Network security system of data center, control method and storage medium

By introducing switch modules, operation and maintenance modules, load balancing modules, security defense modules and log audit modules in the data center, the problem of insufficient security protection in the data center is solved, especially the defense of internal horizontal attacks, and overall security and stability are improved.

CN120474740APending Publication Date: 2025-08-12SOUTHERN UNIVERSITY OF SCIENCE AND TECHNOLOGY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510523191.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

In the prior art, the network security protection level of data centers is insufficient, especially when facing internal horizontal attacks, there are significant security vulnerabilities.

Method used

The switch module, operation and maintenance module, load balancing module, security defense module and log audit module are used to map the login site to a preset external network IP address through the load balancing module. The security defense module is used to detect and control external network attacks and internal horizontal network attacks, and monitor and generate alarms through the log audit module.

Benefits of technology

It effectively improves the network security level of data centers, enhances the defense capabilities against internal horizontal attacks, and ensures the stability and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474740A_ABST
    Figure CN120474740A_ABST
Patent Text Reader

Abstract

The invention provides a network security system of a data center, a control method and a storage medium. The system comprises a switch module used for network connection; the operation and maintenance module is used for configuring and managing all login sites, the switch module, the load balancing module, the security defense module and the log auditing module; the load balancing module is used for providing services for all the login sites through preset external network IP addresses and balancing access requests of all the login sites; the security defense module is used for detecting and controlling external network attacks and / or internal transverse network attacks; and the log auditing module is used for collecting logs of each module and a login site for monitoring, and generating an alarm when an abnormal behavior is monitored. The external network attack and / or the internal transverse network attack aiming at the login site are / is detected and controlled through the security defense module, so that the network security level of the data center is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a network security system, control method and storage medium for a data center. Background Art

[0002] In existing technology, data centers primarily rely on firewalls to establish a network security defense line. However, this protection mechanism has significant security vulnerabilities when facing lateral attacks originating from within the system. Take a data center's public service information platform, for example, which often hosts tens of thousands of users. Individual users may leak their account and password information due to weak passwords, computer viruses, and other reasons. Once this information is obtained by an unauthorized user, they can use these legitimate login credentials to access internal computing resources through legitimate channels, thereby launching an internal attack. In this scenario, the network security protection level of data centers needs to be improved.

[0003] Therefore, the existing technology has defects and needs to be improved and developed. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to provide a network security system, control method and storage medium for a data center in response to the above-mentioned defects of the prior art, aiming to solve the problem that the network security protection level of the data center in the prior art needs to be improved.

[0005] The technical solutions adopted by the present invention to solve the technical problems are as follows:

[0006] In a first aspect, an embodiment of the present invention provides a network security system for a data center, the system comprising: a switch module, an operation and maintenance module, a load balancing module, a security defense module, and a log audit module;

[0007] The switch module is used to connect multiple login sites, operation and maintenance modules, load balancing modules, security defense modules and log audit modules of the data center through the network;

[0008] The operation and maintenance module is used to configure and manage all login sites, switch modules, load balancing modules, security defense modules and log audit modules;

[0009] The load balancing module is used to provide services to all login sites through the preset external network IP address and balance the access requests of all login sites;

[0010] The security defense module is used to detect and control external network attacks and / or internal lateral network attacks against the login site;

[0011] The log audit module is used to collect logs of the switch module, operation and maintenance module, load balancing module, security defense module and all login sites for monitoring, and generate alarms when abnormal behavior is detected.

[0012] In one embodiment, the security defense module includes two firewalls supporting active / standby switching and an intrusion prevention device.

[0013] In one embodiment, the firewall includes:

[0014] The first defense unit is used to limit the IP addresses of the target network segment to request access to the login site;

[0015] The second defense unit is used to detect whether the received access request contains a brute force attack, and if it is determined that a brute force attack exists, it blocks the IP address of the attack source;

[0016] The third defense unit is used to limit the firewall configuration operations to the preset bastion host IP address;

[0017] The fourth defense unit is used to perform vulnerability attack detection, botnet detection, and content security detection when a logged-in user or data center staff attempts to access the external network. If any of the following conditions is detected: vulnerability attack, botnet, or insecure content, the external network access will be interrupted.

