Service chain disaster recovery method and device, equipment and storage medium

By monitoring the security protection instance in the service chain and switching to the backup service chain when it fails, the business interruption problem caused by the security protection instance failure is solved, and the availability and reliability of the service chain are achieved.

CN120378290AInactive Publication Date: 2025-07-25SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510856449.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-25
Publication Date
2025-07-25
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

When the existing network service architecture fails in the security protection instance in the service chain, it causes customer business interruption and affects user usage.

Method used

By monitoring security protection instances in the service chain, alarm data is generated, and when necessary, the main and backup service chain switch is triggered to switch to the backup service chain to ensure continuous security protection of traffic data.

Benefits of technology

It realizes automatic switching when security protection instance failure, ensures the availability and reliability of the service chain, and provides continuous and stable security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378290A_ABST
    Figure CN120378290A_ABST
Patent Text Reader

Abstract

The invention discloses a service chain disaster recovery method, device and equipment and a storage medium, and relates to the field of network security, and the method comprises the steps: when a currently used service chain is a main service chain connected with a first routing port of a router, obtaining monitoring data obtained by monitoring each security protection instance in the currently used service chain; based on each monitoring data, determining whether the corresponding security protection instance has a fault, and generating corresponding alarm data for the security protection instance having the fault; determining whether to trigger a main / standby service chain switching operation based on the alarm data; and if yes, switching the currently used service chain from the main service chain to a standby service chain connected with a second routing port of the router. According to the invention, when the security protection instance in the service chain breaks down, disaster recovery is carried out on the service chain in time, automatic switching of the main service chain and the standby service chain is realized by switching the routing port of the router, and then continuous and stable security protection is provided for flow data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and particularly to a service chain disaster recovery method, device, equipment, and storage medium. Background Art

[0002] With the rapid development of technologies such as cloud computing, big data, and the Internet of Things, network traffic has shown explosive growth, which has put forward higher requirements for the flexibility, scalability, and security of the network. Traditional network service architectures are often fixed and difficult to expand, making it difficult to cope with complex and changing business requirements. As an innovative network technology, the Service Function Chain (SFC) realizes flexible processing and control of network traffic by connecting a series of network service function nodes (such as firewalls, load balancers, intrusion detection systems, etc.), thereby optimizing network performance and improving service quality.

[0003] In the existing network service architecture, the cloud platform can provide users with various services such as computing, storage, and security. Therefore, under the existing business system of customers, a service chain can be constructed through security protection instances such as firewalls and log audits to monitor and supervise the network traffic flowing through the service chain, thereby providing security protection for customer services.

[0004] In a virtualized environment, the importance of High Availability (HA) is self-evident. It is directly related to the stability of the system, the integrity of data, and the continuity of business. However, in the case of a single service chain in the existing service chain, if a security protection instance in the service chain fails, it will directly cause the interruption of customer services, thereby affecting user usage. Summary of the Invention

[0005] In view of this, the purpose of the present invention is to provide a service chain disaster recovery method, device, equipment, and storage medium, which can perform disaster recovery on the service chain in a timely manner when a security protection instance in the service chain fails, and realize automatic switching between the primary and standby service chains by switching the routing ports of the router, thereby providing continuous and stable security protection for traffic data. The specific solutions are as follows:

[0006] In a first aspect, the present application provides a service chain disaster recovery method, including:

[0007] When the currently used service chain is the primary service chain connected to the first routing port of the router, obtain the monitoring data obtained by monitoring each security protection instance in the currently used service chain; wherein, if the router obtains traffic data, the traffic data is sent to the security protection instance via the transit machine in the currently used service chain through the routing port connected to the currently used service chain, so that the security protection instance performs security monitoring on the traffic data;

[0008] Based on each piece of the monitoring data, determine whether the corresponding security protection instance has a fault, and generate corresponding alarm data for the security protection instance with a fault;

[0009] Based on the alarm data, determine whether to trigger the primary and standby service chain switching operation;

[0010] If the primary and standby service chain switching operation is triggered, switch the currently used service chain from the primary service chain to the standby service chain connected to the second routing port of the router, so as to use the standby service chain as the new currently used service chain.

[0011] Optionally, the obtaining the monitoring data obtained by monitoring each security protection instance in the currently used service chain includes:

[0012] Embed monitoring probes into each security protection instance in the currently used service chain to collect the data during the operation of each security protection instance from the inside of each security protection instance, so as to obtain the monitoring data of each security protection instance.

