Disaster recovery environment detection method and device, equipment, storage medium and program product
By dynamically configuring the disaster recovery environment detection framework in the cloud, adding a firewall detection program and configuring program identifiers and environment variables, cross-regional collaborative detection is achieved, solving the real-time availability problem of remote disaster recovery environments and improving the detection automation and response speed of the disaster recovery system.
Patent Information
- Application Number
- CN202511085875.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-04
- Publication Date
- 2025-11-04
Smart Images

Figure CN120896875A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of financial technology or other related fields, in particular to a disaster recovery environment detection method, device, equipment, storage medium and program product. BACKGROUND
[0002] In the financial field, the disaster recovery environment refers to a backup system environment established to cope with various emergencies (such as natural disasters, system failures, network attacks, etc.) that may affect business continuity, and to ensure the safe and stable operation of key financial business systems and data. The environment usually includes off-site backup data centers, redundant hardware facilities, real-time or scheduled data backups, and automatic switching mechanisms to ensure that core financial services such as transactions, payments, and clearing can be quickly recovered in the event of a main system failure.
[0003] In the prior art, the disaster recovery environment detection method includes simulating a fault switching scenario through regular production drills to verify whether the disaster recovery system can start normally, whether the parameter configuration is accurate, whether the network is connected, and whether the external system is available, to ensure that the business can be reliably taken over when actually needed.
[0004] However, in the prior art, the off-site disaster recovery environment is difficult to synchronize and verify its reliability in real time due to the differences in physical environment, parameter configuration, etc. between the off-site disaster recovery environment and the production environment, and the high-cost production drills cannot be performed frequently to adapt to the rhythm of change and production, resulting in difficulty in ensuring the real-time availability of the disaster recovery system. SUMMARY
[0005] The present application provides a disaster recovery environment detection method, device, equipment, storage medium and program product to solve the problem of difficulty in ensuring the real-time availability of the disaster recovery system.
[0006] In a first aspect, the present application provides a disaster recovery environment detection method applied to a diagnosis console of a business system, the method comprising:
[0007] Based on the configuration change information of the environment variable sent by the cloud, a firewall detection program is added;
[0008] The program identifier and the associated environment variable are configured for the added firewall detection program;
[0009] According to the program identifier, the existing firewall detection program and its associated environment variable are distributed to the diagnosis nodes of the business system deployed in multiple business areas, so that the diagnosis nodes execute the acquired firewall detection program to generate a detection report of the deployed business area disaster recovery environment.
[0010] In a second aspect, the present application provides a disaster recovery environment detection method applied to a diagnosis node deployed in a business area of a business system, the method comprising:
[0011] acquire the firewall detection program and the associated environment variable sent by the diagnosis console;
[0012] execute the firewall detection program based on the associated environment variable, and generate a detection report of the deployed disaster recovery environment of the business area.
[0013] In a third aspect, the present application provides a disaster recovery environment detection device applied to a diagnosis console of a business system, and the device comprises:
[0014] a firewall program adding module configured to add a firewall detection program based on the configuration change information of the environment variable sent by the cloud;
[0015] a variable association module configured to configure a program identifier and an associated environment variable for the added firewall detection program;
[0016] a program issuing module configured to issue the existing firewall detection program and the associated environment variable to diagnosis nodes of the business system deployed in multiple business areas according to the program identifier, so that the diagnosis nodes execute the acquired firewall detection program and generate a detection report of the deployed disaster recovery environment of the business area.
[0017] In a fourth aspect, the present application provides a disaster recovery environment detection device applied to a diagnosis node of a business area of a business system, and the device comprises:
[0018] a program acquisition module configured to acquire the firewall detection program and the associated environment variable sent by the diagnosis console;
[0019] an environment detection module configured to execute the firewall detection program based on the associated environment variable, and generate a detection report of the deployed disaster recovery environment of the business area.
[0020] In a fifth aspect, the present application provides an electronic device comprising a processor and a memory in communication connection with the processor; the memory stores computer execution instructions; and the processor executes the computer execution instructions stored in the memory to implement the method provided in the first aspect and the method provided in the second aspect.
[0021] In a sixth aspect, the present application provides a computer readable storage medium, wherein the computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by a processor to implement the method provided in the first aspect and the method provided in the second aspect.
[0022] In a seventh aspect, the present application provides a computer program product comprising a computer program, wherein the computer program is executed by a processor to implement the method provided in the first aspect and the method provided in the second aspect.
[0023] The disaster recovery environment detection method provided by the application can realize flexible binding and management of detection programs and environment parameters by sending environment variable configuration change information based on the cloud, dynamically adding a firewall detection program, and configuring a unique program identifier and associated environment variable for the firewall detection program. On this basis, the system can accurately distribute the existing firewall detection program and its associated environment variable to diagnostic nodes distributed in multiple business areas according to the program identifier, drive each node to execute the corresponding detection logic, and thus generate a detection report of the local disaster recovery environment. The method effectively improves the automation degree, cross-regional collaboration ability and configuration flexibility of the disaster recovery detection process, and enhances the response speed and adaptability of the disaster recovery system to environmental changes, and also improves the real-time availability of the disaster recovery system. BRIEF DESCRIPTION OF DRAWINGS
[0024] The accompanying drawings, which are incorporated herein and form part of the specification, illustrate embodiments consistent with the present application and, together with the description, further serve to explain the principles of the application.
[0025] Figure 1 A flowchart of a disaster recovery environment detection method provided by an embodiment of the application Figure One ;
[0026] Figure 2 A flowchart of a disaster recovery environment detection method provided by an embodiment of the application Figure Two ;
[0027] Figure 3 An interaction diagram of a disaster recovery environment detection method provided by an embodiment of the application
[0028] Figure 4 A flowchart of a disaster recovery environment detection method provided by an embodiment of the application Figure Three ;
[0029] Figure 5 A structural diagram of a disaster recovery environment detection device provided by an embodiment of the application Figure One ;
[0030] Figure 6 A structural diagram of a disaster recovery environment detection device provided by an embodiment of the application Figure Two ;
[0031] Figure 7 A structural diagram of an electronic device provided by an embodiment of the application.
[0032] The above-described drawings have shown specific embodiments of the present application, and more detailed descriptions will be given hereinafter. These drawings and written descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION
[0033] The exemplary embodiments will be described in detail below with reference to the drawings. In the following description, unless otherwise indicated, like numbers in the different drawings represent similar or identical elements. The following exemplary embodiments described in the following description are not meant to be limiting of all the embodiments that would be consistent with the application. Instead, they are merely examples of apparatus and methods consistent with some aspects of the application as detailed in the appended claims.
[0034] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of related data comply with relevant laws, regulations and standards of relevant countries and regions, necessary security measures are taken, public order and good customs are not violated, and appropriate operation portals are provided for users to choose authorization or refusal.
