Cloud computing-oriented high-reliability switch security access method, system and device
Through hierarchical processing of identity authentication, basic function self-test and security assessment, the misjudgment problem of high-reliability switch security access method during business peak hours is solved, and the accuracy of high-reliability switch security access and the continuity of network services are achieved.
Patent Information
- Application Number
- CN202511022959.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-24
- Publication Date
- 2025-09-05
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, highly reliable switch secure access methods are prone to misjudgment during business peak periods, resulting in fluctuations in network performance and insufficient accuracy.
The accuracy and security of the switch at access time are ensured through hierarchical processing of identity authentication, basic function self-check, security assessment and adjustment, including identity authentication, basic function self-check of access, security assessment and adjustment, and comprehensive analysis and adjustment using the authentication server, switch database and operating system software.
It improves the accuracy of switch security access, protects internal enterprise network resources, prevents data leakage and illegal access, and ensures the continuity of network services and data security.
Smart Images

Figure CN120602212A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of switch data processing technology, and in particular to a high-reliability switch security access method, system, and device for cloud computing. Background Art
[0002] With the rapid development of emerging technologies such as cloud computing, big data, and the Internet of Things, data centers are growing in size and complexity. As the core infrastructure for these technologies, the security, reliability, and efficiency of cloud computing data centers are paramount. Switches, as core equipment in data centers, are responsible for efficient network connectivity and data transmission. Their high reliability and security are key factors in ensuring stable data center operations. Furthermore, with the surge in IoT devices, demand for high-performance, highly reliable switches is also increasing across various industries.
[0003] The existing high-reliability switch security access method for cloud computing is implemented through the following steps. For example, virtualization capability supports virtualization capability of 1:8 or more. Through MDC (multi-service customer sharing) technology, a physical switch is virtualized into multiple logical switches to improve resource utilization and reduce investment costs; fully orthogonal architecture, the core switch adopts a fully orthogonal architecture, that is, the device switching matrix board and line board are orthogonally connected to improve the reliability and ventilation and heat dissipation capabilities of the equipment; intrinsic security technology based on mimetic architecture defends against unknown attacks and vulnerability backdoors by dynamically transforming and reconfiguring system resources; security measures are deployed in the three-layer network model of access, aggregation and core, and cooperate with the network security situation awareness platform to monitor the network security status.
[0004] For example, the invention patent announcement with announcement number: CN112099913B discloses a method for implementing secure isolation of virtual machines based on OpenStack, including: creating a first available zone (AZ) and a second AZ through the Nova component; allocating a first physical link access mode to the network card of a service machine connected to the first AZ, the service machine including two or more network cards, and the first physical link access mode is used to access a management network switch and an intranet switch; allocating a second physical link access mode to the network card of a service machine connected to the second AZ, the service machine including two or more network cards, and the second physical link access mode is used to access a management network switch and a DMZ zone switch; selecting a service machine connected to the first AZ, and configuring a first dynamic server configuration protocol DHCP service for the service machine; selecting a service machine connected to the second AZ, and configuring a second DHCP service for the service machine.
[0005] For example, the invention patent publication number CN111309386B discloses a switch hardware driver system and a switch, comprising: a hardware base driver layer comprising the switch's hardware driver modules, and each hardware driver module having a corresponding number of function call interfaces configured according to its function; each hardware driver module is configured to drive a hardware component of the switch; a hardware driver abstraction layer comprising a corresponding number of interface encapsulation modules, and a user space interface configured for each interface encapsulation module, allowing an application program to call the corresponding interface encapsulation module; a one-to-one correspondence between the function call interfaces and the interface encapsulation modules, with each function call interface being encapsulated within its corresponding interface encapsulation module. The switch hardware driver employs the switch hardware driver system.
[0006] However, in the process of implementing the technical solutions of the invention in the embodiments of the present application, the present application found that the above technology has at least the following technical problems: Existing technologies require high-bandwidth, high-reliability, and low-latency network environments for large enterprise networks. High-availability technologies such as VRRP (Virtual Router Redundancy Protocol) and Multi-Layered Access Group (M-LAG) can achieve load balancing and failover across multiple switches. However, the security requirements for secure access are prone to misjudgment due to fluctuations in switch network performance during peak business periods, resulting in insufficient accuracy for secure access methods using highly reliable switches. Summary of the Invention
[0007] The embodiments of the present application solve the problem of insufficient accuracy of the high-reliability switch security access method in the prior art by providing a high-reliability switch security access method, system and device for cloud computing, thereby achieving the effect of improving the accuracy of the reliable switch security access method.
[0008] An embodiment of the present application provides a highly reliable switch security access method for cloud computing, comprising the following steps: a user accesses a target terminal through a switch, the switch performs identity authentication based on user input information, and performs a first security access process based on the identity authentication result; a basic access function self-test is performed on the switch after the first security access process, and a second security access process is performed based on the basic access function self-test result; a first access security assessment is performed on the switch after the second security access process to obtain a first switch security assessment value, a first comparative analysis is performed based on the first switch security assessment value, and a first security access adjustment is performed based on the first comparative analysis result; a second access security assessment is performed on the switch to be assessed to obtain a comprehensive switch security assessment value, a second comparative analysis is performed based on the comprehensive switch security assessment value, and a second security access adjustment is performed based on the second comparative analysis result.
[0009] Furthermore, the switch performs identity authentication based on user input information, specifically including: when the user accesses the network of the target terminal through the switch port, the switch sends an identity authentication request to the user through the authentication server; the authentication server receives the authentication request sent by the switch and performs identity authentication based on the user input information; if the identity authentication is successful, the authentication server sends authorization information to the switch and allows the user to access network resources; if the identity authentication fails, the authentication server sends a non-authorization information to the switch, denies the user from calling the switch to access network resources, and alerts relevant personnel.
[0010] Furthermore, the switch after the first security access processing is subjected to a basic access function self-test, specifically comprising: directly extracting a switch access basic function self-test plan from a switch security access database; performing a basic access function self-test on the switch after the first security access processing according to the switch access basic function self-test plan; the switch access basic function self-test plan includes a switch hardware self-test, a switch software self-test, and a switch access security self-test; if the result of the switch access basic function self-test plan is determined to be passed, accessing the target terminal's network through the switch port and shutting down the switch; if the result of the switch access basic function self-test plan is determined to be failed, issuing an alarm to notify relevant personnel.
[0011] Furthermore, the switch after the second security access processing is subjected to the first access security assessment, and the specific process is as follows: the switch records the MAC address learning rate, MAC address table capacity utilization, MAC address, LLDP message rate and STP topology change times through the built-in operating system software; if the MAC address is in the predefined MAC address in the switch security access database, it is not adjusted; if the MAC address is not in the predefined MAC address in the switch security access database, the corresponding MAC address is recorded as the MAC address to be learned and the switch is made to learn the corresponding MAC address through the built-in operating system software; if the number of MAC addresses to be learned is equal to or greater than the threshold number of MAC addresses to be learned, an alarm is issued to notify relevant personnel ; If the number of MAC addresses to be learned is less than the threshold of the number of MAC addresses to be learned, no adjustment is made; if the MAC address table capacity usage is less than or equal to the threshold of the MAC address table capacity usage, no adjustment is made; if the MAC address table capacity usage is greater than the threshold of the MAC address table capacity usage, an alarm is issued to notify relevant personnel; if the MAC address is in the predefined MAC addresses in the switch security access database and the number of MAC addresses to be learned is less than the threshold of the number of MAC addresses to be learned and the MAC address table capacity usage is less than or equal to the threshold of the MAC address table capacity usage, then the first security assessment value of the switch is obtained through comprehensive analysis of the MAC address table capacity usage, the number of MAC addresses to be learned, the LLDP message rate and the number of STP topology changes.