[0013] Optionally, the obtaining the monitoring data obtained by monitoring each security protection instance in the currently used service chain includes:

[0014] Monitor each security protection instance in the currently used service chain through a monitoring agent to intercept the request data and response data of each security protection instance from the outside of each security protection instance, so as to obtain the monitoring data of each security protection instance.

[0015] Optionally, the determining whether the corresponding security protection instance has a fault based on each piece of the monitoring data includes:

[0016] Parse each piece of monitoring data to obtain the running state of the security protection instance corresponding to each piece of monitoring data;

[0017] Based on the running state of the security protection instance corresponding to each piece of monitoring data, determine whether the security protection instance corresponding to each piece of monitoring data has a fault.

[0018] Optionally, determining whether to trigger the primary / backup service chain switching operation based on the alarm data includes:

[0019] Obtaining each piece of the alarm data within a preset time period;

[0020] Merging the alarm data corresponding to the same security protection instance to obtain each piece of merged alarm data;

[0021] Obtaining the current health status of the security protection instance corresponding to each piece of merged alarm data; wherein, the health status includes a fault status and a normal status;

[0022] Performing a consistency comparison between the current health status and the fault status corresponding to each piece of merged alarm data to obtain a consistency comparison result;

[0023] Based on the consistency comparison result, determining whether to filter out each piece of merged alarm data from the pieces of merged alarm data to obtain filtered alarm data;

[0024] Determining whether to trigger the primary / backup service chain switching operation according to whether the filtered alarm data is empty.

[0025] Optionally, the processing process of the traffic data in the currently used service chain includes:

[0026] After the router obtains the traffic data sent by the data source party and sends the traffic data to the transit machine through a routing port connected to the currently used service chain, the transit machine uses a local first bridge to send the traffic data to the security protection instance;

[0027] The security protection instance performs security monitoring on the traffic data, and after the security monitoring passes, returns the traffic data to the transit machine;

[0028] The transit machine uses a local second bridge to send the traffic data returned by the security protection instance to the router, so that the router sends the traffic data to the data recipient.

[0029] Optionally, the router sending the traffic data to the transit machine through a routing port connected to the currently used service chain includes:

[0030] The router determines a corresponding target routing port from the routing ports connected to the currently used service chain based on the network addresses of the data source party and the data recipient;

[0031] The router sends the traffic data to the transit machine through the target routing port;

[0032] Among the routing ports where the router is connected to the currently used service chain, different data source parties and data recipient parties correspond to different routing ports.

[0033] In a second aspect, the present application provides a service chain disaster tolerance device, including:

[0034] A monitoring data acquisition module, configured to acquire monitoring data obtained by monitoring each security protection instance in the currently used service chain when the currently used service chain is the primary service chain connected to the first routing port of the router; wherein, if the router acquires traffic data, the traffic data is sent to the security protection instance via the transit machine in the currently used service chain through the routing port connected to the currently used service chain, so that the security protection instance performs security monitoring on the traffic data;

[0035] An alarm data generation module, configured to determine whether a corresponding security protection instance fails based on each piece of the monitoring data, and generate corresponding alarm data for the security protection instance that fails;

[0036] A switching operation trigger module, configured to determine whether to trigger a primary and standby service chain switching operation based on the alarm data;

[0037] A service chain switching module, configured to, if the primary and standby service chain switching operation is triggered, switch the currently used service chain from the primary service chain to a standby service chain connected to the second routing port of the router, so as to use the standby service chain as the new currently used service chain.

[0038] In a third aspect, the present application provides an electronic device, including:

[0039] A memory, configured to store a computer program;

[0040] A processor, configured to execute the computer program to implement the foregoing service chain disaster tolerance method.

[0041] In a fourth aspect, the present application provides a computer-readable storage medium, configured to store a computer program, and when the computer program is executed by a processor, the foregoing service chain disaster tolerance method is implemented.

[0042] In this application, when the currently used service chain is the primary service chain connected to the first routing port of the router, monitoring data obtained by monitoring each security protection instance in the currently used service chain is acquired; wherein, if the router obtains traffic data, the traffic data is sent via the routing port connected to the currently used service chain to the transit machine in the currently used service chain and then to the security protection instance, so that the security protection instance can perform security monitoring on the traffic data; based on each of the monitoring data, it is determined whether the corresponding security protection instance has failed, and alarm data corresponding to the failed security protection instance is generated; based on the alarm data, it is determined whether to trigger the primary-standby service chain switching operation; if the primary-standby service chain switching operation is triggered, the currently used service chain is switched from the primary service chain to the standby service chain connected to the second routing port of the router, so as to use the standby service chain as the new currently used service chain.

