Cloud service security protection method, device, equipment, medium and product

By building a firewall resource pool and automatically generating security policies with a large language model, combined with NFV and SDN technologies, the usability and centralized management issues of cloud firewalls are resolved, multi-user sharing and efficient traffic management are achieved, and the protection capabilities of cloud firewalls are enhanced.

CN120856478APending Publication Date: 2025-10-28CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202511358902.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-23
Publication Date
2025-10-28

AI Technical Summary

Technical Problem

In existing technologies, cloud firewalls require customers to manually configure NAT policies, which are difficult to use, cannot be centrally managed, and cannot generate intelligent security policies. In addition, one firewall can only protect a maximum of 5 elastic public IP addresses, which makes it difficult to meet the needs of large customers and cannot achieve cloud firewall sharing.

Method used

By building a firewall resource pool and automatically generating security policies using a large language model, combined with the NFV platform and SDN technology, unified management and intelligent protection of the firewall resource pool are achieved. This supports multi-user sharing, automatically configures NAT policies, and implements traffic transmission channels through Group ENI.

Benefits of technology

It improves the flexibility and automation of security protection, reduces the technical requirements for customers, enables multi-user sharing and efficient traffic management, and enhances protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120856478A_ABST
    Figure CN120856478A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, in particular to a cloud service security protection method and device, equipment, a medium and a product, and the method comprises the steps: receiving a cloud service protection request sent by a user, and determining a target cloud firewall from a pre-constructed firewall resource pool based on the cloud service protection request; acquiring real-time log data generated by a firewall resource pool when the target cloud firewall protects the elastic public network IP; and generating a real-time security policy based on the pre-trained large language model and the real-time log data, and performing security protection on the elastic public network IP by the target cloud firewall according to the security policy and the protection policy. The firewall resource pool is constructed through the self-developed cloud native firewall, manual configuration is not needed after a client purchases the cloud firewall, a manufacturer carries out unified management on the firewall resource pool, a more intelligent security policy can be dynamically generated according to log data generated by the firewall resource pool, and the flexibility and automation of security protection are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of cybersecurity technology, and in particular to a cloud service security protection method, apparatus, equipment, medium, and product. Background Technology

[0002] With the rapid development of cloud computing, businesses and individuals are increasingly relying on cloud services to conduct their business and daily operations. However, moving business to cloud servers has brought many security challenges, thus requiring firewalls to protect the elastic public IP addresses bound to cloud servers.

[0003] However, in related technologies, firewalls generally need to be ordered by the customer themselves. Each customer buys an independent firewall, and cloud service providers cannot centrally manage these firewalls or automatically generate more intelligent security policies. All security policies need to be added manually by the customer, which places high demands on the customer's own network technology and results in poor usability. Summary of the Invention

[0004] This disclosure is made in view of the above-mentioned problems and provides a cloud service security protection method, apparatus, equipment, medium and product.

[0005] According to one aspect of this disclosure, a cloud service security protection method is provided, comprising: Receive a cloud service protection request sent by a user, wherein the cloud service protection request is used to request protection for the elastic public IP specified by the user, the cloud service protection request carries a protection policy, and the protection policy represents the user's explicit protection intention; Based on the cloud service protection request, a target cloud firewall is determined from a pre-built firewall resource pool; wherein, the firewall resource pool includes multiple firewall software deployed on virtual machines; While the target cloud firewall is protecting the elastic public IP according to the protection policy, real-time log data generated by the firewall resource pool is obtained. Based on the pre-trained large language model and the real-time log data, a real-time security policy is generated; wherein, the target cloud firewall provides security protection for the elastic public IP according to the security policy and the protection policy.

[0006] By building a firewall resource pool using a self-developed cloud-native firewall, customers do not need to manually configure NAT policies after purchasing the cloud firewall. The vendor manages the firewall resource pool in a unified manner and can dynamically generate more intelligent security policies based on the real-time log data generated by the firewall resource pool, thereby improving the flexibility and automation of security protection.

[0007] Furthermore, the cloud service security protection method according to one aspect of this disclosure also includes: the training process of the large language model includes: The Transformer model is pre-trained using a masked language model so that it can learn the language and structure of the log data. A supervised learning method based on known attack patterns and corresponding defense strategies is used to retrain the pre-trained Transformer model to obtain the large language model.

[0008] To effectively learn and automatically generate security policies from billions of firewall logs, a masked language model is pre-trained on the Transformer model. This allows the Transformer model to learn the language and structure of the log data, thereby predicting randomly masked portions. After the Transformer model sufficiently understands the log data, it is fine-tuned using supervised learning methods based on known attack patterns and corresponding defense strategies. This enables the large language model to automatically generate security policies for users based on the context of the log data. The Transformer model can also be periodically retrained and fine-tuned to ensure its accuracy and relevance, thus maintaining the effectiveness of protective measures. This not only responds to current security needs but also anticipates potential future threats.

[0009] Furthermore, the cloud service security protection method according to one aspect of this disclosure also includes: generating a real-time security policy based on a pre-trained large language model and the real-time log data, including: Security analysis is continuously performed based on the pre-trained large language model and the real-time log data, and analysis results are generated. When the analysis results indicate the emergence of new potential threats, a real-time security policy is generated and stored in the security policy library.

[0010] By dynamically generating security policies in real time using a large language model, it is possible to protect against potential threat IPs or new attack methods in the network environment. These security policies, built upon a foundation of protective strategies, enable real-time and precise threat hunting and response. The security and protective strategies complement each other, further enhancing security. Furthermore, as the firewall resource pool continues to operate, log data becomes increasingly comprehensive, and model algorithms learn more deeply, enabling the security policy library to more comprehensively and intelligently anticipate potential future security risks.

