Equipment security topology awareness and disaster recovery method based on SDWAN network
By deploying sensor sets in the SDWAN network to detect sensor parameters, calculate risk assessment values and deviations, determine disaster recovery parameters, and selecting appropriate network nodes for data backup, the problem of insufficient disaster recovery intelligence in SDWAN network is solved, and efficient and secure data backup is achieved.
Patent Information
- Application Number
- CN202510799068.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-16
- Publication Date
- 2025-08-08
AI Technical Summary
The existing software-defined wide area network (SDWAN) lacks intelligence in disaster recovery, making it difficult to effectively improve disaster recovery efficiency and intelligence.
By deploying sensor sets in the SDWAN network to detect sensor parameters, calculate risk assessment values and deviations, determine the parameters to be recovered, such as the maximum data memory size and effective disaster recovery time, select network nodes with risk assessment values below the threshold for data backup, and use communication links for parallel disaster recovery.
Improve the disaster recovery intelligence and efficiency of the SDWAN network, ensuring that important data can be backed up efficiently and securely in emergencies.
Smart Images

Figure CN120455286A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology or communication technology, and specifically to a device security topology perception and disaster recovery method based on an SDWAN network. Background Art
[0002] Software-defined networking in a wide area network (SDWAN) is a technology that applies software-defined networking (SDN) technology to manage wide area networks (WAN).
[0003] At present, software-defined wide area networks are not intelligent enough in terms of disaster recovery. Therefore, the problem of how to improve the disaster recovery intelligence of SDWAN networks needs to be solved urgently. Summary of the Invention
[0004] The embodiments of the present application provide a device security topology perception and disaster recovery method based on the SDWAN network, which can improve the disaster recovery intelligence for the SDWAN network.
[0005] The present invention provides a device security topology perception and disaster recovery method based on an SDWAN network, which is applied to a device security topology perception and disaster recovery system based on an SDWAN network. The system includes n network nodes, where n is an integer greater than 1. The method includes:
[0006] Detecting corresponding sensor parameters of a first network node through a sensor set of the first network node, obtaining first sensor parameters; the first network node is any one of the n network nodes;
[0007] determining a risk assessment value of the first network node according to the first sensor parameter to obtain a first risk assessment value;
[0008] When the first risk assessment value is greater than a preset threshold, determining a first degree of deviation according to the first risk assessment value and the preset threshold;
[0009] Determine the disaster recovery parameters according to the first deviation, wherein the disaster recovery parameters include: maximum data memory size and effective disaster recovery time;
[0010] Determine target disaster recovery data according to the disaster recovery parameters;
[0011] Determining m network nodes other than the first network node among the n network nodes, wherein a risk assessment value of each of the m network nodes is not greater than the preset threshold, where m is a positive integer less than or equal to n-1;
[0012] Determining a communication link between the first network node and the m network nodes to obtain m communication links;
[0013] The target data to be restored is restored to the m network nodes via the m communication links.
[0014] The implementation of the embodiments of this application has the following beneficial effects:
[0015] It can be seen that the device security topology perception and disaster recovery method based on the SDWAN network described in the embodiment of the present application is applied to the device security topology perception and disaster recovery system based on the SDWAN network, which includes n network nodes, where n is an integer greater than 1, and the corresponding sensor parameters of the first network node are detected by the sensor set of the first network node to obtain the first sensor parameters; the first network node is any network node among the n network nodes, and the risk assessment value of the first network node is determined according to the first sensor parameter to obtain the first risk assessment value. When the first risk assessment value is greater than the preset threshold, the first deviation is determined according to the first risk assessment value and the preset threshold, and the parameters to be disaster recovered are determined according to the first deviation. The parameters to be disaster recovered include: maximum data memory size Short and effective disaster recovery time, target data to be recovered is determined according to the disaster recovery parameters, m network nodes other than the first network node among the n network nodes are determined, and the risk assessment value of each network node among the m network nodes is not greater than the preset threshold, m is a positive integer less than or equal to n-1, and the communication link between the first network node and the m network nodes is determined to obtain m communication links, and the target data to be recovered is recovered to the m network nodes through the m communication links. When the disaster recovery conditions are met, the first deviation reflects the urgency of disaster recovery, and the target data to be recovered is dynamically determined based on the disaster recovery urgency. Disaster recovery can be performed in parallel based on the m communication links to improve disaster recovery efficiency and disaster recovery intelligence. In this way, the disaster recovery intelligence can be improved for the SDWAN network. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0017] Figure 1This is a flow chart of a device security topology perception and disaster recovery method based on an SDWAN network provided in an embodiment of the present application;
[0018] Figure 2 This is a structural diagram of a device security topology perception and disaster recovery system based on an SDWAN network provided in an embodiment of the present application;
[0019] Figure 3 This is a schematic diagram illustrating a scenario of a first network node provided in an embodiment of the present application;
[0020] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application;
[0021] Figure 5 This is a block diagram of the functional units of a device security topology perception and disaster recovery device based on the SDWAN network provided in an embodiment of the present application. DETAILED DESCRIPTION
[0022] The terms "first," "second," and the like in the specification and claims of this application and the accompanying drawings are used to distinguish between different objects, not to describe a particular order. Furthermore, the terms "including," "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or elements is not limited to the listed steps or elements, but may also include steps or elements not listed, or may include other steps or elements inherent to the process, method, product, or apparatus.
[0023] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0024] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0025] In the embodiments of the present application, the electronic device may include any electronic device with a specific communication function, which may include but is not limited to: an intelligent robot, a smart phone, a server, a router, a gateway, a smart switch, a tablet computer, a wearable device, a smart car, a smart watch, a smart bracelet, smart glasses, an in-vehicle device, a computing device or other processing device connected to a wireless modem, as well as various forms of user equipment (UE), mobile station (MS), terminal device, etc., without limitation herein. The network node may also include the above-mentioned electronic devices.
[0026] See also Figure 1 , Figure 1 This is a flow chart of a device security topology perception and disaster recovery method based on an SDWAN network provided by an embodiment of the present application. As shown in the figure, it is applied to a device security topology perception and disaster recovery system based on an SDWAN network. The system includes n network nodes, where n is an integer greater than 1. The device security topology perception and disaster recovery method based on the SDWAN network includes:
[0027] 101. Detect corresponding sensor parameters of a first network node through a sensor set of the first network node to obtain first sensor parameters; the first network node is any one of the n network nodes.
[0028] Among them, such as Figure 2 As shown, the device security topology perception and disaster recovery system based on the SDWAN network includes n network nodes, where n is an integer greater than 1. The n network nodes constitute the device security topology perception and disaster recovery system based on the SDWAN network based on the SDWAN related protocols.
[0029] In the embodiment of the present application, each network node of the device security topology perception and disaster recovery system based on the SDWAN network can realize the following functions: real-time traffic monitoring, multi-link status monitoring, centralized management platform analysis and device status detection, etc., which are not limited here.