[0043] It can be seen that when the currently used service chain in this application is the primary service chain connected to the first routing port of the router, by monitoring each security protection instance in the currently used service chain, in the event of a failure of the security protection instance, disaster recovery of the service chain can be performed in a timely manner, and the currently used service chain can be switched from the primary service chain to the standby service chain connected to the second routing port of the router. Thus, through the switching of the routing ports of the router, automatic switching of the primary-standby service chain is achieved, ensuring the availability and reliability of the service chain, solving the problem of traffic data interruption due to the failure of the security protection instance, and providing continuous and stable security protection for the traffic data. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.

[0045] Figure 1 It is a flowchart of a service chain disaster recovery method disclosed in an embodiment of the present invention;

[0046] Figure 2 It is a flowchart of the processing of traffic data in a service chain disclosed in an embodiment of the present invention;

[0047] Figure 3 It is a traffic flow diagram of traffic data disclosed in an embodiment of the present invention;

[0048] Figure 4 It is a schematic structural diagram of a service chain disaster recovery device disclosed in an embodiment of the present invention;

[0049] Figure 5 A structural diagram of an electronic device disclosed in an embodiment of the present invention. Specific implementation manners

[0050] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0051] In the case of an existing single-chain service chain, if a security protection instance in the service chain fails, it will directly cause the interruption of the customer's business, thereby affecting the user's use. To this end, the embodiments of the present invention provide a service chain disaster recovery method, which can perform disaster recovery on the service chain in time when a security protection instance in the service chain fails, and realize the automatic switching of the primary and standby service chains by switching the routing ports of the router, so as to provide continuous and stable security protection for traffic data.

[0052] See Figure 1 As shown, the embodiments of the present invention disclose a service chain disaster recovery method, including:

[0053] Step S11, when the currently used service chain is the primary service chain connected to the first routing port of the router, obtain the monitoring data obtained by monitoring each security protection instance in the currently used service chain; wherein, if the router obtains traffic data, the traffic data is sent to the security protection instance via the transit machine in the currently used service chain through the routing port connected to the currently used service chain, so that the security protection instance performs security monitoring on the traffic data.

[0054] In the embodiments of the present invention, when the currently used service chain is the primary service chain connected to the first routing port of the router, the monitoring and alarming module in the preset protection platform monitors each security protection instance in the currently used service chain to obtain the monitoring data of each security protection instance.

[0055] In a specific implementation manner, the monitoring and alarming module in the preset protection platform embeds a monitoring probe into each security protection instance in the currently used service chain to collect the data during the operation of each security protection instance from the inside of each security protection instance, so as to obtain the monitoring data of each security protection instance.

[0056] In another specific embodiment, the monitoring and warning module in the preset protection platform monitors each security protection instance in the currently used service chain through a monitoring agent, so as to intercept the request data and response data of each security protection instance from the outside of each security protection instance, thereby obtaining the monitoring data of each security protection instance.

[0057] It should be noted that if the router obtains the traffic data sent by the data source, the traffic data will be sent to the security protection instance in the currently used service chain through the routing port connected to the currently used service chain via the transit machine in the currently used service chain, so that the security protection instance in the currently used service chain can perform security monitoring on the traffic data to determine whether the traffic data is secure.

[0058] Step S12: Determine whether the corresponding security protection instance fails based on each piece of the monitoring data, and generate corresponding warning data for the security protection instance that fails.

[0059] In the embodiment of the present invention, after obtaining the monitoring data of each security protection instance in the currently used service chain, the monitoring and warning module in the preset protection platform determines whether the corresponding security protection instance fails based on the monitoring data of each security protection instance, and generates corresponding warning data for the security protection instance that fails. Among them, the warning data is mainly used to represent that the security protection instance fails, and may include the instance identifier and failure identifier of the security protection instance, etc.

[0060] For whether the security protection instance in the service chain fails, specifically, it can be determined whether the corresponding security protection instance fails according to the preset failure rule and based on the monitoring data of each security protection instance. It should be noted that the preset failure rule can be flexibly configured and adjusted according to business requirements. For example, the preset failure rule can be set as: when the monitoring data of the security protection instance represents that the security protection instance shuts down or has problems such as network access failure, timeout, non-response, etc., it is determined that the security protection instance fails.

