes, execute step S805; if not, execute step S808.

[0121] S805. Determine whether to create a traffic-type security device.

[0122] If yes, execute step S806; if not, execute step S807.

[0123] S806. Join the business chain.

[0124] S807. Non-serial security devices do not join the business chain.

[0125] S808. Determine whether to create a traffic-type security device.

[0126] If yes, execute step S809.

[0127] S809. Determine whether to create a new business chain.

[0128] If yes, execute step S810; if not, execute step S811.

[0129] S810. Create a new business chain and protect all remaining security domains.

[0130] S811. Join the business chain.

[0131] For the startup state and running state of the perception security device, specifically, it can monitor the startup state (such as start / stop changes) and running state (such as security device anomalies, etc.) of the security device in real time, and perform corresponding service controls based on these state changes. For example, when a certain security device has an anomaly, the system may automatically restart the security device or trigger the corresponding fault recovery process; trigger the bypass of component ha and the business chain of component load, single-point bypass. Trigger the primary-to-standby switch of the primary and standby business chains. If the standby is activated and there are anomalies in the network elements of the standby chain, then bypass. When the start / stop state of the security device changes, the system may update the scheduling policy or resource allocation plan of the business chain. The following is a specific introduction to the specific implementation process after the system perceives the changes in the security device when the security device or the physical host where it is located is abnormal.

[0132] When the computing node monitors an anomaly, it will trigger a series of processing procedures. First, the system will generate a host alarm to indicate that an anomaly has occurred, and then modify the host state. Then the business chain system will query the security device and modify the state of the security device to abnormal.

[0133] Then the system will check whether there is a suitable computing node for migration. In some cases, the system may choose to bypass the business chain or perform single-point bypass; during the entire process, the operation and maintenance personnel may intervene for manual operations.

[0134] Before migration, verify the node data. If there is a suitable computing node, the system will migrate the security device to that node and modify the state of the security device to being automatically migrated. If there is no suitable computing node for migration, the system will not perform any further operations.

[0135] After the migration is completed, the system will check whether the migration is successful. If the migration fails, the system will prompt that the automatic migration has failed and modify the state of the security device to abnormal. If the migration is successful, the system will automatically power on and prompt that the automatic migration is successful, and modify the state of the security device to powered on. The system monitors the state of the security device. The system will also automatically create a bypass drainage policy to ensure the normal transmission of traffic.

[0136] In an implementation manner of the embodiment of the present application, for the security domain change and the security device change, the business chain controller dynamically adjusts the composition and configuration of the business chain according to the perception results of the perception module, including: the business chain controller adopts a dynamic scheduling algorithm, and according to the real-time state information during the operation of the business chain, dynamically adjusts the allocation and processing order of service requests in the business chain to optimize the overall performance and resource utilization rate of the business chain; and the business chain controller adopts a priority algorithm to assign different priorities to different services or service requests in the business chain, and preferentially meets the needs of high-priority services during the resource allocation and service scheduling process.

[0137] For a dynamic scheduling algorithm, it means dynamically adjusting the allocation and processing order of service requests in the service chain based on the real-time status information during the operation of the service chain, such as the load of each service node, network congestion situation, arrival pattern of service requests, etc. Through real-time monitoring and dynamic decision-making, the overall performance and resource utilization rate of the service chain are optimized. This process includes: 1. Real-time monitoring: Using monitoring tools to collect the operation status data of each service node in the service chain, including the CPU utilization rate of the node, memory occupancy, network bandwidth usage, the number of service requests currently being processed, etc. 2. Status analysis: Evaluating the load status of each service node and the overall performance bottleneck of the system based on the monitoring data. For example, if it is found that the CPU utilization rate of a certain service node exceeds 80% for a long time, it is judged that the node may be overloaded. 3. Scheduling decision: Based on the results of the status analysis, formulating a dynamic scheduling strategy. For example, when a certain service node has a high load, reallocate some service requests to other nodes with lighter loads; or adjust the transmission path of the service request according to the network congestion situation to bypass the congested link. 4. Adjustment execution: Applying the scheduling decision to the service chain and changing the processing method of the service request in real time. This may involve operations such as reconfiguring the parameters of the service node at runtime and changing the routing rules of the service request.