[0011] Furthermore, the cloud service security protection method according to one aspect of this disclosure also includes: the construction process of the firewall resource pool includes: Deploy and run firewall software on multiple virtual machines; The firewall software is subject to full lifecycle management, which includes multiple orchestration and scheduling management functions. Create data interfaces corresponding to each of the aforementioned orchestration and scheduling management functions, so that the user can call the corresponding orchestration and scheduling management functions through the data interfaces.

[0012] By managing the firewall software throughout its entire lifecycle, including multiple orchestration and scheduling management functions such as virtual machine warm-up, resource decision-making, fault handling, and configuration distribution, the constructed firewall resource pool has advantages such as elasticity and high reliability, promoting the software-based transformation of (firewall) network elements.

[0013] Furthermore, according to one aspect of the cloud service security protection method disclosed herein, the method further includes: determining the target cloud firewall from a pre-built firewall resource pool based on the cloud service protection request, comprising: Based on the cloud service protection request, the firewall database is queried; wherein, the firewall database is used to store firewall software information of the firewall resource pool; The target cloud firewall is determined from the firewall resource pool based on the firewall database.

[0014] After storing the pre-incubated firewall information in the firewall database, users can automatically enable protection simply by clicking, without needing to configure parameters themselves.

[0015] Furthermore, according to one aspect of the cloud service security protection method disclosed herein, after determining the target cloud firewall from a pre-built firewall resource pool based on the cloud service protection request, the method further includes: Establish a traffic transmission channel between the first virtual private cloud where the target cloud firewall is located and the second virtual private cloud where the elastic public IP is located; Obtain traffic data generated by accessing the elastic public IP address; Based on the traffic transmission channel, the traffic data is sent to the first virtual private cloud.

[0016] By establishing a traffic transmission channel between the first and second virtual private clouds, private domain isolation can be broken, allowing traffic to flow between them. User traffic can be automatically directed to the target cloud firewall for cleaning, and then sent back to the user's business server through the traffic transmission channel.

[0017] Furthermore, according to one aspect of the cloud service security protection method disclosed herein, the method further includes: the target cloud firewall comprising a single cloud firewall or a firewall cluster consisting of multiple cloud firewalls, and also includes: The traffic data is assigned identification information, which is used by the target cloud firewall to identify the user corresponding to the traffic data; The traffic data containing the identification information is sent to the target cloud firewall according to the equal cost multipath routing protocol; The target cloud firewall processes the traffic data using the aforementioned protection strategy to obtain processed traffic data. The identification information carried in the processed traffic data is deleted, and the processed traffic data is sent to the second virtual private cloud based on the traffic transmission channel.

[0018] By assigning identifiers to traffic data pointing to specific users, the firewall cluster can quickly identify which user's traffic it is upon entering the cluster. Then, it can be processed according to that user's protection policy, facilitating the sharing of a single target cloud firewall among multiple users. Sending traffic data to the target cloud firewall using the equal-cost multi-path routing protocol automatically distributes traffic evenly across multiple paths, improving load balancing capabilities and flexibility.

[0019] Furthermore, according to one aspect of the cloud service security protection method disclosed herein, it further includes: establishing a traffic transmission channel between the first virtual private cloud where the target cloud firewall is located and the second virtual private cloud where the elastic public IP is located, including: Obtain the cluster information and service network interface ID of the target cloud firewall; Based on the cluster information and the service network card ID, the first virtual private cloud where the target cloud firewall is located is confirmed; In the absence of a traffic transmission channel established in the first virtual private cloud, obtain the second virtual private cloud where the elastic public IP is located; Establish the traffic transmission channel between the first virtual private cloud and the second virtual private cloud, and assign a fixed IP address to the traffic transmission channel.

[0020] By establishing a fixed IP for the traffic transmission channel, user traffic can be automatically redirected to the target cloud firewall. Furthermore, data such as the business network card ID and fixed IP can be persisted to the database for subsequent management.

[0021] Furthermore, according to one aspect of the cloud service security protection method disclosed herein, it further includes: establishing a fixed IP address for the traffic transmission channel when the first virtual private cloud has already established a traffic transmission channel.

[0022] In addition, the cloud service security protection method according to one aspect of this disclosure also includes: Obtain the fixed IP address of the traffic transmission channel; Based on the fixed IP address, configure the target cloud firewall to redirect traffic; The elastic public IP is unbound from the user's business cloud host and bound to the fixed IP so that the traffic data of the elastic public IP can be routed to the target cloud firewall.

[0023] After binding the Elastic Public IP to a fixed IP, all traffic from the Internet accessing this Elastic Public IP will no longer be sent directly to the user's business cloud host, but will be routed to the traffic transmission channel, and then forwarded by it to the firewall resource pool for processing.

[0024] Furthermore, the cloud service security protection method according to one aspect of this disclosure also includes: updating the status of the elastic public IP to protected and storing it in a database; Send the response information of the cloud service protection request to the user.

[0025] Once the status of the Elastic Public IP is updated to "protected," it means that the user's business traffic has officially flowed through the target cloud firewall and has begun to enjoy security protection. The cloud firewall will faithfully execute the existing protection policies and automatically issued security policies.

[0026] According to another aspect of this disclosure, a cloud service security protection device is provided, comprising: The receiving module is used to receive cloud service protection requests sent by users, wherein the cloud service protection request is used to request protection for the elastic public IP specified by the user, the cloud service protection request carries a protection policy, and the protection policy represents the user's explicit protection intention. The firewall verification module is used to determine the target cloud firewall from a pre-built firewall resource pool based on the cloud service protection request; wherein, the firewall resource pool includes multiple firewall software deployed on virtual machines; The log data acquisition module is used to acquire real-time log data generated by the firewall resource pool during the period when the target cloud firewall protects the elastic public IP according to the protection policy; The security policy generation module is used to generate a real-time security policy based on a pre-trained large language model and the real-time log data; wherein, the target cloud firewall provides security protection for the elastic public IP according to the security policy and the protection policy.