[0012] Furthermore, the first adjustment of security access is performed based on the first comparative analysis result, specifically including: if the switch security first evaluation value is less than the switch security first evaluation security threshold, the switch is recorded as a switch to be evaluated; if the switch security first evaluation value is equal to or greater than the switch security first evaluation security threshold, the corresponding port where abnormal traffic is detected is closed by the switch, the abnormal traffic is redirected to the network security port, BPDU protection is enabled and root protection is started, and relevant personnel are notified to set the switch MAC address table capacity utilization threshold and configure BPDU protection parameters and root protection parameters.
[0013] Furthermore, the second access security assessment of the switch to be assessed specifically includes: if the flow rate of the switch abnormal flow value of the switch to be assessed is equal to or greater than the flow rate threshold of the switch abnormal flow value, issuing an alarm to notify relevant personnel; if the flow rate of the switch abnormal flow value of the switch to be assessed is less than the flow rate threshold of the switch abnormal flow value, obtaining a second switch security assessment value through comprehensive analysis of the switch abnormal flow value, the switch abnormal flow value flow rate, the switch connection number parameter, and the error or retransmission message parameter in the switch.
[0014] Furthermore, the performing of the second access security assessment on the switch to be assessed further includes: performing the first access security assessment and the second access security assessment on the switch to be assessed to obtain a first switch security assessment value and a second switch security assessment value of the switch to be assessed; and obtaining a switch security comprehensive assessment value by comprehensively analyzing the first switch security assessment value and the second switch security assessment value of the switch to be assessed. The specific analysis is as follows: sequentially numbering the first switch monitoring time periods corresponding to the second access security assessment of the switch to be assessed, Indicates the number of the switch's first monitoring time period. , Indicates the total number of numbers in the first monitoring time period of the switch; Indicates the The switch security comprehensive evaluation value of the first monitoring period of each switch is used to quantify the relative negative comprehensive degree of network security threats to the switch to be evaluated; ; Indicates the A first switch security assessment value for a first monitoring period of a switch; Indicates the A second switch security assessment value for each switch in a first monitoring time period; Indicates the The maximum switch access delay of each switch in the first monitoring time period; Indicates the The maximum switch access delay of each switch in the first monitoring time period; Indicates the The average switch access delay of each switch in the first monitoring period; Indicates the a weight factor of a switch security first evaluation value of a switch in a first monitoring time period, wherein the weight factor of the switch security first evaluation value is directly extracted from a switch security access database; Indicates the The weight factors of the second switch security evaluation values in the first monitoring time period of each switch are directly extracted from the switch security access database.
[0015] Furthermore, the second adjustment of security access is performed based on the second comparative analysis result, specifically including: if the switch security comprehensive evaluation value is less than the switch security comprehensive evaluation threshold, no adjustment is made; if the switch security comprehensive evaluation value is equal to or greater than the switch security comprehensive evaluation threshold, the control plane CPU redundancy switching of the switch is performed through a predefined redundant switching scheme, and the bandwidth utilization of the internal port of the switch is recorded; if the bandwidth utilization of the internal port of the switch is less than the bandwidth utilization threshold, no adjustment is made; if the bandwidth utilization of the internal port of the switch is equal to or greater than the bandwidth utilization threshold, the corresponding port is recorded as an early warning port and the number of early warning ports is recorded; if the number of early warning ports is less than the early warning port number threshold, no adjustment is made; if the number of early warning ports is equal to or greater than the early warning port number threshold, the corresponding early warning port is disconnected and an alarm is issued to notify relevant personnel.
[0016] An embodiment of the present application provides a highly reliable switch security access system for cloud computing, including a full access first processing module, a security access second processing module, a security access first adjustment module, and a security access second adjustment module: the security access first processing module is used for a user to access a target terminal through a switch, the switch performs identity authentication based on user input information, and performs a first security access processing based on the identity authentication result; the security access second processing module is used to perform a basic access function self-test on the switch after the first security access processing, and perform a second security access processing based on the basic access function self-test result; the security access first adjustment module is used to perform a first access security assessment on the switch after the second security access processing, obtain a first switch security assessment value, perform a first comparative analysis based on the first switch security assessment value, and perform a first security access adjustment based on the first comparative analysis result; the security access second adjustment module is used to perform a second access security assessment on the switch to be assessed, obtain a comprehensive switch security assessment value, perform a second comparative analysis based on the comprehensive switch security assessment value, and perform a second security access adjustment based on the second comparative analysis result.
[0017] An embodiment of the present application provides a highly reliable switch security access device for cloud computing, including a switch host: the switch host is configured to enable the highly reliable switch security access device for cloud computing to implement any one of the highly reliable switch security access methods for cloud computing.
[0018] One or more technical solutions provided in the embodiments of this application have at least the following technical effects or advantages: 1. By performing hierarchical processing of identity authentication and self-checking of basic access functions during switch access, as well as hierarchical analysis and adjustment after the first and second access security assessments, the accuracy of the reliable switch security access method is improved, solving the problem of insufficient accuracy of the high-reliability switch security access method in the existing technology.
[0019] 2. Perform the first secure access process based on the identity authentication results and the second secure access process based on the access basic function self-test results to protect the internal network resources of the enterprise, prevent data leakage and illegal access, and ensure that only authorized users and devices can access cloud resources, thereby achieving the reliability of the high-reliability switch security access method for cloud computing.
[0020] 3. Make a second adjustment to secure access based on the results of the second comparative analysis. By discovering and resolving potential security issues in advance, network interruptions and failures are avoided, and the continuity of network services is guaranteed. At the same time, when serious security threats are detected, a predefined redundant switching plan is executed to ensure the stable operation of the control plane CPU, thereby improving the availability of network services. This protects the internal network of the data center from various security threats, ensuring data security and business continuity. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 A flow chart of a highly reliable switch secure access method for cloud computing provided in an embodiment of the present application; Figure 2 This is a structural diagram of a highly reliable switch secure access system for cloud computing provided in an embodiment of the present application. DETAILED DESCRIPTION
[0022] The embodiments of the present application solve the problem of insufficient accuracy of the high-reliability switch security access method in the prior art by providing a high-reliability switch security access method, system and device for cloud computing, thereby achieving the effect of improving the accuracy of the reliable switch security access method.
[0023] In order to better understand the above technical solution, the above technical solution will be described in detail below with reference to the accompanying drawings and specific implementation methods.
[0024] like Figure 1As shown, it is a flow chart of a high-reliability switch security access method for cloud computing provided by an embodiment of the present application. The method is applied to a high-reliability switch security access system for cloud computing. The method includes the following steps: a user accesses a target terminal through a switch, the switch performs identity authentication based on user input information, and performs a first security access process based on the identity authentication result; a basic access function self-check is performed on the switch after the first security access process, and a second security access process is performed based on the basic access function self-check result; a first access security assessment is performed on the switch after the second security access process to obtain a first switch security assessment value, a first comparative analysis is performed based on the first switch security assessment value, and a first security access adjustment is performed based on the first comparative analysis result; a second access security assessment is performed on the switch to be assessed to obtain a comprehensive switch security assessment value, a second comparative analysis is performed based on the comprehensive switch security assessment value, and a second security access adjustment is performed based on the second comparative analysis result.