[0030] For example, in terms of real-time traffic monitoring, each network node in the SDWAN network-based device security topology awareness and disaster recovery system can intelligently route traffic based on network performance and application requirements. It can monitor network traffic in real time and analyze information such as traffic source, destination, and bandwidth usage. Through real-time traffic monitoring, abnormal traffic patterns can be discovered in a timely manner, such as sudden large-scale data transmissions and abnormal access sources, thereby determining whether there are security threats or abnormal changes in network topology.
[0031] To illustrate this with multi-link status monitoring, each network node in the SDWAN network-based device security topology awareness and disaster recovery system supports multi-link redundancy and intelligent link load balancing, leveraging multiple network connections simultaneously. By monitoring the status of each link, including metrics such as link availability, bandwidth utilization, and latency, topology changes at the link level can be detected. For example, a sudden increase in latency or excessive bandwidth utilization on a link may indicate a link problem, requiring further investigation and resolution.
[0032] To illustrate this, in terms of centralized management platform analysis, each network node in the SDWAN network-based device security topology awareness and disaster recovery system provides a centralized network management platform. Administrators can use this platform to uniformly manage and monitor the distributed network. This centralized network management platform can collect status information for each device and link, perform data analysis, and visualize it. Through in-depth analysis of this data, it is possible to discover the connection relationships between devices and the changing trends of the topology structure, thereby achieving a comprehensive understanding of the device security topology.
[0033] For example, in the area of device status monitoring, each network node in the SDWAN network-based device security topology awareness and disaster recovery system can monitor the device's status, including its operating status, hardware health, and software version. Device failures or anomalies can impact the security and stability of the network topology. Regular device status monitoring can identify potential issues and enable appropriate remediation measures.
[0034] The first network node is any one of the n network nodes. One or more sensors, i.e., a sensor set, may be set at the location or area where the first network node is located. The sensors may include at least one of the following: temperature sensor, humidity sensor, pressure sensor, smoke sensor, dust sensor, magnetic field detection sensor, etc., which are not limited here. Figure 3 As shown, the first network node may include at least one sensor.
[0035] In a specific implementation, the corresponding sensor parameters can be detected by the sensor set of the first network node to obtain the first sensor parameters, that is, the first sensor parameters can be used to detect the security of the device.
[0036] 102. Determine a risk assessment value of the first network node according to the first sensor parameter to obtain a first risk assessment value.
[0037] In a specific implementation, a mapping relationship between preset sensor parameters and risk assessment values can be pre-stored. Based on this mapping relationship, the risk assessment value of the first network node corresponding to the first sensor parameter can be determined to obtain a first risk assessment value. A larger risk assessment value indicates a higher risk and a greater need for disaster preparedness.
[0038] In a specific implementation, when the first network node has a single sensor, the risk assessment value of the first network node corresponding to the first sensor parameter is directly determined based on the mapping relationship to obtain the first risk assessment value. Accordingly, when the first network node has multiple sensors, the risk assessment value of the first network node corresponding to the first sensor parameter is directly determined based on the mapping relationship to obtain multiple risk assessment values, and a weighted operation is performed on the multiple risk assessment values to obtain the first risk assessment value.
[0039] 103. When the first risk assessment value is greater than a preset threshold, determine a first degree of deviation according to the first risk assessment value and the preset threshold.
[0040] The preset threshold value can be pre-set or set by the system. The first deviation reflects the urgency of disaster preparedness. The greater the deviation, the more urgent the disaster preparedness.
[0041] In a specific implementation, when the first risk assessment value is greater than a preset threshold, it indicates that the disaster recovery condition is met, that is, there is a security risk at the first network node, and the first deviation can be determined based on the first risk assessment value and the preset threshold. Conversely, when the first risk assessment value is less than or equal to the preset threshold, it indicates that the disaster recovery condition is not met, that is, there is no security risk at the first network node.
[0042] Optionally, the above step 103, determining the first deviation according to the first risk assessment value and the preset threshold, can be implemented as follows:
[0043] determining a first difference between the first risk assessment value and the preset threshold;
[0044] The ratio between the first difference and the preset threshold is determined to obtain the first deviation.
[0045] In a specific implementation, the first difference between the first risk assessment value and the preset threshold can be determined, the first difference = the first risk assessment value - the preset threshold, and then the ratio between the first difference and the preset threshold is determined to obtain the first deviation, the first deviation = the first difference / the preset threshold, wherein the first deviation reflects the urgency of disaster preparedness, and the greater the deviation, the more urgent the disaster preparedness.
[0046] 104. Determine disaster recovery parameters based on the first deviation, where the disaster recovery parameters include: maximum data memory size and effective disaster recovery duration.
[0047] Among them, the disaster recovery parameters may include: maximum data memory size, effective disaster recovery time, the maximum data memory size may be the maximum amount of data that can complete disaster recovery, and the effective disaster recovery time may be understood as the maximum disaster recovery time, that is, disaster recovery needs to be completed within the effective disaster recovery time.
[0048] A preset mapping relationship between the deviation degree and the disaster recovery parameter may be pre-stored, and then the disaster recovery parameter corresponding to the first deviation degree may be determined based on the mapping relationship.
[0049] 105. Determine target disaster recovery data according to the disaster recovery parameters.
[0050] In a specific implementation, the target data to be recovered can be determined based on the maximum data memory size and the effective disaster recovery time.
[0051] Optionally, the above step 105, determining the target data to be prepared for disaster recovery according to the prepared for disaster recovery parameters, can be implemented as follows:
[0052] Obtaining an importance level of the data of the first network node, and sorting the data in the first network node in descending order according to the importance level;
[0053] selecting first data to be recovered for disaster recovery according to the maximum data memory size, where the memory size of the first data to be recovered for disaster recovery is less than or equal to the maximum data memory size, and the importance level of data in the first data to be recovered for disaster recovery is higher than the importance level of other data in the first network node except the first data to be recovered for disaster recovery;
[0054] Acquire a first data transmission rate of the first network node;
[0055] Determining a first duration according to the memory size of the first disaster recovery data and the first data transmission rate;
[0056] The target data to be prepared for disaster recovery is determined according to the first duration, the effective disaster recovery duration, and the first data to be prepared for disaster recovery.
[0057] In a specific implementation, the importance level of the data of the first network node (for example, all data, or data that requires disaster recovery, etc.) can be obtained, and the data in the first network node can be sorted in descending order according to the importance level. Then, the first data to be recovered can be selected based on the maximum data memory size. The memory size of the first data to be recovered is less than or equal to the maximum data memory size. The importance level of the data in the first data to be recovered is higher than the importance level of other data in the first network node except the first data to be recovered. In addition, the first data transmission rate of the first network node can be obtained, and the first duration can be determined based on the memory size of the first data to be recovered and the first data transmission rate. The first duration = the memory size of the first data to be recovered / the first data transmission rate. Finally, the target data to be recovered can be determined based on the first duration, the effective disaster recovery duration, and the first data to be recovered. In this way, the maximum data memory size and the effective disaster recovery duration can be used to select data to be recovered that is highly important and has a reasonable data volume. During disaster recovery, data with high importance can be prioritized as much as possible, thereby improving the disaster recovery intelligence for the SDWAN network.