[0027] According to another aspect of this disclosure, a computer device is provided, including a memory, a processor, and a computer program stored in the memory, the processor executing the computer program to implement the method of one aspect above.

[0028] According to another aspect of this disclosure, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the method of one aspect above.

[0029] According to another aspect of this disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the method of the above-described aspect.

[0030] It should be understood that both the foregoing general description and the following detailed description are exemplary and intended to provide further illustration of the claimed technology. Attached Figure Description

[0031] The above and other objects, features, and advantages of this disclosure will become more apparent from the more detailed description of the embodiments thereof in conjunction with the accompanying drawings. The drawings are provided to further illustrate the embodiments of this disclosure and form part of the specification. They are used together with the embodiments of this disclosure to explain the disclosure and do not constitute a limitation thereof. In the drawings, the same reference numerals generally represent the same components or steps.

[0032] Figure 1 This is a system architecture diagram illustrating a cloud service security protection method according to an embodiment of this disclosure.

[0033] Figure 2 This is a diagram illustrating the component interactions of an NFV platform module according to an embodiment of this disclosure.

[0034] Figure 3 This is a flowchart illustrating a cloud service security protection method according to an embodiment of this disclosure.

[0035] Figure 4 This is a schematic diagram of the structure of a cloud service security protection device according to an embodiment of the present disclosure.

[0036] Figure 5 This is a schematic diagram illustrating the structure of a computer device according to an embodiment of the present disclosure.

[0037] Figure 6 This is a schematic diagram illustrating a computer program product according to an embodiment of the present disclosure. Detailed Implementation

[0038] To make the objectives, technical solutions, and advantages of this disclosure more apparent, exemplary embodiments according to this disclosure will now be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this disclosure, and not all embodiments of this disclosure. It should be understood that this disclosure is not limited to the exemplary embodiments described herein.

[0039] With the rapid development of cloud computing, businesses and individuals are increasingly relying on cloud services for their operations and daily activities. However, migrating businesses to the cloud has brought about many security challenges, making cloud security products essential. Among cloud security products, next-generation cloud firewalls are widely favored by customers due to their powerful protection capabilities.

[0040] However, the next-generation cloud firewall still has the following shortcomings: (1) Firewalls are generally ordered by the customer. After purchase, the customer needs to manually configure the NAT policy, which requires high network technology from the customer and results in poor usability.

[0041] (2) The firewalls ordered by the customers are independent and scattered in the customers' own business cloud hosts. The cloud service providers cannot manage these firewalls throughout their entire lifecycle, thus they cannot manage the massive amount of firewall logs in a unified manner and perform big data analysis, which means that security policies still need to be added manually.

[0042] (3) Most of the related technologies use firewall images to be deployed on cloud hosts to become cloud firewalls. However, due to the limitation of the number of network cards, a firewall can only protect a maximum of 5 elastic public IPs, while some large customers have more than 500 elastic public IPs, which is difficult to meet the needs of customers.

[0043] (4) The relevant technologies are still unable to protect multiple users with one firewall and cannot achieve cloud firewall sharing.

[0044] The above description, with reference to the accompanying drawings, illustrates a cloud service security protection method, apparatus, device, medium, and product according to embodiments of the present disclosure. By constructing a firewall resource pool through a self-developed cloud-native firewall (hereinafter referred to as "cloud firewall"), customers do not need to manually configure NAT policies after purchasing the cloud firewall. The vendor manages the firewall resource pool uniformly and can dynamically generate more intelligent security policies based on real-time log data generated by the firewall resource pool, thereby improving the flexibility and automation of security protection.

[0045] To facilitate understanding of this embodiment, a detailed description of the cloud service security protection method disclosed in this disclosure is provided first. The executing entity of the cloud service security protection method provided in this disclosure is generally a computer device with a certain computing capability. This computer device may include, for example, a terminal device, a server, or other processing devices. The terminal device may be a user equipment (UE), mobile device, user terminal, terminal, cellular phone, cordless phone, personal digital assistant (PDA), handheld device, computing device, in-vehicle device, wearable device, etc. In some possible implementations, this cloud service security protection method can be implemented by a processor calling computer-readable instructions stored in memory.

[0046] like Figure 1 The diagram shown illustrates the system architecture of the cloud service security protection method provided in this embodiment, including a console module 1, an NFV platform module 2, a network element controller module 3, and a firewall resource pool module 4. NFV stands for Network Function Virtualization. The specific functions of each module are described below: Console Module 1: This module primarily provides users with an entry page for ordering, modifying, and renewing services. Users can use Console Module 1 to order cloud firewalls (i.e., firewall network elements) developed by cloud vendors to protect their business assets and send corresponding protection policies to the firewall network elements.

[0047] Specifically, after the console module receives the protection policy configured by the user, it calls the API interface of the network element controller module 3. The network element controller module 3 then calls the firewall network element interface to distribute the protection policy to the firewall network element that actually performs the protection.

[0048] Meanwhile, the console module also features Internet Protocol Suite (IPS) configuration, antivirus configuration, and one-click enable / disable protection. The one-click protection feature protects users' business assets (such as Elastic Public IPs). Users can enable it with a simple click, eliminating the need for manual NAT policy configuration and requiring no advanced network technology from the customer, thus improving user experience and satisfaction. The one-click protection feature works by calling the Elastic Public IP unbinding interface, simultaneously calling the interface of NFV platform module 2 to create a network endpoint (creating a Group ENI), and calling the interface of network element controller module 3 to configure the firewall network element for NAT and other traffic redirection.

