Network simulation method and device, electronic equipment and storage medium
By building a network simulation topology for network nodes with a hierarchical encapsulated security domain and configuring a virtual network simulation environment using existing node resources, the problem of inefficiency in traditional methods is solved, and efficient network simulation environment construction and rapid reconstruction are achieved.
Patent Information
- Application Number
- CN202510924185.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-04
- Publication Date
- 2025-08-29
AI Technical Summary
The traditional virtual network simulation environment construction method builds nodes in units of a single network device, resulting in low construction efficiency and low reconstruction efficiency.
The security domain in hierarchical encapsulation is used as network nodes to build a network simulation topology, and the first network node is configured using the node resources of the second network node existing in the network simulation topology to avoid node-by-node configuration.
The construction efficiency and reconstruction efficiency of the virtual network simulation environment are improved. By directly utilizing the existing node resource configuration, frequent access to basic resource management is reduced and the construction speed is improved.
Smart Images

Figure CN120567698A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of Internet technology, and more specifically, to a network simulation method, device, electronic device, and storage medium. Background Art
[0002] With the rapid development of internet technology, cybersecurity threats and challenges are increasing. Various attack methods and approaches, such as network attacks, program vulnerabilities, computer viruses, and malware, are constantly emerging. Consequently, virtual network simulation technology has emerged. Virtual network simulation technology enables network security simulations, offering advantages such as rapid verification of network security, reduced operating costs, and improved network visibility. Traditional methods for building virtual network simulation environments rely on virtualization management platforms or native OpenStack to generate and invoke virtualized simulation nodes to construct the virtual network simulation environment.
[0003] However, the above-mentioned virtual network simulation environment construction method constructs nodes based on single network devices when creating virtual and real nodes. It takes a lot of time to construct the entire virtual network simulation environment, which affects the construction efficiency of the virtual network simulation environment. Summary of the Invention
[0004] In view of this, the purpose of the present application is to provide a network simulation method, device, electronic device and storage medium to overcome at least one of the above-mentioned defects.
[0005] In a first aspect, an embodiment of the present application provides a network simulation method, comprising: Using hierarchically encapsulated security domains as network nodes, a network simulation topology is constructed; In response to a node configuration request for a network simulation topology, obtaining first network node information representing a configuration requirement of the first network node; Determining, based on node connection relationships between different network nodes, a second network node that matches the first network node information in the network simulation topology, where the second network node includes at least one child node; The node connection relationship is updated based on the sub-node connection relationship under the second network node, and the first network node is configured in the network simulation topology using the node resources of the second network node.
[0006] In an optional embodiment, the network simulation topology includes multiple levels of network nodes divided according to different security domains, and the multiple levels of network nodes include first-level network nodes corresponding to the network security domain, second-level network nodes of different business security domains under the same network system, and third-level network nodes of different terminals under the same business security domain.
[0007] In an optional implementation, each level of network nodes includes a firewall and a switch, and the network simulation topology uses the firewall to distinguish different security domains and uses the switch to record network connection relationships.
[0008] In an optional embodiment, the first network node information includes first-level and first sub-node information, and the first sub-node information is used to characterize the information of the sub-nodes under the first network node. The second network node that matches the first network node information in the network simulation topology is determined in the following manner: in the node relationship table that characterizes the node connection relationship, query the second network node corresponding to the first level and first sub-node information.
[0009] In an optional embodiment, the node configuration request includes a node addition request, and the first network node is configured in the network simulation topology in the following manner: based on the first network node information, the parent node of the first network node is determined; and the node resources of the second network node are copied to the parent node to add the first network node in the network simulation topology.
[0010] In an optional embodiment, the method also includes: if the second network node does not exist, adding a node label to the first network node and each child node under the first network node according to a preset naming rule; configuring the added node label in the node relationship table to update the node relationship table; constructing the first network node and the child nodes under the first network node according to the updated node relationship table; applying for resources for the first network node and the child nodes under the first network node, and updating the network simulation topology based on the first network node and the child nodes under the first network node after the resources are applied.