[0018] The fifth defense unit is used to perform vulnerability attack detection, botnet detection, content security detection, web application protection, and website tampering prevention detection when the IP address of the target network segment requests to access the login site. If any of the following conditions are detected: vulnerability attack, botnet, or insecure access information, access to the login site will be interrupted.

[0019] The sixth defense unit is used to protect against ARP flood attacks, DOS / DDOS attacks, data packet attacks, and abnormal message attacks.

[0020] In one embodiment, the intrusion prevention device includes:

[0021] A mirror data generation unit is used to capture traffic data in the network and mirror it to obtain traffic mirror data;

[0022] Traffic analysis unit, used to match traffic mirroring data with built-in protection rules and execute corresponding data interception or transmission based on the matching results;

[0023] The first vulnerability protection unit is used to protect the operating system and applications of the login site from vulnerabilities;

[0024] The second vulnerability protection unit is used to protect the operating systems and applications of the work computers of data center staff from vulnerabilities.

[0025] In one embodiment, the log audit module includes two log audit units, each of which includes:

[0026] Configuration subunit, used to configure the devices to be collected as switch modules, operation and maintenance modules, load balancing modules, security defense modules and login sites;

[0027] The log collection sub-unit is used to collect and save operation logs, network traffic information logs, and security event logs on the switch module, operation and maintenance module, load balancing module, security defense module, and login site;

[0028] The abnormality judgment subunit is used to analyze the collected logs and determine whether there are abnormalities;

[0029] The report and alarm generation subunit is used to generate abnormality reports and alarm information if there is an abnormality.

[0030] In one embodiment, the load balancing module includes:

[0031] IP mapping unit, used to map the intranet IP addresses of all login sites to preset external IP addresses;

[0032] The load balancing unit is used to balance the access requests to the login site according to a preset load balancing algorithm.

[0033] In one embodiment, the operation and maintenance module includes a bastion host, a jump server, a Linux virtual machine and a Linux system host. The bastion host is used to record the operation methods, operation processes, operation results and system prompts of the operation and maintenance personnel, and supports behavior reproduction, security auditing, authority management and operation monitoring. The jump server is used for the operation and maintenance personnel to access the management page of the firewall, the Linux virtual machine is used to execute simulated network attacks, and the Linux system host is used as a system to simulate the attacked login site.

[0034] In one embodiment, the bastion host includes:

[0035] Operation recording unit, used to record the operation methods, operation processes, operation results and system prompts of operation and maintenance personnel;

[0036] A behavior reproduction unit, used to reproduce the selected operation records;

[0037] Security audit unit, used to audit operation records and obtain audit results;

[0038] The authority management unit is used to manage the authority of operation and maintenance personnel;

[0039] The operation monitoring unit is used to monitor the operation behavior of the operation and maintenance personnel in real time and generate prompt information when it is determined that the operation of the operation and maintenance personnel is abnormal.

[0040] In a second aspect, an embodiment of the present invention further provides a data center network security control method, the method comprising:

[0041] Utilize the switch module to connect multiple login sites, operation and maintenance modules, load balancing modules, security defense modules and log audit modules of the data center through the network;

[0042] Use the operation and maintenance module to configure and manage all login sites, switch modules, load balancing modules, security defense modules and log audit modules of the data center;

[0043] Utilize the load balancing module to provide services to all login sites through the preset external network IP address and balance the access requests of all login sites;

[0044] Utilizing the security defense module to detect and control external network attacks and / or internal lateral network attacks against the login site;

[0045] The log audit module is used to collect logs from the switch module, operation and maintenance module, load balancing module, security defense module and all login sites for monitoring, and generate alarms when abnormal behavior is detected.

[0046] In a third aspect, an embodiment of the present invention further provides a computer-readable storage medium, which stores a network security control program for a data center, and the network security control program for a data center can be executed to implement the steps of the network security control method for a data center as described above.