[0025] Furthermore, the switch performs identity authentication based on the user input information, specifically including: when the user accesses the network of the target terminal through the switch port, the switch sends an identity authentication request to the user through the authentication server; the authentication server receives the authentication request sent by the switch and performs identity authentication based on the user input information; if the identity authentication is successful, the authentication server will send authorization information to the switch and allow the user to access network resources; if the identity authentication fails, the authentication server will send an unauthorized information to the switch, denying the user from calling the switch to access network resources and alerting relevant personnel.
[0026] In this embodiment, the highly reliable switch secure access method for cloud computing generally involves multiple steps in identity authentication to ensure that only authorized users and devices can access the network.
[0027] When a user accesses the network through a switch port, they first need to initiate an authentication request. This can be achieved through various methods, such as 802.1X authentication, MAC address authentication, and Web Portal authentication.
[0028] The switch and the authentication server communicate using a specific authentication protocol. Common protocols include RADIUS (Remote Authentication Dial-In User Service) and TACACS+ (Terminal Access Controller Access Control System).
[0029] It should be noted that, depending on the actual situation, the switch or the authentication server can be integrated together. For example, in 802.1X authentication, the switch acts as an authentication relay (authenticator), coordinating the authentication process between the authentication client and the authentication server.
[0030] After receiving the authentication request forwarded by the switch, the authentication server verifies the user's identity information. Verification methods include two-factor authentication, which adds another layer of verification, such as a dynamic token or biometric recognition, to the username and password to enhance security.
[0031] Once the user passes identity verification, the authentication server sends authorization information to the switch, allowing the user to access specific network resources. At the same time, the authentication server records the user's access time and usage for auditing and billing purposes.
[0032] The switch controls user access based on the authorization information provided by the authentication server. Users who fail authentication will be denied network access.
[0033] The highly reliable switch secure access method for cloud computing can ensure that only legitimate users and devices can access the network, thereby improving the security of the overall network.
[0034] Furthermore, a basic access function self-test is performed on the switch after the first security access processing, specifically including: directly extracting a switch access basic function self-test plan from a switch security access database; performing a basic access function self-test on the switch after the first security access processing according to the switch access basic function self-test plan; the switch access basic function self-test plan includes switch hardware self-test, switch software self-test, and switch access security self-test; if the result of the switch access basic function self-test plan is judged to be passed, accessing the target terminal's network through the switch port and switching the switch; if the result of the switch access basic function self-test plan is judged to be failed, an alarm is issued to notify relevant personnel.
[0035] In this embodiment, the self-test of the highly reliable switch secure access method for cloud computing is to ensure that the switch can continue to provide high reliability and security during operation. The self-test may involve the following aspects: Perform a hardware self-test to check whether the power module, fan, interface module, and other hardware are functioning properly. Also check whether hardware connections, such as cables and optical fiber connections, are secure.
[0036] Software self-check: Check whether the operating system and applications are up to date, whether there are known vulnerabilities, and whether the configuration files are complete and comply with security policies.
[0037] Security self-check: Check whether security features such as firewall, intrusion detection system (IDS), intrusion prevention system (IPS) are enabled, and check whether access control lists (ACLs) are configured correctly.
[0038] The specific example steps of self-test are as follows: initialization self-test, which automatically performs basic hardware and software checks when the switch starts; setting periodic self-test tasks, such as performing a comprehensive self-test once a day, week, or month; real-time monitoring of system status, and triggering self-test immediately if an abnormality is found; event-driven self-test, which triggers self-test when a specific event occurs, such as receiving an alarm message, configuration change, etc.; manually triggered self-test, the network administrator can manually trigger self-test to verify the status of the switch; self-test result report, after the self-test is completed, a report is generated and notified to the administrator, the report should include the self-test results and any problems found; problem handling, based on the self-test results, take corresponding measures, such as repairing hardware faults, updating software, adjusting configurations, etc.; through these self-test steps, it can be ensured that the switch continues to operate with high reliability and security, and problems are discovered and measures are taken in a timely manner, thereby ensuring the stability and security of the cloud computing environment.
[0039] Furthermore, the switch after the second security access processing is subjected to the first access security assessment. The specific process is as follows: the switch records the MAC address learning rate, MAC address table capacity usage, MAC address, LLDP message rate and STP topology change count through the built-in operating system software; if the MAC address is among the predefined MAC addresses in the switch's security access database, no adjustment is made; if the MAC address is not among the predefined MAC addresses in the switch's security access database, the corresponding MAC address is recorded as a MAC address to be learned and the switch is caused to learn the corresponding MAC address through the built-in operating system software; if the number of MAC addresses to be learned is equal to or greater than the threshold number of MAC addresses to be learned, an alarm is issued to notify relevant personnel; If the number of MAC addresses to be learned is less than the threshold for the number of MAC addresses to be learned, no adjustment is made; if the MAC address table capacity usage is less than or equal to the threshold for the number of MAC addresses to be learned, no adjustment is made; if the MAC address table capacity usage is greater than the threshold for the number of MAC addresses to be learned, an alarm is issued to notify relevant personnel; if the MAC address is among the predefined MAC addresses in the switch security access database and the number of MAC addresses to be learned is less than the threshold for the number of MAC addresses to be learned and the MAC address table capacity usage is less than or equal to the threshold for the number of MAC addresses to be learned, then the first security assessment value of the switch is obtained through a comprehensive analysis of the MAC address table capacity usage, the number of MAC addresses to be learned, the LLDP message rate, and the number of STP topology changes.
[0040] In this embodiment, the switch learns MAC addresses through its ASICs (Application Specific Integrated Circuits), and the operating system software records the learning rate.
[0041] MAC address table capacity utilization: The switch operating system monitors MAC address table usage and provides a percentage of capacity utilization.
[0042] The switches that have undergone the second security access processing are numbered in sequence for the first monitoring time periods corresponding to the first access security assessment. Indicates the number of the first monitoring time period of the switch. , Indicates the total number of numbers in the first monitoring time period of the switch.
[0043] Indicates the The first switch security evaluation value of the switch in the first monitoring time period is used to quantify the relative negative degree of security threat to the switch after the second secure access processing. The larger the first switch security evaluation value, the higher the relative degree of security threat to the actual switch.
[0044] ; Represents a natural constant.
[0045] Indicates the The MAC address table capacity utilization rate for each switch during the first monitoring period. The MAC address table capacity utilization rate refers to the ratio between the number of currently used MAC address table entries and the total capacity of the switch. The MAC address table stores the MAC addresses of devices connected to the switch and their corresponding port information, enabling the switch to quickly forward data frames.
[0046] Indicates the MAC address table capacity usage threshold. The MAC address table capacity usage threshold is directly extracted from the switch security access database and is set by the switch factory log or by personnel.
[0047] Indicates the The number of MAC addresses to be learned by each switch in the first monitoring time period.
[0048] Indicates the threshold for the number of MAC addresses to be learned. This threshold is directly extracted from the switch's secure access database and is set by the switch's factory log or personnel.