[0138] The priority algorithm assigns different priorities to different services or service requests in the service chain. The priority reflects factors such as the importance and urgency of the service. During the resource allocation and service scheduling process, the needs of high-priority services are preferentially met to ensure the quality and response time of critical services. The implementation process of the priority algorithm is as follows: Determine the priority levels of different services or service requests according to business requirements and the importance of the service. For example, in an enterprise-level service chain, services related to core business are defined as high priority, while some auxiliary services are defined as low priority. When a service request enters the service chain, mark the corresponding priority information for it so that subsequent service nodes and scheduling mechanisms can identify it. In the case of limited resources, resources are preferentially allocated to high-priority services. For example, in network bandwidth allocation, if a high-priority service request needs to transmit data, its bandwidth requirement is preferentially guaranteed; in the processing order of service nodes, high-priority service requests are inserted in front of low-priority service requests for processing. Dynamically adjust the priority of the service according to the actual situation of service operation and changes in the external environment. For example, if the delay of a low-priority service exceeds a certain threshold, its priority may be increased to avoid excessive degradation of service quality; or when the urgency of a high-priority service decreases, its priority is appropriately reduced to balance resource utilization.

[0139] The above are some specific implementation manners of an automated security service chain system for a cloud security resource pool provided by an embodiment of the present application. Based on this, the present application also provides a corresponding method. Figure 9 It is a flowchart of an automated security service chain method for a cloud security resource pool provided by an embodiment of the present application. In combination with Figure 9 As shown, the automated security service chain method for a cloud security resource pool provided by an embodiment of the present application includes:

[0140] S901. Obtain a direct scheduling request and sense changes in security devices and security domains.

[0141] S902. Dynamically adjust the composition and configuration of the service chain according to the direct scheduling request and the sensing result.

[0142] In an implementation manner of an embodiment of the present application, the obtaining a direct scheduling request and sensing changes in security devices and security domains includes:

[0143] Obtain a direct scheduling request through the direct scheduling sensing unit of the sensor;

[0144] The security domain change sensing unit monitors the status or configuration changes of the security domain and analyzes its impact on the service chain;

[0145] The security device change sensing unit monitors the life cycle events and operating status changes of security devices and triggers corresponding service chain adjustment operations.

[0146] In an implementation manner of an embodiment of the present application, for the direct scheduling request, the dynamically adjusting the composition and configuration of the service chain according to the direct scheduling request and the sensing result includes:

[0147] Through the micro service chain mode, it is allowed to set a subset within the security domain for a single network element node;

[0148] The traffic conforming to the subset will enter the network element, and the traffic not conforming will continue to the next node of the service chain;

[0149] When there is no separate configuration for the network element, the complete security domain will take effect by default.

[0150] In an implementation manner of an embodiment of the present application, for the direct scheduling request, different processing mechanisms are adopted for different types of service chains. The adopting different processing mechanisms for different types of service chains includes:

[0151] For the component high-availability service chain, tasks are assigned to the components within the load group. When any component within the load group has an exception, the service chain controller skips the faulty component through the single-point bypass mechanism and schedules the tasks to other normal components;

[0152] For the primary and backup service chains, tasks are preferentially scheduled to the primary chain. When a device in the primary chain fails, the tasks are switched to the backup chain.

[0153] For the component load service chain, tasks are assigned to the components within the load group according to the preset load balancing policy. When any component within the load group experiences an exception, the entire load group is bypassed, and the tasks are re-assigned to other normal components.

[0154] In one implementation of the embodiment of the present application, for the security domain change and the security device change, the dynamic adjustment of the composition and configuration of the service chain according to the perception result of the perception module includes:

[0155] The service chain controller adopts a dynamic scheduling algorithm and dynamically adjusts the allocation and processing order of service requests in the service chain according to the real-time status information during the operation of the service chain, so as to optimize the overall performance and resource utilization rate of the service chain;

[0156] And the service chain controller adopts a priority algorithm to assign different priorities to different services or service requests in the service chain, and preferentially meets the requirements of high-priority services during the resource allocation and service scheduling process.

[0157] In one implementation of the embodiment of the present application, the perceived security device includes:

[0158] Perceiving the life cycle events of the security device, including the creation, deletion, and migration of the security device;

[0159] And perceiving the startup status and running status of the security device.

[0160] In one implementation of the embodiment of the present application, the change of the security domain includes:

[0161] Perceiving the status or configuration change situation of the security domain.

[0162] The embodiment of the present application also provides a corresponding device and a computer storage medium for implementing the solution provided by the embodiment of the present application.

[0163] Among them, the device includes a memory and a processor. The memory is used to store instructions or codes, and the processor is used to execute the instructions or codes so that the device executes the method described in any embodiment of the present application.