[0049] NFV Platform Module 2: Utilizes cloud computing technology to deploy firewall software on virtual machines, pooling firewall resources and building a firewall resource pool.

[0050] This embodiment leverages the elasticity and high reliability of resource pooling to promote the software-based deployment of firewall network elements. By running software firewall network elements on virtual machines, higher-performance virtualized firewall network elements can be built. Resource pool management requires providing platform-based NFV management capabilities on the cloud host. Combined with the scheduling of network element controller module 3, this enables the NFV capabilities of cloud firewall network elements, replacing the current firewall architecture that cannot be centrally managed, saving costs while providing platform-based capabilities.

[0051] NFV Platform Module 2, based on general-purpose cloud hosts (virtual machines) and leveraging the active-active, multi-tenant characteristics of Software-Defined Networking (SDN), enables full lifecycle management of firewall network elements, including quota management, cluster management, resource decision-making, and orchestration and scheduling management functions such as configuration distribution. NFV Platform Module 2 also facilitates network traffic between the firewall network element's Virtual Private Cloud (VPC) and the user's VPC, establishing a traffic transmission channel between the firewall network element VPC and the user's VPC. In addition, NFV Platform Module 2 is responsible for creating network element domains, virtual machine warm-up (e.g., creating or destroying firewall network elements), network element health checks, fault handling, and monitoring and alarming.

[0052] NFV Platform Module 2 provides multiple API interfaces, packaging all the aforementioned capabilities (resource creation, network configuration, etc.) into standard API interfaces, such as domain creation (i.e., initial configuration), firewall resource pool creation, and network endpoint creation, for console module 1 to call, automating traffic flow and enabling protection with a single click. Console module 1 does not need to know the internal complexity of NFV Platform Module 2; it only needs to call these API interfaces to automatically complete all background preparation work and enable protection with a single click.

[0053] To enable cross-VPC traffic flow, NFV platform module 2 connects to Tianchi SDN. SDN has developed its own Group ENI component and provides an interface for the NFV platform to call the Group ENI component. Ultimately, this achieves automated diversion of user traffic to the cloud firewall for protection before returning to the user's business cloud host, thus realizing protection for business traffic through the firewall.

[0054] Specifically, Group ENI is mainly used in NFV scenarios. Traffic originating from a business cloud host (or virtual machine) is routed to one or more VNF network elements via Equal-cost Multi-Path Routing (ECMP). VNF (Virtual Network Function) is a core concept in the NFV architecture, and in this context, it can refer to a firewall network element. The VNF network element may be a vLB / vNAT firewall cluster or other firewall network elements, which can improve the multi-active and load balancing capabilities of virtual machine (VM) traffic to the VNF network element. Furthermore, to enable multi-tenant sharing of the same VNF network element, this embodiment supports VLAN TRUNK functionality. This adds specified user VLAN information to the traffic data from VMs to the VNF network element, facilitating user differentiation within the VNF network element. After the traffic data returns to the VM, the VLAN needs to be stripped. Group ENI functionality mainly includes traffic redirection, ECMP multicast, and VLAN TRUNK.

[0055] Meanwhile, Group ENI combines traffic redirection, Group multicast, and VLAN TRUNK functions to achieve load balancing and VLAN conversion from VMs to VNFs. Group ENI will utilize existing OpenFlow flow tables and add new flow tables to implement this functionality, which can be further divided into: traffic classification flow tables, traffic redirection flow tables, and ECMP multicast tables.

[0056] Group ENI acts as a "logistics sorting center," serving as a traffic transmission channel. User traffic data originates from their own cloud host, enters Group ENI, and is tagged with VLAN information. Based on real-time traffic congestion, Group ENI selects one or more suitable paths (ECMP) to send the traffic data to the NFV platform. Firewall network elements distinguish users based on the VLAN information and clean the traffic data. The cleaned traffic data is then sent back to Group ENI. After deleting the VLAN information, Group ENI sends the cleaned traffic data back to the user's own cloud host.

[0057] like Figure 2 The diagram shows the component interaction of the NFV platform module. By combining the NFV platform with Group ENI, it solves the core pain points of traditional solutions, such as the inability to centrally manage firewalls, performance bottlenecks, and the inability to share resources among multiple users. It is the underlying technological foundation for achieving "one-click protection" and "intelligent security".

[0058] Network element controller module 3: It is mainly used to receive protection policies, IPS, etc. issued by console module 1, transfer them and then issue them to the firewall network element, while verifying and controlling the consistency of protection policies.

[0059] The most important function of the network element controller module 3 is to analyze the massive amounts of log data (tens of billions of records) generated by the firewall resource pool, forming a general security policy library and automatically adding security policies for users. Specifically, it first collects and integrates the log data, processing it into a unified format. Then, it analyzes the data using SQL statements, such as identifying abnormal attacking IPs from the past week. These IPs are written into the security policy library and automatically added to the user's firewall blacklist for proactive protection. As the firewall resource pool continues to operate, the log data becomes more comprehensive and intelligent, and the model algorithms learn more deeply. This allows the security policy library to become increasingly comprehensive and intelligent in anticipating potential future security risks.

[0060] This embodiment uses a large model algorithm to analyze log data. The Transformer model, based on a self-attention mechanism, has the following advantages: (1) The Transformer model is particularly suitable for processing long sequence data and can effectively capture the time dependency and complex contextual relationships in log data.

[0061] (2) The self-attention mechanism allows the model to process all data points simultaneously during training, and its parallel computing capability can significantly improve the efficiency of processing large-scale datasets.