[0035] And the present application involves big data analysis of user information (including but not limited to personal biological characteristics, identity data, consumption data, asset data, electronic terminal operation data, etc.), and uses artificial intelligence technology for automatic decision-making, and makes technical solutions based on automatic decision-making results that have a significant impact on personal rights and interests, provides appropriate operation portals for users to choose to agree or refuse automatic decision-making results; if the user chooses to refuse, the expert decision-making process is entered.
[0036] It should be noted that the disaster recovery environment detection system, disaster recovery environment detection method and request initiation provided by the present application can be used in the field of financial technology, and can also be used in any field other than the field of financial technology. The application field of the disaster recovery environment detection system, disaster recovery environment detection method and request initiation in the present application is not limited.
[0037] In the financial field, disaster recovery environment is a backup system environment established to ensure the safety and stability of key business systems and data in the face of unexpected events. These unexpected events include natural disasters, system failures and network attacks, which can all affect business continuity. Therefore, disaster recovery environments are usually composed of off-site backup data centers, redundant hardware facilities, real-time or timed data backup mechanisms and automatic switching mechanisms to ensure that core financial services such as trading, payment and clearing can be quickly restored in the event of a main system failure.
[0038] In the prior art, the detection of the disaster recovery environment mainly relies on periodic production drills to verify the reliability of the disaster recovery system by simulating a fault switching scenario. By checking whether the disaster recovery system can be started normally, whether the parameter configuration is accurate, whether the network connection is smooth, and whether the external connection system is available, it is ensured that the disaster recovery system can reliably take over the business process when actually needed.
[0039] However, for a remote disaster recovery environment, since it is not connected to the daily production traffic, and its physical environment and parameter configuration are different from those of the production environment, it is difficult to synchronize and verify its reliability in real time. At the same time, since the production drill is costly, it cannot be performed frequently to adapt to the rapidly changing business requirements and technical changes, which makes it difficult to fully guarantee the real-time availability of the disaster recovery system.
[0040] The disaster recovery environment detection method, device, equipment, storage medium and program product provided by the present application aim to solve the above technical problems of the prior art. Specifically, by constructing a disaster recovery environment detection framework based on cloud dynamic configuration, the change information of the environment variable is taken as the basis for adding a new firewall detection program, and a unique program identifier and its associated environment variable are allocated to each new program. Then, the system dispatches and issues the existing firewall detection program and its corresponding environment variable to the diagnosis nodes in multiple business areas according to the program identifier, drives each node to execute the corresponding detection task according to the local environment, and generates a disaster recovery environment detection report. This method realizes the effective cooperation of centralized control and distributed execution of the disaster recovery detection process through the program identifier management and cross-region distribution mechanism, and improves the real-time availability of the disaster recovery system.
[0041] The technical solutions of the present application and how the technical solutions of the present application solve the above technical problems will be described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of the present application will be described below with reference to the accompanying drawings.
[0042] Figure 1 Flowchart of a disaster recovery environment detection method provided by an embodiment of the present application Figure One The method provided by the present application can be executed by a diagnosis console of a business system, or by a device in communication connection with the diagnosis console of the business system, such as a computer or a server. As shown in Figure 1 The disaster recovery environment detection method provided by the present application includes the following steps:
[0043] S101: Based on the configuration change information of the environment variable sent by the cloud, a firewall detection program is added.
[0044] The configuration change information of the environment variable is key data generated when the environment variable is added, deleted, or value modified, and includes a variable name to specify the changed environment variable, and records the old value and the new value for comparison.
[0045] The firewall detection program is a software tool specially designed for detecting, evaluating, and analyzing the running state and configuration rules of a firewall. It can actively scan the settings of the firewall, check whether the rules are complete, reasonable, and in line with the security policy, and detect network traffic and firewall logs in real time to discover abnormal behavior or potential security vulnerabilities.
[0046] A firewall detection program is built based on a cloud environment variable configuration change notification mechanism. The cloud detects the configuration of the environment variable in real time, and once a configuration change is detected, it sends the change information to the designated system or program. The newly added firewall detection program receives this information and performs targeted detection on the system firewall based on the change content to determine whether the firewall rules have been affected by the environment variable configuration change, whether there are security vulnerabilities or unexpected configuration situations, thereby ensuring the security of the system at the network level.
[0047] Specifically, first, an environment variable configuration detection module is built in the cloud, and the detection tools of the cloud service or custom scripts are used to continuously detect the configurations of the system environment variables. When a configuration change is detected, the change information is accurately sent to the firewall detection program through message queues, API calls, etc. Second, the firewall detection program is developed, which needs to have the ability to analyze the environment variable configuration change information sent by the cloud, and can determine the range of firewall rules to be detected according to the change content.
[0048] S102: Configure the program identifier and associated environment variables for the newly added firewall detection program.
[0049] In a computer system or network environment, when a new program for detecting the state of the firewall is added, a unique identifier needs to be assigned to the program so that the system can accurately identify and distinguish it from other programs. At the same time, environment variables closely related to the program's operation need to be set, which contain various parameters, paths, and other information required for the program's operation.
[0050] In a complex system, there are many programs running, and without a unique configuration program identifier, the system will be difficult to accurately manage, schedule and detect this new firewall detection program. For example, when the program needs to be upgraded, stopped or viewed running status, clear identification can make the operation more accurate. And the associated environment variables are the basis for the normal operation of the program, the firewall detection program may rely on a specific system path to find related configuration files, or need specific parameters to adjust the sensitivity and range of detection. Only by correctly setting these environment variables, the program can get the required resources in the appropriate environment, perform detection tasks as expected, and ensure accurate detection of the firewall state.
[0051] S103: According to the program identifier, the existing firewall detection program and its associated environment variables are distributed to the diagnostic nodes of the business system deployed in multiple business areas, so that the diagnostic nodes execute the acquired firewall detection program to generate a detection report of the deployed business area disaster recovery environment.
[0052] Among them, the diagnostic node is the core equipment for carrying out detection and evaluation work on the business area disaster recovery environment, which can automatically perform detection tasks according to the preset period, can immediately carry out a detection when receiving a specific instruction, and can accurately complete the detection and evaluation operation of the corresponding number of times according to the specific number of times required by the console.
[0053] Specifically, according to the unique program identifier set for the firewall detection program in advance, the firewall detection program that has been developed and associated with specific environment variables is accurately transmitted to the diagnostic nodes of the business system distributed in multiple different business areas. The distribution process ensures that the program and its associated environment variables reach the target node without error, and then the diagnostic node will run the acquired firewall detection program, which will conduct a comprehensive detection of the disaster recovery environment in the business area according to the associated environment variables, and finally generate a detection report reflecting the safety status and configuration compliance of the disaster recovery environment.
[0054] In the case of a business system widely distributed in multiple business areas, each area's disaster recovery environment has its own uniqueness, but it also needs unified firewall security detection standards. By distributing the firewall detection program and its associated environment variables according to the program identifier, it can ensure that each diagnostic node obtains consistent and accurate detection tools and data basis. The program identifier ensures that the diagnostic node receives the correct, specific program for firewall detection, avoiding program confusion and incorrect deployment; the associated environment variables enable the program to detect according to the actual situation of the disaster recovery environment in different business areas and generate a detection report.