[0047] Beneficial effects of the present invention: The present invention sets a switch module for network connection in the network security system of the data center; an operation and maintenance module for configuring and managing all login sites, switch modules, load balancing modules, security defense modules and log audit modules; a load balancing module for providing services to all login sites through preset external network IP addresses and balancing access requests of all login sites; a security defense module for detecting and controlling external network attacks and / or internal lateral network attacks; and a log audit module for collecting logs of each module and login site for monitoring and generating alarms when abnormal behavior is detected. The present invention detects and controls external network attacks and / or internal lateral network attacks against login sites through the security defense module, effectively improving the network security level of the data center. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1 It is a structural diagram of a preferred embodiment of the network security system of the data center in the present invention.

[0049] Figure 2 It is a schematic diagram of the network security system architecture of the data center in the present invention.

[0050] Figure 3 It is a flow chart of a preferred embodiment of the network security control method of a data center in the present invention. DETAILED DESCRIPTION

[0051] In order to make the purpose, technical solutions and advantages of the present invention more clear and distinct, the present invention is further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0052] In existing technology, data centers primarily rely on firewalls to establish a network security defense line. However, this protection mechanism has significant security vulnerabilities when facing lateral attacks originating from within the system. Take a data center's public service information platform, for example, which often hosts tens of thousands of users. Individual users may leak their account and password information due to weak passwords, computer viruses, and other reasons. Once this information is obtained by an unauthorized user, they can use these legitimate login credentials to access internal computing resources through legitimate channels, thereby launching an internal attack. In this scenario, the network security protection level of data centers needs to be improved.

[0053] In response to the above-mentioned deficiencies in the prior art, the present invention provides a network security system, control method, and storage medium for a data center. The system includes: a switch module for network connection; an operation and maintenance module for configuring and managing all login sites, switch modules, load balancing modules, security defense modules, and log audit modules; a load balancing module for providing services to all login sites through preset external network IP addresses and balancing access requests from all login sites; a security defense module for detecting and controlling external network attacks and / or internal lateral network attacks; and a log audit module for collecting logs from each module and login site for monitoring, and generating alarms when abnormal behavior is detected. The present invention uses the security defense module to detect and control external network attacks and / or internal lateral network attacks against login sites, effectively improving the network security level of the data center.

[0054] See Figure 1The network security system of the data center described in the embodiment of the present invention includes: a switch module 1, an operation and maintenance module 2, a load balancing module 3, a security defense module 4 and a log audit module 5; the switch module 1 is used to connect multiple login sites, operation and maintenance module 2, load balancing module 3, security defense module 4 and log audit module 5 of the data center through the network; the operation and maintenance module 2 is used to configure and manage all login sites, switch module 1, load balancing module 3, security defense module 4 and log audit module 5; the load balancing module 3 is used to provide services to all login sites through preset external network IP addresses and balance access requests of all login sites; the security defense module 4 is used to detect and control external network attacks and / or internal lateral network attacks against login sites; the log audit module 5 is used to collect logs of the switch module 1, operation and maintenance module 2, load balancing module 3, security defense module 4 and all login sites for monitoring, and generate alarms when abnormal behavior is detected.

[0055] Specifically, an internal lateral network attack occurs when an attacker, having already compromised a target network or system, attempts to move or spread within the network to gain higher privileges or access sensitive information. While existing security defenses primarily target external network attacks, this invention adds defense against internal lateral network attacks, effectively improving data center network security.

[0056] In one implementation, the security defense module includes two firewalls supporting active / standby switching and an intrusion prevention device.

[0057] Specifically, to prevent security disruptions caused by a single firewall failure, the present invention employs two firewalls that support active / standby switchover. The firewalls primarily defend against external network attacks. Furthermore, the present invention incorporates an intrusion prevention device to defend against both external and internal lateral network attacks. This effectively improves the network security of the data center.

[0058] In one implementation, the firewall includes:

[0059] The first defense unit is used to limit the IP addresses of the target network segment to request access to the login site;

[0060] The second defense unit is used to detect whether the received access request contains a brute force attack, and if it is determined that a brute force attack exists, it blocks the IP address of the attack source;

[0061] The third defense unit is used to limit the firewall configuration operations to the preset bastion host IP address;

[0062] The fourth defense unit is used to perform vulnerability attack detection, botnet detection, and content security detection when a logged-in user or data center staff attempts to access the external network. If any of the following conditions is detected: vulnerability attack, botnet, or insecure content, the external network access will be interrupted.