[0061] Specifically, the monitoring and warning module in the preset protection platform parses each piece of monitoring data to obtain the running state of the security protection instance corresponding to each piece of monitoring data; based on the running state of the security protection instance corresponding to each piece of monitoring data, it determines whether the security protection instance corresponding to each piece of monitoring data fails, and generates corresponding warning data for the security protection instance that fails.

[0062] Step S13: Determine whether to trigger the main-backup service chain switching operation based on the warning data.

[0063] In the embodiment of the present invention, the disaster recovery module in the preset protection platform obtains the alarm data sent by the monitoring and alarm module, and determines whether to trigger the primary and standby service chain switching operation based on the alarm data.

[0064] Considering that there may be alarm data of the same security protection instance in the alarm data, and the health status of the security protection instance reflected by the alarm data may be inconsistent with the current health status of the security protection instance, therefore, in the embodiment of the present invention, the alarm data can be filtered first, and then it is determined whether to trigger the primary and standby service chain switching operation based on the filtered alarm data.

[0065] It should be noted that the health status of the security protection instance includes a fault state and a normal state, and the health status of the security protection instance reflected by the alarm data is the fault state.

[0066] Specifically, the disaster recovery module obtains each alarm data within a preset time period, and merges the alarm data corresponding to the same security protection instance to obtain each merged alarm data; obtains the current health status of the security protection instance corresponding to each merged alarm data, and makes a consistency comparison between the current health status and the fault state corresponding to each merged alarm data to obtain a consistency comparison result; based on the consistency comparison result, determines whether to filter out each merged alarm data from the merged alarm data to obtain the filtered alarm data; determines whether to trigger the primary and standby service chain switching operation according to whether the filtered alarm data is empty.

[0067] It can be understood that the disaster recovery module regularly pulls the alarm data from the monitoring and alarm module by using Prometheus (an independent open-source system monitoring and alarm tool), and merges the alarm data corresponding to the same security protection instance to obtain each merged alarm data. For each merged alarm data in the merged alarm data, a consistency comparison is made between the current health status of the security protection instance corresponding to each merged alarm data and the fault state of the security protection instance reflected by each merged alarm data to obtain a consistency comparison result. If the consistency comparison result indicates that the current health status of the security protection instance corresponding to each merged alarm data is inconsistent with the fault state of the security protection instance reflected by each merged alarm data, then each merged alarm data is filtered out from the merged alarm data. If the consistency comparison result indicates that the current health status of the security protection instance corresponding to each merged alarm data is consistent with the fault state of the security protection instance reflected by each merged alarm data, then each merged alarm data is retained in the merged alarm data, and finally the filtered alarm data is obtained. It is determined whether to trigger the primary and standby service chain switching operation according to whether the filtered alarm data is empty; if the filtered alarm data is not empty, the primary and standby service chain switching operation is triggered, and if the filtered alarm data is empty, the primary and standby service chain switching operation is not triggered.

[0068] It should be noted that for the filtered alarm data, the filtered alarm data can be written into the database for query and traceability when needed later.

[0069] Step S14: If the primary-backup service chain switching operation is triggered, switch the currently used service chain from the primary service chain to the backup service chain connected to the second routing port of the router, so as to use the backup service chain as the new currently used service chain.

[0070] In the embodiment of the present invention, if the disaster recovery module in the preset protection platform triggers the primary-backup service chain switching operation, the filtered alarm data is sent to the service chain switching module in the preset protection platform through a message queue (MQ, Message Queue), so that the service chain switching module can switch the currently used service chain from the primary service chain to the backup service chain connected to the second routing port of the router, thereby using the backup service chain as the new currently used service chain, that is, the backup service chain replaces the work of the primary service chain.

[0071] It should be noted that when the currently used service chain is the primary service chain connected to the first routing port of the router, if the router obtains traffic data, the traffic data is sent through the first routing port to the security protection instance in the primary service chain via the transit machine in the primary service chain, so that the security protection instance in the primary service chain can perform security monitoring on the traffic data.

[0072] When switching the currently used service chain from the primary service chain to the backup service chain connected to the second routing port of the router, if the router obtains new traffic data, the new traffic data is sent through the second routing port to the security protection instance in the backup service chain via the transit machine in the backup service chain, so that the security protection instance in the backup service chain can perform security monitoring on the traffic data.

[0073] Among them, the transit machine and the security protection instance in the backup service chain are kept in the same configuration and state as those in the primary service chain, so as to ensure that after the primary-backup service chain is switched, the backup service chain can seamlessly take over the service and take over the work of the primary service chain. Of course, after switching the currently used service chain from the primary service chain to the backup service chain, it is also necessary to monitor the faults of the security protection instances in the backup service chain.