[0058] Optionally, the above step of determining the target data to be recovered based on the first duration, the effective recovery duration, and the first data to be recovered can be implemented as follows:
[0059] When the first duration is less than or equal to the effective disaster recovery duration, directly using the first data to be recovered for disaster recovery as the target data to be recovered for disaster recovery;
[0060] When the first duration is greater than the effective disaster recovery duration, determining a reference memory size according to the effective disaster recovery duration and the first data transmission rate;
[0061] Data of an amount equal to the reference memory size is selected from the first data to be recovered for disasters as the target data to be recovered for disasters, and the importance level of the data in the target data to be recovered for disasters is higher than the importance level of other data in the first data to be recovered for disasters except the target data to be recovered for disasters.
[0062] In a specific implementation, when the first duration is less than or equal to the effective disaster recovery duration, the first data to be prepared for disaster recovery can be directly used as the target data to be prepared for disaster recovery, which means that disaster recovery can be completed within the effective disaster recovery duration. In this way, the maximum data memory size and the effective disaster recovery duration can be used to select data to be prepared for disaster recovery that is highly important and has a reasonable amount of data. During disaster recovery, data with high importance can be prioritized as much as possible, thereby improving the disaster recovery intelligence for the SDWAN network.
[0063] In a specific implementation, when the first time period is greater than the effective disaster recovery time period, the reference memory size can be determined based on the effective disaster recovery time period and the first data transmission rate, that is, the effective disaster recovery time period × the first data transmission rate = the reference memory size, and then data equal to the reference memory size is selected from the first data to be disaster recovered as the target data to be disaster recovered. The importance level of the data in the target data to be disaster recovered is higher than the importance level of other data in the first data to be disaster recovered except the target data to be disaster recovered, which means that the first data to be disaster recovered cannot be completely disaster recovered within the effective disaster recovery time period. In this way, the maximum data memory size and the effective disaster recovery time period can be used to select data to be disaster recovered that is highly important and has a reasonable data volume. During disaster recovery, data with high importance can be prioritized as much as possible, thereby improving the disaster recovery intelligence for the SDWAN network.
[0064] Optionally, the above step of obtaining the first data transmission rate of the first network node may be implemented as follows:
[0065] Acquire a data transmission rate of the first network node in a preset time period to obtain multiple data transmission rates; the preset time period is a time period before a current moment, and the preset time period includes the current moment;
[0066] Perform fitting according to the multiple data transmission rates to obtain a first data transmission rate straight line;
[0067] intercepting a data transmission rate straight line segment corresponding to the effective disaster recovery duration after the current moment in the first data transmission rate straight line;
[0068] The data transmission rate at the midpoint of the data transmission rate straight line segment is determined to obtain the first data transmission rate.
[0069] The length of the preset time period can be preset or set by system default. The preset time period is a time period before the current moment, and the preset time period includes the current moment.
[0070] In a specific implementation, the data transmission rate of the first network node in a preset time period can be obtained to obtain multiple data transmission rates, each data transmission rate corresponds to a detection moment, that is, the multiple data transmission rates and the detection moment corresponding to each data transmission rate in the multiple data transmission rates can be regarded as multiple coordinate points, and the coordinate system corresponding to the multiple coordinate points is a horizontal axis for time, and a vertical axis for data transmission rate.
[0071] Next, fitting can be performed based on multiple data transmission rates to obtain a first data transmission rate straight line, that is, straight line fitting can be performed based on multiple coordinate points to obtain the first data transmission rate straight line, and then the data transmission rate straight line segment corresponding to the effective disaster recovery period after the current moment in the first data transmission rate straight line is intercepted, and the data transmission rate of the midpoint of the data transmission rate straight line segment is determined to obtain the first data transmission rate. The first data transmission rate can be understood as the average data transmission rate within the effective disaster recovery period, which represents the disaster recovery efficiency at future moments.
[0072] 106. Determine m network nodes other than the first network node among the n network nodes, wherein a risk assessment value of each of the m network nodes is not greater than the preset threshold, where m is a positive integer less than or equal to n-1.
[0073] In a specific implementation, m network nodes excluding the first network node among n network nodes can be determined, and the risk assessment value of each network node among the m network nodes is not greater than a preset threshold, and m is a positive integer less than or equal to n-1, that is, the network nodes that meet the disaster recovery conditions can be restored to the network nodes that do not meet the disaster recovery conditions, that is, the data of the network nodes with security risks can be restored to the safe network nodes.
[0074] Optionally, the above step 106, determining the m network nodes other than the first network node among the n network nodes, may be implemented as follows:
[0075] Obtaining risk assessment values of n-1 network nodes other than the first network node among the n network nodes to obtain n-1 risk assessment values;
[0076] Selecting a risk assessment value that is less than or equal to the preset threshold value from the n-1 risk assessment values to obtain a risk assessment value, where a is a positive integer less than or equal to n-1;
[0077] Determining the distance between the first network node and the network nodes corresponding to the a risk assessment values to obtain a distance;
[0078] determining a distance threshold corresponding to the first degree of deviation;
[0079] Selecting distances smaller than the distance threshold from the a distances to obtain m distances, where m is a positive integer smaller than or equal to a;
[0080] The m network nodes corresponding to the m distances are determined.
[0081] In an embodiment of the present application, risk assessment values of n-1 network nodes other than the first network node among the n network nodes can be obtained to obtain n-1 risk assessment values, and then risk assessment values less than or equal to a preset threshold value among the n-1 risk assessment values are selected to obtain a risk assessment values, where a is a positive integer less than or equal to n-1. Then, the distance between the first network node and the network nodes corresponding to the a risk assessment values is determined to obtain a distances.
[0082] Among them, the mapping relationship between the preset deviation degree and the distance threshold can be pre-stored. Based on the mapping relationship, the distance threshold corresponding to the first deviation degree can be determined, and then the distance less than the distance threshold is selected from a distances to obtain m distances, where m is a positive integer less than or equal to a, and then the m network nodes corresponding to the m distances are determined. In this way, a safe network node with a short transmission distance can be selected as a network node for disaster recovery.
[0083] 107. Determine the communication links between the first network node and the m network nodes to obtain m communication links.
[0084] The communication link between the first network node and each of the m network nodes can be determined to obtain m communication links. Thus, the m communication links can be used to implement parallel disaster recovery, thereby improving disaster recovery efficiency.