[0063] The fifth defense unit is used to perform vulnerability attack detection, botnet detection, content security detection, web application protection, and website tampering prevention detection when the IP address of the target network segment requests to access the login site. If any of the following conditions are detected: vulnerability attack, botnet, or insecure access information, access to the login site will be interrupted.

[0064] The sixth defense unit is used to protect against ARP flood attacks, DOS / DDOS attacks, data packet attacks, and abnormal message attacks.

[0065] Specifically, the firewall of the present invention only supports the IP address of the target network segment to request the login site of the data center, preventing unauthorized IP addresses from accessing. After receiving the access request sent by the IP address of the target network, the access request is analyzed. If the IP address sends access requests more than the preset number of times per minute, it is determined that the access request of the IP address is a brute force attack. At this time, the IP address of the attack source is blocked, that is, the IP address is prevented from continuing to access the login site. When the user logged in to the data center or the staff of the data center accesses the external network, vulnerability attack detection, botnet detection and content security detection are performed to prevent internal users from encountering security threats when accessing the external network. When the IP address of the target network segment requests to access the login site, in addition to vulnerability attack, botnet and content security detection, Web application protection and website anti-tampering detection functions are added. This is because when external users access the business data of the data center, in addition to preventing vulnerability attacks, they also need to focus on protecting security issues at the Web application level, such as SQL injection, XSS attacks, etc., and prevent website content from being tampered with.

[0066] In one implementation, the intrusion prevention device includes:

[0067] A mirror data generation unit is used to capture traffic data in the network and mirror it to obtain traffic mirror data;

[0068] Traffic analysis unit, used to match traffic mirroring data with built-in protection rules and execute corresponding data interception or transmission based on the matching results;

[0069] The first vulnerability protection unit is used to protect the operating system and applications of the login site from vulnerabilities;

[0070] The second vulnerability protection unit is used to protect the operating systems and applications of the work computers of data center staff from vulnerabilities.

[0071] Specifically, the intrusion prevention device can monitor the traffic of the entire network, generate traffic mirror data and input it into the traffic analysis unit. The traffic analysis unit can analyze network traffic in real time, identify and block potential security threats. The first vulnerability defense unit can protect the login site from hacker attacks and malware, ensure the integrity and security of user data, and support preventing brute force cracking of system and application accounts and passwords. Applications on the login site include but are not limited to web browsers, DNS service applications, FTP service applications, TFTP service applications, Telnet service applications, mail service applications, database service applications, and media server logins. The second vulnerability defense unit ensures the security of the internal system of the data center, prevents the work computers of internal personnel from becoming a springboard or target for attackers, and defends against vulnerabilities in common applications, such as vulnerabilities in webactivex controls, web browsers, etc., and can intercept connections of malware on work computers.

[0072] In one implementation, the log audit module includes two log audit units, each of which includes:

[0073] Configuration subunit, used to configure the devices to be collected as switch modules, operation and maintenance modules, load balancing modules, security defense modules and login sites;

[0074] The log collection sub-unit is used to collect and save operation logs, network traffic information logs, and security event logs on the switch module, operation and maintenance module, load balancing module, security defense module, and login site;

[0075] The abnormality judgment subunit is used to analyze the collected logs and determine whether there are abnormalities;

[0076] The report and alarm generation subunit is used to generate abnormality reports and alarm information if there is an abnormality.

[0077] Specifically, the present invention integrates a single firewall function and a single log audit unit into a security all-in-one device. The network security system of the present invention deploys two such security all-in-one devices, which serve as the primary and backup for each other to ensure the high availability and reliability of the system. The log audit unit can configure the device to be collected, and then perform security analysis and audit on its log to promptly discover abnormal security events. In the present invention, the devices to be collected can be set as switch modules, operation and maintenance modules, load balancing modules, security defense modules and login sites. Specifically, the IP addresses of these modules and login credentials are input into the configuration subunit for configuration. After the connection is established, the log information of each module is collected regularly or in real time, and the collected logs are sent to the log audit unit for storage and analysis through the SYSLOG protocol. The log is kept for 180 days. During the analysis process, the logs of different devices and the logs of the same device in different time periods can be associated to identify more complex network attacks. If an abnormality is found in the analysis, an abnormality report and alarm information are generated to remind the user to take corresponding security measures in time.