[0049] Indicates the The number of ARP requests received by each switch during the first monitoring period. ARP requests refer to the number of Address Resolution Protocol (ARP) request packets sent on the network within a specified period. ARP requests are used to resolve IP addresses to MAC addresses and are a fundamental process in LAN communication. Software Analysis: The switch's operating system or built-in monitoring software can analyze the switch's total network traffic, identify and count ARP request packets, or remotely obtain switch performance parameters such as the number of ARP requests using the Simple Network Management Protocol.
[0050] As the total network traffic on a switch increases, more devices connect to the network, forcing the switch to learn more MAC addresses, which in turn increases MAC address table usage. High traffic levels can prevent the switch from learning all newly added MAC addresses, increasing the number of MAC addresses to learn. Increased network traffic on a switch typically comes with more devices communicating, which requires more ARP requests to resolve IP-to-MAC address mappings.
[0051] Indicates the The MAC address table capacity usage weight factor of each switch in the first monitoring time period is directly extracted from the switch security access database.
[0052] Indicates the The weight factor of the number of MAC addresses to be learned in the first monitoring time period of each switch is directly extracted from the switch security access database.
[0053] Indicates the The ARP request quantity weight factor of each switch in the first monitoring time period is directly extracted from the switch security access database.
[0054] The MAC address table capacity utilization weight factor, the number of MAC addresses to be learned weight factor, and the ARP request number weight factor respectively represent the relative impact weight levels of the MAC address table capacity utilization rate, the number of MAC addresses to be learned, and the number of ARP requests on the switch's security first evaluation value.
[0055] For example, a mapping set of the real-time total network traffic of the switch and its corresponding MAC address table capacity utilization weight factor, the weight factor of the number of MAC addresses to be learned, and the weight factor of the number of ARP requests is constructed. The real-time total network traffic of the switch is input into the mapping set to obtain a mapping set of the corresponding MAC address table capacity utilization weight factor, the weight factor of the number of MAC addresses to be learned, and the weight factor of the number of ARP requests, wherein the mapping relationship is a one-to-one correspondence or a many-to-one relationship.
[0056] Indicates the The historical average value of ARP requests in a corresponding historical period of the first monitoring time period of each switch is directly calculated and extracted from the switch security access database.
[0057] MAC address flooding may cause the switch MAC address table to overflow, forcing the switch to enter flooding mode. In this case, ARP spoofing attacks are more likely to succeed because the switch cannot correctly learn MAC addresses.
[0058] MAC address flooding attacks increase the number of abnormal MAC addresses and may cause abnormal ARP request and response rates because the switch cannot correctly associate MAC and IP addresses.
[0059] Indicates the The number of STP topology changes received by the switch in the first monitoring time period.
[0060] Indicates the The average number of STP topology changes received by the switch in the first monitoring time period of each switch is directly calculated and extracted from the switch security access database.
[0061] Indicates the LLDP message rate received by the switch in the first monitoring time period; Indicates the The standard value of the LLDP message received by the switch in the first monitoring time period of each switch is directly extracted from the switch security access database.
[0062] STP / BPDU flooding attacks can disrupt the network topology, while LLDP / CDP spoofing attacks can be used to mislead network devices about neighboring devices.
[0063] An increase in the frequency of STP topology changes may be accompanied by an abnormal LLDP packet rate because attackers may use both protocols to launch attacks.
[0064] LLDP (Link Layer Discovery Protocol) is a protocol used to exchange information between network devices. It helps network administrators understand network topology and device connection status. Under normal circumstances, the LLDP message transmission rate is relatively stable. However, when the network topology changes, these message rates may become abnormal.
[0065] LLDP packets are usually sent at a fixed interval (such as 30 seconds), so the packet rate is stable.
[0066] When STP (Spanning Tree Protocol) detects a topology change, network devices recalculate the spanning tree. This may cause a temporary increase in the LLDP message rate because devices need to exchange information more quickly to update the network topology.
[0067] During a topology change, the LLDP message rate may fluctuate because devices are reestablishing connections and synchronizing information.
[0068] If the LLDP or CDP message rate is consistently higher than normal, it may indicate frequent topology changes on the network. This may be caused by switch failures, link instability, or configuration errors.
[0069] In some cases, if network devices are too busy processing STP topology changes, the LLDP packet rate may decrease because the devices may prioritize STP-related tasks.
[0070] A switch failure may cause an STP topology change, increasing the number of topology changes. A switch failure can also increase the average number of STP topology changes. A switch failure can also cause an abnormal LLDP message rate because the device may send more LLDP messages when it fails. A switch failure can also cause a change in the LLDP message standard value to reflect the failure.
[0071] Indicates the The weight factor of the number of STP topology changes in the first monitoring time period of each switch is directly extracted from the switch security access database.
[0072] Indicates the The LLDP message rate weight factor of each switch in the first monitoring time period is directly extracted from the switch security access database.
[0073] The STP topology change count weight factor and LLDP message rate weight factor respectively indicate the relative impact of the STP topology change count and LLDP message rate on the switch's security-first evaluation value.
[0074] For example, a mapping set of the real-time switch device failure rate and its corresponding STP topology change number weight factor and LLDP message rate weight factor is constructed, and the real-time switch device failure rate is input into the mapping set to obtain a mapping set of its corresponding STP topology change number weight factor and LLDP message rate weight factor, where the mapping relationship is a one-to-one correspondence or a many-to-one relationship.
[0075] When a switch is connected to the network, identifying abnormal traffic typically involves monitoring and analyzing the switch's total network traffic. For example, NetFlow / IPFIX protocols can collect detailed information about the switch's total network traffic, including source and destination IP addresses, port numbers, protocol types, and traffic volume. By allowing personnel to independently set standard values for source and destination IP addresses, port numbers, protocol types, and traffic volume, automated analysis using NetFlow / IPFIX protocols can identify abnormal traffic patterns and thus obtain abnormal switch traffic values.
[0076] Indicates the The MAC address table fluctuation weight factor of each switch in the first monitoring time period is directly extracted from the switch security access database.
[0077] Indicates the The topology message fluctuation weight factor of each switch in the first monitoring time period is directly extracted from the switch security access database.
[0078] The MAC address table fluctuation weight factor and the topology message fluctuation weight factor respectively represent the relative impact weights of the abnormal switch traffic value corresponding to the corresponding data collection time on the MAC address table fluctuation and the topology message fluctuation.
[0079] For example, a mapping set of real-time switch abnormal traffic values and their corresponding MAC address table fluctuation weight factors and topology message fluctuation weight factors is constructed, and the real-time switch abnormal traffic values are input into the mapping set to obtain a mapping set of their corresponding MAC address table fluctuation weight factors and topology message fluctuation weight factors, wherein the mapping relationship is a one-to-one correspondence or a many-to-one relationship.
[0080] Changes in these parameters may be the result of multiple attacks occurring simultaneously, so their interrelationships must be considered when analyzing them. For example, a complex attack might simultaneously cause MAC address flooding and ARP spoofing. These attacks work together, making detection and defense more difficult. Therefore, security systems must be able to comprehensively analyze these parameters to identify complex attack patterns.
[0081] Furthermore, a first adjustment of security access is performed based on the first comparative analysis result, specifically including: if the switch security first evaluation value is less than the switch security first evaluation security threshold, the switch is recorded as a switch to be evaluated; if the switch security first evaluation value is equal to or greater than the switch security first evaluation security threshold, the corresponding port where abnormal traffic is detected is closed by the switch, the abnormal traffic is redirected to the network security port, BPDU protection is enabled and root protection is started, and relevant personnel are notified to set the switch MAC address table capacity usage threshold and configure BPDU protection parameters and root protection parameters.