[0011] In an optional implementation manner, the node label is used to identify the type of the network node and mark the location of the network node in the network simulation topology.
[0012] In a second aspect, an embodiment of the present application further provides a network simulation device, the device comprising: A construction module is used to construct a network simulation topology using hierarchically encapsulated security domains as network nodes; an acquisition module, configured to acquire, in response to a node configuration request for a network simulation topology, first network node information representing a configuration requirement of a first network node; a matching module, configured to determine, based on node connection relationships between different network nodes, a second network node that matches the first network node information in the network simulation topology, wherein the second network node includes at least one sub-node; The configuration module is used to update the node connection relationship based on the sub-node connection relationship under the second network node, and configure the first network node in the network simulation topology using the node resources of the second network node.
[0013] In a third aspect, an embodiment of the present application further provides an electronic device comprising: a processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor. When the electronic device is running, the processor and the memory communicate through the bus, and when the machine-readable instructions are executed by the processor, the steps of the network simulation method described above are performed.
[0014] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the network simulation method as described above are executed.
[0015] The embodiments of the present application bring the following beneficial effects: The embodiments of the present application provide a network simulation method, apparatus, electronic device, and storage medium. These methods can, when configuring a virtual network simulation environment, utilize the node resources of a second network node already in a network simulation topology to configure a first network node. By simultaneously configuring all subnodes under the second network node directly into the network simulation topology, node-by-node configuration based on a single network device is avoided. Compared with network simulation methods in the prior art, these methods solve the problem of low efficiency in constructing a virtual network simulation environment.
[0016] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.
[0018] Figure 1 A flowchart of a network simulation method provided by an embodiment of the present application is shown; Figure 2 A schematic diagram showing the structure of the network simulation topology provided in an embodiment of the present application is shown; Figure 3 A flowchart of a network simulation topology construction method provided in an embodiment of the present application is shown; Figure 4 A schematic diagram showing the structure of a network simulation device provided in an embodiment of the present application is shown; Figure 5 A schematic structural diagram of an electronic device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0019] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application generally described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application for which protection is claimed, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, each other embodiment obtained by those skilled in the art without making creative work falls within the scope of protection of the present application.
[0020] It is worth noting that before the present application was filed, with the rapid development of Internet technology, the security threats and challenges facing cyberspace were also increasing day by day. Various attack means and methods such as network attacks, program vulnerabilities, computer viruses, and malware emerged in an endless stream. Therefore, virtual network simulation technology came into being. Virtual network simulation technology can perform network security deductions and has the advantages of quickly verifying network security, reducing operating costs, and improving network visibility. The traditional method of building a virtual network simulation environment relies on a virtualization management platform or native Openstack to generate and call virtualization simulation nodes to build a virtual network simulation environment.
[0021] However, the aforementioned virtual network simulation environment construction method constructs nodes based on individual network devices when creating both virtual and real nodes. This consumes a significant amount of time, impacting the efficiency of constructing the entire virtual network simulation environment. Furthermore, when reconstructing an existing virtual network simulation environment, adjustments must still be made to individual nodes, resulting in low reconstruction efficiency.
[0022] Based on this, an embodiment of the present application provides a network simulation method to improve the efficiency of constructing a virtual network simulation environment.
[0023] See also Figure 1 , Figure 1 This is a flow chart of a network simulation method provided by an embodiment of the present application. Figure 1 As shown, the network simulation method provided in the embodiment of the present application includes: Step S101, constructing a network simulation topology with hierarchically encapsulated security domains as network nodes; Step S102, in response to a node configuration request for a network simulation topology, obtaining first network node information representing a configuration requirement of a first network node; Step S103, determining a second network node that matches the first network node information in the network simulation topology based on the node connection relationship between different network nodes; Step S104 : updating the node connection relationship based on the sub-node connection relationship under the second network node, and configuring the first network node in the network simulation topology using the node resources of the second network node.