[0062] (3) Flexibility and powerful feature extraction capabilities: The Transformer model can learn useful knowledge from a large amount of unstructured log data, which is crucial for identifying complex attack patterns and anomalous behaviors.

[0063] Therefore, this embodiment uses the Transformer model to train a large language model, enabling it to learn from billions of firewall log data points and automatically generate security policies. Specifically, the complete model training process, from data preprocessing to model deployment and continuous updates, is as follows: 1) Data preprocessing stage: Clean the log data, remove irrelevant items and unify the format, and then perform tokenization to convert the log entries into a format that the Transformer model can understand; 2) Pre-training model stage: The Transformer model is pre-trained using a large amount of historical log data to help it learn and understand the language and structure of web log data.

[0064] During the pre-training phase, the self-supervised learning task of Masked Language Model (MLM) is mainly used to train the Transformer model to predict the randomly masked parts of the log.

[0065] 3) Model Fine-tuning Stage: After the Transformer model has a sufficient understanding of the log data, supervised learning methods based on known attack patterns and corresponding defense strategies are used to fine-tune the model for specific security policy generation tasks. For example, the Transformer model is trained to automatically generate security policies based on the context of the log data.

[0066] After the model is trained, the large language model is deployed to a real-world environment for real-time analysis, dynamically generating security policies and automatically updating these security policies to the user's firewall settings.

[0067] In addition, considering the constant changes in the network environment and the emergence of new attack techniques, the model can be retrained and fine-tuned periodically to ensure its accuracy and relevance, thereby maintaining the effectiveness of the protection measures. This ensures that this embodiment can not only respond to current security needs, but also predict potential future threats.

[0068] Firewall resource pool module 4: It is used to protect the user's business traffic and will send the generated billions of log data (such as attack logs) to network element controller module 3.

[0069] This embodiment deeply integrates three cutting-edge technologies—NFV (resource pooling and management automation), SDN (network traffic intelligence), and AI big model (security policy intelligence)—through the console module 1, NFV platform module 2, network element controller module 3, and firewall resource pool module 4, to solve some of the problems existing in current cloud firewalls.

[0070] In practical applications, the essence of one-click protection activation is to automatically rearrange network traffic through a series of interface calls and database operations. This redirects public network traffic that would otherwise flow directly to the user's cloud host to a shared firewall resource pool for cleaning before sending it back. The entire process involves the collaborative work of console module 1, NFV platform module 2 (including SDN), network element controller module 3, and firewall resource pool module 4. The process for one-click protection deactivation is the reverse of one-click activation; therefore, this embodiment only describes the implementation process of "one-click protection activation," as follows: Step 1: The user selects an Elastic Public IP address in the console module and clicks "Enable Protection with One Click". The backend service of the console module receives this cloud service protection request and sends it to NFV platform module 2.

[0071] Step 2: After receiving the cloud service protection request, NFV platform module 2 executes an SQL query to retrieve the firewall network element details table (fw_host_details) to obtain information about the firewall network element, such as NFV_RESOURCE_POOL_ID and TRUNK_ID.

[0072] The firewall network element details table (fw_host_details) includes information about pre-incubated firewall resource pools, as shown in Table 1, which is a table of fields for the firewall network element details table: Table 1. Fields of the Firewall Network Element Details Table

[0073] Step 3: The NFV platform module uses the obtained NFV_RESOURCE_POOL_ID and TRUNK_ID to call the network API interface to obtain relevant network information, such as networkId, subnetId, and routerId.

[0074] The NFV platform module takes the TRUNK_ID obtained in the previous step, calls the northbound API of SDN (e.g., GET / v1 / ports / {trunk_port_id}), queries the network details carrying the firewall network element service, and determines whether to create a new Group ENI from the routerId (router ID) returned by SDN.

[0075] Step 4: Based on the network information such as routerId obtained in Step 3, query the Group ENI table to determine if the Group ENI is being created for the first time under this VPC. If it is being created for the first time, it means this is the first request from the routerId (i.e., this user's VPC), and a new Group ENI needs to be created, along with an automatic fixed IP address. If a Group ENI has already been created under this VPC, it means the Group ENI already exists, and a new fixed IP address only needs to be assigned to this Group ENI.

[0076] Simultaneously, the relevant information of the created Group ENI is persisted to the Group ENI Details table (groupeni_details) in the database. Table 2 shows the fields of the Group ENI Details table: Table 2: Fields of the Group ENI Details Table

[0077] Step 5: After creating the Group ENI, add a default route to the business cloud host. Only after adding a default route can the traffic of the business cloud host be sent to the firewall network element.

[0078] Step 6: Call the interface of the network element controller module to configure firewall traffic redirection, including configuring NAT, default route, creating VLAN, etc., to complete the traffic connection from firewall to business cloud host.

[0079] Step 7: After completing the firewall traffic redirection configuration, unbind the elastic public IP of the business cloud host and bind it to the fixed IP of GroupENI. From then on, all traffic accessing the elastic public IP will no longer be directed to the user's business cloud host, but to Group ENI, which will then forward it to the firewall network element. The firewall network element will clean the traffic and then forward it to the business cloud host, thus completing the protection of customer business traffic through the firewall.

[0080] Step 8: After completing the above steps, mark the information that the Elastic Public IP has enabled protection in the database, as shown in Table 3, which is the Elastic Public IP Details Table (publicip_detail): Table 3. Details of Elastic Public IP Addresses

[0081] Based on the above embodiments, this embodiment provides a cloud service security protection method, such as... Figure 3 The diagram shows a flowchart of cloud service security protection methods, including S301-S304: S301: Receives cloud service protection requests sent by users.