[0082] In this embodiment, when the switch security first evaluation value is equal to or greater than the switch security first evaluation security threshold, it indicates that the switch may be potentially attacked.
[0083] Close affected ports: Directly close ports where abnormal traffic is detected to prevent the attack from spreading.
[0084] Redirecting abnormal traffic to a secure network port, such as a honeypot, is a network security technology designed to attract and lure potential attackers by simulating vulnerable targets. Honeypot systems do not directly protect actual production environments, but rather serve as a detection and defense mechanism to help security teams understand attacker behavior, methods, and motivations.
[0085] Enable BPDU protection to prevent STP flood attacks.
[0086] Configure root protection to prevent unauthorized devices from becoming the root bridge of STP.
[0087] By combining these methods, you can effectively isolate and respond to potential attacks on switches, protecting network security and stability. The specific method you use depends on the type of attack, network architecture, and available security devices.
[0088] Furthermore, a second access security assessment is performed on the switch to be assessed, specifically including: if the flow rate of the switch abnormal flow value of the switch to be assessed is equal to or greater than the flow rate threshold of the switch abnormal flow value, an alarm is issued to notify relevant personnel; if the flow rate of the switch abnormal flow value of the switch to be assessed is less than the flow rate threshold of the switch abnormal flow value, a second switch security assessment value is obtained through comprehensive analysis of the switch abnormal flow value, the switch abnormal flow value flow rate, the switch connection number parameter, and the error or retransmission message parameters in the switch.
[0089] In this embodiment, the first monitoring time periods of the switches corresponding to the second access security evaluation of the switches to be evaluated are numbered in sequence. Indicates the number of the first monitoring time period of the switch. , Indicates the total number of numbers in the first monitoring time period of the switch.
[0090] Indicates the The second switch security evaluation value of each switch in the first monitoring time period is used to quantify the relative negative degree to which the switch to be evaluated is affected by access network fluctuations. A larger second switch security evaluation value indicates a higher relative degree to which the actual switch is affected by network fluctuations.
[0091] ; Represents a natural constant.
[0092] Indicates the The abnormal traffic value of each switch in the first monitoring period.
[0093] Indicates the The traffic rate of the switch abnormal traffic value in the first monitoring time period of each switch.
[0094] Indicates the The traffic rate threshold for abnormal switch traffic during the first monitoring period for each switch is directly extracted from the switch security access database. During peak business hours, some traffic may be misidentified as abnormal switch traffic due to misjudgment or connection failures, causing the traffic rate of the abnormal switch traffic to increase. However, if the traffic rate threshold for abnormal switch traffic exceeds the threshold, it indicates that the traffic rate has suddenly peaked and is far higher than normal, which may indicate an ongoing attack.
[0095] Indicates the The maximum number of switch connections in the first monitoring time period for each switch.
[0096] Indicates the The minimum number of switch connections in the first monitoring time period for each switch.
[0097] Indicates the The average value of the number of switch connections in the corresponding historical period of the first monitoring time period of each switch is directly calculated and extracted from the switch security access database.
[0098] Abnormal increase: A sharp increase in the number of connections within a short period of time may indicate a SYN flood attack or other connection-based attacks.
[0099] In the context of a switch, connections generally refer to the number of active connections on the switch. These connections can be between the switch and connected devices (such as computers, servers, and other network devices), or between devices forwarding traffic through the switch.
[0100] Connection between a switch and an access device: For example, a computer is connected to a port on a switch via a network cable, establishing a connection.
[0101] Connections between devices forwarded through a switch: For example, if two computers are connected to different ports on a switch, the communication between them will be forwarded through the switch, which also counts as part of the number of connections.
[0102] When monitoring the switch's total network traffic and connections, an abnormally high number of connections may indicate a network attack, such as a SYN flood attack. A SYN flood attack exploits a vulnerability in the three-way handshake during TCP connection establishment. The attacker sends a large number of SYN requests but fails to complete the handshake, causing a sharp increase in the number of half-open connections on the target device. This depletes system resources and prevents legitimate users from establishing connections.
[0103] Indicates the The maximum number of erroneous or retransmitted messages in the switch during the first monitoring period of each switch.
[0104] Indicates the The minimum number of erroneous or retransmitted messages in the switch in the first monitoring time period.
[0105] Indicates the The average number of switch connections for each switch during the first monitoring period. This average number of switch connections is directly calculated and extracted from the switch security access database. An abnormally high percentage of erroneous or retransmitted messages may indicate malicious packet injection or network interference.
[0106] Indicates the The switch abnormal traffic value weight factor of the switch in the first monitoring time period is directly extracted from the switch security access database.
[0107] Indicates the The flow rate weight factor of the abnormal flow value of the switch in the first monitoring time period of each switch is directly extracted from the switch security access database.
[0108] Indicates the The weight factor of the difference between the maximum number of switch connections and the minimum number of switch connections in the first monitoring time period of each switch is directly extracted from the switch security access database.
[0109] Indicates the A weight factor of the difference between the maximum value of erroneous or retransmitted messages in the switch and the minimum value of erroneous or retransmitted messages in the switch during the first monitoring time period of each switch is directly extracted from the switch security access database.
[0110] Excessive network load utilization can cause an increase in abnormal traffic. Network load utilization directly affects traffic rate. Excessive network load utilization can lead to an increase in the number of connections. Excessive network load utilization can also result in more packet errors and retransmissions.
[0111] The switch abnormal traffic value weight factor, the switch abnormal traffic value flow rate weight factor, the switch abnormal traffic value difference between the maximum number of switch connections and the minimum number of switch connections weight factor, and the switch error or retransmission message maximum value and the minimum number of error or retransmission message weight factor respectively represent the relative impact of the switch abnormal traffic value, the switch abnormal traffic value flow rate, the switch abnormal traffic value difference between the maximum number of switch connections and the minimum number of switch connections weight factor, and the switch error or retransmission message maximum value and the minimum number of error or retransmission message weight factor on the second switch security evaluation value.
[0112] For example, a mapping set of real-time network load utilization and its corresponding switch abnormal traffic value weight factor, switch abnormal traffic value flow rate weight factor, switch abnormal traffic value difference weight factor, switch maximum connection number difference weight factor, and switch minimum connection number difference weight factor, is constructed. The real-time network load utilization is input into the mapping set to obtain a mapping set of its corresponding switch abnormal traffic value weight factor, switch abnormal traffic value flow rate weight factor, switch maximum connection number difference weight factor, and switch minimum connection number difference weight factor, and switch maximum error or retransmitted message difference weight factor, wherein the mapping relationship is a one-to-one correspondence or a many-to-one relationship.