[0085] Optionally, the above step 107, determining the communication links between the first network node and the m network nodes to obtain m communication links, can be implemented as follows:
[0086] Determine x communication links between the first network node and a second network node, where the second network node is any one of the m network nodes; x is a positive integer;
[0087] Determining a network parameter of each of the x communication links to obtain x network parameters;
[0088] Determining a link evaluation value of each communication link using the x network parameters to obtain x link evaluation values;
[0089] A maximum value among the x link evaluation values is selected, and a communication connection corresponding to the maximum value is used as a communication link between the first network node and the second network node.
[0090] In a specific implementation, taking the second network node as an example, the second network node is any network node among the m network nodes. It is possible to determine x communication links between the first network node and the second network node, where x is a positive integer, and then determine the network parameters of each of the x communication links to obtain x network parameters, where the network parameters may include at least one of the following: network bandwidth, network delay, network transmission rate, network disconnection rate, etc., which are not limited here.
[0091] Next, the mapping relationship between the preset network parameters and the link evaluation value can be pre-stored, and the link evaluation value of each communication link can be determined based on the mapping relationship using x network parameters to obtain x link evaluation values. The maximum value among the x link evaluation values is then selected, and the communication connection corresponding to the maximum value is used as the communication link between the first network node and the second network node. In this way, a high-quality link can be configured for each network node that requires disaster recovery to ensure disaster recovery efficiency and effectiveness.
[0092] 108. Disaster recovery the target data to be recovered to the m network nodes through the m communication links.
[0093] In a specific implementation, the target data to be recovered can be restored to m network nodes through m communication links. In this way, disaster recovery can be performed in parallel based on m communication links, thereby improving disaster recovery efficiency and intelligence.
[0094] Optionally, the above step 108, performing disaster recovery of the target data to be recovered to the m network nodes through the m communication links, can be implemented as follows:
[0095] Determining a data transmission rate of each of the m communication links to obtain m data transmission rates;
[0096] Dividing the target data to be recovered for disaster recovery into m parts according to the m data transmission rates to obtain m parts of data to be recovered for disaster recovery, wherein the larger the data transmission rate, the larger the corresponding data memory size, and the larger the data transmission rate, the higher the corresponding data importance;
[0097] Determining a security score value of each of the m network nodes to obtain m security score values;
[0098] Determine the importance score of each of the m pieces of data to be recovered for disaster recovery, and obtain m importance score values;
[0099] According to the m security score values and the m importance score values, the m copies of the data to be restored are restored to the m network nodes through the m communication links.
[0100] In a specific implementation, the data transmission rate of each of the m communication links can be determined to obtain m data transmission rates, and then the target disaster recovery data can be divided into m parts according to the m data transmission rates to obtain m parts of disaster recovery data. The larger the data transmission rate, the larger the corresponding data memory size, and the larger the data transmission rate, the higher the corresponding data importance. For example, the sum of the m data transmission rates can be calculated to obtain the total data transmission rate, and the ratio between the m data transmission rates and the total data transmission rate can be determined to obtain m ratios. Each ratio corresponds to a larger data memory size. In this way, the transmission rate of the communication link can be used for reasonable division.
[0101] Next, a security score is determined for each of the m network nodes to obtain m security scores. For example, security software can be used to perform a security score on each network node to obtain m security scores. Alternatively, operating parameters of each network node can be obtained and used to perform a security score to obtain m security scores, etc. Furthermore, an importance score is determined for each of the m pieces of data to be recovered. For example, keyword extraction can be performed on the data to obtain target keywords. Based on a preset mapping relationship between keywords and importance scores, the importance score corresponding to the target keyword is determined.
[0102] Finally, based on m security score values and m importance score values, m copies of disaster recovery data can be restored to m network nodes through m communication links. In this way, data can be dynamically encrypted based on the security of the communication link and the importance of the disaster recovery data, thereby ensuring disaster recovery security and efficiency, and thus improving disaster recovery intelligence for the SDWAN network.
[0103] Optionally, the above step of backing up the m copies of the data to be backed up to the m network nodes through the m communication links according to the m security score values and the m importance score values may be implemented as follows:
[0104] Determining m reference safety score values according to the m importance score values;
[0105] Determining m data processing parameters according to the m safety score values and m reference safety score values;
[0106] Processing the m copies of the data to be recovered for disaster recovery according to the m data processing parameters to obtain m copies of the processed data to be recovered for disaster recovery;
[0107] The m processed data to be recovered are restored to the m network nodes via the m communication links.
[0108] Among them, m reference security score values can be determined based on m importance score values. For example, a mapping relationship between preset importance score values and reference security score values can be pre-stored. Based on this mapping relationship, m reference security score values corresponding to the m importance score values can be determined. The reference security score value can be understood as the security score value required by the data.
[0109] Then, m data processing parameters can be determined based on the m security score values and the m reference security score values, and then the m copies of the data to be recovered can be processed according to the m data processing parameters to obtain m processed copies of the data to be recovered. Finally, the m processed copies of the data to be recovered can be recovered to the m network nodes through m communication links. In this way, the data can be dynamically encrypted based on the security of the communication link and the importance of the disaster recovery data, thereby ensuring the security and efficiency of disaster recovery, and thus improving the disaster recovery intelligence for the SDWAN network.
[0110] Optionally, the above step of determining m data processing parameters based on the m safety score values and m reference safety score values may be implemented as follows:
[0111] Determine a difference between a first security score value and a first reference security score value; the first security score value is any one of the m security score values; the first reference security score value is a reference security score value corresponding to the first security score value among the m reference security score values;
[0112] When the difference is greater than or equal to 0, determining the data processing parameter corresponding to the first security score value includes not processing the disaster recovery data corresponding to the first reference score value;
[0113] When the difference is less than 0, a first encryption parameter is determined based on the difference, a link identifier of the communication link corresponding to the first encryption parameter is selected, and the first encryption parameter is bound to the link identifier, wherein the communication links for transmitting the first encryption parameter and the disaster recovery data corresponding to the first security score value are different.
[0114] The link identifier is used to uniquely identify a communication link. For example, the link identifier may be a number.
[0115] In a specific implementation, taking the first security score value as an example, the first security score value is any security score value among m security score values, and the first reference security score value is a reference security score value corresponding to the first security score value among the m reference security score values. The difference between the first security score value and the first reference security score value can be determined. When the difference is greater than or equal to 0, the data processing parameter corresponding to the first security score value is determined, including not processing the data to be recovered corresponding to the first reference score value. When the difference is less than 0, a first encryption parameter is determined based on the difference, a link identifier of the communication link corresponding to the first encryption parameter is selected, and the first encryption parameter is bound to the link identifier. The communication links for transmitting the first encryption parameter and the data to be recovered corresponding to the first security score value are different. In this way, data can be dynamically encrypted based on the security of the communication link and the importance of the disaster recovery data, thereby ensuring disaster recovery security and disaster recovery efficiency. Therefore, the disaster recovery intelligence for the SDWAN network can be improved. In addition, the encryption parameter and the encrypted data are transmitted using different communication links, further ensuring disaster recovery security, and the disaster recovery intelligence for the SDWAN network can be improved.