[0024] The second network node includes at least one sub-node.
[0025] The network simulation method provided in the embodiment of the present application can utilize the node resources of the second network node already in the network simulation topology to configure the first network node when configuring the virtual network simulation environment. By directly configuring all sub-nodes under the second network node into the network simulation topology at the same time, it avoids configuring each node one by one based on a single network device, thereby solving the problem of low efficiency in constructing the virtual network simulation environment.
[0026] To facilitate understanding of this embodiment, each of the above exemplary steps provided in the embodiment of the present application is described below.
[0027] In step S101, a network simulation topology is constructed with hierarchically encapsulated security domains as network nodes.
[0028] In this step, security domains can refer to dividing network resources into different security areas through logical or physical isolation. Each area implements specific security policies to reduce risk spread and achieve refined protection.
[0029] A network node may refer to a basic unit in a network topology, and a network node is a virtual node obtained through an encapsulation security domain.
[0030] A network simulation topology uses virtualization technology to simulate a real-world network structure and device interactions in a digital model, providing a test environment for network design, testing, and optimization. The network simulation topology includes multiple levels of network nodes, divided according to different security domains. These levels include first-level network nodes corresponding to the network security domain, second-level network nodes for different service security domains within the same network, and third-level network nodes for different terminals within the same service security domain.
[0031] Refer to the following Figure 2 To introduce the structure of the constructed network simulation topology.
[0032] Figure 2 The schematic diagram of the network simulation topology provided in the embodiment of the present application is shown in FIG. Figure 2As shown in the figure, first-level network nodes are encapsulated by network security domain. First-level network nodes include routers, firewalls, and core switches. The security protection of first-level network nodes is primarily used for network boundary security, encapsulating security devices such as network ciphers, channel ciphers, and firewalls. First-level network nodes are encapsulated as Group 0 (Rn (NPMn, ECMn)-Fn-CSWn (TPn)), where n represents the network sequence number. For example, n represents the number corresponding to different units and regions.
[0033] Rn (NPMn, ECMn) represents the internal encapsulation of the router in the first-level network node of the nth network system. Rn represents the router in the first-level network node of the nth network system. NPMn represents the network cipher machine encapsulated in the router. ECM represents the signal cipher machine encapsulated in the router. Fn represents the firewall in the first-level network node of the nth network system. CSWn (TPn) represents the internal encapsulation of the core switch in the first-level network node of the nth network system. CSWn represents the core switch in the first-level network node of the nth network system. TPn represents the traffic monitoring probe encapsulated in the router.
[0034] Secondary network nodes are encapsulated in business security domains. These nodes include firewalls, core switches, and access switches. Security protection for these nodes is primarily used for network-wide monitoring and includes security products such as traffic probes, security management, security auditing, and security posture monitoring. Secondary network nodes are encapsulated as Group 1 (Fn-CSWn-Fnm-SWnm).
[0035] Among them, Fn represents the firewall under the nth network system, CSWn represents the core switch in the nth network system, Fnm represents the firewall under the mth service under the nth network system, that is, the mth firewall used for access control and data isolation under CSWn, that is, the mth service domain, and SWnm represents the access switch under the mth service under the nth network system in the same access control zone as the firewall, that is, the access switch connected to CSWn.
[0036] The third-level network nodes are encapsulated based on the terminals within the business security domain. The third-level network nodes include third-level network node 1, third-level network node 2, and third-level network node 3. Each third-level network node includes a firewall, an access switch, and a terminal. The terminal includes business equipment and security equipment corresponding to the business.