[0082] Among them, the cloud service protection request is used to request protection for the elastic public IP specified by the user. The cloud service protection request carries the protection policy, and the protection policy represents the user's explicit protection intention. S302: Based on cloud service protection requests, identify the target cloud firewall from a pre-built firewall resource pool.

[0083] The firewall resource pool includes multiple firewall software programs deployed on virtual machines. S303: During the period when the target cloud firewall is protecting the elastic public IP according to the protection policy, obtain the real-time log data generated by the firewall resource pool.

[0084] S304: Generate real-time security policies based on pre-trained large language models and real-time log data.

[0085] Among them, the target cloud firewall provides security protection for elastic public IPs based on security policies and protection policies.

[0086] This embodiment builds a firewall resource pool using a self-developed cloud-native firewall. After purchasing the cloud firewall, users do not need to manually configure NAT policies. The vendor manages the firewall resource pool in a unified manner and can dynamically generate more intelligent security policies based on the real-time log data generated by the firewall resource pool, thereby improving the flexibility and automation of security protection.

[0087] In one or more embodiments, the training process of a large language model includes: The Transformer model is pre-trained using a masked language model to learn the language and structure of log data. The pre-trained Transformer model is then retrained using a supervised learning method based on known attack patterns and corresponding defense strategies to obtain a large language model.

[0088] Specifically, the complete model training process in this embodiment, from data preprocessing to model deployment and continuous updates, is as follows: 1) Data preprocessing stage: Clean the log data, remove irrelevant items and unify the format, and then perform tokenization to convert the log entries into a format that the Transformer model can understand; 2) Pre-training model stage: The Transformer model is pre-trained using a large amount of historical log data to help it learn and understand the language and structure of web log data.

[0089] During the pre-training phase, the self-supervised learning task of Masked Language Model (MLM) is mainly used to train the Transformer model to predict the randomly masked parts of the log.

[0090] 3) Model Fine-tuning Stage: After the Transformer model has a sufficient understanding of the log data, supervised learning methods based on known attack patterns and corresponding defense strategies are used to fine-tune the model for specific security policy generation tasks. For example, the Transformer model is trained to automatically generate security policies based on the context of the log data.

[0091] After the model is trained, the large language model is deployed to a real-world environment for real-time analysis, dynamically generating security policies and automatically updating these security policies to the user's firewall settings.

[0092] In one or more embodiments, a real-time security policy is generated based on a pre-trained large language model and real-time log data, including: Security analysis is continuously performed based on pre-trained large language models and real-time log data, and analysis results are generated. When the analysis results indicate the emergence of new potential threats, real-time security policies are generated and stored in the security policy library.

[0093] User-configured protection policies represent the user's explicit protection intentions and build a basic security environment, while automatically generated protection policies are used on top of this basic security environment for real-time and precise threat hunting and response. The two are complementary and reinforcing.

[0094] In one or more embodiments, the process of building a firewall resource pool includes: Deploy and run firewall software on multiple virtual machines; perform full lifecycle management of the firewall software, which includes multiple orchestration and scheduling management functions; create data interfaces corresponding to each orchestration and scheduling management function so that users can call the corresponding orchestration and scheduling management functions through the data interfaces.

[0095] Specifically, the orchestration and scheduling management functions include quota management, cluster management, resource decision-making, configuration distribution, virtual machine warm-up, etc. Specific functions can be selected according to actual needs.

[0096] In one or more embodiments, determining a target cloud firewall from a pre-built firewall resource pool based on a cloud service protection request includes: Based on the cloud service protection request, the firewall database is queried; the firewall database is used to store firewall software information of the firewall resource pool; based on the firewall database, the target cloud firewall is determined from the firewall resource pool.

[0097] In one or more embodiments, after determining the target cloud firewall from a pre-built firewall resource pool based on the cloud service protection request, the method further includes: Establish a traffic transmission channel between the first virtual private cloud where the target cloud firewall is located and the second virtual private cloud where the elastic public IP is located; obtain traffic data generated by accessing the elastic public IP; and send traffic data to the first virtual private cloud based on the traffic transmission channel.

[0098] Specifically, Group ENI is equivalent to a traffic transmission channel, which connects the target cloud firewall VPC (first virtual private cloud) and the user VPC (second virtual private cloud) to automatically redirect user traffic to the cloud firewall for protection before returning to the user's business cloud host, thus achieving protection for business traffic through the firewall.

[0099] In one or more embodiments, the target cloud firewall includes a single cloud firewall or a firewall cluster consisting of multiple cloud firewalls, and further includes: The system sets identification information for traffic data, which is used by the target cloud firewall to identify the user corresponding to the traffic data; it sends the traffic data with identification information to the target cloud firewall according to the equal cost multipath routing protocol; the target cloud firewall processes the traffic data through the protection policy to obtain the processed traffic data; it deletes the identification information carried by the processed traffic data and sends the processed traffic data to the second virtual private cloud based on the traffic transmission channel.

[0100] In one or more embodiments, establishing a traffic transmission channel between a first virtual private cloud where the target cloud firewall resides and a second virtual private cloud where the elastic public IP address resides includes: Obtain the cluster information and service NIC ID of the target cloud firewall; based on the cluster information and service NIC ID, confirm the first virtual private cloud where the target cloud firewall is located; if no traffic transmission channel is established in the first virtual private cloud, obtain the second virtual private cloud where the elastic public IP is located; establish a traffic transmission channel between the first virtual private cloud and the second virtual private cloud, and establish a fixed IP for the traffic transmission channel.

[0101] In one or more embodiments, if a traffic transmission channel has been established in the first virtual private cloud, a fixed IP address is established for the traffic transmission channel.

[0102] In one or more embodiments, it further includes: Obtain the fixed IP address for the traffic transmission channel; configure the target cloud firewall to redirect traffic based on the fixed IP address; unbind the elastic public IP address from the user's business cloud host and bind it to the fixed IP address so that the traffic data of the elastic public IP address can be routed to the target cloud firewall.