[0074] It should also be noted that when switching the currently used service chain from the primary service chain to the standby service chain, it is also necessary to control the router to clear the routing policy corresponding to the primary service chain and obtain and execute the routing policy corresponding to the standby service chain. Among them, the routing policy indicates how the router obtains traffic data from the data recipient, sends the traffic data to the service chain, and sends the traffic data returned by the service chain to the data recipient, etc.

[0075] It can be seen that when the currently used service chain in the embodiment of the present invention is the primary service chain connected to the first routing port of the router, by monitoring each security protection instance in the currently used service chain, when a security protection instance fails, disaster recovery of the service chain is performed in a timely manner to switch the currently used service chain from the primary service chain to the standby service chain connected to the second routing port of the router. Thus, through the switching of the routing ports of the router, automatic switching of the primary and standby service chains is realized, ensuring the availability and reliability of the service chain, solving the problem of traffic data interruption due to the failure of the security protection instance, and providing continuous and stable security protection for the traffic data.

[0076] See Figure 2 As shown, the embodiment of the present invention discloses a processing process of traffic data in the currently used service chain, including:

[0077] Step S21: After the router obtains the traffic data sent by the data source party and sends the traffic data to the transit machine in the currently used service chain through the routing port connected to the currently used service chain, the transit machine uses the local first bridge to send the traffic data to the security protection instance in the currently used service chain.

[0078] In the embodiment of the present invention, the router obtains the traffic data sent by the data source party through the routing port that establishes a communication connection with the data source party, and sends the traffic data to the transit machine in the currently used service chain through the routing port connected to the currently used service chain. After receiving the traffic data sent by the router, the transit machine uses the local first bridge to send the traffic data to the security protection instance in the currently used service chain.

[0079] Since among the routing ports where the router is connected to the currently used service chain, different data source parties and data recipients correspond to different routing ports, after the router obtains the traffic data sent by the data source party, it is necessary to determine the corresponding target routing port from the routing ports connected to the currently used service chain based on the network addresses of the data source party and the data recipient, and send the traffic data to the transit machine through the target routing port.

[0080] Among them, if the data source is a device in the public network, the data receiver is a device in the internal network, such as a virtual machine. At this time, the target routing port is the A routing port. If the data source is a device in the internal network, the data receiver is a device in the public network. At this time, the target routing port is the B routing port.

[0081] Further, after the router sends the traffic data to the transit device through the target routing port, the transit device receives the traffic data through the first internal port that establishes a communication connection with the target routing port, and uses the local first bridge to send the traffic data through the second internal port to the security protection instance in the currently used service chain. The first internal port and the second internal port are different ports in the transit device.

[0082] Step S22: The security protection instance performs security monitoring on the traffic data, and after the security monitoring passes, returns the traffic data to the transit device.

[0083] In the embodiment of the present invention, after the transit device uses the local first bridge to send the traffic data through the second internal port to the security protection instance, the security protection instance receives the traffic data sent by the transit device through the local first instance port, performs security monitoring on the traffic data, and after the security monitoring passes, returns the traffic data through the local second instance port to the transit device. The first instance port and the second instance port are different ports in the security protection instance.

[0084] Step S23: The transit device uses the local second bridge to send the traffic data returned by the security protection instance to the router, so that the router sends the traffic data to the data receiver.

[0085] In the embodiment of the present invention, the transit device receives the traffic data returned by the security protection instance through the third internal port, and uses the local second bridge to send the traffic data through the third internal port to the router. The router receives the traffic data sent by the transit device through another routing port, and sends the traffic data through the routing port that establishes a communication connection with the data receiver to the data receiver. The another routing port is another port different from the target routing port among the routing ports through which the router is connected to the currently used service chain.

[0086] Further, after the data receiver obtains the traffic data, it responds to the traffic data and generates return packet traffic, and then sends the return packet traffic to the router. The router sends the return packet traffic to the transit device through the routing port connected to the currently used service chain. After receiving the return packet traffic sent by the router, the transit device uses the local first bridge to send the return packet traffic to the security protection instance. The security protection instance performs security monitoring on the return packet traffic sent by the transit device, and after the security monitoring passes, returns the return packet traffic to the transit device. Finally, the transit device uses the local second bridge to send the return packet traffic returned by the security protection instance to the router, so that the router can return the return packet traffic to the data source. It should be noted that the processing process of the data receiver's return packet traffic in the service chain is similar to that of the data source's traffic data in the service chain, and will not be elaborated here.