[0113] Furthermore, performing the second access security assessment on the switch to be assessed further includes: performing the first access security assessment and the second access security assessment on the switch to be assessed to obtain a first switch security assessment value and a second switch security assessment value of the switch to be assessed; and obtaining a switch security comprehensive assessment value by comprehensively analyzing the first switch security assessment value and the second switch security assessment value of the switch to be assessed. The specific analysis is as follows: sequentially numbering the first switch monitoring time periods corresponding to the second access security assessment of the switch to be assessed, Indicates the number of the switch's first monitoring time period. , Indicates the total number of numbers in the first monitoring time period of the switch; Indicates the The switch security comprehensive evaluation value of the first monitoring period of each switch is used to quantify the relative negative comprehensive degree of network security threats to the switch to be evaluated; ; Indicates the A first switch security assessment value for a first monitoring period of a switch; Indicates the A second switch security assessment value for each switch in a first monitoring time period; Indicates the The maximum switch access delay of each switch in the first monitoring time period; Indicates the The maximum switch access delay of each switch in the first monitoring time period; Indicates the The average switch access delay of each switch in the first monitoring period; Indicates the a weight factor of a switch security first evaluation value of a switch in a first monitoring time period, wherein the weight factor of the switch security first evaluation value is directly extracted from a switch security access database; Indicates the The weight factors of the second switch security evaluation values of the switches in the first monitoring time period are directly extracted from the switch security access database.
[0114] In this embodiment, an increase in delay may cause an increase in jitter value, because delay fluctuation directly affects jitter, and a sudden increase in delay may indicate network congestion or delay attack.
[0115] Bandwidth utilization: The ratio of the bandwidth used by the entire switch to its maximum bandwidth.
[0116] When bandwidth utilization is low, it means that the switch has sufficient computing resources. If a network attack occurs, the switch's second security assessment value is likely to increase sharply, and the weight factor ratio of the switch's second security assessment value needs to be increased. When bandwidth utilization is high, it means that the switch's computing resources are insufficient. If a network attack occurs, the switch's second security assessment value does not change significantly, and the switch's first security assessment value is likely to increase sharply, and the weight factor ratio of the switch's first security assessment value needs to be increased.
[0117] The weight factor of the first switch security evaluation value and the weight factor of the second switch security evaluation value respectively represent the relative influence weight levels of the weight factor of the first switch security evaluation value and the weight factor of the second switch security evaluation value corresponding to different switch bandwidth utilization rates on the comprehensive switch security evaluation value.
[0118] For example, a mapping set of real-time bandwidth utilization and its corresponding weighting factors of the first switch security evaluation value and the second switch security evaluation value is constructed, and the real-time bandwidth utilization is input into the mapping set to obtain a mapping set of its corresponding weighting factors of the first switch security evaluation value and the second switch security evaluation value, wherein the mapping relationship is a one-to-one correspondence or a many-to-one relationship.
[0119] Furthermore, a second adjustment of the secure access is performed based on the second comparative analysis result, specifically including: if the switch security comprehensive evaluation value is less than the switch security comprehensive evaluation threshold, no adjustment is made; if the switch security comprehensive evaluation value is equal to or greater than the switch security comprehensive evaluation threshold, the control plane CPU redundancy switching of the switch is performed through a predefined redundant switching scheme, and the bandwidth utilization of the internal port of the switch is recorded; if the bandwidth utilization of the internal port of the switch is less than the bandwidth utilization threshold, no adjustment is made; if the bandwidth utilization of the internal port of the switch is equal to or greater than the bandwidth utilization threshold, the corresponding port is recorded as an early warning port and the number of early warning ports is recorded; if the number of early warning ports is less than the early warning port number threshold, no adjustment is made; if the number of early warning ports is equal to or greater than the early warning port number threshold, the corresponding early warning port is disconnected and an alarm is issued to notify relevant personnel.
[0120] In this embodiment, a control plane CPU redundancy switching solution is provided to meet the network's growing demand for higher network service availability; The switch supports simplex-active or active-standby (1+1) control plane CPU redundancy. After a redundancy switchover, two types of protocol recovery are included. For example, immediate recovery of protocols with a full checkpoint of all protocol states is performed. Link Aggregation Control Protocol (LACP), Multiple Spanning Tree Protocol (MSTP), and the Network Services Manager (NSM), which hosts the Routing Information Base (RIB) and Interface Manager, provide full checkpointing between the active and standby controllers. Another example is a graceful restart of all remaining protocol modules. This allows the routing database and protocol state of any Layer 3 routing protocol to be rebuilt without retrieving its routes from the system's global routing RIB.
[0121] During the post-switch recovery process, the forwarding planes at different levels continue to forward packets uninterrupted while the control plane is switched to the active controller.
[0122] It also supports the ability to update in-service software (ISSU). For example, the Check Point Abstraction Layer (CAL) enables the system HA module to be used with multiple HA middleware software packages. Replication SSO using the System Spanning Tree Protocol (STP) and Link Aggregation Control Protocol (LACP) modules supports stateful switchover operations. Replication of the Routing Information Base (RIB) is used to support SSO to maintain nonstop routing (NSR).
[0123] like Figure 2 As shown, it is a structural diagram of a high-reliability switch security access system for cloud computing provided by an embodiment of the present application. The high-reliability switch security access system for cloud computing provided by an embodiment of the present application includes: a first security access processing module, a second security access processing module, a first security access adjustment module, and a second security access adjustment module: the first security access processing module is used for a user to access a target terminal through a switch, the switch performs identity authentication according to user input information, and performs a first security access processing according to the identity authentication result; the second security access processing module is used to perform a basic access function self-test on the switch after the first security access processing, and perform a second security access processing according to the basic access function self-test result; the first security access adjustment module is used to perform a first access security assessment on the switch after the second security access processing, obtain a first switch security assessment value, perform a first comparative analysis based on the first switch security assessment value, and perform a first security access adjustment based on the first comparative analysis result; the second security access adjustment module is used to perform a second access security assessment on the switch to be assessed, obtain a comprehensive switch security assessment value, perform a second comparative analysis based on the comprehensive switch security assessment value, and perform a second security access adjustment based on the second comparative analysis result.
[0124] An embodiment of the present application provides a highly reliable switch security access device for cloud computing, including a switch host: the switch host is configured to enable the highly reliable switch security access device for cloud computing to implement any one of the highly reliable switch security access methods for cloud computing.
[0125] It should be noted that the switch can use the S5520-48T4X SW Gigabit Ethernet enterprise aggregation switch host (48 10 / 100 / 1000Base-T electrical ports, 4 10GSFP+ optical ports, and support for 2 expansion slots), support dual power supplies and dual fans, and AC 220V power supply; The switch motherboard hardware system uses the SW831 as the core computing unit, with 8 cores, supporting 2.4Ghz, and one PCIE4.0X16 signal (splittable). The SW831 memory channel MM0 is connected to the SODIMM slot, which uses the LOTES ADDR0207 slot with a height of 5.2mm. The core board splits the processor's PCIE X16 signal into two PCIE X8 signals, and the PCIE is connected to Upd720201 for PCIE to USB interface expansion; Upd720201 can provide 4 USB interfaces, USB0 / 1 is connected to the core board connector USB0 / 1, and provides 2 USB3.0 interfaces; USB2 is connected to RTL8153B to provide a 1000BASE-T network signal, which can support 1000M / 100M / 10M adaptive; USB3 connected to TUSB9216 provides 1 SATA2.0 interface; The core board provides 1 serial port, 1 IIC interface, and 1 LPC interface, all of which are provided by the CPU.
[0126] The core board connector is connected to the DC-12V main power supply and DC-5V Stand by power supply, and outputs various voltages through the on-board power supply module; The core board provides various required clocks through crystals, crystal oscillators, clock generators and clock buffer chips.