[0103] In one or more embodiments, the method further includes: updating the status of the Elastic Public IP to protected and storing it in a database; and sending a response message of a cloud service protection request to the user.

[0104] According to another aspect of the embodiments of this disclosure, a cloud service security protection device is provided, such as... Figure 4 As shown, the device includes: The receiving module 401 is used to receive a cloud service protection request sent by a user, wherein the cloud service protection request is used to request protection for the elastic public IP specified by the user, the cloud service protection request carries a protection policy, and the protection policy represents the user's explicit protection intention. Firewall confirmation module 402 is used to determine the target cloud firewall from a pre-built firewall resource pool based on the cloud service protection request; wherein, the firewall resource pool includes multiple firewall software deployed on virtual machines; The log data acquisition module 403 is used to acquire real-time log data generated by the firewall resource pool during the period when the target cloud firewall protects the elastic public IP according to the protection policy; The security policy generation module 404 is used to generate a real-time security policy based on a pre-trained large language model and the real-time log data; wherein, the target cloud firewall provides security protection for the elastic public IP according to the security policy and the protection policy.

[0105] The cloud service security protection device and the cloud service security protection method provided in this disclosure are based on the same inventive concept and have the same beneficial effects as the methods they adopt, operate or implement.

[0106] This disclosure also provides a computer device for implementing the above-described cloud service security protection method. Please refer to... Figure 5 It illustrates a schematic diagram of a computer device provided by some embodiments of this disclosure. For example... Figure 5 As shown, the computer device 5 includes: a processor 500, a memory 501, a bus 502, and a communication interface 503. The processor 500, the communication interface 503, and the memory 501 are connected via the bus 502. The memory 501 stores a computer program that can run on the processor 500. When the processor 500 runs the computer program, it executes the cloud service security protection method provided by any of the foregoing embodiments of this disclosure.

[0107] The memory 501 may include high-speed random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Communication between this device network element and at least one other network element is achieved through at least one communication interface 503 (which can be wired or wireless), such as the Internet, wide area network, local area network, metropolitan area network, etc.

[0108] Bus 502 can be an ISA bus, PCI bus, or EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. The memory 501 is used to store programs. After receiving an execution instruction, the processor 500 executes the program. The cloud service security protection method disclosed in any of the foregoing embodiments of this disclosure can be applied to the processor 500, or implemented by the processor 500.

[0109] The processor 500 may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed by the integrated logic circuitry in the hardware of the processor 500 or by instructions in software form. The processor 500 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf programmable gate array (FPTA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this disclosure. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this disclosure can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules may reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory 501. The processor 500 reads the information in memory 501 and, in conjunction with its hardware, completes the steps of the above method.

[0110] The computer device and the cloud service security protection method provided in this disclosure are based on the same inventive concept and have the same beneficial effects as the methods they adopt, operate or implement.

[0111] This disclosure also provides a computer-readable storage medium corresponding to the cloud service security protection method provided in the foregoing embodiments. The computer-readable storage medium is an optical disc, on which a computer program (i.e., a computer program product) is stored. When the computer program is run by a processor, it executes the cloud service security protection method provided in any of the foregoing embodiments.

[0112] It should be noted that examples of the computer-readable storage medium may also include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other optical and magnetic storage media, which will not be elaborated here.

[0113] The computer-readable storage medium provided in the above embodiments of this disclosure and the cloud service security protection method provided in the embodiments of this disclosure are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the applications stored therein.

[0114] This disclosure also provides a computer program product; please refer to [link / reference]. Figure 6 The computer program product 600 carries program code, namely computer program 601. The instructions included in the computer program 601 can be used to execute the steps of the cloud service security protection method described in the above method embodiments. For details, please refer to the above method embodiments, which will not be repeated here.

[0115] The aforementioned computer program product can be implemented through hardware, software, or a combination thereof. In one optional embodiment, the computer program product is specifically embodied in a computer storage medium; in another optional embodiment, the computer program product is specifically embodied in a software product, such as a software development kit (SDK), etc.

[0116] The basic principles of this disclosure have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this disclosure are merely examples and not limitations, and should not be considered as essential features of each embodiment of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the aforementioned specific details for implementation.

[0117] The block diagrams of devices, apparatuses, devices, and systems disclosed herein are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as “comprising,” “including,” “having,” etc., are open-ended terms meaning “including but not limited to,” and are used interchangeably with them. The terms “or” and “and” as used herein refer to the terms “and / or,” and are used interchangeably with them unless the context clearly indicates otherwise. The term “such as” as used herein refers to the phrase “such as but not limited to,” and is used interchangeably with it.

[0118] Additionally, as used herein, the "or" used in a list of items beginning with "at least one" indicates a separate list, such that a list of, for example, "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the word "exemplary" does not imply that the described example is preferred or better than other examples.

[0119] It should also be noted that in the systems and methods of this disclosure, the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered as equivalent solutions to this disclosure.

[0120] Various changes, substitutions, and modifications can be made to the technology described herein without departing from the teachings defined by the appended claims. Furthermore, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, events, means, methods, and actions described above. Currently existing or later-developed processes, machines, manufactures, events, means, methods, or actions that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Therefore, the appended claims include such processes, machines, manufactures, events, means, methods, or actions within their scope.

[0121] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to be carried out within the widest scope consistent with the principles and novel features disclosed herein.

[0122] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.