[0087] It should be noted that when the data source is a device in the public network and the data receiver is a device in the private network, the network address of the data receiver obtained by the router is the FIP address (Floating Internet Protocol Address) after being converted by the external firewall device; moreover, before sending the traffic data to the transit device, the router needs to use the DNAT (Destination Network Address Translation) technology to convert the network address (FIP address) of the data receiver into an internal network address.

[0088] Correspondingly, when the data source is a device in the private network and the data receiver is a device in the public network, after the router obtains the return packet traffic sent by the transit device, it needs to first use the SNAT (Source Network AddressTranslation) technology to convert the network address (internal network address) of the data source into an FIP address, and then return the return packet traffic to the data source. The purpose of doing this is to ensure that the data receiver's return packet traffic and the data source's traffic data are symmetric when reaching the security protection instance, and to avoid the situation where data is discarded due to asymmetry.

[0089] Such as Figure 3As shown below, taking a device in the public network as the data source and a virtual machine in the private network as the data receiver as an example, the router obtains the traffic data sent by the data source, and obtains the network address of the data source and the network address of the data receiver (the network address of the data receiver is the FIP address obtained after converting the public network address (100.122.2.131) of the data receiver), and then uses the DNAT technology to convert the network address (FIP address) of the data receiver into the private network address (192.168.1.172); based on the network address of the data source and the private network address of the data receiver, determine the corresponding target routing port (11.0.12.1) from the routing ports connected to the currently used service chain, and send the traffic data to the transit machine through the target routing port. The transit machine receives the traffic data through the first internal port (11.0.10.253), and uses the local first bridge to send the traffic data to the security protection instance through the second internal port (11.0.10.251). The security protection instance receives the traffic data sent by the transit machine through the local first instance port (11.0.10.7), and performs security monitoring on the traffic data, and after the security monitoring passes, returns the traffic data to the transit machine through the local second instance port (11.0.11.32). The transit machine receives the traffic data returned by the security protection instance through the third internal port (11.0.11.252), and uses the local second bridge to send the traffic data to the router through the third internal port (11.0.11.252). The router receives the traffic data sent by the transit machine through another routing port (11.0.11.1), and sends the traffic data to the data receiver through the routing port (192.168.0.1) that establishes a communication connection with the data receiver.

[0090] It can be seen that through the above-mentioned processing process of traffic data in the service chain in the embodiment of the present invention, the traffic data flows away in the service chain. Through this rigorous and standardized traffic flow direction, the security of the traffic data flowing away in the service chain is guaranteed.

[0091] See Figure 4 As shown below, the embodiment of the present invention discloses a service chain disaster recovery device, including:

[0092] A monitoring data acquisition module 11, configured to acquire monitoring data obtained by monitoring each security protection instance in the currently used service chain when the currently used service chain is the main service chain connected to the first routing port of the router; wherein, if the router obtains traffic data, the traffic data is sent to the security protection instance through the routing port connected to the currently used service chain via the transit machine in the currently used service chain, so that the security protection instance performs security monitoring on the traffic data;

[0093] An alarm data generation module 12 is configured to determine whether a corresponding security protection instance fails based on each piece of the monitoring data, and generate corresponding alarm data for the security protection instance that fails.

[0094] A switching operation trigger module 13 is configured to determine whether to trigger a primary / backup service chain switching operation based on the alarm data.

[0095] A service chain switching module 14 is configured to, if the primary / backup service chain switching operation is triggered, switch the currently used service chain from the primary service chain to a backup service chain connected to a second routing port of the router, so as to use the backup service chain as the new currently used service chain.

[0096] It can be seen that when the currently used service chain in this application is the primary service chain connected to the first routing port of the router, by monitoring each security protection instance in the currently used service chain, when a security protection instance fails, the service chain can be timely disaster-tolerated, so as to switch the currently used service chain from the primary service chain to the backup service chain connected to the second routing port of the router. Thus, through the switching of the routing ports of the router, the automatic switching of the primary / backup service chain is realized, ensuring the availability and reliability of the service chain, solving the problem that traffic data is interrupted due to the failure of the security protection instance, and providing continuous and stable security protection for the traffic data.

[0097] In some specific embodiments, the monitoring data acquisition module 11 includes:

[0098] A first monitoring data acquisition unit is configured to embed a monitoring probe into each security protection instance in the currently used service chain, so as to collect data during the operation of each security protection instance from the inside of each security protection instance, and obtain the monitoring data of each security protection instance.