[0078] In one implementation, the load balancing module includes:

[0079] IP mapping unit, used to map the intranet IP addresses of all login sites to preset external IP addresses;

[0080] The load balancing unit is used to balance the access requests to the login site according to a preset load balancing algorithm.

[0081] Specifically, the present invention maps the intranet IP addresses of all login sites to a fixed external IP address through IP address mapping. By hiding the intranet IP address and exposing only a fixed external IP address to external users, the risk of direct attacks on intranet sites can be reduced to a certain extent. When an access request is received, the access requests of each login site are balanced according to the load balancing algorithm, and the latest access request is distributed to the login site with a small load. It can ensure that even if a login site fails or its performance degrades, the access request can be quickly redirected to other healthy sites. This enhances the fault tolerance and stability of the system and improves the user experience. It avoids the situation where some sites are overloaded due to too many requests while other sites have idle resources, thereby improving overall resource utilization.

[0082] In one implementation, the operation and maintenance module includes a bastion host, a jump server, a Linux virtual machine and a Linux system host. The bastion host is used to record the operation methods, operation processes, operation results and system prompts of the operation and maintenance personnel, and supports behavior reproduction, security auditing, authority management and operation monitoring. The jump server is used for the operation and maintenance personnel to access the management page of the firewall, the Linux virtual machine is used to execute simulated network attacks, and the Linux system host is used as a system for simulating the attacked login site.

[0083] Specifically, the bastion host includes: an operation recording unit for recording the operation methods, operation processes, operation results, and system prompts of the operation and maintenance personnel; a behavior reproduction unit for reproducing selected operation records; a security audit unit for auditing the operation records and obtaining audit results; a permission management unit for managing the permissions of the operation and maintenance personnel; and an operation monitoring unit for real-time monitoring of the operation and maintenance personnel's operation behavior and generating prompts when abnormal operations are determined. The present invention utilizes the bastion host to effectively trace the operation process, quickly locate problems, and conduct subsequent security audits to ensure the authenticity, correctness, compliance, and effectiveness of the operation and maintenance operations. The bastion host can also manage the permissions of the operation and maintenance personnel, ensuring that only authorized personnel can perform specific operations, thereby enhancing system security. Real-time monitoring of the operation and maintenance personnel's operation behavior allows for the timely detection and handling of abnormal operations, ensuring system security. The present invention deploys a Windows system in a virtual machine as a jump server, allowing access to the firewall management interface only through this jump server. This approach further enhances system security. In addition, the present invention also sets up a Linux virtual machine to simulate network attacks and a Linux system host as the simulated target, whose system settings are consistent with the login site settings. By performing network attack simulations at irregular intervals, the current network security system can be further checked for vulnerabilities and further optimized. This method can effectively ensure the network security of the data center.

[0084] In one implementation, the switch module includes a first access switch, a core switch, a second access switch, and an out-of-band management switch.

[0085] Specifically, if Figure 2As shown, the first access switch is used to receive external access requests to the data center. This 10G fiber optic switch improves network throughput. The core switch forwards traffic between the data center's servers (including the login site, the computing center portal, the user management system, and the computer room environmental monitoring system), work computers, and network security systems, connecting various network nodes. The security appliance is deployed between the first access switch and the core switch. Its internal firewall effectively safeguards the data center's network security, and its internal log audit unit enables smooth access to logs from all devices to be collected. The intrusion prevention module connects the core switch and the first access switch via the network. Accessing the core switch mirrors internal network traffic, facilitating the detection and control of lateral network attacks (i.e., internal network attacks). Accessing the first access switch mirrors external network traffic, facilitating the detection and control of external network attacks. The second access switch is a 1G fiber optic switch. This second access switch serves as a downstream switch, connecting to the core switch at its upper end and computers, load balancing modules, jump servers, Linux virtual machines, and Linux system hosts in the data center's office area at its lower end. The out-of-band management switch is a gigabit fiber optic switch that connects the security appliance, core switch, and bastion host to facilitate the management of IP address segments.