[0127] The core board IO expansion uses CPU_PCIE to connect to upd720201 to expand 4 USB3.0 signals, USB0 / 1 is connected to USB0 / 1 of the COME connector; USB2 is connected to Realtek's RTL8153B, and outputs 1 1000BASE-T, supporting 1000M / 100M / 10M adaptive.
[0128] The processor unit used in the switch CPU has the following main features: The full chip integrates 8 computing cores with a maximum operating frequency of 2.5GHz, and each physical core supports 1 thread.
[0129] Integrated active safety management module ASP, with a maximum operating frequency of 750MHz.
[0130] The entire chip integrates 16MB of L3 cache, uses CC_NUMA to share the on-chip L3 cache, uses SMP to access the main memory, and supports cache consistency between the core and various IO interfaces in accessing the storage space.
[0131] The third-level cache is divided into four parts (each part is 4MB), each part forms a core group with two cores, and the four core groups and IO interfaces are interconnected on-chip using a ring network.
[0132] The active security management module ASP is connected to the on-chip IO routing component IRU and SPBU (Security Pre-Boot Unit), supporting the ASP to issue continuous memory access requests and IO requests to the on-chip computing subsystem.
[0133] Examples of network protocols included with the switch include: 1. Network Services Manager. The system Network Services Manager (NSM) is a fundamental module that communicates independently and simultaneously with each system routing and switching process. The NSM serves as the backbone of the system software modules and supports IPv4, IPv6, MPLS, GMPLS, Mobile IP, Differentiated Services (DiffServ) extensions, DiffServ Traffic Engineering (TE), multicast, Layer 2 switching, and Layer 3 routing protocols. The NSM also supports router redundancy, virtual routing, IGMPv1 and v2, and management and services for all protocol modules.
[0134] The NSM communicates directly with each system routing and switching module to manage routing tables and perform route translation and route redistribution. The NSM also interfaces with the Platform Abstraction Layer (PAL) and Hardware Abstraction Layer (HAL) to communicate with the underlying operating system or network processor for forwarding table updates. For Layer 3 multicast routing, the system Multicast Routing Information Base Daemon (MRIBd) interfaces with the PAL and HAL to communicate with the underlying operating system or network processes for multicast forwarding table updates. The NSM and MRIBd provide a unified hardware programming interface and support forwarding state persistence across protocol restarts and upgrades.
[0135] 2. Management Interface: The system network platform management interface module provides a comprehensive set of tools for managing and controlling system routing and switching protocols. These tools include the Integrated Management Interface (IMI), IMI Shell (IMISH), basic access, and the IPv6 tunneling and translation module. The management interface module enables hardware manufacturers to seamlessly integrate a complete management plane with an industry-standard command line interface (CLI) into their routing and switching devices, allowing them to quickly build and deliver enhanced IP service solutions for access devices.
[0136] 3. Integrated Management Interface. The system IMI module provides complete, unified management of the system Network Services Module (NSM) and various system network platform protocols. It allows system administrators to configure and monitor all system daemons through a centralized user connection. As a standalone management daemon, the IMI maintains a persistent connection with the routing daemon, stores configuration data, and provides extensive monitoring and logging capabilities.
[0137] The System IMI provides a feature-rich, hierarchical CLI that includes Exec, Privileged Exec, Configure, Router, and Interface command modes. It also supports syntax checking, command auto-completion, and context-sensitive help. The System IMI also allows end users to easily configure and manage network services included in the Linux operating system, including DNS, DHCP, NAT, ACL, and PPPoE, using the Basic Access Module. The Basic Access Module provides a series of interfaces that enable device vendors to easily and quickly integrate access software into their products and pass on easy-to-manage features to end users.
[0138] IMI architecture,IMI uses the mechanisms established in the system IMI IPC to operate as a server for NSM and routing protocols.,NSM listens to NSM IPC and protocol modules, then IMI initiates the connection.,IMI listens to IMI IPC and NSM,protocol modules, then IMISH initiates the connection.
[0139] IMI maintains a master database of data such as prefix lists, route maps, key chains, and access lists and distributes this information to protocols. This database facilitates functionality and responses to commands such as "show" or "write to file"; IMI does collect and organize data from protocols, but displays the data directly.
[0140] IMI daemon, IMI provides a centralized, persistent daemon to manage system configuration. It has the following advantages: Persistent daemon. IMI maintains up-to-date configuration information about the entire system. If you restart a protocol daemon, IMI can preserve the daemon's configuration before it was stopped and configure it again after the restart.
[0141] Configuration saving. The IMI saves configuration changes and uses them when the protocol daemon is restarted. To save configuration information, the user must use the write file or write memory command. When a protocol module first connects, it initiates the connection and requests the currently saved configuration from the IMI. The IMI reads the configuration file and passes the configuration corresponding to the specific protocol module.
[0142] Centralized information control. IMI provides centralized control of all system protocols, both operational and static configurations. Information can be consolidated for display, configuration writes, and persistent backup.
[0143] Master copy of common data. Several system components receive the same type of information, each protocol used for various purposes.
[0144] Multiple access types. IMI provides the foundation for enabling several types of configuration options for the system. IMI supports Layer 2 TELNET CLI, IMISH, and Web configuration.
[0145] System IMISH is a client application that connects to the IMI and supports SSH or TELNET management. It can be deployed on a routing device or a separate management console. System IMISH supports role-based management and leverages the operating system's secure authentication methods to manage and verify usernames and passwords. Additionally, System IMISH supports sophisticated input and output capabilities, allowing administrators to, for example, save the output of show commands to a file.
[0146] 4. IPv6 Tunneling and Transition. The IPv6 Tunneling and Transition module provides tools and a CLI through the system network services module to configure and set parameters for IPv6-to-IPv4 transition and tunneling protocols, such as 6to4, Intra-Site Automatic Tunnel Addressing Protocol (ISATAP), Generic Routing Encapsulation (GRE), and IP-in-IP encapsulation, provided by the Linux kernel. These features provide enhanced performance, ease of integration, and management for access product OEMs and ODMs.
[0147] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0148] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0149] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0150] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.
[0151] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.
[0152] Obviously, those skilled in the art may make various modifications and variations to the present invention without departing from the spirit and scope of the present invention. Thus, if such modifications and variations fall within the scope of the claims and their equivalents, the present invention is intended to include such modifications and variations.
Claims
1. A highly reliable switch secure access method for cloud computing, characterized in that: The following steps are involved: The user accesses the target terminal through the switch, and the switch performs identity authentication based on the user input information and performs the first secure access processing based on the identity authentication result; Performing a basic access function self-test on the switch after the first secure access process, and performing a second secure access process based on the result of the basic access function self-test; Performing a first access security assessment on the switch after the second security access processing to obtain a first switch security assessment value, performing a first comparative analysis based on the first switch security assessment value, and performing a first security access adjustment based on the first comparative analysis result; Perform a second access security assessment on the switch to be assessed to obtain a comprehensive switch security assessment value, perform a second comparative analysis based on the comprehensive switch security assessment value, and perform a second adjustment on secure access based on the second comparative analysis result.
2. The highly reliable switch secure access method for cloud computing according to claim 1, wherein: The switch performs identity authentication based on user input information, specifically including: When a user accesses the target terminal's network through a switch port, the switch sends an identity authentication request to the user through the authentication server; The authentication server receives the authentication request from the switch and performs identity authentication based on the user input information; If the authentication is successful, the authentication server sends authorization information to the switch and allows the user to access network resources; If the identity authentication fails, the authentication server will send an unauthorized message to the switch, denying the user access to network resources through the switch and alerting relevant personnel.