[0099] In some specific embodiments, the monitoring data acquisition module 11 includes:

[0100] A second monitoring data acquisition unit is configured to monitor each security protection instance in the currently used service chain through a monitoring proxy, so as to intercept request data and response data of each security protection instance from the outside of each security protection instance, and obtain the monitoring data of each security protection instance.

[0101] In some specific embodiments, the alarm data generation module 12 includes:

[0102] An operating state acquisition unit is configured to parse each piece of monitoring data to obtain the operating state of the security protection instance corresponding to each piece of monitoring data.

[0103] A fault determination unit, configured to determine whether a fault has occurred in each security protection instance corresponding to each monitoring data based on the operating state of the security protection instance corresponding to each monitoring data.

[0104] In some specific embodiments, the switching operation trigger module 13 includes:

[0105] An alarm data acquisition unit, configured to acquire each of the alarm data within a preset time period;

[0106] An alarm data merging unit, configured to merge the alarm data corresponding to the same security protection instance to obtain each merged alarm data;

[0107] A health status acquisition unit, configured to acquire the current health status of the security protection instance corresponding to each merged alarm data; wherein, the health status includes a fault state and a normal state;

[0108] A health status comparison unit, configured to perform a consistency comparison between the current health status and the fault state corresponding to each merged alarm data to obtain a consistency comparison result;

[0109] An alarm data filtering unit, configured to determine whether to filter out each merged alarm data from the respective merged alarm data based on the consistency comparison result to obtain filtered alarm data;

[0110] A switching operation trigger unit, configured to determine whether to trigger a primary and standby service chain switching operation according to whether the filtered alarm data is empty.

[0111] In some specific embodiments, the service chain disaster tolerance device includes:

[0112] A first traffic data sending unit, configured to, after the router acquires the traffic data sent by the data source and sends the traffic data to the transit machine through a routing port connected to the currently used service chain, the transit machine uses a local first bridge to send the traffic data to the security protection instance;

[0113] A traffic data security monitoring unit, configured to perform security monitoring on the traffic data by the security protection instance, and after the security monitoring passes, return the traffic data to the transit machine;

[0114] A second traffic data sending unit, configured to the transit machine uses a local second bridge to send the traffic data returned by the security protection instance to the router, so that the router sends the traffic data to the data recipient.

[0115] In some specific embodiments, the first traffic data sending unit includes:

[0116] A destination port determination unit, configured to enable the router to determine a corresponding destination routing port from the routing ports connected to the currently used service chain based on the network addresses of the data source party and the data receiving party, and send the traffic data to the transit machine through the destination routing port; wherein, among the routing ports connected to the currently used service chain by the router, different data source parties and data receiving parties correspond to different routing ports.

[0117] Furthermore, an embodiment of the present application also discloses an electronic device. Figure 5 It is a structural diagram of an electronic device 20 shown according to an exemplary embodiment, and the content in the figure should not be considered as any limitation to the scope of use of the present application.

[0118] Figure 5 It is a schematic structural diagram of an electronic device 20 provided by an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the service chain disaster tolerance method disclosed in any of the foregoing embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0119] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and no specific limitation is imposed on it here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application requirements, and no specific limitation is made here.

[0120] In addition, the memory 22, as a carrier for resource storage, may be a read-only memory, a random access memory, a magnetic disk, or an optical disc, etc., and the resources stored thereon may include an operating system 221, a computer program 222, etc., and the storage method may be temporary storage or permanent storage.

[0121] Among them, the operating system 221 is used to manage and control each hardware device and computer program 222 on the electronic device 20, and it can be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program that can be used to complete the service chain disaster recovery method executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs that can be used to complete other specific tasks.

[0122] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the service chain disaster recovery method disclosed above is implemented. For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be repeated here.

[0123] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts between the various embodiments, reference can be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method part.

[0124] Those skilled in the art can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed in this document can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0125] The steps of the method or algorithm described in combination with the embodiments disclosed in this document can be directly implemented by hardware, a software module executed by a processor, or a combination of both. The software module can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.

[0126] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising said element.

[0127] The technical solutions provided in this application have been introduced in detail above. Specific examples are used in this text to elaborate on the principles and implementation manners of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to this application.