[0055] First, existing firewall detection programs need to be organized and packaged, ensuring the integrity of the program files. Simultaneously, associated environment variables should be bound to the program in a suitable format (such as configuration files), and the program identifier should be clearly recorded. Then, based on the network architecture of the business system and the distribution of diagnostic nodes, an appropriate distribution method should be selected, such as through a dedicated software distribution system, using a secure file transfer protocol, or leveraging automated deployment tools. During distribution, the program identifier must be strictly followed to ensure that each diagnostic node receives the correct program and environment variable package. After distribution, the corresponding runtime environment should be configured on the diagnostic nodes to enable the firewall detection program to start and execute normally. Once running, the program will detect the disaster recovery environment of the business area based on the associated environment variables and generate a detection report based on the results.
[0056] The disaster recovery environment detection method provided in this application adds a firewall detection program based on configuration change information of environmental variables sent from the cloud. The new firewall detection program is configured with a program identifier and associated environmental variables. According to the program identifier, the existing firewall detection program and its associated environmental variables are distributed to diagnostic nodes deployed in multiple business areas of the business system. This allows the diagnostic nodes to execute the acquired firewall detection program and generate a detection report of the disaster recovery environment in the deployed business area. This method, through dynamic cloud configuration and program identifier management, enables flexible distribution and execution of firewall detection programs across business areas, thereby efficiently generating detection reports for disaster recovery environments in each area and improving the real-time availability of the disaster recovery system.
[0057] Figure 2 A flowchart illustrating a disaster recovery environment detection method provided in this application embodiment. Figure One The method provided in this application can be executed by diagnostic nodes deployed in the business area of a business system, or by devices such as computers or servers that are communicatively connected to these diagnostic nodes. Figure 2 As shown, the disaster recovery environment detection method provided in this embodiment includes the following steps:
[0058] S201: Retrieves the firewall detection program and its associated environment variables sent by the diagnostic console.
[0059] The system retrieves the firewall detection program sent from the diagnostic console, along with the environment variables closely associated with it. The firewall detection program is a software tool used to detect the status and functionality of firewalls in a disaster recovery environment; the associated environment variables contain various parameters necessary for the firewall detection program to run, such as network address and port number. These variables provide the specific environmental configuration for the program's correct execution.
[0060] This method is of great significance in disaster recovery environments. On the one hand, disaster recovery environments are critical facilities that ensure the quick recovery and continuous operation of business systems in the event of disasters. Firewalls are an important line of defense for network security in disaster recovery environments, and their normal operation is directly related to the security of disaster recovery environments. By obtaining and running the firewall detection program at the diagnostic node, the status of the firewall can be detected in real time and accurately, and potential faults, configuration errors, or security vulnerabilities can be discovered in a timely manner, thereby ensuring the network security protection capability of the disaster recovery environment. On the other hand, obtaining the associated environment variables ensures that the firewall detection program can adapt to the respective operating environment on different diagnostic nodes. Since the business areas of business systems may be widely distributed, the network environment, security policy, and other factors of each diagnostic node differ. The environment variables provide targeted configuration for the program, enabling it to run stably in various complex environments and improving the accuracy and reliability of the detection.
[0061] To implement this method, first, the corresponding configuration and development need to be performed on the diagnostic console side. The diagnostic console should have the function of packaging and sending the firewall detection program and its associated environment variables. A special interface or service can be designed to encapsulate the program and environment variables in a certain format (such as JSON, XML, etc.), and then send the data to each diagnostic node in the business area through a network transmission protocol (such as HTTP, TCP, etc.). On the diagnostic node side, a corresponding receiving program needs to be developed to receive the data packet sent by the diagnostic console and perform unpacking operations to extract the firewall detection program and environment variables. At the same time, the diagnostic node should provide a suitable operating environment to ensure that the firewall detection program can be correctly configured and initialized based on the obtained environment variables, and then start the program to begin detecting the firewall. In addition, a complete log recording and error handling mechanism needs to be established to record detailed log information during the processes of receiving data, unpacking, running programs, etc., so that problems can be quickly located and troubleshooting when problems occur.
[0062] S202: Based on the associated environment variables, execute the firewall detection program to generate a detection report for the deployed business area disaster recovery environment.
[0063] This description refers to the basis of obtaining environment variables associated with the firewall detection program, using these environment variables as the configuration basis for program running, starting and running the firewall detection program. The firewall detection program will detect the firewall in the disaster recovery environment of the deployed business area according to the parameters set in the environment variables, such as network address, port information, authentication method, etc., including the connectivity of the firewall, the correctness of the rule configuration, the effectiveness of the security policy, etc. After the detection is completed, the program will collect and organize various data and results in the detection process, and then generate a detailed and comprehensive detection report, which can intuitively present the actual running status of the firewall in the disaster recovery environment of the business area.
[0064] This has important significance in many aspects. From the perspective of the security of the disaster recovery environment, the firewall is the key line of defense to protect the network security of the disaster recovery environment. By executing the firewall detection program based on the associated environment variables and generating a detection report, potential problems with the firewall, such as rule vulnerabilities and configuration errors, can be detected in a timely manner, so that measures can be taken in advance to repair and optimize them, prevent security threats from invading the disaster recovery environment, and ensure that business data and systems can be effectively protected in the event of a disaster. From the perspective of business continuity, accurate detection reports can help operations personnel understand the handling of business traffic by the firewall, ensuring that the firewall does not become a bottleneck for business recovery during disaster switching, and ensuring that the business can quickly and stably resume operation. In addition, the detection report can also provide strong data support for subsequent disaster recovery environment planning, optimization and upgrading, helping enterprises continuously improve the reliability and performance of the disaster recovery environment.
[0065] First, ensure that the associated environment variables are accurate and complete. Before executing the firewall detection program, carefully check and audit the environment variables to ensure that the parameters meet the actual needs of the disaster recovery environment of the business area, such as whether the network address is correct, whether the port is open, whether the authentication information is valid, etc. Special scripts or tools can be used to pre-check the environment variables to ensure that the program can run based on the correct configuration. Second, start the firewall detection program according to the predetermined process. According to the running requirements of the program, execute the program in a suitable system environment and ensure that the program can normally read and use the associated environment variables. During the program running process, real-time detection of its running state is recorded in the running log, so that in case of problems, the fault can be quickly located and debugged. Finally, after the firewall detection program completes the detection, the generated detection report is sorted and analyzed. Check whether the data and results in the report are accurate and complete, classify and prioritize the problems in the report, and timely feedback the report to the relevant operations personnel and management personnel. At the same time, the detection report is archived for subsequent query and comparative analysis, providing a reference basis for the continuous optimization of the disaster recovery environment.
[0066] Figure 3An interaction diagram of a disaster recovery environment detection method provided by an embodiment of the present application is shown in FIG. 1. As shown in FIG. 1, a disaster recovery environment detection method provided by an embodiment of the present application includes the following steps: Figure 3 Figure 2 Figure 1
[0067] S301: The diagnosis console of the business system acquires the configuration change information of the environment variables sent by the cloud.