Claims

1. A cloud service security protection method, characterized in that, include: Receive a cloud service protection request sent by a user, wherein the cloud service protection request is used to request protection for the elastic public IP specified by the user, the cloud service protection request carries a protection policy, and the protection policy represents the user's explicit protection intention; Based on the cloud service protection request, a target cloud firewall is determined from a pre-built firewall resource pool; wherein, the firewall resource pool includes multiple firewall software deployed on virtual machines; While the target cloud firewall is protecting the elastic public IP according to the protection policy, real-time log data generated by the firewall resource pool is obtained. Based on the pre-trained large language model and the real-time log data, a real-time security policy is generated; wherein, the target cloud firewall provides security protection for the elastic public IP according to the security policy and the protection policy.

2. The cloud service security protection method as described in claim 1, characterized in that, The training process of the large language model includes: The Transformer model is pre-trained using a masked language model so that it can learn the language and structure of the log data. A supervised learning method based on known attack patterns and corresponding defense strategies is used to retrain the pre-trained Transformer model to obtain the large language model.

3. The cloud service security protection method as described in claim 1, characterized in that, Based on the pre-trained large language model and the real-time log data, a real-time security policy is generated, including: Security analysis is continuously performed based on the pre-trained large language model and the real-time log data, and analysis results are generated. When the analysis results indicate the emergence of new potential threats, a real-time security policy is generated and stored in the security policy library.

4. The cloud service security protection method as described in claim 1, characterized in that, The process of constructing the firewall resource pool includes: Deploy and run firewall software on multiple virtual machines; The firewall software is subject to full lifecycle management, which includes multiple orchestration and scheduling management functions. Create data interfaces corresponding to each of the aforementioned orchestration and scheduling management functions, so that the user can call the corresponding orchestration and scheduling management functions through the data interfaces.

5. The cloud service security protection method as described in claim 1, characterized in that, The step of determining the target cloud firewall from a pre-built firewall resource pool based on the cloud service protection request includes: Based on the cloud service protection request, the firewall database is queried; wherein, the firewall database is used to store firewall software information of the firewall resource pool; The target cloud firewall is determined from the firewall resource pool based on the firewall database.

6. The cloud service security protection method as described in claim 1, characterized in that, After determining the target cloud firewall from a pre-built firewall resource pool based on the cloud service protection request, the process further includes: Establish a traffic transmission channel between the first virtual private cloud where the target cloud firewall is located and the second virtual private cloud where the elastic public IP is located; Obtain traffic data generated by accessing the elastic public IP address; Based on the traffic transmission channel, the traffic data is sent to the first virtual private cloud.

7. The cloud service security protection method as described in claim 6, characterized in that, The target cloud firewall includes a single cloud firewall or a firewall cluster consisting of multiple cloud firewalls, and also includes: The traffic data is assigned identification information, which is used by the target cloud firewall to identify the user corresponding to the traffic data; The traffic data containing the identification information is sent to the target cloud firewall according to the equal cost multipath routing protocol; The target cloud firewall processes the traffic data using the aforementioned protection strategy to obtain processed traffic data. The identification information carried in the processed traffic data is deleted, and the processed traffic data is sent to the second virtual private cloud based on the traffic transmission channel.

8. The cloud service security protection method as described in claim 6, characterized in that, Establishing a traffic transmission channel between the first virtual private cloud where the target cloud firewall is located and the second virtual private cloud where the elastic public IP is located includes: Obtain the cluster information and service network interface ID of the target cloud firewall; Based on the cluster information and the service network card ID, the first virtual private cloud where the target cloud firewall is located is confirmed; In the absence of a traffic transmission channel established in the first virtual private cloud, obtain the second virtual private cloud where the elastic public IP is located; Establish the traffic transmission channel between the first virtual private cloud and the second virtual private cloud, and assign a fixed IP address to the traffic transmission channel.

9. The cloud service security protection method as described in claim 8, characterized in that, If a traffic transmission channel has been established in the first virtual private cloud, a fixed IP address is established for the traffic transmission channel.

10. The cloud service security protection method as described in claim 6, characterized in that, Also includes: Obtain the fixed IP address of the traffic transmission channel; Based on the fixed IP address, configure the target cloud firewall to redirect traffic; The elastic public IP is unbound from the user's business cloud host and bound to the fixed IP so that the traffic data of the elastic public IP can be routed to the target cloud firewall.

11. The cloud service security protection method as described in claim 1, characterized in that, Also includes: Update the status of the elastic public IP to "protected" and store it in the database; Send the response information of the cloud service protection request to the user.

12. A cloud service security protection device, characterized in that, include: The receiving module is used to receive cloud service protection requests sent by users, wherein the cloud service protection request is used to request protection for the elastic public IP specified by the user, the cloud service protection request carries a protection policy, and the protection policy represents the user's explicit protection intention. The firewall verification module is used to determine the target cloud firewall from a pre-built firewall resource pool based on the cloud service protection request; wherein, the firewall resource pool includes multiple firewall software deployed on virtual machines; The log data acquisition module is used to acquire real-time log data generated by the firewall resource pool during the period when the target cloud firewall protects the elastic public IP according to the protection policy; The security policy generation module is used to generate a real-time security policy based on a pre-trained large language model and the real-time log data; wherein, the target cloud firewall provides security protection for the elastic public IP according to the security policy and the protection policy.

13. A computer embedded device, comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the method according to any one of claims 1 to 11.

14. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method described in any one of claims 1 to 11.

15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method described in any one of claims 1 to 11.

Citation Information

Patent Citations

  • Virtual flow monitoring method based on cloud platform and device thereof

    CN104917653A

  • Automatic query method and system for firewall policy

    CN105681327A

  • Firewall deployment method and device

    CN109120577A

  • Method and device for adjusting virtual firewall in private cloud environment

    CN116015749A

  • Firewall configuration method and device, electronic equipment and computer readable storage medium

    CN116366269A