[0116] It can be seen that the device security topology perception and disaster recovery method based on the SDWAN network described in the embodiment of the present application is applied to the device security topology perception and disaster recovery system based on the SDWAN network, which includes n network nodes, where n is an integer greater than 1, and the corresponding sensor parameters of the first network node are detected by the sensor set of the first network node to obtain the first sensor parameters; the first network node is any network node among the n network nodes, and the risk assessment value of the first network node is determined according to the first sensor parameter to obtain the first risk assessment value. When the first risk assessment value is greater than the preset threshold, the first deviation is determined according to the first risk assessment value and the preset threshold, and the parameters to be disaster recovered are determined according to the first deviation. The parameters to be disaster recovered include: maximum data memory size Short and effective disaster recovery time, target data to be recovered is determined according to the disaster recovery parameters, m network nodes other than the first network node among the n network nodes are determined, and the risk assessment value of each network node among the m network nodes is not greater than the preset threshold, m is a positive integer less than or equal to n-1, and the communication link between the first network node and the m network nodes is determined to obtain m communication links, and the target data to be recovered is recovered to the m network nodes through the m communication links. When the disaster recovery conditions are met, the first deviation reflects the urgency of disaster recovery, and the target data to be recovered is dynamically determined based on the disaster recovery urgency. Disaster recovery can be performed in parallel based on the m communication links to improve disaster recovery efficiency and disaster recovery intelligence. In this way, the disaster recovery intelligence can be improved for the SDWAN network.
[0117] In accordance with the above embodiment, please refer to Figure 4 , Figure 4This is a structural diagram of an electronic device provided in an embodiment of the present application. As shown in the figure, the electronic device includes a processor, a memory, a communication interface, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the processor. In an embodiment of the present application, the device security topology perception and disaster recovery system based on the SDWAN network is applied. The system includes n network nodes, where n is an integer greater than 1. The program includes instructions for performing the following steps:
[0118] Detecting corresponding sensor parameters of a first network node through a sensor set of the first network node, obtaining first sensor parameters; the first network node is any one of the n network nodes;
[0119] determining a risk assessment value of the first network node according to the first sensor parameter to obtain a first risk assessment value;
[0120] When the first risk assessment value is greater than a preset threshold, determining a first degree of deviation according to the first risk assessment value and the preset threshold;
[0121] Determine the disaster recovery parameters according to the first deviation, wherein the disaster recovery parameters include: maximum data memory size and effective disaster recovery time;
[0122] Determine target disaster recovery data according to the disaster recovery parameters;
[0123] Determining m network nodes other than the first network node among the n network nodes, wherein a risk assessment value of each of the m network nodes is not greater than the preset threshold, where m is a positive integer less than or equal to n-1;
[0124] Determining a communication link between the first network node and the m network nodes to obtain m communication links;
[0125] The target data to be restored is restored to the m network nodes via the m communication links.
[0126] Optionally, in the aspect of determining m network nodes other than the first network node among the n network nodes, the program includes instructions for performing the following steps:
[0127] Obtaining risk assessment values of n-1 network nodes other than the first network node among the n network nodes to obtain n-1 risk assessment values;
[0128] Selecting a risk assessment value that is less than or equal to the preset threshold value from the n-1 risk assessment values to obtain a risk assessment value, where a is a positive integer less than or equal to n-1;
[0129] Determining the distance between the first network node and the network nodes corresponding to the a risk assessment values to obtain a distance;
[0130] determining a distance threshold corresponding to the first degree of deviation;
[0131] Selecting distances smaller than the distance threshold from the a distances to obtain m distances, where m is a positive integer smaller than or equal to a;
[0132] The m network nodes corresponding to the m distances are determined.
[0133] Optionally, in determining the first degree of deviation based on the first risk assessment value and the preset threshold, the program includes instructions for executing the following steps:
[0134] determining a first difference between the first risk assessment value and the preset threshold;
[0135] The ratio between the first difference and the preset threshold is determined to obtain the first deviation.
[0136] Optionally, in determining the target data to be recovered for disaster recovery according to the recovery parameters, the program includes instructions for executing the following steps:
[0137] Obtaining an importance level of the data of the first network node, and sorting the data in the first network node in descending order according to the importance level;
[0138] selecting first data to be recovered for disaster recovery according to the maximum data memory size, where the memory size of the first data to be recovered for disaster recovery is less than or equal to the maximum data memory size, and the importance level of data in the first data to be recovered for disaster recovery is higher than the importance level of other data in the first network node except the first data to be recovered for disaster recovery;
[0139] Acquire a first data transmission rate of the first network node;
[0140] Determining a first duration according to the memory size of the first disaster recovery data and the first data transmission rate;
[0141] The target data to be prepared for disaster recovery is determined according to the first duration, the effective disaster recovery duration, and the first data to be prepared for disaster recovery.
[0142] Optionally, in determining the target data to be prepared for disaster recovery based on the first duration, the effective disaster recovery duration, and the first data to be prepared for disaster recovery, the program includes instructions for executing the following steps:
[0143] When the first duration is less than or equal to the effective disaster recovery duration, directly using the first data to be recovered for disaster recovery as the target data to be recovered for disaster recovery;
[0144] When the first duration is greater than the effective disaster recovery duration, determining a reference memory size according to the effective disaster recovery duration and the first data transmission rate;
[0145] Data of an amount equal to the reference memory size is selected from the first data to be recovered as the target data to be recovered, and the importance level of the data in the target data to be recovered is higher than the importance level of other data in the first data to be recovered except the target data to be recovered.
[0146] Optionally, in terms of obtaining the first data transmission rate of the first network node, the program includes instructions for performing the following steps:
[0147] Acquire a data transmission rate of the first network node in a preset time period to obtain multiple data transmission rates; the preset time period is a time period before a current moment, and the preset time period includes the current moment;
[0148] Perform fitting according to the multiple data transmission rates to obtain a first data transmission rate straight line;
[0149] intercepting a data transmission rate straight line segment corresponding to the effective disaster recovery duration after the current moment in the first data transmission rate straight line;
[0150] The data transmission rate at the midpoint of the data transmission rate straight line segment is determined to obtain the first data transmission rate.
[0151] Optionally, in the aspect of determining the communication link between the first network node and the m network nodes to obtain m communication links, the program includes instructions for performing the following steps:
[0152] Determine x communication links between the first network node and a second network node, where the second network node is any one of the m network nodes; x is a positive integer;
[0153] Determining a network parameter of each of the x communication links to obtain x network parameters;
[0154] Determining a link evaluation value of each communication link using the x network parameters to obtain x link evaluation values;
[0155] A maximum value among the x link evaluation values is selected, and a communication connection corresponding to the maximum value is used as a communication link between the first network node and the second network node.