[0068] S302: The diagnosis console of the business system generates a firewall detection strategy according to the configuration change information.
[0069] The firewall detection strategy is a comprehensive and systematic detection plan and criterion formulated for the firewall (firewall), which clearly specifies the detection target, such as verifying whether the firewall rules are accurate and effective, checking whether the security policy can resist potential threats, and evaluating whether the firewall performance meets the business requirements; determines the detection range, covering various functional modules of the firewall, protection settings of different network areas, etc.
[0070] The firewall detection strategy contains specific detection methods, such as simulation attack testing, rule compliance checking, and traffic analysis; it also sets the detection frequency, whether it is regular detection (such as daily or weekly) or triggered detection according to specific events; at the same time, it specifies the processing method of the detection result, including the classification and grading of the discovered problems, the process of notifying relevant personnel, etc., aiming to ensure that the firewall is always in good running state and effectively protect the security of the network system.
[0071] Specifically, after acquiring the configuration change information, a comprehensive and detailed analysis is performed on these information. The configuration change may involve the addition, deletion, or modification of firewall rules, such as adding access restriction rules for specific IP addresses or modifying the port range of the original rules; it may also be the adjustment of security policy, such as changing the access permission settings for some application programs. Through the analysis of the change information, the specific part of the firewall configuration that has changed can be accurately located, and then the key direction of detection can be determined. For example, if the change information shows that multiple network access control rules have been added, then the detection strategy needs to focus on whether these new rules can effectively block illegal access while ensuring that legitimate access is not affected, and avoid network interruption or security vulnerabilities caused by incorrect rule configuration.
[0072] After determining the detection direction, the specific detection content is determined in combination with the actual needs of the business system. Different business systems have different requirements for the functions of the firewall. For example, the business system of the financial industry has very high requirements for data security and transaction process confidentiality, so the firewall detection strategy needs to focus on whether the rules and strategies related to data transmission encryption and transaction authentication are running normally; while the e-commerce business system focuses on user experience and business continuity, and the detection content should focus on whether the firewall will cause users to be unable to normally access the website, place orders, etc. due to excessive interception.
[0073] S303: The diagnosis console of the business system generates a corresponding firewall detection program based on the firewall detection strategy and stores it by calling a preset program generation template.
[0074] The program generation template is a pre-designed framework file or code set with fixed structure and standardized format, which provides a standardized mode for program generation. The program generation template includes various general elements required for program execution, such as variable definition, function interface, flow control structure, etc.
[0075] The pre-prepared firewall detection strategy is used as the core guide, which clearly defines the key elements of firewall detection, such as target, scope, rules, and detection methods. Then select the appropriate template from the system preset program generation template library, which has the basic framework and general logic for generating specific function firewall detection programs. By fusing and customizing the specific requirements in the firewall detection strategy with the template, a special program that can accurately perform firewall detection tasks is finally generated and properly stored in the designated storage location.
[0076] On the one hand, different business scenarios and system environments have diverse needs for firewall detection. Firewall detection strategies can be precisely customized according to these specific needs to ensure the relevance and effectiveness of the detection. The preset program generation template provides a standardized development framework, avoiding the complex process of starting from scratch, greatly improving development efficiency. On the other hand, generating a special firewall detection program and storing it can provide stable support for subsequent firewall detection work. When firewall detection is needed, the stored program can be directly called to quickly carry out detection work, reducing the time cost of repeated development and configuration, and also ensuring the consistency and reliability of the detection program, which is conducive to maintaining the security and stability of the system.
[0077] Specifically, first, the firewall detection strategy is analyzed and interpreted in detail to determine the various detection requirements contained therein, such as the type of firewall rules to be detected, the frequency of detection, the source of the data for detection, and the like. Then, in the pre-set program generation template library, the most suitable template is selected according to the characteristics and needs of the firewall detection strategy. This template should have basic functions and structures that match the detection strategy, such as support for specific types of firewall rule analysis and detection logic. Next, using specialized program generation tools or development environments, the specific parameters and requirements in the firewall detection strategy are embedded into the selected template, which is customized, modified, and improved to generate a firewall detection program that meets the requirements. Finally, the generated firewall detection program is comprehensively tested and verified to ensure that it can correctly perform the detection task and output accurate results. After passing the test, the program is stored in the specified storage system according to the specified storage format and path.
[0078] S304: The diagnostic console of the business system configures a program identifier and associated environment variables for the newly added firewall detection program.
[0079] S305: The diagnostic node deployed in the business area of the business system obtains the firewall detection program and its associated environment variables sent by the diagnostic console.
[0080] The firewall detection program sent by the diagnostic console is obtained, and the environment variables closely associated with the firewall detection program are also obtained. The firewall detection program is a tool software used to detect the status and function of the firewall in the disaster recovery environment, and the associated environment variables contain various parameter information necessary for the firewall detection program to run, such as network addresses and port numbers. These variables provide specific environmental configurations for the correct execution of the program.
[0081] On the one hand, the disaster recovery environment is a key facility to ensure that the business system can quickly recover and continuously operate in the event of a disaster, and the firewall is an important line of defense for the network security of the disaster recovery environment. Its normal operation is directly related to the security of the disaster recovery environment. By obtaining and running the firewall detection program on the diagnostic node, the status of the firewall can be detected in real time and accurately, and possible faults, configuration errors, or security vulnerabilities in the firewall can be discovered in a timely manner, thereby ensuring the network security protection capability of the disaster recovery environment. On the other hand, obtaining the associated environment variables ensures that the firewall detection program can adapt to the respective operating environments on different diagnostic nodes. Since the business areas of the business system may be widely distributed, the network environments and security policies of the diagnostic nodes differ, and the environment variables provide targeted configurations for the program, enabling the program to run stably in various complex environments and improving the accuracy and reliability of the detection.
[0082] Specifically, the first step is to configure and develop the corresponding system on the diagnostic console. The diagnostic console should have the capability to package and send the firewall detection program and its associated environment variables. This can be achieved by designing a dedicated interface or service to encapsulate the program and environment variables in a specific format (such as JSON or XML), and then sending the data to the diagnostic nodes in various business areas via network transmission protocols (such as HTTP or TCP). On the diagnostic node side, a corresponding receiving program needs to be developed to receive the data packets sent from the diagnostic console, unpack the packets, and extract the firewall detection program and environment variables. Simultaneously, the diagnostic node must provide a suitable runtime environment to ensure that the firewall detection program can correctly configure and initialize based on the obtained environment variables, and then start the program to begin firewall detection.
[0083] S501: The diagnostic nodes deployed in the business area of the business system execute the obtained firewall detection program and generate a detection report of the disaster recovery environment of the deployed business area.
[0084] The firewall detection program performs a comprehensive test on the firewall in the disaster recovery environment of the deployed business area based on parameters set in the environment variables, such as network address, port information, and authentication method. This includes aspects such as firewall connectivity, the correctness of rule configuration, and the effectiveness of security policies. After the test is completed, the program collects and organizes all data and results from the test process, generating a detailed and comprehensive test report.