[0037] The three-level network node encapsulation is Group2 (Fnm-SWnm-Rnmj (RPM, DAP, DAG, DCAP, DLP...)), where Rnmj represents the jth disk array in the mth service under the nth network system. Rnmj (RPM, DAP, DAG, DCAP, DLP) represents the disk array and its internal security encapsulation. R is the identifier corresponding to the disk array, and encapsulates RPM, DAP, DAG, DCAP, and DLP. Here, RPM (Requests Per Minute) represents the storage password machine, DAP (Device Access Policy) represents the device access protocol, DAG (Data Aggregation Gateway) represents the data aggregation gateway, DCAP (Dynamic Control Access Policy) represents the dynamic control access policy, and DLP (Data Leakage Prevention) represents data leakage prevention. In addition, different terminals can be encapsulated as different three-level network nodes. For example, a three-level network node can also be encapsulated as Group2 (Fnm-SWnm-Mnmj (EPP)) or Group2 (Fnm-SWnm-Tnmj, where Mnmj represents the j-th tape drive in the m-th service under the n-th network system, M is the identifier corresponding to the tape drive (Magnetic Tape Unit), and EPP (Endpoint Protection Platform) represents the terminal protection platform encapsulated inside the tape drive.
[0038] It should be noted that each level of network nodes in the constructed network simulation topology includes firewalls and switches. Firewalls are used to distinguish different security domains, and switches are used to record network connection relationships. Each business domain has its own access control policy. Each business domain is an independent security domain. Each business can include hardware and / or software. As an example, a business domain can be a data center, a studio, or a machine-to-machine interconnection. Taking the data center as an example, the data center business includes storage servers, access switches and other equipment. The data center security protection is access control, data transmission and storage security. The business package includes business hardware and software and business-related security protection equipment such as firewalls, storage password machines, database audits, and database security protection. Taking the terminal business as an example, the business includes servers and various terminals. The corresponding security protection software and hardware products are mainly system security protection. The business package includes terminal business hardware and software products and corresponding trusted modules, identity authentication, host integrated protection systems and antivirus software and other security protection products.
[0039] Refer to the following Figure 3The network simulation method provided in the embodiment of the present application is applied to a network simulation system, which includes a receiving and checking module, an encapsulation module, a basic resource management module, and a node management module.
[0040] Figure 3 A flowchart of the network simulation topology construction method provided in an embodiment of the present application is shown. Figure 3 As shown, the network simulation topology construction method includes: Step S1011 : In response to a task for creating a network simulation topology, task information is acquired.
[0041] The receiving and verification module receives the created task, obtains the task information from the created task, and generates a unified descriptive file based on the task information. For example, this file can be in XML format. The task information includes, but is not limited to, a network topology diagram, background traffic, and foreground traffic. The network topology diagram includes multiple interconnected network devices, including firewalls, routers, core switches, and access switches.
[0042] For example, if the task information is a task file, the task information in the task file is extracted and written into the unified descriptive file, so as to convert the task file into the unified descriptive file.
[0043] The receiving and verifying module sends the unified descriptive file to the encapsulation module.
[0044] Step S1012: encapsulate network nodes according to task information.
[0045] After receiving the unified descriptive file, the encapsulation module encapsulates the network node according to the task information in the unified descriptive file. Here, the network node encapsulation process is divided into three steps: In the first step, a node label is set for each network node described by the task information in the unified descriptive file using the preset naming rules.
[0046] The preset naming rules include distinguishing different levels of network nodes by network device type and the number of subscripts, using preset characters to represent network devices, using numbers to represent network node numbers, and using preset symbols to indicate that a node contains a network device or protocol. For example, the preset symbol could be "()"; the preset character F represents a firewall, the preset character R represents a router, the preset character CSW represents a core switch, and the preset character SW represents an access switch. Furthermore, in the preset naming rules, the network node number of a child node includes the network node number of the parent node.
[0047] For example, Rn(NPMn, ECMn) indicates the nth router encapsulated with NPM and ECM, and CSWn(TPn) indicates the nth core switch encapsulated with TP.