[0086] In summary, a switch module for network connection is provided in the network security system of the data center; an operation and maintenance module is provided for configuring and managing all login sites, switch modules, load balancing modules, security defense modules and log audit modules; a load balancing module is provided for providing services to all login sites through preset external network IP addresses and balancing access requests of all login sites; a security defense module is provided for detecting and controlling external network attacks and / or internal lateral network attacks; and a log audit module is provided for collecting logs of each module and login site for monitoring and generating an alarm when abnormal behavior is detected. The present invention detects and controls external network attacks and / or internal lateral network attacks against login sites through the security defense module, thereby effectively improving the network security level of the data center.

[0087] In one embodiment, if Figure 3 As shown, based on the above-mentioned network security system of the data center, the present invention also provides a network security control method of the data center, including:

[0088] Step S100: Using the switch module to connect multiple login sites, operation and maintenance modules, load balancing modules, security defense modules, and log audit modules of the data center through the network;

[0089] Step S200: Utilize the operation and maintenance module to configure and manage all login sites, switch modules, load balancing modules, security defense modules, and log audit modules of the data center;

[0090] Step S300: Utilize the load balancing module to provide services to all login sites through the preset external network IP address and balance access requests to all login sites;

[0091] Step S400: Detect and control external network attacks and / or internal lateral network attacks against the login site using the security defense module;

[0092] Step S500: Use the log audit module to collect logs of the switch module, operation and maintenance module, load balancing module, security defense module and all login sites for monitoring, and generate an alarm when abnormal behavior is detected.

[0093] Specifically, the present invention utilizes a load balancing module to balance access requests across all login sites, effectively avoiding single point overload and improving overall performance and response speed. The security defense module effectively reduces the risk of cyberattacks on the data center and protects data integrity and confidentiality. The log audit module effectively improves system transparency and maintainability.

[0094] It should be noted that the aforementioned explanation of the embodiment of the network security system for a data center is also applicable to the network security control method for a data center of this embodiment, and will not be repeated here.

[0095] An embodiment of the present invention also provides a computer-readable storage medium, on which a network security control program for a data center is stored. When the network security control program for the data center is executed by a processor, the steps of any one of the network security control methods for a data center provided in an embodiment of the present invention are implemented.

[0096] It should be understood that the sequence numbers of the steps in the above embodiments do not imply a specific order of execution; the order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0097] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the above-mentioned device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of the present invention. The specific working process of the units and modules in the above-mentioned device can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.

[0098] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.

[0099] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.

[0100] In the embodiments provided by the present invention, it should be understood that the disclosed apparatus / terminal device and method can be implemented in other ways. For example, the apparatus / terminal device embodiments described above are merely illustrative. For example, the division of the modules or units described above is merely a logical functional division. In actual implementation, other division methods may be used. For example, multiple units or components may be combined or integrated into another device, or some features may be omitted or not implemented.

[0101] The embodiments described above are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, it should be understood by those skilled in the art that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features thereof may be replaced by equivalents. However, these modifications or replacements do not deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included in the scope of protection of the present invention.

Claims

1. A network security system for a data center, characterized in that: The system includes: a switch module, an operation and maintenance module, a load balancing module, a security defense module and a log audit module; The switch module is used to connect multiple login sites, operation and maintenance modules, load balancing modules, security defense modules and log audit modules of the data center through the network; The operation and maintenance module is used to configure and manage all login sites, switch modules, load balancing modules, security defense modules and log audit modules; The load balancing module is used to provide services to all login sites through the preset external network IP address and balance the access requests of all login sites; The security defense module is used to detect and control external network attacks and / or internal lateral network attacks against the login site; The log audit module is used to collect logs of the switch module, operation and maintenance module, load balancing module, security defense module and all login sites for monitoring, and generate alarms when abnormal behavior is detected.

2. The network security system for a data center according to claim 1, characterized in that: The security defense module includes two firewalls supporting active / standby switching and an intrusion prevention device.