[0085] Firewalls are a critical line of defense for ensuring network security in disaster recovery environments. By executing firewall detection programs based on associated environment variables and generating detection reports, potential problems with the firewall can be identified in a timely manner, such as rule vulnerabilities and configuration errors. This allows for proactive measures to be taken for remediation and optimization, preventing security threats from intruding into the disaster recovery environment and ensuring that business data and systems are effectively protected in the event of a disaster. Accurate detection reports help operations personnel understand how the firewall handles business traffic, ensuring that the firewall does not become a bottleneck for business recovery during disaster recovery switchover, and guaranteeing that services can be restored quickly and stably.
[0086] S401: The diagnostic console of the business system retrieves new availability check policies for the external environment.
[0087] A set of newly formulated rules and methods for evaluating whether these external environments are available, can normally provide services or meet business needs are collected and integrated. These strategies may cover multiple aspects, such as checking the stability of external network connection, judging by continuously detecting network delay, packet loss rate and other indicators; test the response ability of external service, for example, send a specific request and observe the return result and response time; evaluate the availability of external resources (such as storage space, computing power, etc.), confirm whether it meets the threshold required for system operation, etc.
[0088] In today's digital business environment, systems often rely heavily on external environments to carry out work. The availability of external environment directly affects the overall performance of the system and the continuity of business. If the external environment fails or is unavailable, it may cause the system to be unable to obtain necessary data, unable to call key services, and thus cause business interruption, data loss and other problems. By obtaining new availability check strategies, the external environment can be more comprehensive and accurate.
[0089] S402: The diagnostic console of the business system generates a new external availability check program based on the newly added availability check strategy and stores it.
[0090] According to the new strategy rules specially formulated for the availability evaluation of external connection environment (such as external server, network service, third-party interface, etc.), programming techniques and development tools are used to write computer programs with automatic check function. The program can detect the external environment according to the indicators (such as response time, connection success rate, data accuracy, etc.) and processes set by the strategy, judge whether it is available, and save the written program in the form of file to the designated storage medium (such as local hard disk, network storage device, code version library, etc.).
[0091] The availability of external environment directly affects the normal operation of business. The newly added availability check strategy is often formulated for the new changes, new needs and potential risks of the current external environment, which is more in line with the actual situation and can more accurately find the problems in the external environment. Based on these strategies, new check programs are generated, which can realize automatic and efficient check process. Compared with manual inspection, it not only greatly saves time and labor cost, but also avoids the problems of missed inspection and false inspection caused by human negligence.
[0092] S403: The diagnostic console of the business system configures the program identifier and associated environment variables for the new external availability check program.
[0093] The program identifier of the new external connectivity availability check program can be accurately found and operated. For example, when the program needs to be upgraded, stopped, or the running status is checked, the explicit identifier can ensure accurate operation. The associated environment variables are the basis for the normal operation of the program. The external connectivity availability check program may rely on specific system paths to find configuration files or require specific parameters to adjust the frequency, range, and other aspects of the check. Correctly setting the environment variables can provide the program with the required resource access permissions and operating conditions, avoiding program running errors or problems with detecting the availability of the external connectivity environment due to environment mismatches.
[0094] Optionally, the environment variables associated with the new external connectivity availability check program are implemented by the following method, comprising:
[0095] In response to an environment variable configuration request sent by the application server, an environment variable configuration template is returned to the application server; the application server is the server where the application calling the new external connectivity availability check program is located.
[0096] Specifically, when the application server (i.e., the server where the application calling the new external connectivity availability check program is located) sends an environment variable configuration request, the system will respond by returning a pre-set environment variable configuration template to the application server. This environment variable configuration template contains various environment variable-related information required for the normal operation of the new external connectivity availability check program, providing a basis for the subsequent accurate configuration of the application server.
[0097] On the one hand, the new external connectivity availability check program highly depends on specific environment variables when running, which determine how the program interacts with the external connectivity environment, where it obtains configuration information, and how it processes data and other key operations. By returning the environment variable configuration template, the application server can obtain the correct and complete environment variable configuration requirements, avoiding program malfunctions due to incorrect or incomplete environment variable settings, and ensuring the stability and accuracy of the external connectivity availability check function. On the other hand, this response-request-return-template approach realizes standardized and standardized management of environment variable configuration. Regardless of who maintains the application server or where it is located, environment variable configuration can be performed according to uniform standards, improving the maintainability and scalability of the entire system and reducing potential risks caused by environment variable configuration differences.
[0098] Obtain new environment variables configured by the application server through the environment variable configuration template;
[0099] The new environment variable is generated by the application server combining the actual running environment and the requirement of the new external availability check program, and is generated by assigning specific values to each parameter in the template, containing various key information required for program running, such as connection address, port number, authentication credentials, etc.
[0100] On the basis of returning the environment variable configuration template to the application server, the system collects and receives the new environment variable set by the application server according to the template and submitted. On the one hand, the network environment, business scenario and security policy of different application servers are different, and the unified environment variable configuration template cannot completely adapt to all situations. The new environment variable configured by the application server can ensure the accurate running of the program in a specific environment, accurately interact with the external environment, and complete the availability check task. On the other hand, obtaining the new environment variable helps to realize the centralized detection and management of the program running environment.
[0101] The new environment configuration variable is associated with the new external availability check program.
[0102] Among them, the close connection between the newly obtained environment configuration variable set by the application server according to the environment variable configuration template and the new program specially used to detect the availability of external connection environment is established. This association enables the program to automatically read and use the parameter values in these new environment configuration variables when running, so as to accurately interact with the target external environment according to the specific network address, port, authentication information, etc., and complete the availability check task.
[0103] On the one hand, the new external availability check program itself does not have the self-adaptation ability to different application server environments. The network architecture, security policy and connection method with external environment of each application server are different, and the specific environment details stored in the new environment configuration variable are just these. Only by associating them can the program be correctly configured and run according to the actual environment, avoiding the failure or error result caused by environment mismatch. On the other hand, the association operation realizes the centralized management and unified scheduling of environment variables and programs. The operation and maintenance personnel can conveniently check and modify the environment variables related to the program, quickly adjust the running parameters of the program to adapt to the changes of the external environment, improve the flexibility and maintainability of the system, and reduce the operation and maintenance cost.
[0104] S404: The diagnostic console of the business system delivers the existing firewall detection program and external availability check program, and the environment variables associated with each program to the diagnostic nodes of the business system deployed in multiple business areas according to the program identifier.
[0105] The diagnostic console transmits the program for checking whether an external connection (external connection) is available and various environment parameter variables closely related to the normal operation of the program to a target receiving end (which can be a certain service node, server or specific processing module, etc.). The external connection availability checking program is a set of software codes with the function of detecting the connection state of an external network, service or system; and the associated environment variables cover parameters such as network address, port number, authentication information, timeout setting required for program operation, which together determine whether the program can accurately and effectively perform the external connection checking task.