[0164] The computer storage medium stores codes. When the codes are run, the device running the codes implements the method described in any embodiment of the present application.

[0165] As can be seen from the description of the above embodiments, those skilled in the art can clearly understand that all or part of the steps in the above embodiment methods can be implemented by means of software plus a general hardware platform. Based on such an understanding, the technical solution of the present application can be embodied in the form of a software product, and the computer software product can be stored in a storage medium, such as a read-only memory (ROM) / RAM, magnetic disk, optical disk, etc., including several instructions for causing a computer device (which can be a personal computer, a server, or a network communication device such as a router) to execute the methods described in various embodiments or some parts of the embodiments of the present application.

[0166] It can be understood that in the specific implementation of the present application, the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved, when the above embodiments of the present application are applied to specific products or technologies, user permission or consent needs to be obtained, and the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards of relevant countries and regions.

[0167] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.

[0168] It should also be noted that the various embodiments in this specification are described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other, and the key point of each embodiment is to illustrate the differences from other embodiments. In particular, for the device and system embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and reference can be made to the relevant parts of the method embodiments for the related content. The device and system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components indicated as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative efforts.

[0169] As described above, this is only a specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed in the present application should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. An automated security service chain system for a cloud security resource pool, characterized in that including: A perceptron module, which is used to obtain direct scheduling requests in real time, perceive changes in security devices and security domains, and trigger dynamic updates of the service chain; A service chain controller, which is used to dynamically adjust the composition and configuration of the service chain according to the perception results of the perceptron module to meet the service protection and security compliance requirements of cloud tenants.

2. The system according to claim 1, wherein The perceptron module includes: A direct scheduling perception unit, which is used to obtain direct scheduling requests; A security domain change perception unit, which is used to monitor the status or configuration changes of the security domain and analyze its impact on the service chain; A security device change perception unit, which is used to monitor the life cycle events and operating status changes of security devices and trigger corresponding service chain adjustment operations.

3. The system according to claim 2, wherein For the direct scheduling request, the service chain controller dynamically adjusts the composition and configuration of the service chain according to the perception results of the perceptron module, including: Through the micro-service chain mode, it is allowed to set subsets within the security domain for individual network element nodes; Traffic that conforms to the subset will enter the network element, and traffic that does not conform will continue to the next node of the service chain; When there is no separate configuration for the network element, the complete security domain will take effect by default.

4. The system according to claim 3, wherein For the direct scheduling request, the service chain controller is also used to adopt different processing mechanisms for different types of service chains. The adoption of different processing mechanisms for different types of service chains includes: For the component high-availability service chain, the service chain controller distributes tasks to components within the load group. When any component within the load group fails, the service chain controller uses the single-point bypass mechanism to skip the faulty component and schedule the tasks to other normal components; For the primary and standby service chain, tasks are preferentially scheduled to the primary chain. When a device in the primary chain fails, the tasks are switched to the standby chain; For the component load service chain, tasks are distributed to components within the load group according to the preset load balancing strategy; when any component within the load group fails, the entire load group is bypassed and the tasks are reallocated to other normal components.

5. The system according to claim 2, wherein For the security domain change and the security device change, the service chain controller dynamically adjusts the composition and configuration of the service chain according to the perception results of the perceptron module, including: The service chain controller adopts a dynamic scheduling algorithm to dynamically adjust the distribution and processing order of service requests in the service chain according to the real-time status information during the operation of the service chain to optimize the overall performance and resource utilization rate of the service chain; And the service chain controller adopts a priority algorithm to assign different priorities to different services or service requests in the service chain and preferentially meet the needs of high-priority services during the resource allocation and service scheduling process.

6. The system according to claim 1, wherein The perceived security devices include: Perceiving the life cycle events of security devices, including the creation, deletion, and migration of the security devices; And perceiving the startup status and operating status of security devices.

7. The system according to claim 1, characterized in that, The changes in the security domain include: Perceiving the status or configuration change situation of the security domain.

8. An automated security service chain method for a cloud security resource pool, characterized in that, The method includes: Obtaining direct scheduling requests, perceiving changes in security devices and security domains; Dynamically adjusting the composition and configuration of the service chain according to the direct scheduling request and perception results.

9. A computing device, characterized in that, The computing device includes: a memory and a processor; The memory is used for storing a computer program; The processor is used for implementing the method as claimed in claim 8 when executing the computer program.

10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and the method as claimed in claim 8 is implemented when the computer program is executed by the processor.