[0048] The encapsulation module extracts the task information and sets a node label for each network device in the task information according to the preset naming rules to proceed to the second step.
[0049] The second step is to generate a node relationship table based on the node labels and the connection relationships between different network nodes.
[0050] The encapsulation module adds node labels to the node relationship table according to the connection relationship between different network nodes to proceed to step 3. While generating the node relationship table, the node relationship table is sent to the node management module.
[0051] There may be overlapping network devices between network nodes of different levels. For example, a first-level network node includes a router, a firewall, and a core switch; a second-level network node includes the firewall and core switch in the first-level network node, as well as the firewall and access switch of the second-level network node itself; a third-level network node includes the firewall, access switch, and terminal of the second-level network node itself.
[0052] The third step is to encapsulate network nodes according to the node relationship table.
[0053] The encapsulation module encapsulates network nodes by calling a preset encapsulation function according to the node relationship table.
[0054] The following describes the encapsulation process of network nodes by taking the encapsulation of a three-level network node as an example. The program code for encapsulating a network node is as follows: FUNCTIONGroup2DataCenter(); Storage=StorageDevice("SSD","40TB"); AuditLog=enableDatabaseAuditing(Database); Security=configureDatabaseSecurity(Database); RPM=StorageRPMachine; RETURN{Storage,AuditLog,SecurityRPM}.
[0055] Among them, Storage is used to deploy storage devices; AuditLog is used for database auditing; Security is used for database security protection; RPM is used to store password machines.
[0056] In this embodiment of the present application, encapsulation functions for network nodes at different levels have been established in advance. When encapsulating network nodes at each level in the node relationship table, it is only necessary to call the encapsulation function corresponding to the corresponding level and the configuration requirements of the corresponding network node. For example, when encapsulating a third-level network node in the node relationship table, it is only necessary to call the Group2DataCenter() function to implement the third-level network node encapsulation. Step S1013: store the node relationship table and apply for resources for each network node.
[0057] The node management module receives the node relationship table sent by the encapsulation module, and stores the node relationship table with the node labels added thereto in the node management module to establish a mirror image of each network node.
[0058] After storing the node relationship table, the node management module sends a resource request to the basic resource management module for each network node in the network simulation topology.
[0059] The basic resource management module receives resource requests and allocates corresponding virtual and real resources to each network node. The virtual and real resources may refer to virtual resources and / or real resources.
[0060] Step S1014: configure the network simulation topology.
[0061] The node management module configures the network simulation topology according to the allocated virtual and real resources, for example: drawing the network simulation topology diagram, configuring the interface IP, defining the security zone, and performing connectivity testing.
[0062] In step S102, in response to a node configuration request for a network simulation topology, first network node information representing a configuration requirement of a first network node is obtained.
[0063] In this step, the node configuration request may refer to a configuration request for a network node. As an example, the node configuration request may be a node addition request.
[0064] The node configuration request is used to configure a network node in a network simulation topology. The network node configured in the node configuration request is referred to as a first network node. The node configuration request includes first network node information. The first network node information is used to represent the configuration requirements of the first network node.
[0065] The first network node information includes the node label of the first network node. If the first network node is a first-level network node or a second-level network node, the first network node information also includes node information of all sub-network nodes under the first network node.
[0066] As an example, if the first network node is a secondary network node, the first network node information includes Group1 ( - - - )、Group2( - - (DAP, DAG, DCAP). In addition, the first network node information can also be represented in the form of a network topology diagram.
[0067] From the first network node information Group1, we can know that the first network node is a secondary network node. - - (DAP, DAG, DCAP)) can know the child node information of the first network node, that is, the first network node information includes the first level and the first child node information, and the first child node information is used to represent the information of the child nodes under the first network node.
[0068] In an embodiment of the present application, a node configuration request for a network simulation topology is equivalent to a node creation task. The receiving and verification module receives the node creation task and obtains the first network node information from the node creation task.