[0156] Optionally, in the aspect of backing up the target data to be backed up to the m network nodes through the m communication links, the program includes instructions for executing the following steps:
[0157] Determining a data transmission rate of each of the m communication links to obtain m data transmission rates;
[0158] Dividing the target data to be recovered for disaster recovery into m parts according to the m data transmission rates to obtain m parts of data to be recovered for disaster recovery, wherein the larger the data transmission rate, the larger the corresponding data memory size, and the larger the data transmission rate, the higher the corresponding data importance;
[0159] Determining a security score value of each of the m network nodes to obtain m security score values;
[0160] Determine the importance score of each of the m pieces of data to be recovered for disaster recovery, and obtain m importance score values;
[0161] According to the m security score values and the m importance score values, the m copies of the data to be restored are restored to the m network nodes through the m communication links.
[0162] Optionally, in the aspect of backing up the m copies of the data to be backed up to the m network nodes through the m communication links according to the m security score values and the m importance score values, the program includes instructions for performing the following steps:
[0163] Determining m reference safety score values according to the m importance score values;
[0164] Determining m data processing parameters according to the m safety score values and m reference safety score values;
[0165] Processing the m copies of the data to be recovered for disaster recovery according to the m data processing parameters to obtain m copies of the processed data to be recovered for disaster recovery;
[0166] The m processed data to be recovered are restored to the m network nodes via the m communication links.
[0167] Optionally, in determining m data processing parameters based on the m security score values and the m reference security score values, the program includes instructions for performing the following steps:
[0168] Determine a difference between a first security score value and a first reference security score value; the first security score value is any one of the m security score values; the first reference security score value is a reference security score value corresponding to the first security score value among the m reference security score values;
[0169] When the difference is greater than or equal to 0, determining the data processing parameter corresponding to the first security score value includes not processing the disaster recovery data corresponding to the first reference score value;
[0170] When the difference is less than 0, a first encryption parameter is determined based on the difference, a link identifier of the communication link corresponding to the first encryption parameter is selected, and the first encryption parameter is bound to the link identifier, wherein the communication links for transmitting the first encryption parameter and the disaster recovery data corresponding to the first security score value are different.
[0171] It can be seen that the electronic device described in the embodiment of the present application is applied to a device security topology perception and disaster recovery system based on an SDWAN network, the system including n network nodes, n being an integer greater than 1, detecting corresponding sensor parameters through a sensor set of a first network node to obtain first sensor parameters; the first network node is any one of the n network nodes, determining a risk assessment value of the first network node according to the first sensor parameter to obtain a first risk assessment value, when the first risk assessment value is greater than a preset threshold, determining a first deviation according to the first risk assessment value and the preset threshold, determining parameters to be prepared for disaster recovery according to the first deviation, the parameters to be prepared for disaster recovery including: maximum data memory size, effective disaster recovery time, Determine the target data to be recovered according to the parameters to be recovered, determine m network nodes other than the first network node among the n network nodes, the risk assessment value of each network node among the m network nodes is not greater than a preset threshold, m is a positive integer less than or equal to n-1, determine the communication link between the first network node and the m network nodes, obtain m communication links, and recover the target data to be recovered to the m network nodes through the m communication links. When the disaster recovery conditions are met, the first deviation reflects the urgency of disaster recovery. The target data to be recovered is dynamically determined based on the urgency of disaster recovery. Disaster recovery can be performed in parallel based on the m communication links to improve disaster recovery efficiency and disaster recovery intelligence. In this way, disaster recovery intelligence can be improved for the SDWAN network.
[0172] Figure 5 This is a functional unit composition block diagram of a device security topology perception and disaster recovery device 500 based on an SDWAN network involved in an embodiment of the present application. The device security topology perception and disaster recovery device 500 based on an SDWAN network is applied to a device security topology perception and disaster recovery system based on an SDWAN network. The system includes n network nodes, where n is an integer greater than 1. The device security topology perception and disaster recovery device 500 based on the SDWAN network includes: a detection unit 501, a determination unit 502, and a disaster recovery unit 503, wherein:
[0173] The detection unit 501 is configured to detect corresponding sensor parameters of a first network node through a sensor set of the first network node to obtain first sensor parameters; the first network node is any network node among the n network nodes;
[0174] The determining unit 502 is configured to determine a risk assessment value of the first network node according to the first sensor parameter to obtain a first risk assessment value; when the first risk assessment value is greater than a preset threshold, determine a first deviation according to the first risk assessment value and the preset threshold; determine a disaster recovery parameter according to the first deviation, the disaster recovery parameter including: a maximum data memory size and an effective disaster recovery duration; determine target disaster recovery data according to the disaster recovery parameter; determine m network nodes other than the first network node among the n network nodes, wherein the risk assessment value of each of the m network nodes is not greater than the preset threshold, where m is a positive integer less than or equal to n-1; determine a communication link between the first network node and the m network nodes to obtain m communication links;
[0175] The disaster recovery unit 503 is configured to restore the target data to be restored to the m network nodes via the m communication links.
[0176] Optionally, in determining the m network nodes other than the first network node among the n network nodes, the determining unit 502 is specifically configured to:
[0177] Obtaining risk assessment values of n-1 network nodes other than the first network node among the n network nodes to obtain n-1 risk assessment values;
[0178] Selecting a risk assessment value that is less than or equal to the preset threshold value from the n-1 risk assessment values to obtain a risk assessment value, where a is a positive integer less than or equal to n-1;
[0179] Determining the distance between the first network node and the network nodes corresponding to the a risk assessment values to obtain a distance;
[0180] determining a distance threshold corresponding to the first degree of deviation;
[0181] Selecting distances smaller than the distance threshold from the a distances to obtain m distances, where m is a positive integer smaller than or equal to a;
[0182] The m network nodes corresponding to the m distances are determined.
[0183] Optionally, in determining the first degree of deviation according to the first risk assessment value and the preset threshold, the determining unit 502 is specifically configured to:
[0184] determining a first difference between the first risk assessment value and the preset threshold;
[0185] The ratio between the first difference and the preset threshold is determined to obtain the first deviation.
[0186] Optionally, in determining the target data to be prepared for disaster recovery according to the parameters to be prepared for disaster recovery, the determining unit 502 is specifically configured to:
[0187] Obtaining an importance level of the data of the first network node, and sorting the data in the first network node in descending order according to the importance level;
[0188] selecting first data to be recovered for disaster recovery according to the maximum data memory size, where the memory size of the first data to be recovered for disaster recovery is less than or equal to the maximum data memory size, and the importance level of data in the first data to be recovered for disaster recovery is higher than the importance level of other data in the first network node except the first data to be recovered for disaster recovery;
[0189] Acquire a first data transmission rate of the first network node;
[0190] Determining a first duration according to the memory size of the first disaster recovery data and the first data transmission rate;
[0191] The target data to be prepared for disaster recovery is determined according to the first duration, the effective disaster recovery duration, and the first data to be prepared for disaster recovery.