[0106] The diagnostic console transmits the program for checking whether an external connection (external connection) is available and various environment parameter variables closely related to the normal operation of the program to a target receiving end (which can be a certain service node, server or specific processing module, etc.). The external connection availability checking program is a set of software codes with the function of detecting the connection state of an external network, service or system; and the associated environment variables cover parameters such as network address, port number, authentication information, timeout setting required for program operation, which together determine whether the program can accurately and effectively perform the external connection checking task.
[0107] Specifically, according to the unique program identifier previously set for the firewall detection program and the external connection availability checking program, the existing firewall detection program, external connection availability checking program and environment variables closely related to the two programs and providing necessary parameters and conditions for program operation are accurately distributed to the diagnostic nodes of multiple different business areas deployed by the business system. These diagnostic nodes are key positions in the business system for detecting and diagnosing network and program running state, etc., and through the issuing operation, the related programs can play a role in each business area.
[0108] On the one hand, different business areas may face different network environments and security threats, and distributing the firewall detection program to each diagnostic node can detect the state of the firewall in each area in real time, discover firewall faults or abnormal configurations in time, prevent external illegal access and protect the network security of the business system. The external connection availability checking program can detect whether the connection between the business system and external services and resources is smooth, ensure that the business system can normally obtain external data and call external services, and maintain the continuity of the business. On the other hand, the programs and environment variables are uniformly distributed according to the program identifier, which facilitates centralized management and maintenance of the programs and environment variables. When the program needs to be updated or the environment variable needs to be adjusted, the operation can be quickly and accurately performed on each diagnostic node, improving the operation and maintenance efficiency and reducing the management cost.
[0109] S501: The diagnostic node deployed by the business area of the business system executes the acquired firewall detection program to generate a detection report of the disaster recovery environment of the deployed business area.
[0110] According to the deployment strategy of the business system, the business system is first divided into different resource domains according to the business coupling, thereby forming a plurality of business areas. In each business area, a standardized deployment is implemented by the related technical platform, and the areas are isolated from each other, thereby ensuring the independence and security of the business of each area. Meanwhile, the firewall in each area is completely opened, thereby ensuring smooth communication in the area, and an independent diagnosis node is deployed in each business area.
[0111] Specifically, according to the associated environment variables, a firewall detection program and an external availability checking program are executed to generate a detection report of the deployed business area disaster recovery environment.
[0112] According to the environment variables, the firewall detection program and the external availability checking program are simultaneously started and run. The firewall detection program is responsible for comprehensively detecting the firewall in the business area disaster recovery environment, checking whether the rule configuration, security policy and the like are normal; the external availability checking program detects whether the connection between the disaster recovery environment and the external network and service is smooth and available. Finally, the detection results of the two programs are integrated to generate a detection report that comprehensively reflects the actual status of the deployed business area disaster recovery environment.
[0113] Optionally, the diagnosis node locally stores a connectivity test program for detecting environment variables; according to the associated environment variables, a firewall detection program and an external availability checking program are executed to generate a detection report of the deployed business area disaster recovery environment, and the specific implementation manner comprises:
[0114] According to the associated environment variables, a connectivity test program, a firewall detection program and an external availability checking program are executed to generate a detection report of the deployed business area disaster recovery environment.
[0115] The connectivity test program mainly checks whether the network path and equipment involved in the environment variables can normally communicate.
[0116] The diagnosis node is a key detection unit in the business area disaster recovery environment, and the diagnosis node locally pre-stores a test program for detecting the connectivity of the environment variables. When performing a detection task, the connectivity test program, the firewall detection program and the external availability checking program are simultaneously started according to the associated environment variables. The firewall detection program checks whether the rule configuration, security policy and the like of the firewall in the disaster recovery environment are effective; the external availability checking program checks whether the connection between the disaster recovery environment and the external network and service is smooth. Finally, the detection results of the connectivity test program, the firewall detection program and the external availability checking program are integrated to generate a detection report that comprehensively reflects the status of the business area disaster recovery environment.
[0117] The connectivity test procedure can verify the validity of the environment variables in advance, ensuring that the subsequent firewall detection procedure and external connection availability check procedure are based on correct network configurations, avoiding distorted detection results caused by environment variable errors. The firewall is the core defense line of network security in the disaster recovery environment. Through the firewall detection procedure, vulnerabilities and improper configurations of the firewall can be discovered in a timely manner, preventing external attacks on the disaster recovery environment and ensuring the security of business data. The external connection availability check procedure ensures that the disaster recovery environment can connect normally when it needs to interact with the outside (such as data synchronization, remote access, etc.), avoiding the impact of external connection failures on business continuity. Integrating the detection results of the three procedures into a report can provide comprehensive and systematic disaster recovery environment evaluation for operation and maintenance personnel.
[0118] S601: The diagnostic console of the business system obtains a detection report.
[0119] S602: The diagnostic console of the business system generates alarm information based on the failed procedures in the detection report.
[0120] The detection report records the results of the detection on specific objects (such as programs, systems, networks, etc.), which may include the time of detection, the items of detection, the numerical values of the indicators, and the final state of detection (success or failure), etc.
[0121] After obtaining the detection report, the report content is analyzed and screened to obtain the information related to the failed procedures, and then alarm notifications are created and sent based on this information to remind relevant personnel to pay attention to and handle the problem.
[0122] On the one hand, the detection report can quickly feedback the abnormal conditions in the program execution process, and the generated alarm information can ensure that relevant personnel are informed of the problem in the first time, avoiding the problem from further deteriorating and reducing the possible losses. On the other hand, the alarm information can clearly indicate the failed procedures, providing precise positioning for operation and maintenance personnel or developers, so that they can quickly focus on the problem and carry out troubleshooting and repair work, improving the efficiency of problem solving. From the perspective of system stability and reliability, timely handling of failed procedures helps to maintain the normal operation of the entire system or business, ensuring the stability and reliability of the system, and improving user experience and business continuity.
[0123] In some embodiments, the environment variables include configurations of at least one of a logical address, a domain name, and a port.
[0124] The logical address is usually an address used to identify devices or services within a specific network architecture or system, which is different from the physical address and focuses more on logical positioning.
[0125] Domain name is a readable name used to identify servers or websites on the Internet, which is resolved to the corresponding IP address through the domain name system.
[0126] Port is a numerical identifier on a computer used to distinguish different network services, different services usually run on different ports.
[0127] Logical address allows programs to accurately locate the logical location of target devices or services, ensuring accurate data transmission and reception in complex network topologies. For example, in a large enterprise's internal network, there may be multiple subnets and servers, and through logical addresses, it can be specified which server in which subnet to communicate with.
[0128] Domain name is easier for users and programs to identify and record than directly using IP addresses that are difficult to remember. Moreover, when the IP address of a server changes, only the resolution record of the domain name needs to be updated, and the program can continue to access normally without modifying the code.
[0129] Port determines the specific channel for program to establish a connection with the target service. Different network services (such as HTTP (HyperText Transfer Protocol), FTP (File Transfer Protocol), SSH (Secure Shell) protocol, etc.) use different ports, and clear port configuration can avoid connecting to the wrong service and ensure the accuracy and security of communication.