[0069] In step S103 , based on the node connection relationship between different network nodes, a second network node matching the first network node information in the network simulation topology is determined.
[0070] In this step, the second network node may refer to a target network node to be configured, and the first network node and the second network node may be the same network node or different network nodes.
[0071] For example: when the node configuration request is to add a network node in the existing network simulation topology, there is no first network node in the constructed network simulation topology. The configuration of the first network node can be quickly implemented by querying the second network node in the existing network simulation topology that matches the first network node information. At this time, the first network node and the second network node are different network nodes.
[0072] When the node configuration request is to modify the node information of a network node in an existing network simulation topology, the first network node may already exist in the constructed network simulation topology. The configuration of the first network node can be quickly implemented by querying the second network node that matches the first network node information in the existing network simulation topology. At this time, the first network node and the second network node are the same network node.
[0073] When the second network node is a primary network node or a secondary network node, the second network node includes at least one sub-node.
[0074] In an embodiment of the present application, the node management module stores a node relationship table that represents the node relationships between all nodes in the current network simulation topology. Upon receiving a node configuration request, the node management module determines, based on the node relationship table, whether a second network node matching the first network node information exists in the network simulation topology.
[0075] In one case, if there is a second network node that matches the first network node information, step S104 is executed.
[0076] In another case, if there is no second network node matching the first network node information, the first network node is configured. In this case, the first network node is configured with reference to the process of constructing the network simulation topology.
[0077] For example: if the second network node does not exist, a node label is added to the first network node and each sub-network node under the first network node according to the preset naming rules; the added node label is configured in the node relationship table to update the node relationship table; according to the updated node relationship table, the first network node and the sub-network nodes under the first network node are constructed and encapsulated; resources are applied for the first network node and the sub-network nodes under the first network node, and the network simulation topology is updated and configured based on the first network node and the sub-network nodes under the first network node after the resources are applied.
[0078] In one example, when determining whether there is a second network node that matches the first network node information in the network simulation topology, it is possible to query in the node relationship table that represents the node connection relationship whether there is a network node corresponding to the first level and first sub-node information. If there is a network node corresponding to the first level and first sub-node information, then the network node is used as the second network node.
[0079] The query method of the second network node is described in detail below with reference to Table 1.
[0080] Table 1: Node relationship table before update.
[0081]
[0082] As shown in Table 1, in the node relationship table, the first-level network node Group0 ( - - ( )) include Group1 ( - - - )、Group1( - - - )、Group1( - - - ) three secondary network nodes. Assume that the first network node information includes Group1 ( - - - )、Group2( - - (DAP, DAG, DCAP)), it can be determined that the first-level network node Group0 ( - - ( )) Add a secondary network node Group1 ( - - - ), and the newly added secondary network node includes a third-level network node Group2 ( - - (DAP, DAG, DCAP)).
[0083] It should be noted that the node relationship table may include multiple first-level network nodes, but only one first-level network node is listed here, namely Group1 ( - - - ), the first-level network node can also be Group1 ( - - - )、Group1( - - - ) etc., which are not listed here.
[0084] In step S104, the node connection relationship is updated based on the sub-node connection relationship under the second network node, and the first network node is configured in the network simulation topology using the node resources of the second network node.
[0085] In an embodiment of the present application, taking the node configuration request as an example of a node addition request, if there is a second network node, the node management module can configure the first network node in the network simulation topology in the following manner: based on the first network node information, determine the parent node of the first network node; copy the node resources of the second network node to the parent node to add the first network node in the network simulation topology.
[0086] Taking the above example as an example, when adding a secondary network node, the node management module will set a node label for the newly added secondary network node based on the existing network node data in the node relationship table.