[0192] Optionally, in determining the target data to be prepared for disaster recovery according to the first duration, the effective disaster recovery duration, and the first data to be prepared for disaster recovery, the determining unit 502 is specifically configured to:
[0193] When the first duration is less than or equal to the effective disaster recovery duration, directly using the first data to be recovered for disaster recovery as the target data to be recovered for disaster recovery;
[0194] When the first duration is greater than the effective disaster recovery duration, determining a reference memory size according to the effective disaster recovery duration and the first data transmission rate;
[0195] Data of an amount equal to the reference memory size is selected from the first data to be recovered as the target data to be recovered, and the importance level of the data in the target data to be recovered is higher than the importance level of other data in the first data to be recovered except the target data to be recovered.
[0196] Optionally, in terms of acquiring the first data transmission rate of the first network node, the determining unit 502 is specifically configured to:
[0197] Acquire a data transmission rate of the first network node in a preset time period to obtain multiple data transmission rates; the preset time period is a time period before a current moment, and the preset time period includes the current moment;
[0198] Perform fitting according to the multiple data transmission rates to obtain a first data transmission rate straight line;
[0199] intercepting a data transmission rate straight line segment corresponding to the effective disaster recovery duration after the current moment in the first data transmission rate straight line;
[0200] The data transmission rate at the midpoint of the data transmission rate straight line segment is determined to obtain the first data transmission rate.
[0201] Optionally, in determining the communication links between the first network node and the m network nodes to obtain m communication links, the determining unit 502 is specifically configured to:
[0202] Determine x communication links between the first network node and a second network node, where the second network node is any one of the m network nodes; x is a positive integer;
[0203] Determining a network parameter of each of the x communication links to obtain x network parameters;
[0204] Determining a link evaluation value of each communication link using the x network parameters to obtain x link evaluation values;
[0205] A maximum value among the x link evaluation values is selected, and a communication connection corresponding to the maximum value is used as a communication link between the first network node and the second network node.
[0206] Optionally, in terms of backing up the target data to be backed up to the m network nodes through the m communication links, the determining unit 502 is specifically configured to:
[0207] Determining a data transmission rate of each of the m communication links to obtain m data transmission rates;
[0208] Dividing the target data to be recovered for disaster recovery into m parts according to the m data transmission rates to obtain m parts of data to be recovered for disaster recovery, wherein the larger the data transmission rate, the larger the corresponding data memory size, and the larger the data transmission rate, the higher the corresponding data importance;
[0209] Determining a security score value of each of the m network nodes to obtain m security score values;
[0210] Determine the importance score of each of the m pieces of data to be recovered for disaster recovery, and obtain m importance score values;
[0211] According to the m security score values and the m importance score values, the m copies of the data to be restored are restored to the m network nodes through the m communication links.
[0212] Optionally, in the aspect of backing up the m copies of the data to be backed up to the m network nodes through the m communication links according to the m security score values and the m importance score values, the determining unit 502 is specifically configured to:
[0213] Determining m reference safety score values according to the m importance score values;
[0214] Determining m data processing parameters according to the m safety score values and m reference safety score values;
[0215] Processing the m copies of the data to be recovered for disaster recovery according to the m data processing parameters to obtain m copies of the processed data to be recovered for disaster recovery;
[0216] The m processed data to be recovered are restored to the m network nodes via the m communication links.
[0217] Optionally, in determining the m data processing parameters according to the m security score values and the m reference security score values, the determining unit 502 is specifically configured to:
[0218] Determine a difference between a first security score value and a first reference security score value; the first security score value is any one of the m security score values; the first reference security score value is a reference security score value corresponding to the first security score value among the m reference security score values;
[0219] When the difference is greater than or equal to 0, determining the data processing parameter corresponding to the first security score value includes not processing the disaster recovery data corresponding to the first reference score value;
[0220] When the difference is less than 0, a first encryption parameter is determined based on the difference, a link identifier of the communication link corresponding to the first encryption parameter is selected, and the first encryption parameter is bound to the link identifier, wherein the communication links for transmitting the first encryption parameter and the disaster recovery data corresponding to the first security score value are different.
[0221] It can be seen that the device security topology perception and disaster recovery device based on the SDWAN network described in the embodiment of the present application is applied to the device security topology perception and disaster recovery system based on the SDWAN network, which includes n network nodes, where n is an integer greater than 1, and the sensor set of the first network node detects its corresponding sensor parameters to obtain the first sensor parameters; the first network node is any network node among the n network nodes, and the risk assessment value of the first network node is determined according to the first sensor parameter to obtain the first risk assessment value. When the first risk assessment value is greater than the preset threshold, the first deviation is determined according to the first risk assessment value and the preset threshold, and the parameters to be disaster recovered are determined according to the first deviation. The parameters to be disaster recovered include: maximum data memory size Short and effective disaster recovery time, target data to be recovered is determined according to the disaster recovery parameters, m network nodes other than the first network node among the n network nodes are determined, and the risk assessment value of each network node among the m network nodes is not greater than the preset threshold, m is a positive integer less than or equal to n-1, and the communication link between the first network node and the m network nodes is determined to obtain m communication links, and the target data to be recovered is recovered to the m network nodes through the m communication links. When the disaster recovery conditions are met, the first deviation reflects the urgency of disaster recovery, and the target data to be recovered is dynamically determined based on the disaster recovery urgency. Disaster recovery can be performed in parallel based on the m communication links to improve disaster recovery efficiency and disaster recovery intelligence. In this way, the disaster recovery intelligence can be improved for the SDWAN network.
[0222] It can be understood that the functions of each program module of the SDWAN network-based device security topology perception and disaster recovery device in this embodiment can be specifically implemented according to the method in the above-mentioned method embodiment. The specific implementation process can refer to the relevant description of the above-mentioned method embodiment and will not be repeated here.
[0223] An embodiment of the present application also provides a computer storage medium, wherein the computer storage medium stores a computer program for electronic data exchange, and the computer program enables a computer to execute part or all of the steps of any method described in the above method embodiments, and the above computer includes an electronic device.
[0224] The present application also provides a computer program product comprising a non-transitory computer-readable storage medium storing a computer program, wherein the computer program is operable to cause a computer to perform some or all of the steps of any of the methods described in the above method embodiments. The computer program product may be a software installation package, and the computer may comprise an electronic device.
[0225] It should be noted that for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by this application.
[0226] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0227] In the several embodiments provided in this application, it should be understood that the disclosed devices can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the above-mentioned units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, and the indirect coupling or communication connection of devices or units can be electrical or other forms.
[0228] The units described above as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0229] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0230] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a memory and includes a number of instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the above-mentioned methods of each embodiment of the present application. The aforementioned memory includes: various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.