[0130] In the configuration management of business systems, environment variables include at least one of logical addresses (such as IP addresses), domain names, and port configurations. These environment parameters are sunk to the infrastructure level and set for specific deployment areas (such as independent resource domains divided according to business fields or business system coupling). Different areas can also be reused through parameter hierarchical management, and then automatically injected into containers through the cloud. In each area, the application nodes supported by the uniform standard deployment obtain relevant parameters according to the uniform environment variables. This makes the relevant application version no longer need to define and configure these environment parameters separately, saving the maintenance work of the operation and maintenance personnel, and the environment variable name is uniformly managed with the environment, achieving the independence of version and environment.
[0131] Figure 4 The flowchart of a disaster recovery environment detection method provided by an embodiment of the present application Figure Three As shown in Figure 4 , the disaster recovery environment detection method provided by the embodiment includes the following steps:
[0132] The cloud configures environment variables, which include logical addresses (IP), domain names, and port (port number) information. The cloud platform monitors changes in environment variables in real time and sends these changes to the diagnostic console. This ensures that the diagnostic console can be adjusted in a timely manner according to the latest configuration.
[0133] The diagnostic console of the business system configures changes in environment variables based on the environment variable configuration change information sent by the cloud platform. The diagnostic console automatically generates a new firewall detection program (firewall detection ID). A unique program identifier (diagnostic program ID) is configured for the new firewall detection program and is associated with related environment variables. According to the program identifier, the existing firewall detection program and its associated environment variables are distributed to the diagnostic nodes of the business system deployed in multiple business regions (region ID). The newly added availability check strategy of the external connection environment is obtained. Based on the new strategy, a new external connection availability check program is generated and stored. The program identifier and associated environment variables are configured for the new external connection availability check program. According to the program identifier, the existing firewall detection program and external connection availability check program, and the environment variables associated with each program are distributed to the diagnostic nodes. The detection report generated by the diagnostic nodes is obtained, and alarm information is generated based on the programs that fail to execute in the report.
[0134] The diagnostic nodes deployed in the business regions of the business system are deployed in multiple business regions. The diagnostic nodes obtain the firewall detection program and its associated environment variables sent by the diagnostic console, execute the program based on these environment variables, and generate a detection report for the disaster recovery environment of the deployed business region. The diagnostic nodes obtain the external connection availability check program and its associated environment variables sent by the diagnostic console, execute the firewall detection program and the external connection availability check program, and generate a detection report. The detection report generated by the diagnostic nodes is sent to the related system to generate a final report. If an exception occurs during the detection process, the system generates an alarm message and sends it to the relevant personnel through the mail system. At the same time, the alarm message is also sent to the monitoring center so that the monitoring personnel can handle it in a timely manner.
[0135] Figure 5 The structure of a disaster recovery environment detection device provided in an embodiment of the present application Figure One As shown in Figure 5 , the disaster recovery environment detection device provided in the embodiment is applied to a diagnostic console of a business system and includes a firewall program adding module 701, a variable association module 702, and a program distribution module 703.
[0136] The firewall program adding module 701 is configured to add a firewall detection program based on the configuration change information of the environment variables sent by the cloud.
[0137] The variable association module 702 is configured to configure a program identifier and associated environment variables for the added firewall detection program.
[0138] The program issuing module 703 is configured to issue the existing firewall detection program and the associated environment variables to the diagnostic nodes of the business system deployed in the plurality of business regions according to the program identifier, so that the diagnostic nodes execute the acquired firewall detection program to generate a detection report of the deployed disaster recovery environment of the business region.
[0139] Optionally, the firewall program adding module 701 is specifically configured to:
[0140] generate a firewall detection strategy according to the configuration change information;
[0141] based on the firewall detection strategy, call a preset program generation template to generate a corresponding firewall detection program and store the firewall detection program.
[0142] Optionally, the program issuing module 703 is further configured to:
[0143] acquire a new availability check strategy of the externally connected environment; based on the new availability check strategy, generate a new externally connected availability check program and store the new externally connected availability check program;
[0144] configure a program identifier and an associated environment variable for the new externally connected availability check program;
[0145] issue the existing firewall detection program and the associated environment variables to the diagnostic nodes of the business system deployed in the plurality of business regions according to the program identifier, including:
[0146] issue the existing firewall detection program and the externally connected availability check program and the environment variables associated with the programs to the diagnostic nodes of the business system deployed in the plurality of business regions according to the program identifier.
[0147] Optionally, the variable association module 702 is further configured to:
[0148] in response to an environment variable configuration request sent by the application server, return an environment variable configuration template to the application server;
[0149] the application server is a server where an application for calling the new externally connected availability check program is located;
[0150] acquire a new environment variable configured by the application server through the environment variable configuration template;
[0151] associate the new environment configuration variable with the new externally connected availability check program.
[0152] Optionally, the disaster recovery environment detection apparatus further includes an environment variable determination module 704.
[0153] The environment variable determination module 704 is configured to determine that the environment variable includes at least one of a logical address, a domain name, and a port.
[0154] Optionally, the disaster recovery environment monitoring device also includes: an alarm information generation module 705;
[0155] Alarm information generation module 705 is used to obtain detection reports;
[0156] An alarm message is generated based on the program that failed to execute in the test report.
[0157] Figure 6 A schematic diagram of the structure of a disaster recovery environment monitoring device provided in this application embodiment. Figure Two .like Figure 6 As shown, the disaster recovery environment detection device provided in this embodiment is applied to the diagnostic node deployed in the business area of the business system, and includes: a program acquisition module 801 and an environment detection module 802.
[0158] The program acquisition module 801 is used to acquire the firewall detection program and its associated environment variables sent by the diagnostic console;
[0159] The environment detection module 802 is used to execute the firewall detection program based on the associated environment variables and generate a detection report of the disaster recovery environment of the deployed business area.
[0160] Optional, the environmental monitoring module 802 is specifically used for:
[0161] Retrieve the external availability checker sent by the diagnostic console and its associated environment variables;
[0162] Based on the associated environmental variables, the firewall detection program is executed to generate a detection report of the deployed business area disaster recovery environment, including:
[0163] Based on the associated environment variables, the firewall detection program and external connectivity availability check program are executed to generate a detection report of the disaster recovery environment deployed in the business area.
[0164] Optional, the environmental monitoring module 802 is specifically used for:
[0165] Based on the associated environment variables, the system executes connectivity testing, firewall testing, and external availability checks to generate a test report for the deployed business area disaster recovery environment.
[0166] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 7 As shown, the electronic device of this embodiment may include: at least one processor 901; and a memory 902 communicatively connected to at least one processor; wherein the memory 902 stores instructions that can be executed by at least one processor 901, and the instructions are executed by at least one processor 901 to cause the electronic device to perform the method as described in any of the above embodiments.
[0167] Optionally, the memory 902 can be independent or integrated with the processor 901. When the memory 902 is independent, the device further includes a bus for connecting the memory 902 and the processor 901.