[0087] For example: the first network node information includes Group1 ( - - - )、Group2( - - (DAP, DAG, DCAP)), since the second network node Group1 ( - - - ) already includes Group2 ( - - (DAP, DAG, DCAP)), Group2 ( - - )、Group2( - - ) three third-level network nodes. Therefore, the newly added second-level network nodes are automatically numbered and added to the existing second-level network node Group1 ( - - - ) plus one to the secondary network node number "2", the newly added secondary network node is Group1 ( - - - ), the third-level network node under the added second-level network node is Group2 ( - - (DAP, DAG, DCAP)).
[0088] Then, the node management module fills the newly added node label into the node relationship table to update the node relationship table.
[0089] The updated node relationship table is shown in Table 2: Table 2: Updated node relationship table.
[0090]
[0091] As shown in Table 2, a set of data is added in the last row, which includes 、 、 (DAP, DAG, DCAP), this group of data represents the added secondary network nodes and the tertiary network nodes under the added secondary network nodes.
[0092] Then, based on the updated node relationship table, the node resources of the second network node are directly copied to the parent node to add the first network node to the network simulation topology. This shows that the present application can directly configure the first network node using the existing node resources of the second network node, eliminating the need to frequently access the basic resource management module or individually configure network nodes based on individual network devices. This greatly improves the efficiency of building the network simulation topology and the network simulation environment.
[0093] In an optional embodiment of the present application, the node configuration request includes a node deletion request. When the network topology module receives the node deletion request, the node relationship table stored in the node management module queries whether there is a second network node that matches the first network node to be deleted. If the second network node exists, the node management module deletes the upper and lower connection relationships of the second network node in the network simulation topology, and directly deletes the second network node in the node relationship table, returns the node resources used by the second network node to the node management module, and releases the node resources used by the second network node to achieve rapid update of the network simulation topology. In an embodiment of the present application, during the operation of a network simulation task, the connection relationship between network nodes of different levels will be mirrored and stored in a node management module. When adding existing network nodes in the network simulation topology, the existing network nodes can be directly used to achieve rapid configuration. There is no need to reconfigure network nodes based on individual network devices one by one, nor is there a need to frequently request resources from the underlying layer, thereby achieving rapid construction of a network simulation environment and elastic scaling of the network simulation environment.
[0094] Based on the same inventive concept, a network simulation device corresponding to the network simulation method is also provided in the embodiment of the present application. Since the principle of solving the problem by the device in the embodiment of the present application is similar to the above-mentioned network simulation method in the embodiment of the present application, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be repeated.
[0095] See also Figure 4 , Figure 4 This is a schematic diagram of the structure of a network simulation device provided in an embodiment of the present application. Figure 4 As shown in , the network simulation device 200 includes: A construction module 201 is used to construct a network simulation topology using hierarchically encapsulated security domains as network nodes; An acquisition module 202 is configured to acquire, in response to a node configuration request for a network simulation topology, first network node information representing a configuration requirement of a first network node; A matching module 203 is configured to determine, based on node connection relationships between different network nodes, a second network node that matches the first network node information in the network simulation topology, where the second network node includes at least one child node; The configuration module 204 is configured to update the node connection relationship based on the sub-node connection relationship under the second network node, and configure the first network node in the network simulation topology using the node resources of the second network node.
[0096] See also Figure 5 , Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Figure 5 As shown in FIG, the electronic device 300 includes a processor 310 , a memory 320 and a bus 330 .
[0097] The memory 320 stores machine-readable instructions executable by the processor 310. When the electronic device 300 is running, the processor 310 communicates with the memory 320 via the bus 330. When the machine-readable instructions are executed by the processor 310, the above-mentioned Figure 1 The specific implementation of the steps of the network simulation method in the method embodiment shown can be found in the method embodiment and will not be repeated here.
[0098] The embodiment of the present application also provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the computer program can execute the above-mentioned Figure 1 The specific implementation of the steps of the network simulation method in the method embodiment shown can be found in the method embodiment and will not be repeated here.