3. The highly reliable switch secure access method for cloud computing according to claim 1, wherein: The step of performing a self-check on basic access functions on the switch after the first secure access process specifically includes: Directly extract the switch access basic function self-test solution from the switch security access database; Perform a basic access function self-test on the switch after the first secure access process according to the basic access function self-test solution for the switch; The switch access basic function self-test solution includes switch hardware self-test, switch software self-test, and switch access security self-test; If the result of the switch access basic function self-test solution is determined to be passed, the network of the target terminal is connected through the switch port and the switch is turned on. If the result of the switch access basic function self-test solution is determined to be failed, an alarm is issued to notify relevant personnel.
4. The highly reliable switch secure access method for cloud computing according to claim 1, wherein: The specific process of performing the first access security assessment on the switch after the second security access processing is as follows: The switch uses the built-in operating system software to record the MAC address learning rate, MAC address table capacity usage, MAC addresses, LLDP message rate, and STP topology change count; If the MAC address is among the predefined MAC addresses in the switch's secure access database, it is not adjusted; If the MAC address is not in the predefined MAC addresses in the switch's secure access database, the corresponding MAC address is recorded as a to-be-learned MAC address and the switch is instructed to learn the corresponding MAC address through the built-in operating system software. If the number of MAC addresses to be learned is equal to or greater than the threshold number of MAC addresses to be learned, an alarm is issued to notify relevant personnel; If the number of MAC addresses to be learned is less than the threshold, no adjustment is made. If the MAC address table capacity usage is less than or equal to the MAC address table capacity usage threshold, no adjustment is made. If the MAC address table capacity usage rate exceeds the MAC address table capacity usage rate threshold, an alarm is issued to notify relevant personnel; If the MAC address is among the predefined MAC addresses in the switch's secure access database, the number of MAC addresses to be learned is less than the threshold for the number of MAC addresses to be learned, and the MAC address table capacity usage is less than or equal to the threshold for the MAC address table capacity usage, the first security assessment value of the switch is obtained through a comprehensive analysis of the MAC address table capacity usage, the number of MAC addresses to be learned, the LLDP message rate, and the number of STP topology changes.
5. The highly reliable switch secure access method for cloud computing according to claim 1, wherein: The first adjustment of secure access according to the first comparison and analysis result specifically includes: If the switch security first evaluation value is less than the switch security first evaluation security threshold, the switch is marked as a switch to be evaluated; If the switch security first assessment value is equal to or greater than the switch security first assessment security threshold, the corresponding port where abnormal traffic is detected is closed by the switch, the abnormal traffic is redirected to the network security port, BPDU protection is enabled and root protection is started, and relevant personnel are notified to set the switch MAC address table capacity usage threshold and configure BPDU protection parameters and root protection parameters.
6. The highly reliable switch secure access method for cloud computing according to claim 1, wherein: The second access security assessment of the switch to be assessed specifically includes: If the flow rate of the switch abnormal flow value of the switch to be evaluated is equal to or greater than the flow rate threshold of the switch abnormal flow value, an alarm is issued to notify relevant personnel; If the traffic rate of the switch abnormal traffic value of the switch to be evaluated is less than the traffic rate threshold of the switch abnormal traffic value, a second switch security evaluation value is obtained through comprehensive analysis of the switch abnormal traffic value, the switch abnormal traffic value traffic rate, the switch connection number parameter, and the error or retransmission message parameters in the switch.
7. The highly reliable switch secure access method for cloud computing according to claim 1, wherein: The second access security assessment of the switch to be assessed further includes: Performing a first access security assessment and a second access security assessment on the switch to be assessed, and obtaining a first switch security assessment value and a second switch security assessment value of the switch to be assessed; The switch security comprehensive evaluation value is obtained by comprehensively analyzing the switch security first evaluation value and the switch security second evaluation value of the switch to be evaluated. The specific analysis is as follows: The first monitoring time periods of the switches corresponding to the second access security assessment of the switches to be assessed are numbered in sequence. Indicates the number of the first monitoring time period of the switch. , Indicates the total number of numbers in the first monitoring time period of the switch; Indicates the The switch security comprehensive evaluation value of the first monitoring period of each switch is used to quantify the relative negative comprehensive degree of network security threats to the switch to be evaluated; ; Indicates the A first switch security assessment value for a first monitoring period of a switch; Indicates the A second switch security assessment value for each switch in a first monitoring time period; Indicates the The maximum switch access delay of each switch in the first monitoring time period; Indicates the The maximum switch access delay of each switch in the first monitoring time period; Indicates the The average switch access delay of each switch in the first monitoring period; Indicates the a weight factor of a switch security first evaluation value of a switch in a first monitoring time period, wherein the weight factor of the switch security first evaluation value is directly extracted from a switch security access database; Indicates the The weight factors of the second switch security evaluation values of the switches in the first monitoring time period are directly extracted from the switch security access database.
8. The highly reliable switch secure access method for cloud computing according to claim 1, wherein: The performing a second adjustment on the secure access according to the second comparative analysis result specifically includes: If the switch security comprehensive evaluation value is less than the switch security comprehensive evaluation threshold, no adjustment will be made; If the switch's comprehensive security assessment value is equal to or greater than the switch's comprehensive security assessment threshold, the switch's control plane CPU redundancy is switched using a predefined redundancy switching scheme, and the bandwidth utilization of the switch's internal ports is recorded. If the bandwidth utilization of the switch internal port is less than the bandwidth utilization threshold, no adjustment is made. If the bandwidth utilization of the switch internal port is equal to or greater than the bandwidth utilization threshold, the corresponding port is marked as a warning port and the number of warning ports is recorded. If the number of warning ports is less than the warning port number threshold, no adjustment will be made. If the number of warning ports is equal to or greater than the warning port number threshold, the corresponding warning port will be disconnected and an alarm will be issued to notify relevant personnel.
9. High-reliability switch security access system for cloud computing, characterized by: It includes a first secure access processing module, a second secure access processing module, a first secure access adjustment module, and a second secure access adjustment module: Secure access first processing module: used for users to access the target terminal through the switch. The switch performs identity authentication based on the user input information and performs secure access first processing based on the identity authentication result. The second secure access processing module is used to perform a self-test of basic access functions on the switch after the first secure access processing, and perform a second secure access processing according to the result of the self-test of basic access functions; A first security access adjustment module is configured to perform a first access security assessment on the switch after the second security access processing, obtain a first switch security assessment value, perform a first comparative analysis based on the first switch security assessment value, and perform a first security access adjustment based on the first comparative analysis result; The second security access adjustment module is used to perform a second access security assessment on the switch to be assessed, obtain a comprehensive security assessment value of the switch, perform a second comparative analysis based on the comprehensive security assessment value of the switch, and perform a second security access adjustment based on the second comparative analysis result.
10. A highly reliable switch security access device for cloud computing, characterized in that: The switch host is configured to enable the cloud computing-oriented high-reliability switch security access device to implement the cloud computing-oriented high-reliability switch security access method according to any one of claims 1 to 8.
Citation Information
Patent Citations
A switch hardware driver system and a switch
CN111309386B
A method for implementing secure isolation of virtual machines based on OpenStack
CN112099913B