[0168] The implementation principle and technical effects of the electronic device provided in the embodiment can be referred to the foregoing embodiments, which will not be described here.
[0169] The embodiment of the present application further provides a computer readable storage medium, and the computer readable storage medium stores computer execution instructions. When the computer execution instructions are executed by a processor, the method provided in any of the foregoing embodiments can be implemented.
[0170] The embodiment of the present application further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the method provided in any of the foregoing embodiments can be implemented.
[0171] It should be noted that, for the foregoing method embodiments, in order to simply describe, each is described as a combination of a series of actions, but those skilled in the art should know that the present application is not limited to the order of the actions described, because according to the present application, certain steps can be performed in other order or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily required by the present application.
[0172] It should be further noted that, although each step in the flowchart is displayed in sequence according to the arrow, these steps are not necessarily executed in sequence according to the arrow. Unless otherwise stated in this document, the execution of these steps has no strict order limitation, and these steps can be executed in other order. Moreover, at least part of the steps in the flowchart can include multiple sub-steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution order of these sub-steps or stages is not necessarily sequential, but can be executed in rotation or alternation with other steps or sub-steps or stages of other steps.
[0173] It should be understood that the above-mentioned device embodiments are only schematic, and the device of the present application can also be implemented in other ways. For example, the division of units / modules in the above-mentioned embodiments is only a logical function division, and actual implementation can have another division way. For example, multiple units, modules or components can be combined, or can be integrated into another system, or some features can be ignored or not executed.
[0174] In addition, each functional unit / module in each of the embodiments of the present application can be integrated in one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated unit / module can be realized in the form of hardware or in the form of a software program module.
[0175] Unless otherwise specified, the processor can be any appropriate hardware processor, such as a CPU, a GPU, an FPGA, a DSP, an ASIC, and the like. Unless otherwise specified, the storage unit can be any appropriate magnetic storage medium or magneto-optical storage medium, such as a resistive random access memory (RRAM), a dynamic random access memory (DRAM), a static random access memory (SRAM), an enhanced dynamic random access memory (EDRAM), a high-bandwidth memory (HBM), a hybrid memory cube (HMC), and the like.
[0176] If the integrated unit / module is realized in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the present application, essentially or the part that makes a contribution to the prior art, or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods in each embodiment of the present application. The aforementioned storage medium includes: a U disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.
[0177] In the above embodiments, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments. Each technical feature of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described, however, as long as the combination of the technical features does not exist contradictory, it should be considered as the scope of the present application.
[0178] Other embodiments of the application will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. It is intended that the specification and examples be considered as exemplary only, with the true scope and spirit of the application being indicated by the following claims.
[0179] It is to be understood that the application is not limited to the precise construction herein disclosed and shown in the drawings, and that various modifications and changes can be made by those skilled in the art without departing from the scope of the application. The scope of the application is limited only by the claims that follow.
Claims
1. A disaster recovery environment detection method, characterized in that, The method, applied to the diagnostic console of a business system, includes: A new firewall detection program has been added based on configuration change information of environment variables sent from the cloud. Configure the program identifier and associated environment variables for the newly added firewall detection program; According to the program identifier, the existing firewall detection program and its associated environment variables are distributed to the diagnostic nodes of the business system deployed in multiple business areas, so that the diagnostic nodes can execute the acquired firewall detection program and generate a detection report of the disaster recovery environment of the deployed business area.
2. The method according to claim 1, characterized in that, The configuration change information of the environment variables sent from the cloud, and the newly added firewall detection program, include: Based on the configuration change information, a firewall detection strategy is generated; Based on the firewall detection strategy, a preset program generation template is invoked to generate the corresponding firewall detection program and store it.
3. The method according to claim 1, characterized in that, The method further includes: Obtain new availability check policies for external environments; Based on the newly added availability check strategy, a new external connection availability check program is generated and stored; Configure the program identifier and associated environment variables for the new external connection availability checker; The step of distributing existing firewall detection programs and their associated environment variables to diagnostic nodes deployed across multiple business regions of the business system, according to program identifiers, includes: According to the program identifier, the existing firewall detection program and external connection availability check program, as well as the environment variables associated with each program, are distributed to the diagnostic nodes of the business system deployed in multiple business areas.
4. The method according to claim 3, characterized in that, The environment variables associated with the new external availability checker include: In response to the environment variable configuration request sent by the application server, the environment variable configuration template is returned to the application server; the application server is the server where the application that calls the new external connection availability check program resides. Obtain the new environment variables configured by the application server through the environment variable configuration template; Associate the new environment configuration variable with the new external availability checker.
5. The method according to any one of claims 1-4, characterized in that, The environment variables include the configuration of at least one of logical address, domain name, and port.
6. The method according to any one of claims 1-4, characterized in that, The method further includes: Obtain the test report; An alarm message is generated based on the program that failed to execute in the aforementioned test report.
7. A disaster recovery environment detection method, characterized in that, The method includes: A diagnostic node deployed in a business area of a business system. Retrieve the firewall detection program and its associated environment variables sent by the diagnostic console; Based on the associated environmental variables, the firewall detection program is executed to generate a detection report of the disaster recovery environment of the deployed business area.
8. The method according to claim 7, characterized in that, The method further includes: Retrieve the external availability checker sent by the diagnostic console and its associated environment variables; Based on the associated environmental variables, the firewall detection program is executed to generate a detection report of the deployed business area disaster recovery environment, including: Based on the associated environmental variables, the firewall detection program and the external connectivity availability check program are executed to generate a detection report of the deployed business area disaster recovery environment.
9. The method according to claim 8, characterized in that, The diagnostic node locally stores a connectivity test program for detecting the environment variables; based on the associated environment variables, it executes the firewall detection program and the external connectivity availability check program to generate a detection report for the deployed business area disaster recovery environment, including: Based on the associated environment variables, the connectivity test program, the firewall detection program, and the external connectivity availability check program are executed to generate a detection report of the deployed business area disaster recovery environment.
10. A disaster recovery environment monitoring device, characterized in that, A diagnostic console for use in business systems, the device comprising: A new module has been added to the firewall program to handle configuration changes to environment variables sent from the cloud; a new firewall detection program has also been added. The variable association module is used to configure the program identifier and associated environment variables for newly added firewall detection programs; The program distribution module is used to distribute existing firewall detection programs and their associated environment variables to diagnostic nodes of the business system deployed in multiple business areas according to the program identifier, so that the diagnostic nodes can execute the acquired firewall detection programs and generate detection reports of the disaster recovery environment of the deployed business areas.
11. A disaster recovery environment monitoring device, characterized in that, A diagnostic node deployed in a business area of a business system, the device comprising: The program acquisition module is used to acquire the firewall detection program sent by the diagnostic console and its associated environment variables; The environment detection module is used to execute the firewall detection program based on associated environmental variables and generate a detection report of the disaster recovery environment of the deployed business area.
12. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1-9.
13. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-9.
14. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1-9.