Claims

1. A service chain disaster recovery method, characterized in that, Including: When the currently used service chain is the primary service chain connected to the first routing port of the router, obtaining monitoring data obtained by monitoring each security protection instance in the currently used service chain; wherein, if the router obtains traffic data, the traffic data is sent to the security protection instance via the transit machine in the currently used service chain through the routing port connected to the currently used service chain, so that the security protection instance performs security monitoring on the traffic data. Based on each of the monitoring data, determining whether the corresponding security protection instance has a fault, and generating corresponding alarm data for the security protection instance with a fault. Based on the alarm data, determining whether to trigger a primary and standby service chain switching operation. If the primary and standby service chain switching operation is triggered, switching the currently used service chain from the primary service chain to the standby service chain connected to the second routing port of the router, so as to use the standby service chain as the new currently used service chain.

2. The service chain disaster recovery method according to claim 1, wherein The obtaining of the monitoring data obtained by monitoring each security protection instance in the currently used service chain includes: Embedding a monitoring probe into each security protection instance in the currently used service chain to collect data during the operation of each security protection instance from the inside of each security protection instance, so as to obtain the monitoring data of each security protection instance.

3. The service chain disaster recovery method according to claim 1, wherein The obtaining of the monitoring data obtained by monitoring each security protection instance in the currently used service chain includes: Monitoring each security protection instance in the currently used service chain through a monitoring agent to intercept the request data and response data of each security protection instance from the outside of each security protection instance, so as to obtain the monitoring data of each security protection instance.

4. The service chain disaster recovery method according to claim 1, wherein The determining, based on each of the monitoring data, whether the corresponding security protection instance has a fault includes: Parsing each monitoring data to obtain the running state of the security protection instance corresponding to each monitoring data. Based on the running state of the security protection instance corresponding to each monitoring data, determining whether the security protection instance corresponding to each monitoring data has a fault.

5. The service chain disaster recovery method according to claim 1, characterized in that The determining, based on the alarm data, whether to trigger a primary and standby service chain switching operation includes: Obtaining each of the alarm data within a preset time period. Merging the alarm data corresponding to the same security protection instance to obtain each merged alarm data. Obtaining the current health state of the security protection instance corresponding to each merged alarm data; wherein, the health state includes a fault state and a normal state. Performing a consistency comparison between the current health state and the fault state corresponding to each merged alarm data to obtain a consistency comparison result. Based on the consistency comparison result, determining whether to filter out each merged alarm data from the each merged alarm data to obtain filtered alarm data. According to whether the filtered alarm data is empty, determining whether to trigger a primary and standby service chain switching operation.

6. The service chain disaster recovery method according to any one of claims 1 to 5, characterized in that The processing process of the traffic data in the currently used service chain includes: After the router obtains the traffic data sent by the data source and sends the traffic data to the transit machine through the routing port connected to the currently used service chain, the transit machine uses the local first bridge to send the traffic data to the security protection instance; The security protection instance performs security monitoring on the traffic data, and after the security monitoring passes, returns the traffic data to the transit machine; The transit machine uses the local second bridge to send the traffic data returned by the security protection instance to the router, so that the router can send the traffic data to the data recipient.

7. The service chain disaster recovery method according to claim 6, wherein The router sends the traffic data to the transit machine through the routing port connected to the currently used service chain, including: The router determines the corresponding target routing port from the routing ports connected to the currently used service chain based on the network addresses of the data source and the data recipient; The router sends the traffic data to the transit machine through the target routing port; Among them, among the routing ports connected to the currently used service chain of the router, different data sources and data recipients correspond to different routing ports.

8. A service chain disaster recovery device, characterized in that, Including: A monitoring data acquisition module, configured to acquire monitoring data obtained by monitoring each security protection instance in the currently used service chain when the currently used service chain is the main service chain connected to the first routing port of the router; wherein, if the router obtains traffic data, it will send the traffic data to the security protection instance through the routing port connected to the currently used service chain via the transit machine in the currently used service chain, so that the security protection instance can perform security monitoring on the traffic data; An alarm data generation module, configured to determine whether a corresponding security protection instance fails based on each piece of monitoring data, and generate corresponding alarm data for the failed security protection instance; A switching operation trigger module, configured to determine whether to trigger a primary and standby service chain switching operation based on the alarm data; A service chain switching module, configured to, if a primary and standby service chain switching operation is triggered, switch the currently used service chain from the main service chain to the standby service chain connected to the second routing port of the router, so as to use the standby service chain as the new currently used service chain.

9. An electronic device, characterized in that, Including: A memory, configured to store a computer program; A processor, configured to execute the computer program to implement the service chain disaster recovery method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, For storing a computer program, the computer program, when executed by a processor, implements the service chain disaster recovery method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Service chain generation method and device, electronic equipment and storage medium

    CN112838986A

  • Main-standby switching method, system and equipment of network and storage medium

    CN113542932A