[0099] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0100] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. There may be other division methods in actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed may be through some communication interface, indirect coupling or communication connection of devices or units, which may be electrical, mechanical or other forms.
[0101] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0102] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0103] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium that is executable by a processor. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program code, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0104] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present application, which are used to illustrate the technical solutions of the present application, rather than to limit them. The scope of protection of the present application is not limited thereto. Although the present application has been described in detail with reference to the above-mentioned embodiments, those skilled in the art should understand that any person skilled in the art can modify or easily conceive of changes to the technical solutions described in the above-mentioned embodiments within the technical scope disclosed in the present application, or perform equivalent replacements for some of the technical features thereof. These modifications, changes, or replacements do not deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A network simulation method, characterized in that: include: Using hierarchically encapsulated security domains as network nodes, a network simulation topology is constructed; In response to a node configuration request for the network simulation topology, obtaining first network node information representing a configuration requirement of the first network node; Determining, based on a node connection relationship between different network nodes, a second network node that matches the first network node information in the network simulation topology, where the second network node includes at least one child node; The node connection relationship is updated based on the sub-node connection relationship under the second network node, and the first network node is configured in the network simulation topology using the node resources of the second network node.
2. The method according to claim 1, characterized in that The network simulation topology includes multiple levels of network nodes divided according to different security domains. The multiple levels of network nodes include first-level network nodes corresponding to the network security domain, second-level network nodes of different business security domains under the same network system, and third-level network nodes of different terminals under the same business security domain.
3. The method according to claim 2, characterized in that Each level of network nodes includes a firewall and a switch. The network simulation topology uses the firewall to distinguish different security domains and uses the switch to record network connection relationships.
4. The method according to claim 2, characterized in that The first network node information includes first-level and first child node information, where the first child node information is used to represent information of child nodes under the first network node. A second network node matching the first network node information in the network simulation topology is determined in the following manner: In a node relationship table representing the node connection relationship, a second network node corresponding to the first level and the first sub-node information is searched.
5. The method according to claim 4, characterized in that The node configuration request includes a node addition request, and the first network node is configured in the network simulation topology in the following manner: Determining a parent node of the first network node based on the first network node information; The node resources of the second network node are copied to the parent node to add the first network node to the network simulation topology.
6. The method according to claim 4, characterized in that The method further comprises: If the second network node does not exist, adding a node label to the first network node and each child node under the first network node according to a preset naming rule; Configuring the added node label in the node relationship table to update the node relationship table; Constructing the first network node and the child nodes under the first network node according to the updated node relationship table; Apply for resources for the first network node and the sub-nodes under the first network node, and update the network simulation topology according to the first network node and the sub-nodes under the first network node after the resources are applied.
7. The method according to claim 6, characterized in that The node label is used to identify the type of the network node and the location of the network node in the network simulation topology.
8. A network simulation device, characterized in that: include: A construction module is used to construct a network simulation topology using hierarchically encapsulated security domains as network nodes; an acquisition module, configured to acquire, in response to a node configuration request for the network simulation topology, first network node information representing a configuration requirement of a first network node; Matching module, Used for Determining, based on a node connection relationship between different network nodes, a second network node that matches the first network node information in the network simulation topology, where the second network node includes at least one child node; A configuration module is used to update the node connection relationship based on the sub-node connection relationship under the second network node, and use the node resources of the second network node to configure the first network node in the network simulation topology.
9. An electronic device, characterized in that: include: A processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor. When the electronic device is running, the processor and the memory communicate via the bus, and the processor executes the machine-readable instructions to perform the steps of the network simulation method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, executes the steps of the network simulation method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Fast configuration method for large-scale smart-grid communication simulation platform
CN107391815A
Networking method and apparatus, computing device and storage medium
CN113452567A
Porting Virtual Images Between Platforms
US20110161952A1
Method for generating a simulated network using a graphical user interface
US7225117B1