[0231] Those skilled in the art will appreciate that all or part of the steps in the various methods of the above embodiments can be completed by instructing related hardware through a program. The program can be stored in a computer-readable memory, and the memory can include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0232] The above is a detailed introduction to the embodiments of the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method and core idea of the present application. At the same time, for those skilled in the art, according to the idea of the present application, there may be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A device security topology perception and disaster recovery method based on SDWAN network, characterized in that: Applied to a device security topology perception and disaster recovery system based on an SDWAN network, the system includes n network nodes, where n is an integer greater than 1, and the method includes: Detecting corresponding sensor parameters of a first network node through a sensor set of the first network node, obtaining first sensor parameters; the first network node is any one of the n network nodes; determining a risk assessment value of the first network node according to the first sensor parameter to obtain a first risk assessment value; When the first risk assessment value is greater than a preset threshold, determining a first degree of deviation according to the first risk assessment value and the preset threshold; Determine the disaster recovery parameters according to the first deviation, wherein the disaster recovery parameters include: maximum data memory size and effective disaster recovery time; Determine target disaster recovery data according to the disaster recovery parameters; Determining m network nodes other than the first network node among the n network nodes, wherein a risk assessment value of each of the m network nodes is not greater than the preset threshold, where m is a positive integer less than or equal to n-1; Determining a communication link between the first network node and the m network nodes to obtain m communication links; The target data to be restored is restored to the m network nodes via the m communication links.
2. The method according to claim 1, characterized in that The determining m network nodes other than the first network node among the n network nodes includes: Obtaining risk assessment values of n-1 network nodes other than the first network node among the n network nodes to obtain n-1 risk assessment values; Selecting a risk assessment value that is less than or equal to the preset threshold value from the n-1 risk assessment values to obtain a risk assessment value, where a is a positive integer less than or equal to n-1; Determining the distance between the first network node and the network nodes corresponding to the a risk assessment values to obtain a distance; determining a distance threshold corresponding to the first degree of deviation; Selecting distances smaller than the distance threshold from the a distances to obtain m distances, where m is a positive integer smaller than or equal to a; The m network nodes corresponding to the m distances are determined.
3. The method according to claim 1 or 2, characterized in that The determining of the first degree of deviation according to the first risk assessment value and the preset threshold comprises: determining a first difference between the first risk assessment value and the preset threshold; The ratio between the first difference and the preset threshold is determined to obtain the first deviation.
4. The method according to claim 1 or 2, characterized in that The determining target data to be prepared for disaster recovery according to the prepared for disaster recovery parameters includes: Obtaining an importance level of the data of the first network node, and sorting the data in the first network node in descending order according to the importance level; selecting first data to be recovered for disaster recovery according to the maximum data memory size, where the memory size of the first data to be recovered for disaster recovery is less than or equal to the maximum data memory size, and the importance level of data in the first data to be recovered for disaster recovery is higher than the importance level of other data in the first network node except the first data to be recovered for disaster recovery; Acquire a first data transmission rate of the first network node; Determining a first duration according to the memory size of the first disaster recovery data and the first data transmission rate; The target data to be prepared for disaster recovery is determined according to the first duration, the effective disaster recovery duration, and the first data to be prepared for disaster recovery.
5. The method according to claim 4, characterized in that The determining the target data to be prepared for disaster recovery according to the first duration, the effective disaster recovery duration, and the first data to be prepared for disaster recovery includes: When the first duration is less than or equal to the effective disaster recovery duration, directly using the first data to be recovered for disaster recovery as the target data to be recovered for disaster recovery; When the first duration is greater than the effective disaster recovery duration, determining a reference memory size according to the effective disaster recovery duration and the first data transmission rate; Data of an amount equal to the reference memory size is selected from the first data to be recovered as the target data to be recovered, and the importance level of the data in the target data to be recovered is higher than the importance level of other data in the first data to be recovered except the target data to be recovered.
6. The method according to claim 4, characterized in that The acquiring the first data transmission rate of the first network node includes: Acquire a data transmission rate of the first network node in a preset time period to obtain multiple data transmission rates; the preset time period is a time period before a current moment, and the preset time period includes the current moment; Perform fitting according to the multiple data transmission rates to obtain a first data transmission rate straight line; intercepting a data transmission rate straight line segment corresponding to the effective disaster recovery duration after the current moment in the first data transmission rate straight line; The data transmission rate at the midpoint of the data transmission rate straight line segment is determined to obtain the first data transmission rate.
7. The method according to claim 1 or 2, characterized in that The determining the communication links between the first network node and the m network nodes to obtain m communication links includes: Determine x communication links between the first network node and a second network node, where the second network node is any one of the m network nodes; x is a positive integer; Determining a network parameter of each of the x communication links to obtain x network parameters; Determining a link evaluation value of each communication link using the x network parameters to obtain x link evaluation values; A maximum value among the x link evaluation values is selected, and a communication connection corresponding to the maximum value is used as a communication link between the first network node and the second network node.
8. The method according to claim 1 or 2, characterized in that The step of backing up the target data to be backed up to the m network nodes through the m communication links includes: Determining a data transmission rate of each of the m communication links to obtain m data transmission rates; Dividing the target data to be recovered for disaster recovery into m parts according to the m data transmission rates to obtain m parts of data to be recovered for disaster recovery, wherein the larger the data transmission rate, the larger the corresponding data memory size, and the larger the data transmission rate, the higher the corresponding data importance; Determining a security score value of each of the m network nodes to obtain m security score values; Determine the importance score of each of the m pieces of data to be recovered for disaster recovery, and obtain m importance score values; According to the m security score values and the m importance score values, the m copies of the data to be restored are restored to the m network nodes through the m communication links.
9. The method according to claim 8, characterized in that The step of backing up the m copies of the data to be backed up to the m network nodes through the m communication links according to the m security score values and the m importance score values includes: Determining m reference safety score values according to the m importance score values; Determining m data processing parameters according to the m safety score values and m reference safety score values; Processing the m copies of the data to be recovered for disaster recovery according to the m data processing parameters to obtain m copies of the processed data to be recovered for disaster recovery; The m processed data to be recovered are restored to the m network nodes via the m communication links.
10. The method according to claim 9, characterized in that The determining of m data processing parameters according to the m safety score values and the m reference safety score values includes: Determine a difference between a first security score value and a first reference security score value; the first security score value is any one of the m security score values; the first reference security score value is a reference security score value corresponding to the first security score value among the m reference security score values; When the difference is greater than or equal to 0, determining the data processing parameter corresponding to the first security score value includes not processing the disaster recovery data corresponding to the first reference score value; When the difference is less than 0, a first encryption parameter is determined based on the difference, a link identifier of the communication link corresponding to the first encryption parameter is selected, and the first encryption parameter is bound to the link identifier, wherein the communication links for transmitting the first encryption parameter and the disaster recovery data corresponding to the first security score value are different.