3. The network security system for a data center according to claim 2, characterized in that: The firewall includes: The first defense unit is used to limit the IP addresses of the target network segment to request access to the login site; The second defense unit is used to detect whether the received access request contains a brute force attack, and if it is determined that a brute force attack exists, it blocks the IP address of the attack source; The third defense unit is used to limit the firewall configuration operations to the preset bastion host IP address; The fourth defense unit is used to perform vulnerability attack detection, botnet detection, and content security detection when a logged-in user or data center staff attempts to access the external network. If any of the following conditions is detected: vulnerability attack, botnet, or insecure content, the external network access will be interrupted. The fifth defense unit is used to perform vulnerability attack detection, botnet detection, content security detection, web application protection, and website tampering prevention detection when the IP address of the target network segment requests to access the login site. If any of the following conditions are detected: vulnerability attack, botnet, or insecure access information, access to the login site will be interrupted. The sixth defense unit is used to protect against ARP flood attacks, DOS / DDOS attacks, data packet attacks, and abnormal message attacks.

4. The network security system for a data center according to claim 2, characterized in that: The intrusion prevention device includes: A mirror data generation unit is used to capture traffic data in the network and mirror it to obtain traffic mirror data; Traffic analysis unit, used to match traffic mirroring data with built-in protection rules and execute corresponding data interception or transmission based on the matching results; The first vulnerability protection unit is used to protect the operating system and applications of the login site from vulnerabilities; The second vulnerability protection unit is used to protect the operating systems and applications of the work computers of data center staff from vulnerabilities.

5. The network security system for a data center according to claim 1, characterized in that: The log audit module includes two log audit units, each of which includes: Configuration subunit, used to configure the devices to be collected as switch modules, operation and maintenance modules, load balancing modules, security defense modules and login sites; The log collection sub-unit is used to collect and save operation logs, network traffic information logs, and security event logs on the switch module, operation and maintenance module, load balancing module, security defense module, and login site; The abnormality judgment subunit is used to analyze the collected logs and determine whether there are abnormalities; The report and alarm generation subunit is used to generate abnormality reports and alarm information if there is an abnormality.

6. The network security system for a data center according to claim 1, characterized in that: The load balancing module includes: IP mapping unit, used to map the intranet IP addresses of all login sites to preset external IP addresses; The load balancing unit is used to balance the access requests to the login site according to a preset load balancing algorithm.

7. The network security system for a data center according to claim 1, characterized in that: The operation and maintenance module includes a bastion host, a jump server, a Linux virtual machine and a Linux system host. The bastion host is used to record the operation methods, operation processes, operation results and system prompts of the operation and maintenance personnel, and supports behavior reproduction, security auditing, authority management and operation monitoring. The jump server is used for the operation and maintenance personnel to access the management page of the firewall, the Linux virtual machine is used to execute simulated network attacks, and the Linux system host is used as a system for simulating the attacked login site.

8. The network security system for a data center according to claim 7, characterized in that: The bastion host includes: Operation recording unit, used to record the operation methods, operation processes, operation results and system prompts of operation and maintenance personnel; A behavior reproduction unit, used to reproduce the selected operation records; Security audit unit, used to audit operation records and obtain audit results; The authority management unit is used to manage the authority of operation and maintenance personnel; The operation monitoring unit is used to monitor the operation behavior of the operation and maintenance personnel in real time and generate prompt information when it is determined that the operation of the operation and maintenance personnel is abnormal.

9. A network security control method for a network security system of a data center according to any one of claims 1 to 8, characterized in that: The method comprises: Utilize the switch module to connect multiple login sites, operation and maintenance modules, load balancing modules, security defense modules and log audit modules of the data center through the network; Use the operation and maintenance module to configure and manage all login sites, switch modules, load balancing modules, security defense modules and log audit modules of the data center; Utilize the load balancing module to provide services to all login sites through the preset external network IP address and balance the access requests of all login sites; Utilizing the security defense module to detect and control external network attacks and / or internal lateral network attacks against the login site; The log audit module is used to collect logs from the switch module, operation and maintenance module, load balancing module, security defense module and all login sites for monitoring, and generate alarms when abnormal behavior is detected.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a network security control program for a data center. When the network security control program for a data center is executed by a processor, the steps of the network security control method for a data center as claimed in claim 9 are implemented.